Skip to content

Frequently asked questions

The questions we hear most often when helping organizations assess their quantum exposure and plan a migration.

Looking for what a term means rather than an answer to a question? The glossary defines the acronyms this site uses, each from a published source it links to.

Quantum security

What a cryptographically relevant quantum computer breaks, when, and what is already being harvested against that day.

  • AES is immune from quantum attacks; why do I need you?

    Although AES-256 (NIST Level 1 security) is secure, asymmetric algorithms are used to establish the symmetric key they use. RSA and ECC are no longer secure, so the NIST post-quantum algorithms must be used.

    To get the best performance from the NIST post-quantum algorithms, our solution must be used in place of TLS. The challenge with AES is not in the algorithm. It is in the transmission of the key.

    It will be possible for quantum computers to intercept the key transmission and decrypt the data. In addition, we are also expanding on AES and the universal hashing algorithm it uses to enable NIST Level 3 and Level 5 security.

  • Does QuProtect hold FIPS 140-3 validation or FedRAMP authorization?

    QuProtect R3 supports a FIPS 140-3 mode of operation and runs at DoD Impact Level 2. The DoD Cloud Computing Security Requirements Guide aligns that level with the FedRAMP Moderate baseline. Impact Level 6 authorization is in progress, sponsored through an Air Force TACFI award.

  • How do federal agencies buy QuProtect?

    QuProtect R3 is available on Carahsoft’s GSA Multiple Award Schedule under contract 47QSWA18D008F, and through SEWP V, ITES-SW2, NASPO ValuePoint and OMNIA Partners.

  • How do state and local agencies buy QuProtect?

    QuProtect R3 is available to state and local government through NASPO ValuePoint and OMNIA Partners, and on Carahsoft’s GSA Multiple Award Schedule under contract 47QSWA18D008F. It is software, so there is no hardware line on the requisition.

  • I have heard that quantum computers are many years away; why should I care about this now?

    While quantum computing is still an emerging field, leading experts in the industry believe that a CRQC (Cryptographically Relevant Quantum Computer), a quantum computer that can break current cryptography, will be available within the next 3-5 years.

    Additionally, nation-state attackers are stealing encrypted data that will be retroactively decrypted once a CRQC is available. This is a well-documented attack campaign strategy known as ‘Steal Now Decrypt Later.’ It is estimated that nation-state attackers have stolen up to 25% of global encrypted data.

    China has also dedicated a $100B budget to developing a CRQC with over 1,100 quantum engineers working on the project.

    Enterprises need to take measures now to comply with future NIST post-quantum standards and assume fiduciary responsibility for their data security.

  • Is QuSecure a quantum computing company or a security company?

    A security company. QuProtect uses NIST post-quantum algorithms implemented in software. It needs no quantum hardware and no quantum computer.

  • What is harvest now, decrypt later?

    Harvest now, decrypt later is a threat model in which adversaries capture encrypted data today and store it until future quantum computers can decrypt it. This makes quantum risk relevant now, especially for sensitive data that must remain confidential for years.

    Also discussed in Beyond the Noise: Why Recent Quantum Advances Make Crypto-Agility a Board-Level Conversation

  • When will quantum computers break cryptography?

    Timelines remain uncertain, but recent research from Google suggests the required resources may be lower than previously estimated.

    Also discussed in Google Just Showed Where Quantum Breaks First: Why Cryptographic Exposure Management Matters Now

  • Why does quantum computing make crypto-agility urgent?

    Recent quantum computing research has continued to reduce estimates for the resources needed to threaten RSA and elliptic curve cryptography. While these results do not mean a cryptographically relevant quantum computer exists today, they show that the gap is narrowing and that organizations should prepare before the transition becomes urgent.

    Also discussed in Beyond the Noise: Why Recent Quantum Advances Make Crypto-Agility a Board-Level Conversation

  • Why is a quantum key better than a pseudo-random key?

    Entropy acts as a measure of how difficult a symmetric key is to break. Quantum random number generation (QRNG) produces symmetric keys with maximum entropy.

