Field assets built for forty years, on cryptography that expires in ten.
Protect SCADA, substation and control-centre links in place with post-quantum mutual TLS, meet NERC CIP encryption requirements without a truck roll, and keep an inventory the auditor can read.
Q-day is uncertain. The requirements for energy and grid are not.
Nobody knows when a cryptographically relevant quantum computer will arrive (Q-day), but your cryptography requirements do not depend on that date. Four reasons to start now:
AI is already finding weaknesses in algorithms
Anthropic’s Claude Mythos preview found serious weaknesses in candidate algorithms without a quantum computer. Cryptography can fail before Q-day arrives.
Adversaries are harvesting encrypted data now
They are collecting grid topology and control traffic which keep their value for years, to decrypt when Q-day arrives: harvest now, decrypt later.
Regulators already require PQC migration
For a grid operator that means the encrypted remote access, protected BES information and protected control-centre communication NERC CIP-005, CIP-011 and CIP-012 require, the segmentation the TSA pipeline directives ask designated operators for, and the inventory the CISA, NSA and NIST quantum-readiness roadmap starts from.
Estimates for Q-day keep shrinking
Google has set 2029 as the target for its own migration. If yours is not finished in time, the foundation of SCADA, remote access and control-centre links is at risk.
Google’s 2029 target and resource estimates: QuSecure, April 2026. NIST IR 8547, initial public draft, November 2024. Anthropic, Claude Mythos preview, 2026.
Why use QuProtect?
Cryptography belongs in a layer you control and configure, not in application code.
No rewrite, no rip-and-replace
QuProtect moves critical and legacy systems to PQC in a fraction of the time and cost.
Discovery and remediation in one platform
Many PQC solutions stop at discovery and leave the fix to you.
Built for large, complex organizations with highly sensitive traffic
Developed with the U.S. Army and U.S. Air Force.
Nothing is re-coded
A grid operator cannot take control systems down to re-code them, so QuProtect does not ask for it.
The next migration is a configuration change
It is made from an Orchestrator you control, not run as another program.
Proven in production
Banco Sabadell validated post-quantum TLS in four months.
Use case in action
Your network, from the cryptography it runs today to the policy change that keeps it current. Move through the five steps, or click a number on the drawing.
-
Substations and DER
- RTUs, IEDs and relays cannot be upgraded
- DER telemetry (solar, storage)
- AMI head-end cannot be upgraded
-
Control centre
- SCADA and EMS cannot be upgraded
- Historian
- Backup control centre
-
Corporate IT
- Engineering workstations
- Asset management and CMDB
- Regulatory reporting
Legacy cryptography, and what Q-day does to it
Relays, RTUs and the AMI head-end reach SCADA on protocols older than TLS 1.2, and the control centre reaches engineering and corporate systems on TLS 1.2 with RSA key exchange. Traffic recorded today can be stored until a quantum computer running Shor’s algorithm recovers those keys, grid topology keeps its value for years, and a forged control command would pass as genuine.
Sensors find the legacy negotiations and rank the violations
Reconnaissance sensors read what is on the OT WAN and record the protocols, cipher suites, certificates and keys in use, without touching a relay or a meter. Each policy violation is ranked by severity: the substation hops first, RSA key exchange between the control centre and corporate IT next.
Encryptors remediate at the network layer
A gateway at each substation boundary and sidecars beside SCADA, the historian and the backup control centre carry each hop over TLS 1.3 with NIST post-quantum key exchange, X25519MLKEM768. No firmware change on the field devices, and no truck roll.
Data in transit is secured, and the CBOM proves it
Control traffic recorded from now on is not readable by a future quantum computer, and a command that did not come from the control centre does not verify. The CBOM lists each connection’s protocol, algorithm and certificate with no open violations, with the asset owner and criticality the NERC audit asks for.
Crypto-agility: the next algorithm is a policy change
When federal guidance moves the algorithms again, the Orchestrator pushes the new policy to each encryptor and the connections renegotiate, here from ML-KEM-768 to ML-KEM-1024, while the grid keeps running. It is a policy push, not a capital plan.
Other use cases
Cryptographic inventory across IT and OT
A CBOM of what substations, control centres and corporate systems negotiate, the first step of the CISA, NSA and NIST quantum-readiness roadmap.
Protected control-centre links (CIP-012)
SCADA and EMS traffic between control centres runs post-quantum mTLS without touching the applications.
DER and telemetry links
Solar, storage and feeder telemetry into the control centre carried over protected connections.
Evidence for the NERC audit
Logged handshakes and a CBOM with asset owner and criticality, exported to the compliance workflow.
Encrypted remote access to substations (CIP-005)
Gateway encryptors at each site carry engineering and vendor access over post-quantum mutual TLS.
Field OT protected without a truck roll
RTUs, IEDs, relays and AMI head-ends sit behind gateway encryptors; the devices are not changed.
Device and system certificates
Automated provisioning and rotation for the identities on the OT WAN.
Algorithm change by policy
When federal guidance moves the algorithms again, the change is a policy push, not a capital plan.
Energy and grid case study
Post-quantum encryption on SCADA and industrial controls.
A national oil company piloted post-quantum encryption for exploration data, protecting SCADA systems and industrial controls at the network layer.