Production lines that outlive their cryptography, protected where they stand.
The compensating control NIST SP 800-82 already describes: post-quantum encryption and identity around PLCs, historians and the OT/IT boundary, with no firmware change and no stop on the line.
Q-day is uncertain. The requirements for manufacturing are not.
Nobody knows when a cryptographically relevant quantum computer will arrive (Q-day), but your cryptography requirements do not depend on that date. Four reasons to start now:
AI is already finding weaknesses in algorithms
Anthropic’s Claude Mythos preview found serious weaknesses in candidate algorithms without a quantum computer. Cryptography can fail before Q-day arrives.
Adversaries are harvesting encrypted data now
They are collecting recipes and process telemetry which are trade secrets for a decade or more, to decrypt when Q-day arrives: harvest now, decrypt later.
Regulators already require PQC migration
For a manufacturer that means the cryptographic integrity and confidentiality IEC 62443 writes into supply contracts at the higher security levels, the compensating controls NIST SP 800-82 rev. 3 describes where legacy equipment cannot do modern cryptography, and the lifecycle security the EU Cyber Resilience Act and NIS2 attach to products sold into the EU.
Estimates for Q-day keep shrinking
Google has set 2029 as the target for its own migration. If yours is not finished in time, the foundation of OT/IT connections and remote access is at risk.
Google’s 2029 target and resource estimates: QuSecure, April 2026. NIST IR 8547, initial public draft, November 2024. Anthropic, Claude Mythos preview, 2026.
Why use QuProtect?
Cryptography belongs in a layer you control and configure, not in application code.
No rewrite, no rip-and-replace
QuProtect moves critical and legacy systems to PQC in a fraction of the time and cost.
Discovery and remediation in one platform
Many PQC solutions stop at discovery and leave the fix to you.
Built for large, complex organizations with highly sensitive traffic
Developed with the U.S. Army and U.S. Air Force.
Nothing is re-coded
A manufacturer cannot stop a line to re-code its controllers, so QuProtect does not ask for it.
The next migration is a configuration change
It is made from an Orchestrator you control, not run as another program.
Proven in production
Banco Sabadell validated post-quantum TLS in four months.
Use case in action
Your network, from the cryptography it runs today to the policy change that keeps it current. Move through the five steps, or click a number on the drawing.
-
Cell and area zones
- PLCs and controllers cannot be upgraded
- Robots and vision systems cannot be upgraded
- Remote sites and yards
-
Site operations
- SCADA and HMI cannot be upgraded
- Historian
- OT and IT DMZ
-
Enterprise
- MES and ERP
- Engineering and vendors
- Cloud analytics
Legacy cryptography, and what Q-day does to it
Controllers and robots reach SCADA on protocols older than TLS 1.2, and the DMZ reaches MES, ERP and vendor access on TLS 1.2 with RSA key exchange. Traffic recorded today can be stored until a quantum computer running Shor’s algorithm recovers those keys, recipes and yields are trade secrets for a decade or more, and a forged setpoint stops a line.
Sensors find the legacy negotiations and rank the violations
Reconnaissance sensors read what crosses the OT/IT boundary and record the protocols, cipher suites, certificates and keys in use, without touching a controller. Each policy violation is ranked by severity: the cell hops first, RSA key exchange on the crossings to the enterprise next.
Encryptors remediate at the network layer
A gateway at each cell boundary and sidecars beside SCADA, the historian and the DMZ carry each hop over TLS 1.3 with NIST post-quantum key exchange, X25519MLKEM768. No firmware change on a PLC, and no stop on the line: the compensating control NIST SP 800-82 describes.
Data in transit is secured, and the CBOM proves it
Process telemetry recorded from now on is not readable by a future quantum computer, and a setpoint that did not come from the HMI does not verify. The CBOM lists each connection’s protocol, algorithm and certificate with no open violations, which answers the cryptographic clauses buyers now write into contracts.
Crypto-agility: the next algorithm is a policy change
A line commissioned today runs into the 2040s. When a standard moves, the Orchestrator pushes the new policy to each encryptor and the connections renegotiate, here from ML-KEM-768 to ML-KEM-1024, while the line keeps running.
Other use cases
Inventory across the OT/IT boundary
A CBOM of what PLCs, SCADA, historians and enterprise systems negotiate.
SCADA and historian links
OT/IT crossings run post-quantum mutual TLS with no stop on the line.
MES, ERP and cloud analytics
Sidecar encryptors on the IT side protect the links the plant depends on.
Device and system certificates
Automated provisioning and rotation for identities on the plant network.
Cells behind gateway encryptors
The compensating control NIST SP 800-82 describes: controllers and robots protected without firmware change.
Vendor remote access
Remote sites and vendor connections carried over protected, identity-bound sessions.
IEC 62443 evidence for contracts and the CRA
Logged handshakes and a CBOM that answers the cryptographic clauses buyers now write in.
Algorithm change by policy
A line commissioned today runs into the 2040s; the next algorithm is a policy push.