Preflight Audit Laboratories
Post-Quantum & Crypto-Agility Readiness
Preflight evaluates migration readiness against finalized NIST post-quantum standards and controlled crypto-agility requirements. A readiness result does not mean a product is automatically quantum-resistant, NIST validated, certified or accredited.
Current implementation status
Quantum-readiness controls implemented; product claims remain evidence-gated.
The Validation Suite contains cryptographic inventory, harvest-now-decrypt-later analysis, crypto-agility controls, immutable PQ implementation/test evidence binding, strict hybrid validation and fail-closed public-claim checks. Each product still requires an exact scoped assessment of its real cryptographic dependencies and deployed implementation.
Cryptographic inventory
Enumerates public-key, symmetric, hash, signing, key-establishment and protocol dependencies before any product-level quantum claim is considered. Duplicate asset identities fail closed.
Harvest-now-decrypt-later analysis
Flags confidentiality-relevant classical public-key dependencies when data may remain valuable beyond the planned migration horizon.
Crypto-agility controls
Requires algorithm policy, replacement mechanisms, key/certificate rotation, protocol versioning, explicit algorithm-negotiation policy, downgrade protection, key separation, dependency monitoring, migration-test coverage, rollback and evidence traceability.
PQC implementation evidence
Post-quantum implementation readiness requires immutable SHA-256 references binding the exact implementation and its test evidence, plus a controlled reviewer role. Algorithm names or symbolic evidence labels alone cannot produce a passing result.
Strict hybrid validation
A classical + PQ declaration is only a hybrid candidate. Hybrid-ready status additionally requires exact component binding, immutable implementation/test digests, an identified combination mode, controlled reviewer role, downgrade-resistance validation and component-separation validation.
Evidence-bounded claims
Blocks unsupported quantum-ready, quantum-resistant, quantum-safe, quantum-secure, quantum-proof, quantum-protected, PQC-ready, PQC-compliant, NIST-validated and similar claims when the exact scope and evidence do not support them.
External validation boundary
Readiness and interoperability testing do not create CAVP, CMVP, NVLAP, FIPS or other external validation, certification or accreditation status.
NIST post-quantum baseline tracked by Preflight
Finalized standards are separated from algorithms still in standardization or programme-specific validation pathways.
FIPS 203
ML-KEM
Key encapsulation
ML-KEM-512 / 768 / 1024
FIPS 204
ML-DSA
Digital signatures
ML-DSA-44 / 65 / 87
FIPS 205
SLH-DSA
Stateless hash-based signatures
Standardized SLH-DSA parameter sets
Fail-closed by design.
If a cryptographic dependency is unknown, duplicated, classical-only and quantum-vulnerable, an unvalidated hybrid candidate, missing immutable PQ/hybrid implementation and test evidence, or outside the declared assessment scope, Preflight will not permit an evidence-backed quantum-readiness result. Hybrid candidates must also prove exact component binding, downgrade resistance and component separation. Absolute product-level quantum claims remain separately authorization-gated, and external validation wording requires a real external grant for the exact scope.