Test if your website supports post-quantum cryptography
Data encrypted today can be recorded today and decrypted once a large quantum computer exists. This scanner shows which post-quantum key exchanges a website actually accepts, not just the one it happens to pick, along with how it authenticates, whether HTTP/3 is protected too, and what an attacker could still downgrade it to.
Try these examples:
?url=pqcrypta.com
/pqcrypta.com
Enter URL above
Standard ML-KEM for every browser, TLS 1.3 only, insists on post-quantum key exchange, no obsolete Kyber.
ML-KEM for every browser, TLS 1.3 only; but classical for a client that lists it first, or Kyber drafts still accepted.
Standard ML-KEM, but older TLS versions are still open: a downgrade can take the post-quantum key exchange away.
Supports ML-KEM, but a browser's handshake does not get it: the server prefers a classical group.
No ML-KEM a browser can use, Kyber drafts alone included: traffic can be recorded today and decrypted later.
How common each post-quantum capability is among the domains this scanner has measured, from the latest scan of each by the current scanner. Every rate is shown with the population it was asked of, because they differ: what a browser gets is asked of every domain, which groups a server accepts only of TLS 1.3 servers that answered every probe, post-quantum key exchange over QUIC only where a QUIC handshake completed. The band on each bar is its 95% interval.
Loadingโฆ
Each rung asks its question of the domains on the rung above, so the fall between rungs shows where a capability stops.
The key exchange Chrome's offer negotiated, every domain.
Offered every group it accepts, what it picked first: TLS 1.3 servers that answered every probe.
These figures are free to reuse under CC BY 4.0, credited to the PQ Crypta PQC Readiness Scanner. Every figure, as JSON: api.pqcrypta.com/pqc-scanner/corpus.
Post-quantum cryptography (PQC) refers to cryptographic algorithms that are designed to be secure against attacks from quantum computers. As quantum computing advances, current encryption methods like RSA and ECC may become vulnerable.
Quantum computers could break current encryption within years. Migrating to PQC now protects your data from future threats.
Combines classical and post-quantum algorithms for security today while preparing for quantum threats tomorrow.
ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) since August 2024; FN-DSA (FIPS 206) is in draft, and HQC was chosen in March 2025 as a second key-encapsulation mechanism.
Cryptography that stays secure against a large quantum computer, which would break RSA and elliptic-curve cryptography. NIST published the first standards in August 2024: ML-KEM (FIPS 203) for key exchange, and ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures.
Traffic recorded today can be decrypted once a large quantum computer exists ("harvest now, decrypt later"), so key exchange has to be post-quantum first. Chrome, Edge, Firefox and Safari already offer X25519MLKEM768 by default: a server that does not accept it gives every visitor a classical key exchange.
One that combines a classical and a post-quantum algorithm, so an attacker has to break both. X25519MLKEM768 (RFC 10024) pairs X25519 with ML-KEM-768, and it is what current browsers offer first.
It makes the handshake a browser makes and records the key exchange it gets. Then it offers each of 60 key-exchange groups on its own, without a key share, so a server that accepts the group answers with a HelloRetryRequest naming it. From those answers it ranks the server's own preference and checks whether it insists on post-quantum key exchange. It also tests TLS 1.2, 1.1 and 1.0, asks for an ML-DSA certificate, and tests post-quantum key exchange over HTTP/3, Encrypted Client Hello and the NSA CNSA 2.0 profile.
A+: standard ML-KEM for every browser, TLS 1.3 only, the server insists on post-quantum key exchange, and it refuses the obsolete Kyber drafts. A: ML-KEM for every browser and TLS 1.3 only, but classical key exchange for a client that lists a classical group first, or Kyber drafts still accepted. B: standard ML-KEM, but older TLS versions are still open, so a downgrade can take the post-quantum key exchange away. C: the server supports ML-KEM, but a browser's handshake does not get it. F: no standard post-quantum key exchange.
The NSA's Commercial National Security Algorithm Suite 2.0. Its TLS profile admits only TLS 1.3 with ML-KEM-1024, AES-256 and ML-DSA-87 certificates; web browsers, servers and cloud services are to support and prefer it by 2025 and use it exclusively by 2033. No public CA issues ML-DSA-87 certificates yet, so today a server meets it only with its own CA, for clients that trust that CA.
Compute on encrypted data without ever decrypting it. Already deployed by major tech companies:
Source: Microsoft SEAL (production), Google Private Join and Compute, IBM HElib, OpenFHE, DARPA DPRIVE program, PQCrypta
Prove knowledge without revealing information. Critical for privacy and blockchain:
Source: StarkWare (mainnet), Zcash (Halo 2), Filecoin, IETF Privacy Pass (RFC 9576โ9578), Polygon zkEVM, PQCrypta
Next-generation processors making PQC as fast as classical cryptography:
Source: ARM Helium (Cortex-M85), Intel Sapphire Rapids, RISC-V Crypto TG, PQShield, PQCrypta
Internet protocols transitioning to quantum-resistant security:
Source: RFC 10024, RFC 9370, Cloudflare Radar (April 2026), OpenSSH 10.0 release notes, IETF TLS and IPsec working groups, PQCrypta
Cryptocurrency networks preparing for quantum threats to trillions in digital assets:
Source: Ethereum Research, Bitcoin Core development, Web3 Foundation, Algorand Foundation
Understanding when quantum computers will actually threaten current cryptography:
Source: Gidney (arXiv 2505.15917, 2025), Iceberg Quantum (2026), Google Quantum AI (2026), QuEra, Quantinuum, IBM roadmap, NSA CNSA 2.0, NIST IR 8547
Post-quantum key exchange is already the default between current browsers and the largest networks, and NSA's CNSA 2.0 expects web servers to prefer it now and use it exclusively by 2033. PQCrypta brings cutting-edge features like WebAssembly acceleration to your browser right now, with experimental zero-knowledge proof and homomorphic encryption APIs still in development.
Try Advanced PQC Features NowPlanning a post-quantum migration for your organization? Tell us about your environment and we'll help you scope a discovery pilot โ agent rollout, full cryptographic asset inventory, and a prioritized remediation report.