{"asOf":"2026-10-02","products":320,"claims":1573,"scenarios":35,"outcomes":[{"slug":"adopt","name":"Works by default","note":"Every role works without configuration."},{"slug":"configure","name":"Works with configuration","note":"At least one role needs a setting, and the result lists each one."},{"slug":"trial","name":"Trial only","note":"At least one role is a preview, a pilot or a test hierarchy."},{"slug":"unknown","name":"Unknown","note":"No claim answers a fact the scenario needs, and the result names it."},{"slug":"blocked","name":"Blocked","note":"A role has no PQ mechanism, or the roles share none."}],"postures":[{"slug":"default","name":"On by default","note":"Used without configuration. For a TLS client, the key share is sent in the first ClientHello."},{"slug":"default_listed","name":"On by default, not preferred","note":"Listed but not predicted (costs a HelloRetryRequest), or supported by a server that prefers classical."},{"slug":"opt_in","name":"Needs configuration","note":"Generally available; the claim's config says how."},{"slug":"preview","name":"Preview","note":"Experimental, behind a flag, beta, nightly, pilot, or declared not production-ready."},{"slug":"absent","name":"Not supported","note":"Evidence says it is not there. Unknown is the absence of a claim, never this."}],"evidence":[{"slug":"V","name":"Vendor statement","note":"Press release, marketing page, announcement without technical detail."},{"slug":"T","name":"Third-party test","note":"A lab result or a packet capture that someone other than the vendor published."},{"slug":"D","name":"Documentation","note":"Release notes, changelog, admin guide, KB, bug tracker, design doc."},{"slug":"S","name":"Source","note":"Code at a tag or commit: repo, ref, file, lines."},{"slug":"E","name":"Empirical","note":"Our own observation: target, date, vantage point, tool and command."},{"slug":"C","name":"Certification","note":"CMVP/CAVP/NIAP/Common Criteria certificate."}],"gaps":[{"slug":"no-claim","name":"No claim yet","note":"No claim covers the capability in this role.","reader":false},{"slug":"range","name":"Claims stop short","note":"Claims exist, and none covers this version.","reader":false},{"slug":"scope","name":"Claims cover another scope","note":"The claims hold only in a scope the need does not accept.","reader":false},{"slug":"dataset","name":"Not in the dataset","note":"The product or the capability is not in the data, or inheritance runs too deep.","reader":false},{"slug":"dated","name":"No release dated by then","note":"The data has no release of the product dated on or before the date, so it cannot say which version was current.","reader":false},{"slug":"component","name":"Name the component's version","note":"The answer comes from a component, and the target does not give its version.","reader":true},{"slug":"components","name":"Name the component","note":"The product can take the capability from more than one component.","reader":true},{"slug":"variant","name":"Name the variant","note":"The claims differ by variant.","reader":true},{"slug":"line","name":"Name the line","note":"The claims differ by line.","reader":true},{"slug":"platform","name":"Name the platform","note":"The claims, or the components, differ by platform.","reader":true}],"categories":[{"slug":"browser","name":"Browser","short":"Browser"},{"slug":"os","name":"Operating system or distribution","note":"Ships components; may have its own TLS stack (SChannel, Network.framework).","short":"Operating system"},{"slug":"library","name":"TLS and cryptographic library","note":"Has a TLS stack, and most have the primitives under it.","short":"TLS library"},{"slug":"crypto-library","name":"Cryptographic primitives library","note":"KEMs, signatures and hashes for a program to call, with no TLS stack of its own. The TLS scenarios do not ask it.","short":"Crypto library"},{"slug":"runtime","name":"Language runtime or standard library","short":"Runtime"},{"slug":"http-client","name":"HTTP client or CLI","short":"HTTP client"},{"slug":"web-server","name":"Web server","short":"Web