Quantum computers able to break RSA and elliptic-curve cryptography do not exist yet, but the deadlines to replace them already do. NIST, the European Union, ANSSI, BSI and the UK NCSC all ask organizations to start with the same step: know which cryptography you use and where.
PQC Status exists to make that first step fast and verifiable. Our free scanner checks what any website exposes over TLS: post-quantum key exchange, protocol versions, cipher suites and certificates. Our reference pages turn dense standards and regulations into clear, sourced facts.
Our principles
- Sources first. Every date and every position on this site links to its primary source. When a document is still a draft, we say so.
- Facts, not fear. We report what we measured and what authorities actually require. We never turn a recommendation into an obligation.
- Privacy by design. No cookies, no trackers, no raw IP addresses stored. Your code never leaves your machine with our upcoming command-line scanner.
- Independence. We do not sell certificates or hardware, and we are not paid by the vendors we mention.
What is next
We are building a command-line scanner and CI integration that produce a CycloneDX cryptographic bill of materials (CBOM) from your source code and configuration, plus reports mapped to PCI DSS, the Cyber Resilience Act, DORA and NIS2. Subscribe to the briefing to be notified.