The migration dependency graph
The real question is not 'is post-quantum cryptography standardised?' It is whether every product, protocol, appliance, trust anchor, device and vendor on the critical path can support a compatible migration before your risk deadline. Each node below is wired to the named products we could verify — and to the layers where no first-party evidence exists at all.
Standards & authorities
Implementations
Trust infrastructure
Platforms
Industry workflows
Select any node to trace what it depends on, what depends on it, and which named products were verified at that layer. Highlighted neighbours are direct dependency edges.
HSM / KMS
ImplementationsKey custody and signing firmware must support the new algorithms before PKI can issue.
NIST FIPS 203/204/205 · Chips & secure elements
PKI providers & CAs · Code & firmware signing
Vendor readiness, stated precisely
A green checkbox has to mean something specific. Each record below names the product release, the capability, the evidence, the evidence class and the verification date — plus what must not be inferred. Where no first-party statement exists, that absence is recorded rather than guessed.
OpenSSL
OpenSSL 3.5 LTS (April 2025)- ML-KEM (FIPS 203)
- Implemented
- ML-DSA (FIPS 204)
- Implemented
- SLH-DSA (FIPS 205)
- Implemented
- TLS 1.3 hybrid keyshare
- Default group list includes X25519MLKEM768
- Hybrid key exchange
- X25519MLKEM768 enabled by default
- PQC certificate authentication
- Not enabled
Do not infer: That browser-visible connections are authenticated with post-quantum signatures.
Company roadmap →Open Quantum Safe
liboqs and oqs-provider- ML-KEM / ML-DSA / SLH-DSA
- Implemented for research and prototyping
- Production assurance
- Project explicitly does not claim production hardening
Do not infer: That an experimental integration is production-hardened or certified.
Company roadmap →Amazon Web Services
AWS-LC- ML-KEM
- Implemented in the open-source cryptographic library
- Scope
- Library capability; downstream service enablement varies
OpenSSH
OpenSSH 9.x / 10.0- Hybrid key exchange
- mlkem768x25519-sha256 default since 10.0
- PQC host and user keys
- Not available
Do not infer: That SSH identities are quantum-resistant — only the session key exchange is.
Company roadmap →Signal
PQXDH / SPQR ratchet- Initial key agreement
- Hybrid ML-KEM since 2023
- Ongoing ratchet
- Post-quantum ratchet rolled out 2025
Red Hat
Red Hat Enterprise Linux 10- Core cryptographic stack
- ML-KEM, ML-DSA and SLH-DSA through OpenSSL 3.5
- Protocol coverage
- Incremental and application-dependent
Do not infer: That every application or package-signing path in RHEL uses PQC.
Company roadmap →Thales
Luna firmware with PQC functionality module- ML-KEM / ML-DSA
- Available via firmware update
- FIPS 140-3 validation of PQC modes
- Track per-firmware certificate, not the datasheet
Do not infer: That an installed appliance already has the PQC firmware, or that the validation certificate covers it.
Company roadmap →Entrust
nShield HSM- ML-KEM / ML-DSA
- NIST CAVP algorithm validation announced
- Deployment
- Depends on supported nShield model and software release
Utimaco
Quantum Protect for u.trust General Purpose HSM- PQC operations
- Lattice- and hash-based algorithms in an HSM application package
- Evaluation
- Simulator available before hardware deployment
Futurex
CryptoHub PKCS #11- ML-KEM / ML-DSA
- Exposed through the PKCS #11 v3.2 interface
Amazon Web Services
Managed key services- PQC-protected API transport
- Hybrid ML-KEM in TLS to KMS endpoints
- PQC customer signing keys
- Not generally available
Do not infer: That keys managed for you are post-quantum key types — the protected item is the connection.
Company roadmap →Infineon
PQC-certified security controller- PQC implementation
- Common Criteria EAL6 certified
- Form factor
- Contactless and dual-interface security controller
NXP
Embedded and secure-element PQC strategy- Product direction
- PQC integration described for long-life embedded products
- Named shipping SKU
- Not established by this source
Do not infer: That the installed NXP device base can be upgraded or that a specific SKU is shipping PQC.
Company roadmap →DigiCert
Private PKI and PQC test CAs- Private-trust ML-DSA issuance
- Available
- Public-trust PQC certificates
- Blocked pending CA/Browser Forum and root programs
Do not infer: That you can buy a publicly trusted post-quantum TLS certificate today.