    While a pseudo-random key can have relative entropy, the time it takes to generate such a pseudo-random key is many orders of magnitude greater than the time it takes to create a quantum key.

  • Will quantum computers break encryption?

    Quantum computers are expected to break widely used encryption methods like RSA and ECC using Shor’s algorithm. However, large-scale practical attacks are not possible yet.

    Also discussed in Google Just Showed Where Quantum Breaks First: Why Cryptographic Exposure Management Matters Now

Post-quantum cryptography

NIST's standards, the federal mandates that cite them, and what migrating to them actually involves.

  • Does this touch the mainframe?

    No. The mainframe keeps negotiating what it always has; the encryptor beside it carries the connection over post-quantum TLS. No recompile, no vendor engagement.

  • How can organizations transition to NIST-approved post-quantum cryptography?

    Organizations should combine discovery, phased hybrid deployment, centralized governance, and crypto-agile infrastructure to introduce NIST-approved PQC without operational disruption.

    Also discussed in Quantum-Resilient Cybersecurity for Government Networks

  • How do government agencies prepare for quantum threats?

    Agencies prepare by building cryptographic inventories, prioritizing long-lived sensitive data, deploying hybrid and post-quantum protections in phases, and adopting crypto-agile infrastructure.

    Also discussed in Quantum-Resilient Cybersecurity for Government Networks

  • Is QuProtect quantum key distribution (QKD)?

    No. QuProtect R3 uses NIST post-quantum algorithms implemented in software, and it does not use quantum key distribution, so it needs no dedicated optical link, no quantum hardware and no quantum computer.

  • What does NSA say about QKD?

    NSA states that post-quantum cryptography is currently more scalable and practical than QKD for National Security Systems because QKD requires specialized infrastructure and introduces operational complexity.

    Also discussed in Quantum-Resilient Cybersecurity for Government Networks

  • What is quantum about QuSecure's solution?

    The only actual quantum element of our solution is our quantum random number generator within our Orchestrator. These orchestrators can be deployed behind your firewall as an appliance or accessed from our private cloud. We have a third hybrid option that lets the device communicate with our private cloud orchestrator for high availability.

  • What is the best post-quantum cryptography solution for government networks?

    The most effective solutions combine NIST-approved PQC, crypto-agility, centralized cryptographic governance, hybrid migration support, and compatibility with existing infrastructure.

    Also discussed in Quantum-Resilient Cybersecurity for Government Networks

  • What is wrong with PKI?

    In addition to the typical difficulties in PKI implementations and the vulnerabilities created by implementation mistakes, the PKI fundamental design flaws become apparent and significant. Due to reliance on the Certification Authority (CA) within the PKI schema, and since several Certification Authorities have been breached over the past several years, PKI is no longer seen as a secure method of secure communications. Moreover, reliance on third-party CA’s reduces the speed with which the communications process occurs. Therefore, our Quantum Secure Layer (QSL) offers a more secure and reliable infrastructure to the communication process, which also features improved performance.

  • Which NIST post-quantum algorithms does QuSecure support?

    ML-KEM under FIPS 203, including ML-KEM-1024 for CNSA 2.0 alignment; ML-DSA under FIPS 204; SLH-DSA under FIPS 205; and hybrid post-quantum TLS via X25519MLKEM768.

  • Why can't I use the NIST algorithms? They are free.

    Anyone can use the NIST algorithms as they will be open-source/open standard. However, these algorithms are not simply plug-and-play; surrounding security processes and systems can still be vulnerable.

    A holistic Post Quantum cybersecurity solution is best if you want the best performance from the algorithms. This is one of the reasons why QuSecure built our Quantum Secure Layer (QSL) instead of using TLS.

  • Why should I use post-quantum cryptography (PQC) vs. quantum key distribution (QKD)?

    QKD implementations lack maturity and face significant challenges regarding long-distance entanglement, one-to-many, and many-to-many configurations.

