Skip to content
Preflight Audit

Preflight Audit Laboratories

Post-Quantum & Crypto-Agility Readiness

Preflight evaluates migration readiness against finalized NIST post-quantum standards and controlled crypto-agility requirements. A readiness result does not mean a product is automatically quantum-resistant, NIST validated, certified or accredited.

Current implementation status

Quantum-readiness controls implemented; product claims remain evidence-gated.

The Validation Suite contains cryptographic inventory, harvest-now-decrypt-later analysis, crypto-agility controls, immutable PQ implementation/test evidence binding, strict hybrid validation and fail-closed public-claim checks. Each product still requires an exact scoped assessment of its real cryptographic dependencies and deployed implementation.

Cryptographic inventory

Enumerates public-key, symmetric, hash, signing, key-establishment and protocol dependencies before any product-level quantum claim is considered. Duplicate asset identities fail closed.

Harvest-now-decrypt-later analysis

Flags confidentiality-relevant classical public-key dependencies when data may remain valuable beyond the planned migration horizon.

Crypto-agility controls

Requires algorithm policy, replacement mechanisms, key/certificate rotation, protocol versioning, explicit algorithm-negotiation policy, downgrade protection, key separation, dependency monitoring, migration-test coverage, rollback and evidence traceability.

PQC implementation evidence

Post-quantum implementation readiness requires immutable SHA-256 references binding the exact implementation and its test evidence, plus a controlled reviewer role. Algorithm names or symbolic evidence labels alone cannot produce a passing result.

Strict hybrid validation

A classical + PQ declaration is only a hybrid candidate. Hybrid-ready status additionally requires exact component binding, immutable implementation/test digests, an identified combination mode, controlled reviewer role, downgrade-resistance validation and component-separation validation.

Evidence-bounded claims

Blocks unsupported quantum-ready, quantum-resistant, quantum-safe, quantum-secure, quantum-proof, quantum-protected, PQC-ready, PQC-compliant, NIST-validated and similar claims when the exact scope and evidence do not support them.

External validation boundary

Readiness and interoperability testing do not create CAVP, CMVP, NVLAP, FIPS or other external validation, certification or accreditation status.

NIST post-quantum baseline tracked by Preflight

Finalized standards are separated from algorithms still in standardization or programme-specific validation pathways.

FIPS 203

ML-KEM

Key encapsulation

ML-KEM-512 / 768 / 1024

FIPS 204

ML-DSA

Digital signatures

ML-DSA-44 / 65 / 87

FIPS 205

SLH-DSA

Stateless hash-based signatures

Standardized SLH-DSA parameter sets

Fail-closed by design.

If a cryptographic dependency is unknown, duplicated, classical-only and quantum-vulnerable, an unvalidated hybrid candidate, missing immutable PQ/hybrid implementation and test evidence, or outside the declared assessment scope, Preflight will not permit an evidence-backed quantum-readiness result. Hybrid candidates must also prove exact component binding, downgrade resistance and component separation. Absolute product-level quantum claims remain separately authorization-gated, and external validation wording requires a real external grant for the exact scope.