server"},{"slug":"proxy","name":"Reverse proxy, API gateway or service mesh","short":"Proxy"},{"slug":"adc","name":"Application delivery controller / load balancer appliance","short":"ADC"},{"slug":"cdn-edge","name":"CDN or edge network","short":"CDN"},{"slug":"cloud-lb","name":"Cloud load balancer","short":"Cloud load balancer"},{"slug":"cloud-api","name":"Cloud provider API endpoints","short":"Cloud API"},{"slug":"firewall","name":"Firewall, secure web gateway or SSE with TLS inspection","short":"Firewall"},{"slug":"vpn-gateway","name":"VPN gateway, router or IKE daemon","note":"Ends site-to-site tunnels: a router, an IKE daemon such as strongSwan, or a cloud VPN service.","short":"VPN gateway"},{"slug":"overlay-vpn","name":"WireGuard implementation or overlay network","note":"Builds tunnels between peers with WireGuard or with a protocol of its own: WireGuard, Rosenpass, Tailscale, Nebula.","short":"WireGuard"},{"slug":"vpn-service","name":"VPN service","note":"Runs both ends of the tunnel: its own apps and its own servers.","short":"VPN service"},{"slug":"network-device","name":"Switch, router or wireless controller","note":"A network device, by its operating system. A router that ends IPsec tunnels is a VPN gateway too.","short":"Network device"},{"slug":"bmc","name":"Server management controller","note":"Manages a server out of band: HPE iLO, Dell iDRAC, OpenBMC.","short":"BMC"},{"slug":"network-access","name":"802.1X supplicant and authenticator software","note":"Software that puts a host at one end of an 802.1X exchange or of a MACsec link: wpa_supplicant and hostapd.","short":"802.1X software"},{"slug":"aaa-server","name":"Authentication server","note":"A RADIUS and EAP server, which ends the EAP-TLS handshake of a supplicant: FreeRADIUS, Cisco ISE. It is never an end of a MACsec link.","short":"RADIUS server"},{"slug":"vpn-client","name":"VPN client","note":"Connects a user's device to a gateway: a vendor's client, or the client an operating system has built in.","short":"VPN client"},{"slug":"vpn-server","name":"TLS VPN server","note":"Ends remote-access VPN tunnels over TLS: a VPN server, or the VPN portal and gateway of a firewall. It is not asked about IKEv2.","short":"TLS VPN server"},{"slug":"ssh-client","name":"SSH client","short":"SSH client"},{"slug":"ssh-server","name":"SSH server","short":"SSH server"},{"slug":"ssh-library","name":"SSH library","short":"SSH library"},{"slug":"ohttp-library","name":"Oblivious HTTP library","note":"A library for both ends of Oblivious HTTP (RFC 9458): it seals a request as a client, and opens one as a gateway.","short":"OHTTP library"},{"slug":"ohttp-gateway","name":"Oblivious HTTP gateway","note":"Gateway software, or a live gateway that we observe. It holds the HPKE key and publishes the key configuration. A relay holds no key, and is no product here.","short":"OHTTP gateway"},{"slug":"hsm","name":"Hardware security module","short":"HSM"},{"slug":"kms","name":"Cloud key management service","short":"Cloud KMS"},{"slug":"ca-software","name":"CA software or private CA service","note":"Issues from a hierarchy the customer controls.","short":"CA software"},{"slug":"ca-service","name":"Public certification authority","note":"Issues publicly trusted certificates, or intends to.","short":"Public CA"},{"slug":"acme-client","name":"ACME client","note":"Gets and renews certificates from a CA over ACME (RFC 8555): a tool such as certbot, or the client built into a server.","short":"ACME client"},{"slug":"code-signer","name":"Code-signing tool or service","note":"Signs software for others to check: a signing tool such as apksigner or cosign, or a signing service.","short":"Code signer"},{"slug":"root-of-trust","name":"Root of trust or bootloader","note":"Checks firmware before it runs or installs: a boot ROM, root-of-trust IP such as Caliptra, a TPM, or a bootloader.","short":"Root of trust"},{"slug":"endpoint","name":"A specific service endpoint we observe","note":"github.com's SSH server, a cloud API host.","short":"Endpoint"}],"functions":[{"slug":"key-establishment","name":"Key