PQC readiness signal
Looks for externally visible evidence that the endpoint is ready for post-quantum migration or already exposes hybrid key exchange signals.
Enter a domain to check visible post-quantum readiness and security posture. After the scan, save the result in a free account and rerun it after fixes.
Looks for externally visible evidence that the endpoint is ready for post-quantum migration or already exposes hybrid key exchange signals.
Checks whether the public website has the modern TLS foundation expected before practical hybrid post-quantum TLS rollout.
Flags older protocol paths and fallback behaviour that can weaken migration work even when a provider later enables PQC.
Reviews visible controls such as HSTS and CSP because cryptographic readiness sits inside the wider web-security posture.
NIST has released the principal PQC standards and says organisations should begin migrating systems to quantum-resistant cryptography. For a public website, the first practical question is whether visible TLS and web posture are ready for that change.
NCSC migration guidance also starts with discovery: know which services depend on cryptography, then build an initial migration plan. This checker gives one public endpoint evidence item for that wider discovery exercise.
A visible hybrid or post-quantum key exchange signal was detected on the public endpoint.
The endpoint has TLS 1.3 and reasonable public posture, but no active PQC signal was visible.
The endpoint appears to rely on classical TLS signals. Treat long-lived sensitive data as a migration priority.
The checker found visible TLS, downgrade or web-security gaps that should be fixed before claiming PQC readiness.
A public endpoint check can find visible readiness and web-security signals. It cannot prove the full organisation is quantum-safe, and it should not be treated as a penetration test or formal audit.
Use the result to decide whether a broader cryptographic inventory, supplier review or readiness assessment is needed.
A single public check is useful, but a saved check gives you a repeatable baseline. Create a free account, add a domain, and the checker opens directly after signup.
Save the first result, fix TLS or header gaps, then rerun the check when your CDN, hosting provider or security team changes the endpoint.
It is a public website check that reviews externally visible signals linked to PQC readiness, including TLS 1.3, hybrid key exchange evidence where visible, downgrade exposure and related security headers.
No. It checks public endpoint evidence only. A full conclusion needs a cryptographic inventory, supplier review, private-system assessment, signing workflow review and migration plan.
First make sure TLS 1.3, HSTS and downgrade controls are clean. Then build an inventory of systems that protect long-lived sensitive data and ask suppliers about NIST-standardised PQC roadmaps.
The PQC TLS checker focuses narrowly on transport security. This page is the broader post-quantum cryptography checker entry point for website PQC readiness, visible web posture and next migration steps.