Your cryptography has an expiry date.
RSA and elliptic curves are deprecated after 2030 and disallowed after 2035 under NIST’s draft IR 8547. See where you stand, then what is left to do.
- March 2025PCI DSS 12.3.3: cipher suite inventory mandatory
- End of 2026EU: inventories and national roadmaps
- December 2027Cyber Resilience Act fully applies
- End of 2030EU: high-risk systems migrated, RSA-2048 deprecated
- 2035RSA and ECC disallowed (NIST, draft)
Passive TLS handshakes, like a browser. No signup.
Where the UK stands
Share of websites that negotiate post-quantum key exchange, measured every month by our observatory.
Without a CDN, only 50% of public services negotiate post-quantum key exchange on their own servers. See the observatory
Observatory, September 2026. Country detected from your IP (not stored) with DB-IP
Developers
pqcstatus scan in CI, SARIF in your merge requests, and a failing build on critical findings.
Get an API keySecurity and compliance
An inventory that stays current, mapped to PCI DSS, DORA, NIS2 and the Cyber Resilience Act.
See the reportVendors
Answer customer questionnaires with a dated report and a live, verifiable badge.
Get the badgeEverything the post-quantum transition needs
- ScannerHybrid ML-KEM, TLS versions, cipher suites and certificates, in seconds.
- CBOM in your CIOne command inventories code, configs and dependencies. Your code never leaves your machine.
- MonitoringDaily rescans, and an alert the day something regresses.
- Readiness reportA PDF for your CISO, auditor and customers: findings, PCI DSS 12.3.3 inventory, dated plan.
- Verified badgeShow it on your site. It updates itself and never claims more than we measured.
- Sourced referenceEvery deadline from NIST, ANSSI, BSI and the EU, linked to the primary text.
Built around the rules you answer to
Full timeline- PCI DSS v4.0.1Requirement 12.3.3 makes a yearly-reviewed inventory of cipher suites and protocols mandatory since 31 March 2025.In force
- Cyber Resilience ActEssential cybersecurity requirements for products, including state-of-the-art encryption of data at rest and in transit.Next: Dec 2027
- DORARequires an encryption policy that can change cryptographic technology as cryptanalysis evolves, plus full key and certificate lifecycle management.In force
- NIS2Cybersecurity risk-management measures include policies on cryptography and encryption; a 2026 proposal adds the PQC transition to national strategies.In force
- EU PQC roadmapCommon EU timeline: first steps and national roadmaps by end of 2026, high-risk systems migrated by end of 2030, medium-risk by end of 2035.Next: Dec 2026
- ANSSI guidanceHybridation mandatory in the regulated scope; start the cryptographic inventory now; PQC expected for product qualification from 2027.Next: Jan 2027
- BSI TR-02102-1Hybrid PQC recommended; classical key agreement alone only until end of 2031; RSA of at least 3000 bits.Next: Dec 2031
- UK NCSCDiscovery and plan by 2028, priority migrations by 2031, full migration by 2035.Next: Dec 2028
- US federal PQC migrationAutomated cryptographic inventory and CBOM, PQC key establishment by end of 2030, PQC signatures by end of 2031, full migration by 2035.Next: Oct 2026
- NSA CNSA 2.0Mandated algorithms: ML-KEM-1024, ML-DSA-87, LMS/XMSS, AES-256, SHA-384/512, with category-specific deadlines.Next: Dec 2030
Frequently asked questions
What does post-quantum ready mean for a website?
It means the server can negotiate a post-quantum or hybrid key exchange such as X25519MLKEM768 in TLS 1.3. The session keys then stay secret even against a future quantum computer. Certificates are a separate step: public web certificates are still RSA or ECDSA today.
Is the scan intrusive?
No. It performs standard TLS handshakes and one HTTP request, like a browser would. It never tries to log in, exploit or stress the server, and results are cached for an hour to avoid repeated connections.
My site is behind Cloudflare or another CDN. Is the result valid?
It is valid for the CDN edge, which is what visitors connect to. The connection between the CDN and your origin server is a separate TLS link: check it too, because it may still use classical key exchange only.
Is this a compliance certification?
No. The scan documents facts about your externally visible TLS configuration, with dates and sources. It helps build the inventory that PCI DSS, DORA or the CRA expect, but it is not an audit or a certificate.
Which deadlines apply to my company?
It depends on your sector and market: PCI DSS for card payments, DORA for EU financial entities, NIS2 for essential and important entities, the CRA for products sold in the EU. Our regulations page lists every requirement with its primary source.
Get the monthly post-quantum briefing
New deadlines, adoption data from our observatory and practical migration guides. One e-mail a month, no spam, unsubscribe in one click.