establishment (confidentiality)"},{"slug":"authentication","name":"Authentication"}],"capabilities":[{"slug":"tls.kex","name":"TLS key exchange","note":"Which PQ key exchange groups does it use in TLS 1.3 over TCP?","functions":["key-establishment"]},{"slug":"quic.kex","name":"QUIC key exchange","note":"Which PQ key exchange groups does it use in QUIC / HTTP/3?","functions":["key-establishment"]},{"slug":"dtls.kex","name":"DTLS key exchange","note":"Which PQ key exchange groups does it use in DTLS (WebRTC)?","functions":["key-establishment"]},{"slug":"tls.cert.verify","name":"Verifies PQ certificates in TLS","note":"Will it accept a peer that authenticates with a PQ certificate chain, and trusted how?","functions":["authentication"]},{"slug":"tls.cert.present","name":"Presents PQ certificates in TLS","note":"Can it be configured with a PQ key and certificate and authenticate with them?","functions":["authentication"]},{"slug":"x509.verify","name":"Validates PQ certificate paths","note":"Can it validate X.509 paths signed with PQ algorithms?","functions":["authentication"]},{"slug":"x509.issue","name":"Issues PQ certificates","note":"Can it issue certificates signed with, or certifying, PQ keys, and trusted by whom?","functions":["authentication"]},{"slug":"mtc.issue","name":"Issues Merkle Tree Certificates","note":"Does it issue MTCs, and trusted by whom?","functions":["authentication"]},{"slug":"mtc.verify","name":"Verifies Merkle Tree Certificates","note":"Does it accept MTCs?","functions":["authentication"]},{"slug":"mtc.present","name":"Serves Merkle Tree Certificates","note":"Can it serve MTCs, choosing them by the client's trust anchor IDs?","functions":["authentication"]},{"slug":"keys.generate","name":"Generates PQ keys","note":"Can it generate and hold PQ keys?","functions":["key-establishment","authentication"]},{"slug":"keys.sign","name":"Signs with PQ keys","note":"Can it sign with PQ keys it holds?","functions":["authentication"]},{"slug":"keys.kem","name":"Encapsulates with PQ keys","note":"Can it encapsulate/decapsulate with PQ KEM keys it holds?","functions":["key-establishment"]},{"slug":"keys.wrap","name":"Wraps PQ keys","note":"Can PQ private keys leave it wrapped, for backup, cloning or export, and come back in?","functions":["key-establishment","authentication"]},{"slug":"ssh.kex","name":"SSH key exchange","note":"Which PQ key exchange methods does it use in SSH?","functions":["key-establishment"]},{"slug":"ssh.hostkey","name":"SSH PQ host keys","note":"Does it present (server) or verify (client) PQ host keys?","functions":["authentication"]},{"slug":"ssh.userkey","name":"SSH PQ user keys","note":"Does it present (client) or verify (server) PQ user keys?","functions":["authentication"]},{"slug":"ike.kex","name":"IKEv2 key exchange","note":"Which PQ key exchange methods does it use in IKEv2, in IKE_SA_INIT or as an additional key exchange (RFC 9370)?","functions":["key-establishment"]},{"slug":"ike.auth","name":"IKEv2 PQ authentication","note":"Can it authenticate to an IKEv2 peer with a PQ signature (RFC 7427), and verify a peer that does?","functions":["authentication"]},{"slug":"ike.ppk","name":"IKEv2 PQ preshared keys","note":"Can it mix a post-quantum preshared key into IKEv2 (RFC 8784), and can the key come from QKD?","functions":["key-establishment"]},{"slug":"wg.kex","name":"WireGuard PQ key exchange","note":"Which automated PQ key exchange fills the preshared-key slot of its WireGuard tunnels?","functions":["key-establishment"]},{"slug":"wg.psk","name":"WireGuard preshared keys","note":"Can an operator set a preshared key on its WireGuard tunnels by hand?","functions":["key-establishment"]},{"slug":"macsec.psk","name":"MACsec preshared keys","note":"Can a preshared key that resists a quantum attacker key its MACsec links, and can the key come from QKD?","functions":["key-establishment"]},{"slug":"tls.inspect","name":"Inspects PQ TLS","note":"What does it do with a PQ ClientHello it is set to inspect?","functions":["key-establishment"]},{"slug":"web.crypto","name":"Web