Guides
Practical, sourced guides to test, plan and migrate to post-quantum cryptography.
How to check if your website supports post-quantum TLS
Three ways to test if a server negotiates hybrid post-quantum key exchange (X25519MLKEM768): an online scan, one OpenSSL command or browser tools.
· minEnable post-quantum TLS on nginx, Apache, HAProxy and Caddy
Exact configuration to enable hybrid X25519MLKEM768 key exchange on nginx, Apache, HAProxy and Caddy, with prerequisites, a safe fallback and how to verify it.
· minPCI DSS 12.3.3: building the cryptographic inventory
PCI DSS requirement 12.3.3 is mandatory since 31 March 2025. What it requires, how to inventory cipher suites and protocols, and a ready-to-use template.
· minPost-quantum migration deadlines: what to do and when
Post-quantum deadlines from NIST, the EU, ANSSI, BSI, the UK NCSC and the US: what is binding, what is guidance, and what to do by each date.
· minWhat is a CBOM, the cryptographic bill of materials?
A CBOM lists the algorithms, keys, certificates and protocols in a system. How it differs from an SBOM, the CycloneDX 1.6 format, and who requires it.