Skip to content

Production lines that outlive their cryptography, protected where they stand.

The compensating control NIST SP 800-82 already describes: post-quantum encryption and identity around PLCs, historians and the OT/IT boundary, with no firmware change and no stop on the line.

Q-day is uncertain. The requirements for manufacturing are not.

Nobody knows when a cryptographically relevant quantum computer will arrive (Q-day), but your cryptography requirements do not depend on that date. Four reasons to start now:

AI is already finding weaknesses in algorithms

Anthropic’s Claude Mythos preview found serious weaknesses in candidate algorithms without a quantum computer. Cryptography can fail before Q-day arrives.

Adversaries are harvesting encrypted data now

They are collecting recipes and process telemetry which are trade secrets for a decade or more, to decrypt when Q-day arrives: harvest now, decrypt later.

Regulators already require PQC migration

For a manufacturer that means the cryptographic integrity and confidentiality IEC 62443 writes into supply contracts at the higher security levels, the compensating controls NIST SP 800-82 rev. 3 describes where legacy equipment cannot do modern cryptography, and the lifecycle security the EU Cyber Resilience Act and NIS2 attach to products sold into the EU.

Estimates for Q-day keep shrinking

Google has set 2029 as the target for its own migration. If yours is not finished in time, the foundation of OT/IT connections and remote access is at risk.

Google’s 2029 target and resource estimates: QuSecure, April 2026. NIST IR 8547, initial public draft, November 2024. Anthropic, Claude Mythos preview, 2026.

Why use QuProtect?

Cryptography belongs in a layer you control and configure, not in application code.

No rewrite, no rip-and-replace

QuProtect moves critical and legacy systems to PQC in a fraction of the time and cost.

Discovery and remediation in one platform

Many PQC solutions stop at discovery and leave the fix to you.

Built for large, complex organizations with highly sensitive traffic

Developed with the U.S. Army and U.S. Air Force.

Nothing is re-coded

A manufacturer cannot stop a line to re-code its controllers, so QuProtect does not ask for it.

The next migration is a configuration change

It is made from an Orchestrator you control, not run as another program.

Proven in production

Banco Sabadell validated post-quantum TLS in four months.

Use case in action

Your network, from the cryptography it runs today to the policy change that keeps it current. Move through the five steps, or click a number on the drawing.

  1. Cell and area zones

    • PLCs and controllers cannot be upgraded
    • Robots and vision systems cannot be upgraded
    • Remote sites and yards
  2. Site operations

    • SCADA and HMI cannot be upgraded
    • Historian
    • OT and IT DMZ
  3. Enterprise

    • MES and ERP
    • Engineering and vendors
    • Cloud analytics

Legacy cryptography, and what Q-day does to it

Controllers and robots reach SCADA on protocols older than TLS 1.2, and the DMZ reaches MES, ERP and vendor access on TLS 1.2 with RSA key exchange. Traffic recorded today can be stored until a quantum computer running Shor’s algorithm recovers those keys, recipes and yields are trade secrets for a decade or more, and a forged setpoint stops a line.

Step 1 of 5

Sensors find the legacy negotiations and rank the violations

Reconnaissance sensors read what crosses the OT/IT boundary and record the protocols, cipher suites, certificates and keys in use, without touching a controller. Each policy violation is ranked by severity: the cell hops first, RSA key exchange on the crossings to the enterprise next.

Step 2 of 5

Encryptors remediate at the network layer

A gateway at each cell boundary and sidecars beside SCADA, the historian and the DMZ carry each hop over TLS 1.3 with NIST post-quantum key exchange, X25519MLKEM768. No firmware change on a PLC, and no stop on the line: the compensating control NIST SP 800-82 describes.

Step 3 of 5

Data in transit is secured, and the CBOM proves it

Process telemetry recorded from now on is not readable by a future quantum computer, and a setpoint that did not come from the HMI does not verify. The CBOM lists each connection’s protocol, algorithm and certificate with no open violations, which answers the cryptographic clauses buyers now write into contracts.

Step 4 of 5

Crypto-agility: the next algorithm is a policy change

A line commissioned today runs into the 2040s. When a standard moves, the Orchestrator pushes the new policy to each encryptor and the connections renegotiate, here from ML-KEM-768 to ML-KEM-1024, while the line keeps running.

Step 5 of 5

Other use cases

Inventory across the OT/IT boundary

A CBOM of what PLCs, SCADA, historians and enterprise systems negotiate.

SCADA and historian links

OT/IT crossings run post-quantum mutual TLS with no stop on the line.

MES, ERP and cloud analytics

Sidecar encryptors on the IT side protect the links the plant depends on.

Device and system certificates

Automated provisioning and rotation for identities on the plant network.

Cells behind gateway encryptors

The compensating control NIST SP 800-82 describes: controllers and robots protected without firmware change.

Vendor remote access

Remote sites and vendor connections carried over protected, identity-bound sessions.

IEC 62443 evidence for contracts and the CRA

Logged handshakes and a CBOM that answers the cryptographic clauses buyers now write in.

Algorithm change by policy

A line commissioned today runs into the 2040s; the next algorithm is a policy push.

Reference material for this page

See what your network negotiates today