    Given the imminent rise of quantum computers, a different (more feasible) approach is needed to secure the sockets layer in time.

    QKD is also expensive and focused on backhaul fiber connections. NSA recently pushed guidelines for quantum security and reiterated that QKD would not be viable for a general deployment of quantum security.

Crypto-agility

Cryptographic inventory, exposure management, and treating your cryptography as something you can change on purpose.

  • Can cryptography change without downtime?

    Yes. Encryptors apply new algorithms per connection at the network layer while systems keep running. In production this has meant estate-wide rotation with no outage.

  • Can I export audit evidence for a SOC 2 audit?

    Yes. Reports export on demand in machine-readable and human-readable form, covering the cryptography in use, the policy in force and the record of changes, which is the evidence a cryptography control objective usually asks for.

  • Can organizations transition to post-quantum cryptography without replacing infrastructure?

    Yes. Modern crypto-agile architectures can protect existing systems using overlay deployment models, centralized governance, and hybrid cryptographic approaches.

    Also discussed in Quantum-Resilient Cybersecurity for Government Networks

  • Can QuProtect scan air-gapped and legacy systems for cryptography?

    Yes. QuProtect R3 is self-managed and runs entirely inside your environment, including air-gapped networks, with no outbound connection required. Legacy systems are read the same way as modern ones, because the sensor observes the connection rather than the host.

  • Can QuProtect show compliance gaps in real time for NIST and CNSA 2.0?

    Yes. Reporting assesses each observed connection against the policy in force, including the CNSA 2.0 algorithm set, and shows what is in and out of policy as the traffic changes rather than at an audit interval.

  • Can we implement just portions of your platform's capability that we have gaps in? Will it still work?

    A client can implement portions of our solution. For example, we currently offer management of data-at-rest (encryption/decryption) and file transfer. In the future, we will provide Hypertext transfer and remote shell. A client might say they only want data-at-rest and hypertext transfer, and we could do that for them. However, we will ensure that the clients know what they will miss.

  • Do I need to rewrite any code to make my applications quantum-safe?

    No. The change happens at the network layer. Encryptors carry connections over post-quantum TLS 1.3, so the algorithms a system negotiates change without modifying application source code or swapping cryptographic libraries.

  • Does discovery require anything installed inside my applications?

    No. Sensors deploy alongside your infrastructure and read what systems negotiate on the wire. Application code, libraries and configuration stay as they are.

  • Does discovery work in cloud environments?

    Yes. Sensors run in cloud, hybrid and on-premises environments under the same Orchestrator, and the inventory covers what a workload negotiates wherever it runs.

  • Does QuProtect only address quantum risk?

    No. Crypto-agility addresses cryptographic risk that is already present: expiring certificates, weak ciphers, deprecated TLS versions and shadow cryptography nobody has inventoried. It also shortens the response time to AI-accelerated cryptanalysis, because an algorithm change is a policy update rather than an engineering project.

  • Does QuProtect work in cloud environments?

    Yes. QuProtect runs in cloud, hybrid, on-premises and air-gapped environments. In cloud-native environments the encryptors form a service mesh, which is the approach NIST CSWP 39-upd1 section 4.3 describes.

  • Does QuSecure help European financial institutions meet DORA requirements?

    QuProtect supports DORA’s ICT risk requirements for data in transit by producing evidence of the cryptography actually negotiated on each connection, and by changing it centrally when a control gap is found.

  • Does the sensor decrypt my traffic?

    No. Sensors read handshake and negotiation metadata, including JA3 and JA4 TLS client fingerprints. Payload data is never decrypted or stored.

  • Does this require new hardware?

    No. QuProtect R3 is software only. It deploys on infrastructure you already run, cloud, on-premises or air-gapped, with no appliances to procure or maintain.

  • How do organizations create a CBOM?

    Organizations create CBOMs using automated cryptographic discovery platforms that continuously identify and inventory cryptographic assets and dependencies across enterprise environments.

