Specifies ML-KEM (formerly CRYSTALS-Kyber), a key-encapsulation mechanism based on the Module Learning With Errors problem. Defines three parameter sets: ML-KEM-512 (NIST Level 1), ML-KEM-768 (Level 3), and ML-KEM-1024 (Level 5).
What Qtonic Quantum Lab evaluates:
- •Correct ML-KEM encapsulation/decapsulation across all parameter sets
- •Known Answer Test (KAT) vector validation against NIST reference
- •Key generation entropy source quality assessment
- +3 more tests
Specifies ML-DSA (formerly CRYSTALS-Dilithium), a digital signature algorithm based on the Module Learning With Errors problem. Defines three parameter sets: ML-DSA-44 (NIST Level 2), ML-DSA-65 (Level 3), and ML-DSA-87 (Level 5).
What Qtonic Quantum Lab evaluates:
- •Correct ML-DSA sign/verify across all parameter sets
- •Known Answer Test (KAT) vector validation against NIST reference
- •Signature non-repudiation verification
- +3 more tests
Specifies SLH-DSA (formerly SPHINCS+), a stateless hash-based digital signature algorithm. Provides conservative security assumptions based solely on hash function properties. Defines 12 parameter sets across SHA-256 and SHAKE variants.
What Qtonic Quantum Lab evaluates:
- •Correct SLH-DSA sign/verify across all 12 parameter sets
- •Known Answer Test (KAT) vector validation against NIST reference
- •WOTS+ chain computation correctness
- +3 more tests
NSA guidance for National Security Systems transitioning to quantum-resistant algorithms. Identifies ML-KEM-1024, ML-DSA-87, and SLH-DSA for relevant NSS profiles and sets staged transition milestones through 2031; applicability depends on system category, mission owner, and governing contract language.
What Qtonic Quantum Lab evaluates:
- •ML-KEM-1024 (Level 5) implementation correctness
- •ML-DSA-87 (Level 5) implementation correctness
- •SLH-DSA support for firmware/software signing use cases
- +3 more tests
Presidential direction for scoped federal actions on quantum-vulnerable cryptography, including inventory reporting and migration prioritization. It is a federal policy anchor, not a universal private-sector PQC mandate.
What Qtonic Quantum Lab evaluates:
- •Cryptographic agility — ability to swap algorithms without code changes
- •Inventory coverage — all cryptographic endpoints discovered
- •Migration readiness — hybrid mode support validated
- +3 more tests
Federal cybersecurity order covering government modernization, software-supply-chain security, and related controls. It is adjacent assurance context for cryptographic implementations, not a PQC migration mandate.
What Qtonic Quantum Lab evaluates:
- •SBOM generation and accuracy for cryptographic dependencies
- •Provenance verification of cryptographic library supply chain
- •FIPS 140-3 validated module usage verification
- +3 more tests
Payment-card security standard with scoped requirements for strong cryptography and key management. PCI DSS v4.0.1 does not itself create a PQC migration mandate; the Lab mapping is forward-looking technical review.
What Qtonic Quantum Lab evaluates:
- •TLS 1.2+ enforcement with strong cipher suites
- •Cryptographic key rotation procedures validation
- •Cardholder data encryption at rest with approved algorithms
- +3 more tests
The HIPAA Security Rule requires safeguards for ePHI. Its current encryption implementation specifications are addressable and risk-based; the rule does not prescribe PQC algorithms.
What Qtonic Quantum Lab evaluates:
- •ePHI encryption in transit using NIST-approved algorithms
- •ePHI encryption at rest using NIST-approved algorithms
- •Access control enforcement on cryptographic key material
- +3 more tests
GDPR Article 32 requires risk-appropriate technical and organizational measures and lists encryption as one possible measure. It does not prescribe PQC or a specific algorithm.
What Qtonic Quantum Lab evaluates:
- •Encryption at rest and in transit using state-of-the-art algorithms
- •Pseudonymization implementation with quantum-resistant mechanisms
- •Data protection impact assessment for long-lived encrypted data
- +3 more tests
POPIA Section 19 requires appropriate, reasonable technical and organizational safeguards. It does not prescribe encryption or PQC; applicability depends on the processing context.
What Qtonic Quantum Lab evaluates:
- •Encryption of personal information using industry-accepted standards
- •Cryptographic integrity controls for data at rest
- •Secure communication channels with quantum-resistant options
- +3 more tests
Singapore PDPA section 24 requires reasonable security arrangements for personal data. It does not prescribe PQC; the Lab mapping tests whether cryptographic controls can remain adequate as threats evolve.
What Qtonic Quantum Lab evaluates:
- •Encryption implementation meeting PDPC guidelines
- •Reasonable security arrangements for personal data protection
- •Cloud encryption controls for Singapore-hosted data
- +3 more tests
LGPD Article 46 requires technical and administrative security measures for personal data. It does not prescribe encryption or PQC; the Lab mapping is a technical risk lens, not a legal determination.
What Qtonic Quantum Lab evaluates:
- •Encryption of personal data meeting ANPD technical guidance
- •Anonymization and pseudonymization using quantum-resistant methods
- •Access control encryption for sensitive personal data categories
- +3 more tests
SWIFT CSP defines mandatory and advisory security controls according to each user architecture. The Lab PQC mapping is readiness analysis and does not assert that every v2026 CSP control mandates PQC.
What Qtonic Quantum Lab evaluates:
- •Payment messaging encryption with NIST-approved PQC algorithms
- •Key management procedures for SWIFT Alliance infrastructure
- •Cryptographic agility for algorithm migration without service disruption
- +3 more tests