Sample report · Q-Ready External
Illustrative data · fictional company, not a real client
Acme Bank LatAm · acme-bank.example

Post-quantum cryptographic exposure report

Issued 2026-07-30 · measured 2026-07-31 → 2026-08-02

The public surface of acme-bank.example negotiates hybrid key exchange only where its CDN brings it by default — 2 of 5 hosts. The other 3 have no CDN in front and remain fully classical, so the protection you have today was not your decision. As a bank, its data must stay secret for decades; under any reasonable scenario, the organization is late. The gap is one of posture, not a single flaw — and it is fixable with a bounded roadmap.

37/ 100
Consciente30–49 · partial hygiene, no material transition
Before you read the rest of this report

Your traffic is already being stored.

This is not a future threat. Intercepting and storing encrypted traffic to decrypt it later —once a machine capable of breaking it exists— is an active practice today, jointly documented by CISA, the NSA and NIST under the name harvest now, decrypt later.

We do not know whether acme-bank.example’s traffic is being captured right now. What is verifiable: any traffic encrypted with classical cryptography —such as 3 of your 5 public hosts, the ones with no CDN in front— is interceptable today and decryptable the day a cryptographically relevant quantum computer exists. You do not choose that date.

We do not claim this organization is being harvested — we do not know. We claim what is documented: the practice exists, classical traffic is interceptable, and the confidentiality window runs from today.

01 · TODAY

It is captured

Any traffic without a post-quantum hybrid is interceptable right now.

02

It is stored

Storing encrypted traffic is cheap; the practice is documented.

03

It is decrypted

The day the machine exists — not before, and not when you decide.

04

It is measured

Only here does this report’s index come in: how much your surface exposes you today.

What follows measures how protected you are against this clock — not whether the clock exists.

CISA, NSA and NIST — joint quantum-readiness factsheet, 2023.

The three numbers

37QEX indexof 100 · external ceiling 84
57Banca mediann = 12 measured organizations
2 of 5Your hosts with hybridand none by your own decision · the sector runs at 93 %

Where this lands

You · 37Banca median · 57Sector middle half · 56–58

The company in this example is fictional. The sector figures it is compared against are NOT: they come from the August 2026 study of 220 Chilean organizations, and are the same ones published in the monthly report.

Your score falls below the minimum we measured in Chilean banking (46). Of the 12 banking organizations with a computed index, none sits this low. On hybrid key exchange support the sector runs at 93 % (n = 15); you have it on 2 of your 5 hosts, and on both by CDN default rather than by your own decision.

The first three things to do

  1. Inventory public certificates and CT hostnames · hours · no cost
  2. Force TLS 1.3 and disable TLS 1.1 on the legacy host · hours · no cost
  3. Enable X25519MLKEM768 on the three hosts with no CDN (api, legacy, mail): OpenSSL 3.5+ or your server’s equivalent · days · no cost

Where you stand, against whom, and how much time is left

One chart, three questions. Your score (the dot), your sector’s middle half (the band), and the probability zones for the threat existing (the background, cited to the Global Risk Institute).

2030 · GRI: ≥1 in 42035 · GRI: ≥1 in 2~2041 · 51–70 %Cripto-ágilPerímetro migradoEn transiciónConscienteExpuestoSector middle half · 56–58Sector median · 57You, today: 37/100the first 12 months of your roadmaptoday · 2026-08-02~15 years

No trajectory line. No model exists today that computes what score results from executing the roadmap, and drawing one would be inventing data. That absence is a decision.

Time zones: Global Risk Institute, Quantum Threat Timeline Report 2025. Sector band: Rosetta’s August 2026 study of 220 Chilean organizations.

Top 5 findings

  • Critical3 of 5 hosts (api, legacy, mail) negotiate classical cryptography only: no CDN in front to bring them the hybrid.
  • CriticalBanking sector (long confidentiality horizon) with no PQC posture → critical HNDL index.
  • HighLegacy host with TLS 1.1 and an RSA-1024 leaf certificate on a live subdomain.
  • MediumWildcards on 4 hosts widen the blast radius; 6 orphan hostnames in CT.
  • InfoNo security.txt or published crypto-agility policy; edge on Cloudflare (partial positive).

Cost of inaction (Mosca). X (confidentiality ~8 yr) + Y (migration ~9 yr) = 17 > Z (CRQC ~9 yr). Every quarter of delay shrinks the margin and grows the volume of already-harvestable traffic.