Crypto API","note":"Which PQ algorithms does it expose through the Web Crypto API (SubtleCrypto), to web pages or to a runtime's scripts?","functions":["key-establishment","authentication"]},{"slug":"webpki.trust","name":"PQ public trust","note":"Does it trust PQ anchors for the public web, by what mechanism and at what stage?","functions":["authentication"]},{"slug":"codesign.sign","name":"Signs code with PQ signatures","note":"Can it sign software, packages or firmware with a PQ signature, and in which format?","functions":["authentication"]},{"slug":"codesign.verify","name":"Verifies PQ code signatures","note":"Does it verify a PQ signature on software, packages or firmware before it installs, loads or runs them?","functions":["authentication"]},{"slug":"codesign.publish","name":"Ships PQ-signed software","note":"Does its vendor sign the software it ships with a PQ signature?","functions":["authentication"]},{"slug":"acme.keys","name":"PQ certificate keys over ACME","note":"Does it make a PQ key and request a certificate for it over ACME (client), or issue one for a PQ key over ACME (CA)?","functions":["authentication"]},{"slug":"acme.ari","name":"ACME Renewal Information","note":"Does it renew when the CA says to, by ACME Renewal Information (RFC 9773), or offer that window as a CA?","functions":["authentication"]},{"slug":"acme.profiles","name":"ACME Profiles","note":"Can it request a certificate profile that the CA advertises (client), or advertise profiles as a CA?","functions":["authentication"]},{"slug":"api.kem","name":"PQ KEMs as an API","note":"Which PQ KEMs can a program call through its API, apart from any protocol?","functions":["key-establishment"]},{"slug":"api.sign","name":"PQ signatures as an API","note":"Which PQ signature algorithms can a program sign with (signer) or verify (verifier) through its API, apart from any protocol?","functions":["authentication"]},{"slug":"hpke.kem","name":"PQ KEMs in HPKE","note":"Which PQ KEMs does its HPKE (RFC 9180) have, for a program to seal to a public key and to open with the private key?","functions":["key-establishment"]},{"slug":"ech.kem","name":"PQ KEMs in ECH","note":"Which PQ HPKE KEMs does its Encrypted Client Hello (RFC 9849) take: in an ECHConfig it accepts as a client, or with a key it holds as a server?","functions":["key-establishment"]},{"slug":"ohttp.kem","name":"PQ KEMs in OHTTP","note":"Which PQ HPKE KEMs does its Oblivious HTTP (RFC 9458) take: in a key configuration it accepts as a client, or in one it publishes as a gateway?","functions":["key-establishment"]},{"slug":"report.kex","name":"Reports the key exchange","note":"Does it tell its operator which key exchange a session negotiated, so that a PQ session can be told from a classical one?","functions":["key-establishment"]},{"slug":"report.auth","name":"Reports the authentication","note":"Does it tell its operator which signature scheme, or which certificate key, authenticated a session, so that a PQ one can be told from a classical one?","functions":["authentication"]}],"profiles":[{"slug":"cnsa-2.0","name":"CNSA 2.0","note":"NSA"},{"slug":"bsi-tr-02102","name":"BSI TR-02102-1","note":"BSI"},{"slug":"asd-ism","name":"ASD ISM","note":"ASD"},{"slug":"ncsc-uk","name":"NCSC PQC guidance","note":"NCSC"}],"targets":["adopt","configure","trial"],"audiences":[{"slug":"federal-agencies","name":"US federal agencies","note":"Executive agencies, for systems other than National Security Systems."},{"slug":"national-security-systems","name":"US National Security Systems","note":"Owners and operators of National Security Systems, which CNSSP-15 governs."},{"slug":"defense","name":"US Department of War","note":"The department's own systems, of every kind."},{"slug":"contractors","name":"US federal contractors","note":"Companies that hold federal contracts, through the acquisition rules."},{"slug":"government","name":"Government bodies","note":"The departments and agencies of the region's own government."},{"slug":"member-states","name":"Member states","note":"The states of a union or a group, which then act at home."