Is It Quantum Safe?
Evidence-scoped reference for 58 algorithms, protocols, and implementation-dependent technologies. Each entry separates NIST standards, draft transition context, implementation evidence, and residual unknowns.
Key Takeaway: The collection contains 7 standards-backed safe entries, 11 not-safe entries, 4 partial or in-transition entries, and 36 implementation-dependent entries that require measured assessment. NIST IR 8547 is an initial public draft, while CNSA 2.0 dates are scoped to National Security Systems and related contexts.
Post-Quantum Standards
NIST-standardized post-quantum cryptography algorithms
ML-KEM
Module-Lattice-Based Key-Encapsulation Mechanism (FIPS 203)
ML-KEM is NIST's standardized post-quantum key-encapsulation mechanism in FIPS 203.
ML-DSA
Module-Lattice-Based Digital Signature Algorithm (FIPS 204)
ML-DSA is NIST's standardized module-lattice digital-signature algorithm in FIPS 204.
SLH-DSA
Stateless Hash-Based Digital Signature Algorithm (FIPS 205)
SLH-DSA is NIST's standardized stateless hash-based signature algorithm in FIPS 205.
Encryption
Symmetric and asymmetric encryption
RSA-2048
RSA with 2048-bit keys
No.
RSA-4096
RSA with 4096-bit keys
No.
RSA-1024
RSA with 1024-bit keys
No.
AES-256
Advanced Encryption Standard with 256-bit keys
AES-256 is the conservative symmetric choice in current post-quantum planning.
AES-128
Advanced Encryption Standard with 128-bit keys
Context dependent.
3DES
Triple Data Encryption Standard (3DES / TDEA)
No.
Key Exchange
Key agreement and encapsulation
Digital Signatures
Authentication and integrity
Hash Functions
Integrity and fingerprinting
SHA-256
Secure Hash Algorithm 256-bit
SHA-256 remains standardized and has no practical quantum break.
SHA-384
Secure Hash Algorithm 384-bit
SHA-384 remains standardized and provides a large current margin under generic quantum preimage and collision models.
SHA-512
Secure Hash Algorithm 512-bit
SHA-512 remains standardized and provides a large current margin under generic quantum preimage and collision models.
SHA-1
Secure Hash Algorithm 1
No.
MD5
Message Digest Algorithm 5
No.
Protocols
TLS, SSH, IPsec, X.509
TLS 1.3
Transport Layer Security 1.3
Partially.
TLS 1.2
Transport Layer Security 1.2
No.
SSH
Secure Shell Protocol
Partially.
IPsec
Internet Protocol Security
Partially.
X.509 Certificates
X.509 Public Key Infrastructure Certificates
Partially.
Cloud Platforms
Provider paths that require product-, region-, version-, and configuration-level evidence
AWS
Amazon Web Services
Assessment required.
Microsoft Azure
Microsoft Azure Cloud Platform
Assessment required.
Google Cloud
Google Cloud Platform (GCP)
Assessment required.
Oracle Cloud
Oracle Cloud Infrastructure (OCI)
Assessment required.
IBM Cloud
IBM Cloud
Assessment required.
SaaS Platforms
Enterprise services that require measured cryptographic-path evidence
Salesforce
Salesforce CRM and Platform
Assessment required.
ServiceNow
ServiceNow IT Service Management Platform
Assessment required.
Workday
Workday HCM and Financial Management
Assessment required.
SAP
SAP ERP and S/4HANA
Assessment required.
Oracle ERP
Oracle ERP Cloud (Fusion Cloud Applications)
Assessment required.
Communication
Messaging, email, and collaboration paths that require protocol-level assessment
Zoom
Zoom Video Communications
Assessment required.
Microsoft Teams
Microsoft Teams
Assessment required.
Slack
Slack (Salesforce)
Assessment required.
WhatsApp (Meta)
Assessment required.
Signal
Signal Private Messenger
Assessment required.
Chrome
Google Chrome Browser
Assessment required.
iOS
Apple iOS and iMessage
Assessment required.
Email Encryption
Email Encryption (S/MIME, PGP)
Assessment required.
Infrastructure
Operating systems, containers, VPNs, and dependencies that require measured assessment
Cloudflare
Cloudflare CDN and Security
Assessment required.
Akamai
Akamai Technologies CDN and Security
Assessment required.
Fastly
Fastly Edge Cloud Platform
Assessment required.
Bitcoin
Bitcoin Cryptocurrency
Assessment required.
VPN
Virtual Private Network Protocols
Assessment required.
Windows
Microsoft Windows
Assessment required.
Docker
Docker Container Platform
Assessment required.
Kubernetes
Kubernetes Container Orchestration
Assessment required.
Online Banking
Online Banking and Payment Systems
Assessment required.
Databases
Encryption, key management, transport, and signing paths that require measured evidence
MongoDB
MongoDB and MongoDB Atlas
Assessment required.
PostgreSQL
PostgreSQL Database
Assessment required.
MySQL
MySQL and MySQL HeatWave
Assessment required.
Oracle Database
Oracle Database (On-Premises and Cloud)
Assessment required.
Identity
Token, SSO, certificate, and authentication paths that require measured evidence
Okta
Okta Identity and Access Management
Assessment required.
Auth0
Auth0 by Okta
Assessment required.
Ping Identity
Ping Identity
Assessment required.
CyberArk
CyberArk Privileged Access Management
Assessment required.
Know Which Algorithms Are in Your Stack?
Most organizations don't have a complete cryptographic inventory. QScout discovers every algorithm, key, and certificate across your infrastructure in 7 days — 72-hour first findings, low-disruption delivery.