PQC Readiness
Post-Quantum Cryptography migration readiness and CNSA 2.0 compliance
Readiness Tier
Migration underway but incomplete. Continue replacing vulnerable algorithms.
PQC Readiness Score
72/100
Based on 3 assessments (2 completed)
Cryptographic Inventory
15 algorithms
Vulnerable (8)
Transitioning (3)
Safe (4)
Migration Progress
Track your PQC migration across the five key phases
CNSA 2.0 Alignment
NSA Commercial National Security Algorithm Suite 2.0 requirement checklist
ML-KEM (FIPS 203) for key encapsulation
ML-KEM-768 deployed for internal key exchange.
ML-DSA (FIPS 204) for digital signatures
ML-DSA-65 used for code signing pipeline.
SLH-DSA (FIPS 205) for stateless hash-based signatures
SLH-DSA-SHA2-128s configured for firmware signing.
AES-256 for symmetric encryption
Some legacy services still use AES-128.
SHA-384+ for hashing
SHA-256 in use; SHA-384 migration pending.
XMSS/LMS for stateful hash-based signatures
Not yet evaluated for deployment.
Hybrid key exchange for TLS 1.3
TLS endpoints not yet configured for hybrid mode.