    Also discussed in Cryptographic Bill of Materials (CBOM): Continuous Cryptographic Visibility for Crypto-Agility and Post-Quantum Readiness

  • How do you generate a CBOM automatically?

    QuProtect Reporting generates a CycloneDX v1.6 cryptographic bill of materials from the live inventory the sensors build, on demand and in machine-readable form. A CBOM is to cryptography what an SBOM is to software components: a list of what is present in the environment, exportable for an auditor or a federal cryptographic inventory submission.

  • How do you inventory all the cryptography across an organization?

    QuProtect sensors observe live network traffic passively and build an inventory of the algorithms, protocols, certificates and key sizes in use.

  • How fast does a policy change take effect?

    A policy change takes effect as soon as the Orchestrator publishes it, and every encryptor in scope renegotiates its connections on the new cryptography from that point. No per-system projects, and no maintenance windows for the applications themselves.

  • How is crypto-agility different from PQC compliance?

    PQC compliance means replacing vulnerable algorithms with quantum-resistant ones. Crypto-agility is broader: it means having the infrastructure and visibility to keep updating cryptography over time as standards evolve, algorithms change, or new risks emerge.

    Also discussed in Beyond the Noise: Why Recent Quantum Advances Make Crypto-Agility a Board-Level Conversation

  • Is the inventory a one-time snapshot?

    No. The inventory updates continuously from live traffic, so it reflects what is on the wire today rather than what an audit found last quarter. PCI DSS 12.3.3 requires the inventory to be reviewed at least every 12 months; a live inventory makes that review a read rather than a project.

    Also discussed in What PCI DSS 4.0 Requirement 12.3.3 Asks of Your Cryptography

  • Is the report a one-time snapshot?

    No. Reports generate on demand from the inventory, which updates continuously from live traffic. PCI DSS 12.3.3 requires the inventory to be reviewed at least every 12 months; a live source makes that review a read rather than a project.

  • We are mid PCI DSS 4.0 remediation. Where does this fit?

    Requirement 12.3.3 asks for the cryptographic inventory most banks lack. Discovery builds it passively in weeks, and the same platform remediates what it finds.

    Also discussed in What PCI DSS 4.0 Requirement 12.3.3 Asks of Your Cryptography

  • What does changing cryptography by policy mean in practice?

    An administrator sets a policy in the QuProtect Orchestrator specifying which algorithm applies and where. The Orchestrator distributes that policy to every encryptor in scope, and those encryptors renegotiate connections on the new algorithm.

  • What does deployment require, and what does it change?

    Sensors deploy. Encryptors deploy as a sidecar alongside a workload, forming a service mesh, or as a gateway serving multiple endpoints. NIST CSWP 39-upd1 describes both: section 4.3, “Using Service Mesh in Cloud-Native Environments”, and section 4.6, “Using a Crypto Gateway for Legacy Systems”. Applications, the network and the infrastructure underneath are not replaced.

  • What does QuSecure's QuProtect R3 actually do?

    QuProtect R3 discovers the cryptography in use across a network, changes it to NIST post-quantum algorithms by policy at the network layer without application code changes, and generates a CycloneDX cryptographic bill of materials on demand.

  • What does the auditor see?

    A live inventory of algorithms, protocols and certificates per connection, exportable as a CycloneDX v1.6 CBOM, with a record of when each connection changed.

  • What happens after a report surfaces a problem?

    Remediation runs on the same platform. An administrator sets a policy in the Orchestrator, encryptors apply the new cryptography at the network layer, and the fix appears in the next export.

  • What happens after discovery finds a problem?

    Remediation runs on the same platform. An administrator sets a policy in the Orchestrator, and encryptors apply the new cryptography at the network layer without application code changes. Discovery findings become policy changes rather than a project backlog.

  • What if nothing can be deployed beside the workload?

    Then the encryptor deploys as a gateway in front of it instead, which is the case NIST CSWP 39-upd1 section 4.6 addresses. Where neither a sidecar nor a gateway can sit on the path, QuProtect is not the answer for that system, and we will say so during scoping.