},{"slug":"critical-infrastructure","name":"Critical infrastructure","note":"Owners and operators of critical infrastructure."},{"slug":"financial-sector","name":"Financial sector","note":"Banks and other regulated financial firms."},{"slug":"vendors","name":"Vendors","note":"Makers of products that seek a certification, or that sell to those a deadline binds."},{"slug":"certificate-authorities","name":"Certificate authorities","note":"Publicly trusted CAs, under a root program or the CA/Browser Forum."},{"slug":"card-payments","name":"Payment card industry","note":"Merchants and service providers that handle payment card data, under PCI DSS."},{"slug":"organizations","name":"Every organization","note":"Any organization in the region, public or private."},{"slug":"issuer","name":"The issuer","note":"The body that set the date, for its own work."}],"places":[{"slug":"us","name":"United States"},{"slug":"eu","name":"European Union"},{"slug":"uk","name":"United Kingdom"},{"slug":"de","name":"Germany"},{"slug":"fr","name":"France"},{"slug":"it","name":"Italy"},{"slug":"ca","name":"Canada"},{"slug":"au","name":"Australia"},{"slug":"jp","name":"Japan"},{"slug":"kr","name":"South Korea"},{"slug":"sg","name":"Singapore"},{"slug":"in","name":"India"},{"slug":"hk","name":"Hong Kong"},{"slug":"cn","name":"China"}],"channels":[{"slug":"record","name":"A record per session","note":"A log line or an event for each session. An operator can ask afterwards which sessions were not PQ."},{"slug":"live","name":"A view of a live session","note":"A panel, a dialog or a show command for a session that is open. It serves a spot check, and is gone when the session ends."},{"slug":"counter","name":"A counter","note":"A count of sessions by group or by scheme, with no link to any one session."},{"slug":"api","name":"An API","note":"A call that the program around a library makes. A user sees nothing unless that program prints it."}],"shown":[{"slug":"scheme","name":"The handshake's signature scheme","note":"The scheme that signed the handshake: a TLS SignatureScheme, an SSH host key algorithm, an IKEv2 authentication method."},{"slug":"cert-key","name":"The certificate's key algorithm","note":"The algorithm of the key in the peer's or the product's own certificate. For ML-DSA it implies the scheme."}],"bindings":[{"slug":"mandatory","name":"Mandatory","note":"A law, an executive order or a binding policy, for those it covers."},{"slug":"contractual","name":"Contractual","note":"An industry standard that contracts enforce."},{"slug":"commitment","name":"Commitment","note":"A joint roadmap that its members agreed to."},{"slug":"guidance","name":"Guidance","note":"A recommendation from an authority."},{"slug":"proposed","name":"Proposed","note":"A draft that is not in force."},{"slug":"plan","name":"Plan","note":"A date a body gives for its own work."}],"scopes":[{"slug":"plan","name":"A plan or an inventory","note":"The date is for a plan, a named lead or an inventory. No system has to change by it."},{"slug":"new-acquisitions","name":"New purchases","note":"What is bought or put out to tender from the date. What is in use stays."},{"slug":"new-products","name":"New products","note":"Products and software built, certified or placed on the market from the date."},{"slug":"new-issuance","name":"New certificates and keys","note":"Certificates and keys issued from the date. Those issued before it run to their expiry."},{"slug":"new-protection","name":"New signatures and encryption","note":"The act of signing or encrypting from the date. Verifying and decrypting what exists stays allowed."},{"slug":"priority-systems","name":"Priority systems in use","note":"Systems in use that the instrument ranks first, such as high-value assets or high-risk use cases."},{"slug":"all-systems","name":"All systems in use","note":"Every system the instrument covers, whatever its age."},{"slug":"issuer","name":"The issuer's own work","note":"A date the issuer sets for its own work, such as a standard or a rule."}]}
