Post-quantum readiness · NIST FIPS 203/204/205

Find the cryptography
that won't survive
a quantum computer.

Most organizations can't migrate to post-quantum cryptography because they don't know where their vulnerable crypto lives. CipherHorizon finds it — across your certificates, your code dependencies, and your public endpoints — and maps every finding to the new NIST standards.

⬤ harvest now, decrypt later
Encrypted data you send today can be recorded now and decrypted the day quantum arrives.
RSA and elliptic-curve keys protecting data with a long shelf-life — health records, financial data, state secrets, IP — are already exposed to adversaries banking on future decryption. The migration deadline isn't when quantum computers arrive. It's now, for anything that must stay secret past that point.
Scan my cryptography → What changed in 2024
Discovery scanner

Three ways in. Real findings, not guesses.

Upload certificates or a dependency manifest for instant in-browser analysis — nothing leaves your machine. Or point us at public domains to inspect live TLS.

01Certificates
02Dependencies
03Live domains
Drop certificate files (.pem / .crt / .cer)
or click to browse · parsed entirely in your browser, never uploaded
— or paste PEM blocks —
[i]We read the public-key algorithm and key size directly from the certificate structure. RSA-2048, ECDSA-P256, and similar classical algorithms are flagged as quantum-vulnerable. This analysis runs locally — your certs never touch a server.
Quantum-readiness grade
0
Vulnerable
0
Needs review
0
Quantum-safe
Findings
free scan limit

This is the first 5 findings.

Your scan found more items. Unlock the full inventory, the prioritized remediation order, and a formatted PDF report you can hand to leadership or auditors.

Single report
One full inventory + PDF
$149
Continuous monitoring
Monthly re-scan + drift alerts
$99/mo
The 2024 reset

The algorithms protecting
the internet just changed.

In August 2024, NIST finalized the first post-quantum cryptographic standards. The classical algorithms below are now on a path to deprecation. Here's what replaces what.

RSA / ECDH key exchange
↓ replaced by
ML-KEM (FIPS 203)
Formerly CRYSTALS-Kyber. The new standard for key encapsulation — how two parties agree on a shared secret.
RSA / ECDSA signatures
↓ replaced by
ML-DSA (FIPS 204)
Formerly CRYSTALS-Dilithium. The primary standard for digital signatures and certificate authentication.
Long-term signing keys
↓ replaced by
SLH-DSA (FIPS 205)
Formerly SPHINCS+. A hash-based signature scheme — a conservative backup with different security assumptions.
[i] Timelines vary by sector. US federal systems follow NSM-10 and CNSA 2.0, with migration windows extending toward 2030–2035. Regulated industries are setting their own deadlines. Verify the specific mandate that applies to you before citing dates — this tool tells you what you have, which is the prerequisite for any timeline.
What you get

From "we have no idea" to a defensible inventory.

The hardest part of post-quantum migration isn't the cryptography — it's discovery. You can't migrate what you can't see. CipherHorizon produces the artifact every migration starts with.

Complete inventory
Every certificate, library, and endpoint, classified vulnerable / review / safe with the exact algorithm and key size detected.
NIST mapping
Each finding mapped to its post-quantum replacement standard, so remediation isn't guesswork.
Prioritized order
Findings ranked by exposure — long-lived secrets and public-facing keys first, where harvest-now-decrypt-later bites hardest.
Audit-ready export
CSV and PDF you can hand to leadership, auditors, or a remediation team without rewriting it.