Free PQC check

Post-Quantum Cryptography Checker

Check a public website for externally visible post-quantum cryptography readiness: TLS 1.3, hybrid key exchange signals, downgrade exposure, security headers and harvest-now-decrypt-later risk indicators.

Check a Public Website

Enter a domain to check visible post-quantum readiness and security posture. After the scan, save the result in a free account and rerun it after fixes.

Loading post-quantum cryptography checker...

What This Checker Reviews

PQC readiness signal

Looks for externally visible evidence that the endpoint is ready for post-quantum migration or already exposes hybrid key exchange signals.

TLS 1.3 baseline

Checks whether the public website has the modern TLS foundation expected before practical hybrid post-quantum TLS rollout.

Downgrade exposure

Flags older protocol paths and fallback behaviour that can weaken migration work even when a provider later enables PQC.

Header and browser controls

Reviews visible controls such as HSTS and CSP because cryptographic readiness sits inside the wider web-security posture.

Result interpretation

A PQC Check Is a First Evidence Point

NIST has released the principal PQC standards and says organisations should begin migrating systems to quantum-resistant cryptography. For a public website, the first practical question is whether visible TLS and web posture are ready for that change.

NCSC migration guidance also starts with discovery: know which services depend on cryptography, then build an initial migration plan. This checker gives one public endpoint evidence item for that wider discovery exercise.

Possible Result Meanings

PQC active

A visible hybrid or post-quantum key exchange signal was detected on the public endpoint.

Ready baseline

The endpoint has TLS 1.3 and reasonable public posture, but no active PQC signal was visible.

Classical-only warning

The endpoint appears to rely on classical TLS signals. Treat long-lived sensitive data as a migration priority.

Needs remediation

The checker found visible TLS, downgrade or web-security gaps that should be fixed before claiming PQC readiness.

What This Public Checker Cannot Prove

A public endpoint check can find visible readiness and web-security signals. It cannot prove the full organisation is quantum-safe, and it should not be treated as a penetration test or formal audit.

Use the result to decide whether a broader cryptographic inventory, supplier review or readiness assessment is needed.

Not covered by a public check

  • -Private APIs, VPNs, service meshes and internal applications
  • -Databases, backups and encryption at rest
  • -Code signing, document signing and firmware signing workflows
  • -Supplier contracts, managed service controls and cloud account configuration
  • -A complete cryptographic inventory across the organisation
Free account

Save the Check and Rerun It

A single public check is useful, but a saved check gives you a repeatable baseline. Create a free account, add a domain, and the checker opens directly after signup.

Save the first result, fix TLS or header gaps, then rerun the check when your CDN, hosting provider or security team changes the endpoint.

Create Your Free Account

Start with Google, Microsoft or a one-time email code. You can add a domain now if you want the scanner to run after signup, but it is not required.

No cardNo passwordFree saved scan
Add a domain to scan after signup (optional)

Leave this blank to create the account first and scan later.

or use email code

No card or password is needed. The free account can keep scan evidence for rescans and badge qualification when you add a public domain.

Post-Quantum Cryptography Checker FAQ

What is a post-quantum cryptography checker?

It is a public website check that reviews externally visible signals linked to PQC readiness, including TLS 1.3, hybrid key exchange evidence where visible, downgrade exposure and related security headers.

Can this checker prove my organisation is quantum-safe?

No. It checks public endpoint evidence only. A full conclusion needs a cryptographic inventory, supplier review, private-system assessment, signing workflow review and migration plan.

What should I do if no PQC signal is detected?

First make sure TLS 1.3, HSTS and downgrade controls are clean. Then build an inventory of systems that protect long-lived sensitive data and ask suppliers about NIST-standardised PQC roadmaps.

Is this different from the PQC TLS checker?

The PQC TLS checker focuses narrowly on transport security. This page is the broader post-quantum cryptography checker entry point for website PQC readiness, visible web posture and next migration steps.