Context · the clock and HNDL

RSA/ECC will be vulnerable to Shor on a CRQC. Replacement standards (FIPS 203/204/205) have existed since 2024; NIST IR 8547 deprecates RSA-2048/ECC by 2030 and disallows them by 2035. Under harvest now, decrypt later, traffic encrypted today can be decrypted once a CRQC exists.

This report measures cryptographic exposure, not quantum advantage. They are different things: that Shor breaks RSA is a proven theorem; that a quantum computer beats a classical method on an optimization problem is an open empirical question, and not what this report answers.

The four clocks

The fair objection is “no rule obliges me yet”. It is true, and it changes nothing: four clocks are running and the regulator’s is the slowest.

  • RunningYour deadline is set by the shelf life of your data. A mortgage has to stay secret for decades. Your deadline is not set by the regulator: it is set by how long your data must remain secret.
  • RunningThe debt is already running. Traffic leaving encrypted today may be stored now to be read later. Nothing you do in 2030 protects what left in 2026.
  • ApproachingThe requirement reaches you by contract before it reaches you by law. Your parent company, a correspondent bank or a large client’s security questionnaire will ask before any Chilean regulator does.
  • ApproachingThe technical dates are already written. NIST sets deprecation of RSA and elliptic curves at 2030 and disallowance at 2035. The document (IR 8547) is still an initial public draft and we say so: not a binding obligation, but the date your vendors plan against.

And in Chile, plainly. As of this report, no Chilean regulator requires post-quantum cryptography. Not the CMF, not the ANCI, not the data protection agency. What does exist are operational-risk and information-security obligations under which a supervisor may ask about your plan. This report will not imply an obligation that does not exist.

Regulatory framework

RuleWhat it establishesRequires PQC?
CMF · RAN Capítulo 20-10 · por verificarInformation security and cybersecurity management for banks.No
Ley 21.663 · ANCI / OIVCybersecurity framework; Vital Importance Operator regime.No
Ley 21.719 · Datos personales · por verificarNew agency, 72-hour breach notification; fully in force Dec-2026.No

Loaded jurisdiction: Chile — this block is a per-country module, not fixed text.

What is good

  • okwww and online negotiate the hybrid today because Cloudflare ships it on by default. It is neither a pending win nor a decision of yours: it is a side effect of your CDN contract, and it covers only 2 of your 5 hosts.
  • okTLS 1.3 present on www and online; no export ciphers observed.
  • okDMARC and SPF configured on the mail domain.

What is wrong / critical

Severity
Finding
Detail
Critical
3 of 5 hosts fully classical
api, legacy and mail do not negotiate X25519MLKEM768. The protection you do have arrives only where the CDN brings it.
Critical
Banking HNDL, unmitigated
Long-lived data exposed under classical cryptography.
High
TLS 1.1 + RSA-1024
legacy.acme-bank.example accepts obsolete protocols and keys.
Medium
Wildcards + CT orphans
Wide blast radius; unmanaged surface.
Low
No crypto-agility policy
No declared owner or rotation process.

Observed inventory

HostTLS / algorithmsHybridEdge
www.acme-bank.exampleTLS 1.3 · X25519MLKEM768 / RSA-2048Sí · por defecto del CDNCloudflare
online.acme-bank.exampleTLS 1.3 · X25519MLKEM768 / RSA-2048Sí · por defecto del CDNCloudflare
api.acme-bank.exampleTLS 1.2 · ECDHE / ECDSA P-256No
legacy.acme-bank.exampleTLS 1.1 · RSA / RSA-1024No
mail.acme-bank.exampleSTARTTLS · ECDHE / RSA-2048No

Your critical path runs through your vendors

We cross the vendors visible on your surface, and the typical ones for your industry, against each manufacturer’s declared post-quantum status. This is what sets your real timeline — and it does not depend on you.

~10 %of origin servers support post-quantum key exchange
60 %+of browsers already offer it

The network edge and the browsers have already solved this. The origin server — yours — is where the migration stalled. Your three hosts without a CDN sit squarely in that 90 % that has not moved.

Cloudflare Radar · Post-Quantum Encryption, 27-Feb-2026.

Part 1

What we did detect on your surface

This is not a general library: it is your actual inventory, crossed against what each vendor does for you.

