Skip to content
Tag

standards

Every article tagged standards, newest first.

5 articles

News

How ML-KEM became the browser default, release by release

Chrome has negotiated hybrid post-quantum key agreement by default since version 131 in November 2024, migrating from a pre-standard Kyber draft to the finalized X25519MLKEM768. The other major browsers and libraries followed. Here is how the switch happened, and what the hybrid does and does not protect.

3 min read
News

NIST's 2030 and 2035 deadlines for legacy cryptography

NIST's transition report, IR 8547, names the dates the whole migration is timed against: today's public-key algorithms deprecated after 2030 and disallowed after 2035. Those are not distant abstractions, they are a schedule you have to work backwards from. Here is what the deadlines say and what they mean.

3 min read
News

CISA's 2026 SBOM minimum elements: what changed, and why

CISA, with the NSA, FBI, and international partners, replaced the 2021 NTIA baseline for what a software bill of materials must contain. The new floor asks for cryptographic hashes on every component, a signature on the SBOM itself, full transitive-dependency depth, and machine-processable identifiers, and it applies to open-source, AI software, and SaaS. Here is what changed, why it was done, and why it lands next to the cryptographic bill of materials we build.

6 min read
Methodology

A field guide to post-quantum readiness, free and in the open

Most post-quantum material is one of two things: a vendor pitch that tells you to panic, or a standard that assumes you already have a doctorate. We built the part in between and put it online for free. The quantakrypto knowledge base is 11 collections, 49 topics, an 85-term glossary, and straight answers, with reading paths for employees, IT, and leadership.

3 min read
Methodology

A well-known URI for cryptographic posture: the crypto-agility manifest

A machine can already ask a site what to crawl (robots.txt) and who to email about a bug (security.txt). It cannot ask what cryptography the site runs or how far along its post-quantum migration is. We are proposing a small well-known file that answers exactly that, and shipping the emitter in qScan. It is a proposal, not a ratified standard.

4 min read
Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.