
Post-quantum email security advances on two IETF tracks
Two August 18 milestones advanced composite ML-KEM for CMS and a CNSA 2.0 S/MIME profile—useful signals for planning, not final standards.
Read postQuanten Security delivers post-quantum cryptography as a drop-in fabric, from TLS handshakes to sovereign key storage.
ML-KEM-1024ML-KEM-1024The NIST-standardised way for two systems to agree on a secret key without a quantum computer being able to work it out. It replaces the key exchange used by most of the internet today. replaces ECDHECDHThe method almost every encrypted connection uses today to agree on a secret key. It is one of the two things a quantum computer would break, which is why ML-KEM replaces it. across every session: TLS, SSH, and proprietary tunnels.
ML-DSAML-DSA-87A quantum-safe digital signature. It is what proves a message, a software update, or a server really came from who it claims, and has not been altered. and SLH-DSASLH-DSAA second quantum-safe signature built on a completely different kind of maths to ML-DSA. It is slower, and it exists as a fallback in case a weakness is ever found in the first approach. sign every packet and firmware image with quantum-safe math.
Algorithm profiles hot-swap without downtime. Quantum or classical: the fabric adapts.
Migration planners commonly model cryptographically relevant quantum risk across a 2029–2033 window.
ShorShor's algorithmThe quantum method that breaks RSA and ECC. It is the specific reason today's public-key encryption has an expiry date.'s algorithm solves the discrete-logarithm and integer-factorisation problems in polynomial time on a quantum computer. Every algorithm that relies on these problems (RSA, ECC, DH) falls.
Lattice problems such as Learning With ErrorsLearning With ErrorsThe hard problem underneath lattice cryptography: recovering a hidden pattern once deliberate noise has been added. Adding that noise is easy, and undoing it is believed to be beyond quantum computers too. (LWE) have no known quantum speedup. ML-KEM and ML-DSA are built on LWE hardness, giving post-quantum security without sacrificing performance.
Air-gappedAir-gappedPhysically disconnected from any network. Keys generated this way cannot be reached remotely at all, because there is no route to them. key generation and storage. FIPS 140-3FIPS 140-3The certification a key-storage device has to pass, covering the hardware itself rather than the maths. It is usually a procurement requirement in regulated sectors.-ready HSMHSMA hardware security module: a sealed, tamper-evident box that generates and stores private keys so they never exist in ordinary computer memory. workflow with tamper evidence.
qs-keygen --algo ml-kem-1024 --hsmSingle-tenant deployment in your jurisdiction. National data-residency requirements met.
qs deploy --mode sovereign --region eu-westDrop the PQC fabric over existing infrastructure. mTLSmTLSMutual TLS: both sides of a connection prove their identity to each other, not just the server to the client. It is a common building block of zero-trust networks. + ML-KEMML-KEM-1024The NIST-standardised way for two systems to agree on a secret key without a quantum computer being able to work it out. It replaces the key exchange used by most of the internet today. without forklift upgrades.
qs overlay --target 10.0.0.0/8 --pqc hybridMigration planners commonly model cryptographically relevant quantum risk across a 2029–2033 window. RSA-2048RSA-2048The encryption behind a large share of today's web traffic, VPNs, and digital certificates. A sufficiently capable quantum computer would break it outright. and ECC-P256ECC-P256The other workhorse of today's internet encryption, used widely in mobile and messaging. It falls to the same quantum attack as RSA. would be broken retroactively once a capable quantum computer exists — any encrypted traffic captured today can be decrypted then.
Nation-state adversaries are recording encrypted sessions now. Once a quantum computer arrives, stored ciphertext becomes plaintext. PQC migration cannot wait until Q-DayQ-DayShorthand for the day a quantum computer can break the encryption in use today. Nobody knows the date, so planners work to a window rather than a deadline. arrives.
ML-KEM-1024ML-KEM-1024The NIST-standardised way for two systems to agree on a secret key without a quantum computer being able to work it out. It replaces the key exchange used by most of the internet today. handshakes add less than 4 ms over baseline TLS 1.3TLSThe protocol behind the padlock in a browser. It encrypts traffic between a visitor and a website, and it is the single biggest place post-quantum encryption has to land. on commodity hardware. Key-share payloads are larger (1,568-byte encapsulation key plus 1,568-byte ciphertext, vs 32 bytes for ECDH), but modern networks absorb the roughly 3.1 KB PQC exchange.
Yes. Quanten's fabric runs dual-algorithm sessions — classical ECDHECDHThe method almost every encrypted connection uses today to agree on a secret key. It is one of the two things a quantum computer would break, which is why ML-KEM replaces it. alongside ML-KEMML-KEM-1024The NIST-standardised way for two systems to agree on a secret key without a quantum computer being able to work it out. It replaces the key exchange used by most of the internet today. — so you remain protected against both classical and quantum attackers during the migration window.

Two August 18 milestones advanced composite ML-KEM for CMS and a CNSA 2.0 S/MIME profile—useful signals for planning, not final standards.
Read post
Coinbase’s custody plan and Ethereum’s public post-quantum roadmap point to the same bottleneck: coordinated key, wallet and protocol migration—not the search for one new signature algorithm.
Read post
Cloudflare now supports ML-DSA certificates on the edge-to-origin hop. The operational lesson is that key agreement, authentication and downgrade resistance must be measured as separate controls.
Read post
FINMA’s survey of 60 Swiss financial institutions found broad awareness but little execution. Its new guidance points to board-approved strategy, a living cryptographic inventory and a PQC roadmap by mid-2027.
Read post
05
Recent quantum news points in one direction: useful scientific workloads, national infrastructure programmes, and enterprise PQC timelines are moving together. Security teams should turn that signal into crypto-agility work now.
Read post
06
IBM, Oak Ridge, and Cleveland Clinic showed quantum computing moving into applied scientific work. Microsoft moved its quantum-safe security timeline to 2029. Together, the message is simple: security teams should stop treating PQC as distant.
Read post
07
Google and Cloudflare have pulled their post-quantum migration targets toward 2029. The lesson for enterprises is not panic; it is that authentication, signing, and crypto inventory need executive attention now.
Read post
08
Browsers, Apple platforms, Java, OpenSSL-based stacks, and CDNs are moving hybrid post-quantum TLS from experiments toward defaults. The new operational question is whether teams can measure coverage.
Read postShare your environment, timeline, and regulatory context. The team will route your request to the right specialist without collecting unnecessary telemetry.