Company roadmap →Entrust
PKI as a Service- PQC-ready private PKI
- Commercially available
- Public Web PKI
- Not established
Microsoft Active Directory Certificate Services
Windows PKI and SymCrypt- ML-KEM / ML-DSA APIs
- In Windows Insider / SymCrypt
- Enterprise CA templates for PQC
- Preview-stage
Sectigo
Sectigo Private PQC- Private PQC certificates
- Available for testing
- Production readiness
- Vendor explicitly says not production-ready
Keyfactor
Command certificate lifecycle management- Cryptographic inventory / CBOM
- Available
- PQC issuance orchestration
- Dependent on the CA and HSM beneath
CyberArk
Venafi machine identity platform- Cryptographic inventory
- Available for discovery and migration planning
- PQC credential issuance
- Dependent on connected CA and HSM support
Yubico
YubiKey / FIDO roadmap- PQC authentication
- Roadmap discussion; no shipping PQC FIDO authenticator evidenced
DigiCert
Software Trust Manager- PQC code-signing keypairs
- ML-DSA keypair creation can be enabled
- Ecosystem verification
- Relying-party compatibility remains separate
Do not infer: That every operating system, package manager or device can verify the resulting signatures.
Company roadmap →Microsoft
Windows 11, Windows Server 2025 and .NET 10 cryptographic APIs- ML-DSA APIs
- Generally available
- Windows trust and secure-boot chains
- Not shown as fully migrated
Cloudflare
Edge network and Zero Trust- Edge key exchange
- Hybrid ML-KEM available on all plans
- Origin connections
- Post-quantum where the origin supports it
- Organisation target
- Full post-quantum security, including authentication, by 2029
Do not infer: That origin servers behind the edge are post-quantum protected.
Company roadmap →Google Cloud
Google Cloud services and KMS- API endpoint key exchange
- Hybrid ML-KEM deployed
- Cloud KMS PQC signing
- Preview for ML-DSA and SLH-DSA
- Organisation target
- Full readiness by 2029
Do not infer: That every customer workload or authentication pathway is already post-quantum secure.
Company roadmap →Amazon Web Services
AWS service endpoints- Hybrid TLS to service endpoints
- Rolling out across services
- Full-estate completion
- Published multi-year migration plan, no single GA date
Microsoft
Azure platform and Windows- SymCrypt PQC primitives
- Shipping into Windows and platform services
- Quantum Safe Program target
- Early adoption by 2029, completion by 2033
Palo Alto Networks
PAN-OS 11.2+ IPsec/IKEv2- RFC 8784 pre-shared keys
- Supported
- RFC 9370 multiple key exchanges (ML-KEM)
- Supported
Cisco
Cisco 8000 Series / IOS XE IKEv2- PQC-hybrid IKEv2
- Available on selected platforms and releases
- Platform-wide coverage
- Release- and hardware-dependent
F5
BIG-IP TMOS- Hybrid PQC TLS
- Supported in client-side and server-side TMM paths
- Coverage
- Version- and configuration-dependent
SAP
SAP CommonCryptoLib quantum-safe version- Quantum-safe crypto library
- Announced for SAP application landscapes
- Estate-wide deployment
- Not established by a product release matrix
Apple
iMessage PQ3- Apple iMessage PQ3
- Shipping since iOS 17.4
- Protocol scope
- End-to-end iMessage sessions on supported Apple OS releases
Signal
Signal with PQXDH and SPQR- Initial agreement
- Hybrid post-quantum PQXDH
- Ongoing sessions
- Sparse Post Quantum Ratchet
IBM
IBM Db2 quantum-safe migration architecture- Product work
- Published migration approach and implementation case study
- GA feature coverage
- No complete release-level capability matrix evidenced
wolfSSL
wolfCrypt / wolfSSL embedded PQC- Embedded ML-KEM / ML-DSA
- Available in the embedded cryptographic stack
- Deployed device coverage
- Depends on OEM integration and firmware rollout
Do not infer: That devices embedding older wolfSSL versions are upgradeable or already migrated.
Company roadmap →- Shipping
- A generally available product release implements the NIST algorithms; documented by the supplier or the project itself.
- Partial
- Some paths are post-quantum (usually key exchange) while others — typically authentication, signing or key custody — are not.
- Announced
- A dated public commitment or preview exists, but no generally available implementation has been verified.
- No public evidence
- No first-party statement of post-quantum support was found for this layer. Absence of evidence is recorded as absence, not as failure.