Company roadmaps, products and proof
Track what each supplier actually ships, what remains partial, and which future dates are backed by a first-party roadmap. Product capability and corporate targets are kept separate.
OpenSSL
The widely embedded cryptographic library ships all three initial NIST PQC standards and hybrid TLS key exchange in its 3.5 LTS line.
Google has deployed hybrid ML-KEM key exchange in browser and cloud paths while post-quantum signatures remain preview-stage in Cloud KMS.
OpenSSH
OpenSSH defaults to hybrid ML-KEM key exchange, protecting session establishment while host and user authentication keys remain classical.
Signal
Signal protects both initial key agreement and continuing message sessions with hybrid post-quantum constructions.
Thales
Luna HSM firmware exposes PQC functionality, but deployment and validation status must be checked per appliance and firmware certificate.
Amazon Web Services
AWS is rolling hybrid ML-KEM transport protection across service endpoints; customer-held PQC signing keys are not generally available across KMS.
Infineon
Newer secure-element families advertise PQC-capable silicon; certification and availability remain part-specific rather than fleet-wide.
DigiCert
DigiCert supports post-quantum experimentation and private-trust issuance, while public Web PKI deployment remains dependent on browser and root-program rules.
Microsoft
Microsoft ships PQC primitives through SymCrypt and preview platform paths, with public programme targets for early adoption and completion.
Cloudflare
Hybrid key exchange is broadly deployed at the edge and is extending to origin connections; authentication remains the major unfinished layer.
Palo Alto Networks
Selected PAN-OS releases support standards-based hybrid IKEv2 exchange; exact coverage depends on release, peer and configuration.
Cisco
Selected Cisco security and routing products expose hybrid IKEv2 capability, with support dependent on platform and software release.
Entrust
Entrust has evidenced PQC capability in both nShield HSMs and private PKI services; public Web PKI readiness remains a separate question.
Utimaco
Utimaco ships its Quantum Protect application package for supported u.trust general-purpose HSMs.
Futurex
Futurex exposes ML-KEM and ML-DSA operations through its CryptoHub PKCS #11 interface.
Open Quantum Safe
The OQS project supplies broad experimental PQC implementations for prototyping, not a production-assurance claim.
Red Hat
RHEL 10 ships the standardized NIST algorithms in its core cryptographic stack, with protocol adoption remaining application-dependent.
NXP
NXP has published an embedded PQC strategy, but the cited evidence does not establish a specific generally available SKU.
Sectigo
Sectigo offers private PQC testing while explicitly disclaiming production readiness for the evidenced product.
Keyfactor
Keyfactor provides cryptographic discovery and certificate lifecycle orchestration whose PQC execution depends on connected CAs and HSMs.
CyberArk
CyberArk's Venafi platform supports machine-identity discovery and migration planning while issuance depends on downstream trust infrastructure.
Yubico
Yubico has discussed a post-quantum authentication roadmap but no shipping PQC FIDO authenticator is evidenced here.
F5
BIG-IP supports hybrid post-quantum TLS on documented client- and server-side paths, subject to release and configuration.
Apple
Apple ships the PQ3 protocol for iMessage on supported operating-system releases.
IBM
IBM has published a Db2 quantum-safe migration approach, but not a complete release-level GA capability matrix.
SAP
SAP has announced quantum-safe CommonCryptoLib work for application landscapes; estate-wide deployment is not yet evidenced.
wolfSSL
wolfSSL provides PQC algorithms for embedded integrations, while actual device readiness depends on each OEM and firmware release.