Website checklist

How to Check if a Website Is Quantum Safe

A website is not quantum-safe just because it has HTTPS. You need to check whether the endpoint is ready for post-quantum transport, whether hybrid key exchange is active, and whether older downgrade paths remain open.

Updated: 1 September 2026|10 min read
01

TLS 1.3 support

TLS 1.3 is the baseline for modern transport security and practical hybrid post-quantum key exchange.

02

Hybrid key exchange

Look for an active post-quantum or hybrid group such as X25519MLKEM768. TLS 1.3 alone is readiness, not proof of active PQC.

03

Legacy downgrade risk

TLS 1.0, TLS 1.1 and unmanaged TLS 1.2 fallbacks can keep older, non-PQC paths alive.

04

Security headers

HSTS, CSP, X-Frame-Options and X-Content-Type-Options reduce avoidable browser and transport risk.

05

Certificate and signature posture

Classical RSA/ECDSA certificates are normal today, but long-term signing workflows need a separate PQC migration plan.

Start With the Public Endpoint

The public website is the fastest place to start because it is visible, measurable and often controlled by a CDN, hosting provider or load balancer that can enable modern TLS features before the rest of the estate is migrated.

A good external check should show whether TLS 1.3 is available, whether old protocol versions are still offered, whether a hybrid post-quantum key exchange is negotiated, and whether browser security headers are present.

Understand the Difference Between Ready and Active

"Ready" means the infrastructure has the foundation for post-quantum transport: modern TLS, sensible ciphers and controlled downgrade behaviour. "Active" means the connection actually negotiates a post-quantum or hybrid key exchange.

Many organisations will pass through a readiness phase first. That is useful, but it does not remove harvest-now-decrypt-later risk for traffic that still uses classical key exchange.

How to Read Your Website Quantum Safety Results

Read each result as evidence about the connection that was tested. Use the table to separate an urgent transport fix from a wider post-quantum migration task.

ResultWhat it meansNext action
Hybrid PQC activeThe tested path negotiated a hybrid key exchange such as X25519MLKEM768.Check important subdomains, APIs and fallback paths, then record the result.
TLS 1.3 readyThe endpoint has a modern TLS foundation, but active PQC was not confirmed.Ask the CDN or hosting provider how to enable hybrid ML-KEM key exchange.
Legacy fallback presentOlder protocol paths may bypass the strongest available key exchange.Confirm client requirements, then restrict obsolete protocols and retest.
Headers missingBrowser protections are incomplete, although this alone does not determine PQC status.Add the recommended headers and keep PQC migration as a separate workstream.

Run the free quantum security scanner to collect the public result, then use the cryptographic inventory guide to find risks that a website test cannot see.

What a Website Check Cannot Prove

No external website scanner can prove an organisation is fully quantum-safe. It cannot inspect private APIs, databases, backups, VPNs, code-signing workflows, identity tokens or supplier systems.

Treat the website result as a first signal. If it shows weak TLS or missing headers, fix those quickly. If it looks good, move to a cryptographic inventory and migration roadmap across the systems that protect long-lived sensitive data.

Check Your Website Now

Run the free scanner, save the result in a free account, then rerun after fixing TLS, headers or provider settings.

Website Quantum Safety FAQ

How can I check if a website is quantum safe?

Check whether the public endpoint supports TLS 1.3, negotiates a hybrid post-quantum key exchange such as X25519MLKEM768, blocks legacy protocol downgrades and uses essential browser security headers. An external check is only the first step because it cannot inspect private systems or stored data.

Does TLS 1.3 make a website quantum safe?

No. TLS 1.3 provides the modern foundation needed for many hybrid deployments, but the connection must also negotiate a post-quantum or hybrid key exchange to protect traffic against future quantum decryption.

What does X25519MLKEM768 mean in a website test?

X25519MLKEM768 is a hybrid key exchange that combines classical X25519 with the NIST-standardised ML-KEM-768 algorithm. Detecting it on the tested connection is evidence that hybrid post-quantum protection is active for that path.

Can a website scanner prove that an organisation is quantum safe?

No. A public scanner can assess visible TLS and security settings, but it cannot inspect private APIs, databases, backups, VPNs, signing systems or supplier dependencies. Those require a cryptographic inventory and migration assessment.

Free readiness account

Keep This Guide Connected to a Real Website Scan

A PQC guide is more useful when it is attached to current evidence. Create a free account, add a public domain now or later, and keep a repeatable baseline for TLS, security headers and visible post-quantum readiness.

No cardStart the free evidence path without a paid plan.
Saved scanKeep the public endpoint result after the browser session.
Rescan laterRerun after TLS, header or provider changes.

Prefer to scan first? Open the free quantum security scanner.

Create Your Free Account

Start with Google, Microsoft or a one-time email code. You can add a domain now if you want the scanner to run after signup, but it is not required.

No cardNo passwordFree saved scan
Add a domain to scan after signup (optional)

Leave this blank to create the account first and scan later.

or use email code

No card or password is needed. The free account can keep scan evidence for rescans and badge qualification when you add a public domain.