Skip to content
Tag

migration

Every article tagged migration, newest first.

10 articles

News

Cloudflare adds post-quantum authentication to origins

Cloudflare now supports post-quantum authentication between its edge and your origin server: Authenticated Origin Pulls and Custom Origin Trust Store both accept ML-DSA (FIPS 204) certificates. Paired with the X25519MLKEM768 key exchange already running on that hop, this is the first mainstream path to a fully post-quantum CDN-to-origin connection, not just the browser-to-edge leg.

3 min read
News

Go 1.27 brings post-quantum signatures to the stdlib

Go 1.27, released this month, adds a crypto/mldsa package implementing ML-DSA (FIPS 204), plus ML-DSA support in crypto/x509 and crypto/tls. Post-quantum signatures are no longer a third-party dependency for Go services, they are a standard-library import. Here is what shipped and what it means for the migration.

3 min read
News

How much of the web already uses post-quantum TLS

By late 2025, around 43% of human web connections to Cloudflare were already using hybrid post-quantum key agreement, and X25519MLKEM768 is on by default in every major browser. The browser-to-edge hop is largely migrated. The unfinished half is origins, authentication, and your own stack. Here is where the line actually is.

3 min read
News

NIST's 2030 and 2035 deadlines for legacy cryptography

NIST's transition report, IR 8547, names the dates the whole migration is timed against: today's public-key algorithms deprecated after 2030 and disallowed after 2035. Those are not distant abstractions, they are a schedule you have to work backwards from. Here is what the deadlines say and what they mean.

3 min read
Methodology

A field guide to post-quantum readiness, free and in the open

Most post-quantum material is one of two things: a vendor pitch that tells you to panic, or a standard that assumes you already have a doctorate. We built the part in between and put it online for free. The quantakrypto knowledge base is 11 collections, 49 topics, an 85-term glossary, and straight answers, with reading paths for employees, IT, and leadership.

3 min read
Methodology

You cannot migrate what you cannot see: build a CBOM with qScan

Every post-quantum migration plan starts with the same step, and almost everyone underestimates it: know exactly what cryptography you have. A cryptographic bill of materials (CBOM) is that inventory in a standard, machine-readable form. Here is how to produce one across your code and your infrastructure in about a minute, with qScan, and what to do with it once you have it.

3 min read
Research

From a snapshot to a signal: continuous post-quantum posture

A one-time scan tells you where you stand today. Migration is a moving target, so we now track posture over time: an append-only snapshot per scan, a drift alert when a commit reintroduces quantum-vulnerable crypto, and migration projects that group findings by an identity that survives a line shift.

3 min read
Methodology

A post-quantum workflow for AI coding agents

AI coding agents are fluent in cryptography and blind to its expiry date. The quantakrypto MCP gives them the missing sense. Here is the workflow we actually use: what to delegate to the agent, and where a human still decides.

3 min read
Research

The clock is already running

Why we don't wait for a quantum computer to arrive before we act, and how to decide what to migrate first using a clock you already own.

2 min read
Methodology

The crypto inventory: finding every place asymmetric crypto hides

“Add post-quantum” is not a single switch. The first deliverable of a serious migration is a cryptographic inventory: every place asymmetric cryptography is used, and what depends on it. Here is how national cyber agencies build one, and why it is the hard part.

5 min read
Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.