Your edge: Cloudflare (www, online)

Cloudflare enables hybrid key exchange by default, on every plan and on both legs. These two hosts already have it without you doing anything; all that is left is confirming that no restricted cipher-suite configuration in your zone is switching it off.

api, legacy, mail — no CDN

There is no provider between your server and anyone watching, which is why they remain fully classical. What Cloudflare does or does not do never reaches them: their exposure depends entirely on what you configure.

Part 2

The vendor library

The typical vendors in your industry, with what you would have to do in each case. Every row carries its source; anything unconfirmed is declared as such.

HSM · appliance and on-premise

Vendor · productWhat you must doDetail
Entrust nShield 5s / 5cFirmwareFirmware v13.8+ (also covers the earlier XC generation). The post-quantum feature ships always on, no separate licence.
Entrust nShield Connect XC / Solo XCSeparate licenceFirmware AND a separately purchased PostQuantum licence — unlike the 5 line.
Thales Luna 7 (firmware 7.9.0+)FirmwareNative ML-KEM and ML-DSA from firmware 7.9.0 (Jul-2025) plus client 10.9.0+, on the Luna 7 hardware you already own.
Thales Luna 8New hardwareNot a firmware upgrade: a hardware replacement (Aug-2026). All certifications restart. This is budget, not a ticket.
Utimaco Quantum ProtectSeparate licenceAdd-on package for u.trust Se-Series and CSe-Series, field-upgradeable without changing hardware. Ships ML-KEM and ML-DSA.
Utimaco CP5 / eIDASNo pathNo published post-quantum path. If your use case is eIDAS qualified signing, there is no route with this vendor today.

Cloud key management

Vendor · productWhat you must doDetail
Azure Key Vault · Managed HSM · Cloud HSMNo PQCNo post-quantum, no preview, no announced date. Verified against the API’s actual enum.
AWS KMSPartialOffers ML-DSA as a signing key type (ML_DSA_44/65/87, since Jun-2025). Does NOT offer ML-KEM as an encapsulation service — AWS’s hybrid lives in the TLS to the API, a different layer. And ML-KEM is precisely what mitigates harvest-now-decrypt-later.
AWS CloudHSMPartialThe vendor contradicts itself: its migration page says ML-DSA is “in preview”; the SDK release notes treat it as available. Ask in writing.
Google Cloud KMSPartialPost-quantum signing generally available (Jul-2026). The protection level — software only or backed by HSM — remains to be confirmed.
IBM z17 (CEX8S)FirmwareIBM’s documented path to the final standards (FIPS 203/204) runs through z17 with CCA 8.4 firmware.
IBM z16 (CEX8S)PartialWhat is documented for z16 is CCA 8.0/8.2 — earlier-round Dilithium and Kyber, pre-standard. Does not satisfy FIPS 203/204. Open question to IBM.
IBM Hyper Protect Crypto ServicesDeprecatedIts PQC is round-2 Dilithium only, on CEX7S — pre-standard. And the hardware behind it is end-of-life.

Certificates and PKI

Vendor · productWhat you must doDetail
¿Existe un certificado TLS post-cuántico públicamente confiable?No pathNot today. The CA/B Forum Baseline Requirements (v2.2.9) allow only RSA and ECDSA. No public authority can issue one even if it wanted to.
PKI privada con ML-DSAAlready thereIt does exist: DigiCert and Sectigo (on request) and Microsoft AD CS already offer it — valid inside your own organization, not on the public internet.
Vigencia de certificados TLSDatedA parallel calendar that changes your operations: 100 days from 15-Mar-2027 and 47 days from 15-Mar-2029 (ballot SC-081v3). If your rotation is manual, this hits you before post-quantum does.

Core banking and payments

Vendor · productWhat you must doDetail
Temenos · Finastra · FIS · Fiserv · FlexcubeNo statementZero occurrences of “quantum” in the FIS Security Statement and in the FY2025 10-K filings of FIS, Fiserv, Visa and Mastercard.
SWIFT — Release 8.0DatedMandatory by end of July 2027, with no upgrade path from 7.7. If you are on 7.7, that jump needs planning of its own.
EMVCoNo statementFormally states it does not expect the threat “until at least 2040 – maybe never”. That is a published position, not silence: know that your card ecosystem thinks this way.

Browsers

Vendor · productWhat you must doDetail
Chrome / Edge 147Already thereNo longer switchable off. Microsoft, verbatim: “This policy has been removed starting in Microsoft Edge version 147.” The client side stopped being optional.