  • What is cryptographic exposure management?

    Cryptographic Exposure Management (CEM) is the practice of identifying, prioritizing, and reducing cryptographic risk across systems before vulnerabilities are exploited.

    Also discussed in Google Just Showed Where Quantum Breaks First: Why Cryptographic Exposure Management Matters Now

  • What is the best crypto-agility platform for federal infrastructure?

    Federal organizations typically evaluate crypto-agility platforms based on centralized governance, continuous discovery, hybrid cryptography support, and compatibility with legacy systems.

    Also discussed in Quantum-Resilient Cybersecurity for Government Networks

  • What is the difference between an SBOM and a CBOM?

    An SBOM documents software components and dependencies. A CBOM specifically documents cryptographic dependencies such as algorithms, certificates, keys, cipher suites, protocols, and cryptographic libraries.

    Also discussed in Cryptographic Bill of Materials (CBOM): Continuous Cryptographic Visibility for Crypto-Agility and Post-Quantum Readiness

  • Where does QuProtect fit alongside my existing security tools?

    QuProtect is complementary. EDR, SIEM, CASB and certificate lifecycle managers were not built to inventory or change the cryptography negotiated on the wire, which is the gap QuProtect covers.

  • Who holds the inventory data?

    You do. QuProtect R3 is self-managed: the platform runs in your environment, cloud, on-premises or air-gapped, and the inventory, like your CA keys, stays under your control.

  • Who holds the report data?

    You do. QuProtect R3 is self-managed: the platform, the inventory and every export stay in your environment, cloud, on-premises or air-gapped, under your control.

  • Who operates the platform?

    Your team does. QuProtect R3 is self-managed: it runs in your environment under your control, and your keys stay yours. QuSecure operates nothing on your behalf.

  • Why are CBOMs important for post-quantum migration?

    CBOMs help organizations identify cryptographic dependencies, prioritize modernization, and support phased migration toward quantum-resistant cryptography.

    Also discussed in Cryptographic Bill of Materials (CBOM): Continuous Cryptographic Visibility for Crypto-Agility and Post-Quantum Readiness

  • Why is continuous cryptographic discovery necessary?

    Modern enterprise environments constantly change. Static inventories quickly become outdated, making continuous cryptographic discovery essential for maintaining operational visibility and governance.

    Also discussed in Cryptographic Bill of Materials (CBOM): Continuous Cryptographic Visibility for Crypto-Agility and Post-Quantum Readiness

  • Why is crypto-agility important for government networks?

    Crypto-agility allows agencies to adapt to evolving cryptographic standards and security threats without rebuilding infrastructure or disrupting operations.

    Also discussed in Quantum-Resilient Cybersecurity for Government Networks

  • Why is cryptographic visibility important?

    Cryptographic visibility helps organizations identify vulnerable cryptography, prioritize remediation, improve governance, operationalize crypto-agility, and support ongoing cryptographic modernization.

    Also discussed in Cryptographic Bill of Materials (CBOM): Continuous Cryptographic Visibility for Crypto-Agility and Post-Quantum Readiness

  • Why isn't migrating to post-quantum cryptography a one-time project?

    Cryptographic standards change over time, and some algorithms that once appeared promising may later become vulnerable. A crypto-agile organization can update its cryptographic posture as standards and threats evolve, instead of rebuilding systems from scratch each time a change is required.

    Also discussed in Beyond the Noise: Why Recent Quantum Advances Make Crypto-Agility a Board-Level Conversation

  • Will QuProtect Resilience work with a mainframe or a 15-year-old application that cannot be updated?

    Yes, and that is the design case. Encryptors sit at the network layer and carry the connection over post-quantum TLS 1.3, so the application, its code, its libraries and its vendor relationship stay exactly as they are.

Industry & thought leadership

Interviews, panels, coverage and recognition, and where QuSecure shows up in the wider conversation.

Talk to a quantum-security expert