Press Releases
QuSecure Achieves SOC 1 and SOC 2 Type 2 Compliance Validating Security Controls and Practices of its Leading Post-Quantum Cryptography Solution
Independent auditors validated QuProtect's internal security controls under SOC 1 and SOC 2 Type 2, with CISO Craig Debban on what that attests to.
Independent, Third-Party Auditors Validate QuProtect’s Operation Aligning Securely and Consistently with Common Security Policies and Requirements
SAN MATEO, Calif. — May 22, 2024 — QuSecure™, Inc., a leader in post-quantum cryptography (PQC), today announced that it has achieved SOC 1 and SOC 2 Type 2 compliance for its QuProtect software solution, validating the rigorous, independent assessment of its internal security controls and practices of its industry-leading PQC solution. This serves as validation of QuSecure’s dedication and adherence to the highest standards for security.
“Our successful SOC 1 and SOC 2 reports, completed through an independent third-party assessment, have validated the improvements in our overall security posture,” said Craig Debban, CISO at QuSecure. “This attestation is the backbone to creating security products that protect our customers from impending quantum computing and classical threats. This important recognition is also the bedrock to our compliance roadmap which is in direct alignment with growing customer requirements. Maintaining this standard is but one step in our continuing journey to improve our security posture for commercial and government adoption.”
Since many organizations require SOC 1 and SOC 2 compliance, such organizations can now be assured that QuSecure has passed rigorous assessments and audits validating the security posture of its post-quantum cryptography and crypto-agility platform, QuProtect. As most organizations require a vendor management review, this new third-party validation immediately attests to QuSecure’s ability to meet the toughest security requirements. QuSecure’s SOC 3 report is available on request.
QuSecure’s QuProtect software, available now for testing and deployment, offers a comprehensive, end-to-end quantum-security-as-a-service architecture that combines zero-trust, next-generation quantum-resilient technology and crypto-agility to protect networks, cloud systems, edge devices, and satellite communications against today’s cyberattacks and future quantum threats, all with minimal disruption to existing systems.
About QuSecure
QuSecure is a post-quantum cryptography (PQC) and crypto-agility pioneer that gives an enterprise one place to set and enforce cryptographic policy across its infrastructure. Recognized as the Global Post-Quantum Cryptography Product Leader, QuSecure enables organizations to build a complete cryptographic inventory across their networks, enforce policy-based governance, and roll out compliant cryptography, from TLS upgrades to full post-quantum migration, without application rewrites. Its QuProtect R3 platform enables security teams to swap algorithms and push cryptographic policy changes across their entire network from one place. Backwards compatible with legacy infrastructure, QuProtect R3 operates across cloud, on-premises, air-gapped, and sovereign environments, supporting compliance with CNSSP 15/NSM-10, CNSA 2.0, PCI DSS, DORA, and more. Customers include U.S. defense agencies, global financial institutions, and critical infrastructure providers.
Filed under
More on Press Releases
Ready to take command of your cryptography?
Get a personalized briefing from our team and see QuProtect R3 in action.