CDN and edge

VendorClient → edgeEdge → origin
CloudflareBy defaultBy default
Akamai Enhanced TLSBy defaultBy default since Oct-2025
AWS CloudFrontBy defaultNo confirmed date (checked Aug-2026)
FastlyBy defaultNo specific statement found
Azure Front DoorNo public statementNo public statement
Akamai Standard TLSNot available at that tierNot available

Word traps — the same finding stated backwards

Entrust · «Post-Quantum Option Pack» — It does not deliver the final standards, only the earlier candidates on CodeSafe, with a separate SEE licence. And in its own documentation: “the underlying Security World protection mechanisms still use classical (non post-quantum) crypto” — the Option Pack protects your post-quantum keys with classical cryptography. It is the lab path, not the production one.

Thales CipherTrust Manager · «soporta PQC» — It is only ML-KEM as TLS key agreement. It neither creates nor manages post-quantum keys: it protects the transport to the manager, not what the manager holds.

Azure · «quantum-resistant» — It appears in marketing material without matching any function available in Key Vault, Managed HSM or Cloud HSM. There is no preview and no date.

Status as declared by each manufacturer in public sources, with the date consulted. A “no date” does not mean the vendor is not working on it: it means you cannot plan against anything.

HNDL index + CRQC scenarios

Banking = high confidentiality horizon. The HNDL index combines sector with observed exposure:

If the threat arrives inProbabilityWhat it means for you
5 years · 2031~15 %Your migration is half done. Four years with a live threat while you migrate.
10 years · 203628–49 %Your migration just finished. Everything harvested before is still readable.
15 years · 2041≥ 51 %Protected from then on; not what left before 2035.
20 years · 2046≥ 69 %Protected.

Global Risk Institute · Quantum Threat Timeline Report 2025 (7th edition, March 2026, 26 experts). Aggregate probability that a computer able to factor 2048 bits in under 24 hours exists.

Source limits: Small sample with varying composition year to year; probability bins are not uniform. The 2019–2021 surveys gave a higher probability for the same horizon.

Global Q-Ready score

Weighted mean of the dimensions measurable at the External tier:

DimensionWeight0–100
Certificates / public PKI40%40
Surface & hygiene25%52
HNDL posture (time)25%15
Edge TLS PQC10%40
Expuesto (0–29)Consciente (30–49)En transición (50–69)Perímetro migrado (70–84)Cripto-ágil (85–100)

Roadmap

30 days · Hygiene & visibility

ActionEffortCost
Inventory public certificates and CT hostnameshoursno cost
Force TLS 1.3 and disable TLS 1.1 on the legacy hosthoursno cost
Replace the RSA-1024 certificatehoursno cost
Publish security.txt with a contact channelminutesno cost

90 days · Hybrid where it is missing

ActionEffortCost
Enable X25519MLKEM768 on the three hosts with no CDN (api, legacy, mail): OpenSSL 3.5+ or your server’s equivalentdaysno cost
Check that no cipher-suite restriction is disabling the hybrid Cloudflare already brings on www and onlineminutesno cost
Consolidate wildcards and retire orphan hostnamesdaysno cost
Name a crypto-agility owner and define key rotationdaysno cost

365 days · Interior

ActionEffortCost
Cryptographic inventory of internal systems (CBOM)weeksneeds budget
Post-quantum plan with HSM and key-management vendorsweeksneeds budget
Migrate signatures to ML-DSA where the vendor already supports itweeksneeds budget
Quarterly re-scansubscription

The “no cost” actions require no purchase: they are your own team’s work with tools you already have. None of them is “flip a toggle on Cloudflare”: on hosts already behind Cloudflare the hybrid ships on by default, and there is nothing to enable.

Visibility gaps

The External tier does not observe the interior. These gaps close with Assisted (uploads + integrations) and Enterprise (partner):

  • gapHSM/KMS inventory and internal keys
  • gapApps, VPN and internal mTLS
  • gapEncrypted databases and backups
  • gapVendor PQC roadmaps
Upgrade to Assisted →

Appendix · methodology & limits

Public-surface evidence only: Certificate Transparency, DNS resolution, TLS probe (ClientHello with hybrid groups), public trust chain and light OSINT. No exploits, no aggressive port-scan, identified User-Agent. Not a certification and no substitute for a formal internal review.

Rosetta seal

Each report is sealed with the hash of the evidence JSON. In production it anchors to the Evidence Ledger (here, a sample, unanchored).

content_hash = sha256:9f2c1a7e…d40b
rosettaq-archive/v2 · sample · not anchored