PQC Status

Your cryptography has an expiry date.

RSA and elliptic curves are deprecated after 2030 and disallowed after 2035 under NIST’s draft IR 8547. See where you stand, then what is left to do.

Today
  1. March 2025PCI DSS 12.3.3: cipher suite inventory mandatory
  2. End of 2026EU: inventories and national roadmaps
  3. December 2027Cyber Resilience Act fully applies
  4. End of 2030EU: high-risk systems migrated, RSA-2048 deprecated
  5. 2035RSA and ECC disallowed (NIST, draft)

Passive TLS handshakes, like a browser. No signup.

Where the UK stands

Share of websites that negotiate post-quantum key exchange, measured every month by our observatory.

Large caps 97.5% Banks and insurers 90.9% Public services 95.2%

Without a CDN, only 50% of public services negotiate post-quantum key exchange on their own servers. See the observatory

Observatory, September 2026. Country detected from your IP (not stored) with DB-IP

Developers

pqcstatus scan in CI, SARIF in your merge requests, and a failing build on critical findings.

Get an API key

Security and compliance

An inventory that stays current, mapped to PCI DSS, DORA, NIS2 and the Cyber Resilience Act.

See the report

Vendors

Answer customer questionnaires with a dated report and a live, verifiable badge.

Get the badge

Everything the post-quantum transition needs

Built around the rules you answer to

Full timeline

Frequently asked questions

What does post-quantum ready mean for a website?

It means the server can negotiate a post-quantum or hybrid key exchange such as X25519MLKEM768 in TLS 1.3. The session keys then stay secret even against a future quantum computer. Certificates are a separate step: public web certificates are still RSA or ECDSA today.

Is the scan intrusive?

No. It performs standard TLS handshakes and one HTTP request, like a browser would. It never tries to log in, exploit or stress the server, and results are cached for an hour to avoid repeated connections.

My site is behind Cloudflare or another CDN. Is the result valid?

It is valid for the CDN edge, which is what visitors connect to. The connection between the CDN and your origin server is a separate TLS link: check it too, because it may still use classical key exchange only.

Is this a compliance certification?

No. The scan documents facts about your externally visible TLS configuration, with dates and sources. It helps build the inventory that PCI DSS, DORA or the CRA expect, but it is not an audit or a certificate.

Which deadlines apply to my company?

It depends on your sector and market: PCI DSS for card payments, DORA for EU financial entities, NIS2 for essential and important entities, the CRA for products sold in the EU. Our regulations page lists every requirement with its primary source.

Get the monthly post-quantum briefing

New deadlines, adoption data from our observatory and practical migration guides. One e-mail a month, no spam, unsubscribe in one click.

Start with one domain

Free, in seconds, without an account.