1. External Readiness Scan
Check public TLS, security headers and observable post-quantum key exchange signals before deeper migration planning.
Check public TLS, security headers and observable post-quantum key exchange signals before deeper migration planning.
Map TLS endpoints, APIs, VPNs, certificates, signing systems, key stores, backups and third-party dependencies.
Prioritise systems against the UK migration milestones for discovery, planning and full PQC migration.
Pilot ML-KEM for key establishment and plan ML-DSA or SLH-DSA workstreams for signatures where needed.
The UK migration challenge is not only choosing algorithms. It is finding where classical public-key cryptography is used, identifying which data has a long confidentiality lifetime and changing systems without breaking clients, partners or compliance evidence.
A practical UK PQC programme should start with visible endpoints and then expand into APIs, VPNs, certificates, identity systems, document signing, code signing, backups and third-party services. The earlier this inventory work begins, the less risky the final migration becomes.
Check TLS 1.3, downgrade exposure, CDN support and hybrid ML-KEM readiness.
Map API gateways, mTLS, partner clients, webhook signatures and service identity.
Plan RSA and ECDSA migration around ML-DSA or SLH-DSA for documents, software and certificates.
Create a migration roadmap that aligns technical pilots with risk, procurement and audit requirements.
UK organisations with long-lived confidential data, regulated data, public-sector exposure, financial data, health data or critical supplier relationships should include PQC migration in their security planning.
Start with a public endpoint scan and a cryptographic inventory. Then rank systems by data lifetime, exposure and dependency complexity before running pilot implementations.
The practical baseline is NIST FIPS 203 for ML-KEM key establishment, FIPS 204 for ML-DSA signatures and FIPS 205 for SLH-DSA signatures, planned against UK NCSC migration guidance.
Use the free scanner to check an externally visible endpoint, then turn the result into a broader UK post-quantum cryptography migration plan.