Skip to content

Field assets built for forty years, on cryptography that expires in ten.

Protect SCADA, substation and control-centre links in place with post-quantum mutual TLS, meet NERC CIP encryption requirements without a truck roll, and keep an inventory the auditor can read.

Q-day is uncertain. The requirements for energy and grid are not.

Nobody knows when a cryptographically relevant quantum computer will arrive (Q-day), but your cryptography requirements do not depend on that date. Four reasons to start now:

AI is already finding weaknesses in algorithms

Anthropic’s Claude Mythos preview found serious weaknesses in candidate algorithms without a quantum computer. Cryptography can fail before Q-day arrives.

Adversaries are harvesting encrypted data now

They are collecting grid topology and control traffic which keep their value for years, to decrypt when Q-day arrives: harvest now, decrypt later.

Regulators already require PQC migration

For a grid operator that means the encrypted remote access, protected BES information and protected control-centre communication NERC CIP-005, CIP-011 and CIP-012 require, the segmentation the TSA pipeline directives ask designated operators for, and the inventory the CISA, NSA and NIST quantum-readiness roadmap starts from.

Estimates for Q-day keep shrinking

Google has set 2029 as the target for its own migration. If yours is not finished in time, the foundation of SCADA, remote access and control-centre links is at risk.

Google’s 2029 target and resource estimates: QuSecure, April 2026. NIST IR 8547, initial public draft, November 2024. Anthropic, Claude Mythos preview, 2026.

Why use QuProtect?

Cryptography belongs in a layer you control and configure, not in application code.

No rewrite, no rip-and-replace

QuProtect moves critical and legacy systems to PQC in a fraction of the time and cost.

Discovery and remediation in one platform

Many PQC solutions stop at discovery and leave the fix to you.

Built for large, complex organizations with highly sensitive traffic

Developed with the U.S. Army and U.S. Air Force.

Nothing is re-coded

A grid operator cannot take control systems down to re-code them, so QuProtect does not ask for it.

The next migration is a configuration change

It is made from an Orchestrator you control, not run as another program.

Proven in production

Banco Sabadell validated post-quantum TLS in four months.

Use case in action

Your network, from the cryptography it runs today to the policy change that keeps it current. Move through the five steps, or click a number on the drawing.

  1. Substations and DER

    • RTUs, IEDs and relays cannot be upgraded
    • DER telemetry (solar, storage)
    • AMI head-end cannot be upgraded
  2. Control centre

    • SCADA and EMS cannot be upgraded
    • Historian
    • Backup control centre
  3. Corporate IT

    • Engineering workstations
    • Asset management and CMDB
    • Regulatory reporting

Legacy cryptography, and what Q-day does to it

Relays, RTUs and the AMI head-end reach SCADA on protocols older than TLS 1.2, and the control centre reaches engineering and corporate systems on TLS 1.2 with RSA key exchange. Traffic recorded today can be stored until a quantum computer running Shor’s algorithm recovers those keys, grid topology keeps its value for years, and a forged control command would pass as genuine.

Step 1 of 5

Sensors find the legacy negotiations and rank the violations

Reconnaissance sensors read what is on the OT WAN and record the protocols, cipher suites, certificates and keys in use, without touching a relay or a meter. Each policy violation is ranked by severity: the substation hops first, RSA key exchange between the control centre and corporate IT next.

Step 2 of 5

Encryptors remediate at the network layer

A gateway at each substation boundary and sidecars beside SCADA, the historian and the backup control centre carry each hop over TLS 1.3 with NIST post-quantum key exchange, X25519MLKEM768. No firmware change on the field devices, and no truck roll.

Step 3 of 5

Data in transit is secured, and the CBOM proves it

Control traffic recorded from now on is not readable by a future quantum computer, and a command that did not come from the control centre does not verify. The CBOM lists each connection’s protocol, algorithm and certificate with no open violations, with the asset owner and criticality the NERC audit asks for.

Step 4 of 5

Crypto-agility: the next algorithm is a policy change

When federal guidance moves the algorithms again, the Orchestrator pushes the new policy to each encryptor and the connections renegotiate, here from ML-KEM-768 to ML-KEM-1024, while the grid keeps running. It is a policy push, not a capital plan.

Step 5 of 5

Other use cases

Cryptographic inventory across IT and OT

A CBOM of what substations, control centres and corporate systems negotiate, the first step of the CISA, NSA and NIST quantum-readiness roadmap.

Protected control-centre links (CIP-012)

SCADA and EMS traffic between control centres runs post-quantum mTLS without touching the applications.

DER and telemetry links

Solar, storage and feeder telemetry into the control centre carried over protected connections.

Evidence for the NERC audit

Logged handshakes and a CBOM with asset owner and criticality, exported to the compliance workflow.

Encrypted remote access to substations (CIP-005)

Gateway encryptors at each site carry engineering and vendor access over post-quantum mutual TLS.

Field OT protected without a truck roll

RTUs, IEDs, relays and AMI head-ends sit behind gateway encryptors; the devices are not changed.

Device and system certificates

Automated provisioning and rotation for the identities on the OT WAN.

Algorithm change by policy

When federal guidance moves the algorithms again, the change is a policy push, not a capital plan.

Energy and grid case study

Post-quantum encryption on SCADA and industrial controls.

A national oil company piloted post-quantum encryption for exploration data, protecting SCADA systems and industrial controls at the network layer.

Read the case study
Reference material for this page

See what your network negotiates today