Q-Shield

Post-Quantum Cryptography Migration Software | Q-Shield

Inventory your cryptography, score quantum risk on five axes, and build a NIST-aligned migration roadmap to ML-KEM before the 2031 / 2035 deadlines.

Why post-quantum migration is now an operational deadline, not a research topic

A large-scale quantum computer capable of running Shor's algorithm would break the public-key cryptography — RSA and elliptic-curve — that protects most data in transit and at rest today. The exposure is not only future: under "harvest now, decrypt later," an adversary can capture encrypted traffic now and decrypt it once that capability exists. Any data whose confidentiality must outlive the migration window is already at risk today.

The dates that make this operational come from published standards and guidance, not from a prediction about when a quantum computer will arrive. U.S. federal guidance directs that high-priority, harvest-exposed systems be migrated by the end of 2031, and all remaining systems by the end of 2035. NIST IR 8547 separately deprecates RSA-2048 and ECC P-256 in 2030 and disallows them after 2035. Two nearer dates apply to regulated teams: FIPS 140-2 validation sunsets in September 2026, and CNSA 2.0 sets a 2027 timeline for U.S. national security systems. Those dates turn PQC from a standards-watching exercise into a multi-year program that has to start now.

A note on the one date nobody can cite: the arrival of a cryptographically relevant quantum computer is genuinely uncertain and debated among researchers. A migration plan should not rest on a countdown to "Q-Day." It rests on the two facts that are certain — the deadlines above, and the fact that harvested ciphertext waits — so the work is justified regardless of exactly when the capability lands.

What Q-Shield does

Q-Shield is post-quantum cryptography migration software built around three jobs:

  • Cryptographic inventory — discover where cryptography lives across your systems, because you cannot migrate what you have not located. Unknown cryptography is unmanaged cryptography.
  • Quantum risk scoring (QRS, five-axis) — rank each asset by exposure so the highest-risk, longest-lived secrets move first, rather than moving everything at once.
  • NIST-aligned roadmap — translate the inventory and scores into a sequenced migration plan toward ML-KEM (FIPS 203), including hybrid ECDH + ML-KEM where appropriate.

Migrate in the right order

Migration fails when teams swap algorithms blindly. The defensible sequence is inventory → risk-rank → hybrid rollout → validate:

1. Inventory — locate every place cryptography is used, because discovery has to precede any algorithm change. 2. Risk-rank — apply the five-axis QRS so the secrets with the longest confidentiality lifetime and the highest exposure — the ones "harvest now, decrypt later" targets hardest — move ahead of low-value, short-lived data. 3. Hybrid rollout — negotiate a hybrid key exchange that combines classical ECDH with ML-KEM (FIPS 203), so established security is preserved even if one layer is later weakened. 4. Validate — confirm each migrated asset actually negotiates the new algorithms, and record the change against the deadline it was meant to satisfy.

Standards this aligns to

Q-Shield scores and recommends against NIST's finalized post-quantum standards rather than any proprietary scheme. In August 2024, NIST published ML-KEM (FIPS 203) for key establishment, alongside ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for digital signatures. Q-Shield targets ML-KEM-768, which sits at NIST security category 3 and is built on the module-learning-with-errors problem with fully public parameters — the underlying design is open for review rather than secret.

A hybrid ECDH + ML-KEM key exchange is the pragmatic default during migration: it keeps the classical protection you already rely on while adding the post-quantum layer, so a later weakness in either component alone does not collapse the session. That is the posture Q-Shield recommends for most assets, with the migration order set by the quantum risk score rather than by convenience.

Run a PQC readiness assessment

Get started