Post-Quantum Cryptography readiness
Post-Quantum Cryptography (PQC) refers to cryptographic algorithms that are designed to secure your organization against quantum computer attacks. These advanced machines could one day break the encryption methods we use today, like RSA and ECC. While quantum computers are not widely available yet, they are coming soon. So it is important for organizations to become future ready and begin their journey towards crypto-agility.
What does PQC readiness mean?
PQC readiness represents the ability of an organization’s assets’ and their associated cryptographic objects, such as keys, certificates, cipher suites, and protocols to withstand attacks by quantum computers. While current classical algorithms (RSA, ECC) remain secure against today’s adversaries, they may become breakable once Cryptographically Relevant Quantum Computers (CRQCs) emerge.
An organization’s PQC readiness is a measure of exposure to quantum threats and alignment with quantum-safe standards such as those being standardized by National Institute of Standards and Technology (NIST) initiative.
Benefits of being PQC ready
Guardium® Cryptography Manager offers comprehensive protection against emerging quantum threats by enabling early risk mitigation. It detects the use of quantum-vulnerable algorithms like RSA and ECC, and identifies cryptographic assets that would become insecure once a cryptographically relevant quantum computer (CRQC) comes into existence. This delivers a single-pane-of-glass view into cryptographic health, lifecycle management, and quantum preparedness.
The solution provides an automated Post-Quantum Cryptography (PQC) readiness assessment, classifying every cryptographic object into two categories, namely, PQC Safe and PQC Unsafe. Built-in policies automatically detect risky assets and generate PQC violations, which include CVSS-style based on CVSS impact scores, to prioritize remediation efforts.
Guardium Cryptography Manager allows for granular policy control and environment awareness, enabling users to enforce stricter PQC rules in production environments while maintaining flexibility in non-production settings. Exceptions can be defined with auditability, facilitating crypto-agility without disruption.
The solution supports a PQC transition roadmap, identifying areas where classical cryptography is still acceptable, where hybrid approaches could be viable, and where full migration to PQC should be planned. It serves as a living inventory of cryptographic assets and their readiness posture.
Lastly, Guardium Cryptography Manager integrates with Certificate Lifecycle Management, tying PQC posture into the same cryptographic inventory used for certificate expiry checks, key rotation policies, and cipher suite enforcement. This ensures a unified view of crypto hygiene, lifecycle state, and quantum safety, with no need for external resource links in this documentation
PQC readiness accessibility
- Cryptographic Posture Management and Certificate Lifecycle Management dashboards.
- Click , select PQC readiness in the field selection to view if the asset is PQC safe or unsafe in the PQC readiness column.
- Click , click on any object. A side panel opens with PQC readiness details.
- From the main menu, click PQC Readiness
Asset Inventory page opens. The assets on this page are sorted by the PQC readiness column value depicting if the asset is PQC safe or unsafe.
Interpreting PQC results
- PQC safe: Fully compliant with PQC standards, quantum future-proof.
- PQC unsafe: Vulnerable, entirely classical crypto, high quantum risk.
- Not evaluated: Policy is yet to run for assets.
- Not applicable: IT assets with no linked cryptographic objects. This state is applicable only for IT assets and not other cryptographic objects..
Predefined PQC policies
| Predefined PQC policies | Description |
|---|---|
| Quantum-Safe Algorithms | Detects if the algorithm is quantum safe or unsafe. For example, Kyber, Dilithium, FALCON, SPHINCS+ are safe. |
| Detection of RSA/ECC Use | Detection of unsafe algorithms, such as RSA,DSA,ECDSA, and ECC. |
| Weak Post-Quantum Security Posture | Detects if algorithm=AES and key length=128, then it leads to weak Post-Quantum Security Posture. |