FIPS 140-2 Is Now Historical: What Changes
What the September 2026 FIPS 140-2 transition means for existing systems, new procurements, FIPS 140-3 validation, and PQC adoption.
What the September 2026 FIPS 140-2 transition means for existing systems, new procurements, FIPS 140-3 validation, and PQC adoption.
Cloudflare 1.1.1.1 now validates ML-DSA-44 DNSSEC signatures. Learn what is deployed, what remains a draft, and what operators should test.
What US federal agencies must include in their M-26-15 post-quantum migration plans, with deadlines, phases, priorities, and evidence.
A practical worksheet for inventorying, testing, rolling out, and rolling back an OpenSSL 3.0-to-3.5 migration for post-quantum cryptography.
What RFC 10042 defines for hybrid ML-KEM SSH key exchange, its three method names, implementation support, limits, and migration checks.
What RFC 10024 standardizes for hybrid ML-KEM TLS 1.3, including final groups, IANA code points, obsolete Kyber drafts, and migration steps.
Build a useful CBOM for post-quantum migration with a downloadable component inventory, dependency fields, evidence, and ownership guidance.
Assess enterprise post-quantum readiness by capability, evidence, ownership, dependencies, testing, and rollback without a misleading universal score.
Structured comparison of six major cryptographic libraries for post-quantum support. ML-KEM, ML-DSA, SLH-DSA, FIPS status, and licensing.
Download and use a practical PQC migration plan covering ownership, crypto functions, dependencies, testing, rollback, dates, and evidence.
A practical vendor questionnaire for verifying PQC algorithms, KMS and HSM support, PKI, hybrid modes, inventory, roadmap, and evidence.
Compare cloud PQC support by workflow: ML-DSA, ML-KEM, KMS, HSM, key import, TLS, PKI, status, and migration use cases.
Practical guide to building a cryptographic inventory. Tools, scanning techniques, and prioritization methods for PQC migration planning.
Complete guide to implementing PQC in Java using Bouncy Castle. ML-KEM key encapsulation, ML-DSA signatures, code examples, and Maven setup.
Practical guide to testing PQC deployments: interop tools, OQS test server, browser dev tools, and TLS handshake capture.
Quick-reference card for all NIST PQC parameter sets: key sizes, signature sizes, ciphertext sizes, and speed class.
Which CAs issue post-quantum certificates today, IETF LAMPS WG progress, and the timeline for PQ certs in the public WebPKI.
Comparing Python post-quantum cryptography libraries for production readiness, algorithm support, and ease of use in 2026.
Why hybrid mode combines classical and post-quantum algorithms, how long it lasts, the key RFCs and IETF drafts, and when organizations can drop classical.
Post-quantum migration guide built for SaaS. You control the stack but your customers may not support PQC yet. Phased timeline with backward compatibility.
What Android versions support ML-KEM and ML-DSA today. TLS stack, Keystore, Conscrypt updates, and what app developers need to know.
Complete guide to GCP post-quantum cryptography support. Cloud KMS algorithms, network encryption, Chrome, and what Certificate Authority Service still lacks.
Comparing liboqs, BoringSSL, wolfSSL, OpenSSL 3.5, and Bouncy Castle for PQC support. Which are production-ready, which are experimental.
Living reference table of PQC support across cloud providers, browsers, VPNs, and messaging apps. ML-KEM, ML-DSA, hybrid mode status.
Technical deep dive into Apple's PQ3 protocol for iMessage. Kyber-1024 + ECDH hybrid, triple ratchet, and what Level 3 security means.
Current state of Microsoft Azure PQC support. SymCrypt, Windows Server 2025, TLS hybrid groups, and what Key Vault still lacks.
Nation-state adversaries are collecting encrypted data now, waiting for quantum computers to decrypt it. The evidence, who is at risk, and what to do.
Crypto agility is the ability to swap cryptographic algorithms without rewriting applications. What it means practically and why PQC makes it urgent.
Which AWS services support post-quantum TLS today. KMS, ACM, Secrets Manager, S3, and Payment Cryptography all have PQ options. Here is how to enable them.
Not every VPN claiming quantum-safe encryption has actually shipped it. Here is which providers have real PQ key exchange today, verified.
Cloudflare enables PQ key exchange by default for client-to-edge traffic. But origin connections need manual configuration. Here is the full picture.
Three ways to check if your TLS connections use post-quantum key exchange today. Browser DevTools, command-line tools, and Cloudflare Radar.
The three finalized NIST post-quantum standards with parameter sets, key sizes, signature sizes, and when to use which. For security engineers, not academics.
Step-by-step guide to enabling post-quantum TLS key exchange on your server with OpenSSL 3.5+. Nginx and Apache configurations included.
Enterprise PQC migration checklist covering ownership, inventory, key establishment, signatures, dependencies, testing, rollback, and evidence.
Post-quantum cryptography replaces algorithms that quantum computers will break. What is actually changing, why now, and what harvest now decrypt later means.