Post-quantum cryptographic exposure report
The public surface of acme-bank.example negotiates hybrid key exchange only where its CDN brings it by default — 2 of 5 hosts. The other 3 have no CDN in front and remain fully classical, so the protection you have today was not your decision. As a bank, its data must stay secret for decades; under any reasonable scenario, the organization is late. The gap is one of posture, not a single flaw — and it is fixable with a bounded roadmap.
Your traffic is already being stored.
This is not a future threat. Intercepting and storing encrypted traffic to decrypt it later —once a machine capable of breaking it exists— is an active practice today, jointly documented by CISA, the NSA and NIST under the name harvest now, decrypt later.
We do not know whether acme-bank.example’s traffic is being captured right now. What is verifiable: any traffic encrypted with classical cryptography —such as 3 of your 5 public hosts, the ones with no CDN in front— is interceptable today and decryptable the day a cryptographically relevant quantum computer exists. You do not choose that date.
We do not claim this organization is being harvested — we do not know. We claim what is documented: the practice exists, classical traffic is interceptable, and the confidentiality window runs from today.
It is captured
Any traffic without a post-quantum hybrid is interceptable right now.
It is stored
Storing encrypted traffic is cheap; the practice is documented.
It is decrypted
The day the machine exists — not before, and not when you decide.
It is measured
Only here does this report’s index come in: how much your surface exposes you today.
What follows measures how protected you are against this clock — not whether the clock exists.
CISA, NSA and NIST — joint quantum-readiness factsheet, 2023.
The three numbers
Where this lands
The company in this example is fictional. The sector figures it is compared against are NOT: they come from the August 2026 study of 220 Chilean organizations, and are the same ones published in the monthly report.
Your score falls below the minimum we measured in Chilean banking (46). Of the 12 banking organizations with a computed index, none sits this low. On hybrid key exchange support the sector runs at 93 % (n = 15); you have it on 2 of your 5 hosts, and on both by CDN default rather than by your own decision.
The first three things to do
- Inventory public certificates and CT hostnames · hours · no cost
- Force TLS 1.3 and disable TLS 1.1 on the legacy host · hours · no cost
- Enable X25519MLKEM768 on the three hosts with no CDN (api, legacy, mail): OpenSSL 3.5+ or your server’s equivalent · days · no cost
Where you stand, against whom, and how much time is left
One chart, three questions. Your score (the dot), your sector’s middle half (the band), and the probability zones for the threat existing (the background, cited to the Global Risk Institute).
No trajectory line. No model exists today that computes what score results from executing the roadmap, and drawing one would be inventing data. That absence is a decision.
Time zones: Global Risk Institute, Quantum Threat Timeline Report 2025. Sector band: Rosetta’s August 2026 study of 220 Chilean organizations.
Top 5 findings
- Critical3 of 5 hosts (api, legacy, mail) negotiate classical cryptography only: no CDN in front to bring them the hybrid.
- CriticalBanking sector (long confidentiality horizon) with no PQC posture → critical HNDL index.
- HighLegacy host with TLS 1.1 and an RSA-1024 leaf certificate on a live subdomain.
- MediumWildcards on 4 hosts widen the blast radius; 6 orphan hostnames in CT.
- InfoNo security.txt or published crypto-agility policy; edge on Cloudflare (partial positive).
Cost of inaction (Mosca). X (confidentiality ~8 yr) + Y (migration ~9 yr) = 17 > Z (CRQC ~9 yr). Every quarter of delay shrinks the margin and grows the volume of already-harvestable traffic.
Context · the clock and HNDL
RSA/ECC will be vulnerable to Shor on a CRQC. Replacement standards (FIPS 203/204/205) have existed since 2024; NIST IR 8547 deprecates RSA-2048/ECC by 2030 and disallows them by 2035. Under harvest now, decrypt later, traffic encrypted today can be decrypted once a CRQC exists.
This report measures cryptographic exposure, not quantum advantage. They are different things: that Shor breaks RSA is a proven theorem; that a quantum computer beats a classical method on an optimization problem is an open empirical question, and not what this report answers.
The four clocks
The fair objection is “no rule obliges me yet”. It is true, and it changes nothing: four clocks are running and the regulator’s is the slowest.
- RunningYour deadline is set by the shelf life of your data. A mortgage has to stay secret for decades. Your deadline is not set by the regulator: it is set by how long your data must remain secret.
- RunningThe debt is already running. Traffic leaving encrypted today may be stored now to be read later. Nothing you do in 2030 protects what left in 2026.
- ApproachingThe requirement reaches you by contract before it reaches you by law. Your parent company, a correspondent bank or a large client’s security questionnaire will ask before any Chilean regulator does.
- ApproachingThe technical dates are already written. NIST sets deprecation of RSA and elliptic curves at 2030 and disallowance at 2035. The document (IR 8547) is still an initial public draft and we say so: not a binding obligation, but the date your vendors plan against.
And in Chile, plainly. As of this report, no Chilean regulator requires post-quantum cryptography. Not the CMF, not the ANCI, not the data protection agency. What does exist are operational-risk and information-security obligations under which a supervisor may ask about your plan. This report will not imply an obligation that does not exist.
Regulatory framework
| Rule | What it establishes | Requires PQC? |
|---|---|---|
| CMF · RAN Capítulo 20-10 · por verificar | Information security and cybersecurity management for banks. | No |
| Ley 21.663 · ANCI / OIV | Cybersecurity framework; Vital Importance Operator regime. | No |
| Ley 21.719 · Datos personales · por verificar | New agency, 72-hour breach notification; fully in force Dec-2026. | No |
Loaded jurisdiction: Chile — this block is a per-country module, not fixed text.
What is good
- okwww and online negotiate the hybrid today because Cloudflare ships it on by default. It is neither a pending win nor a decision of yours: it is a side effect of your CDN contract, and it covers only 2 of your 5 hosts.
- okTLS 1.3 present on www and online; no export ciphers observed.
- okDMARC and SPF configured on the mail domain.
What is wrong / critical
Observed inventory
| Host | TLS / algorithms | Hybrid | Edge |
|---|---|---|---|
| www.acme-bank.example | TLS 1.3 · X25519MLKEM768 / RSA-2048 | Sí · por defecto del CDN | Cloudflare |
| online.acme-bank.example | TLS 1.3 · X25519MLKEM768 / RSA-2048 | Sí · por defecto del CDN | Cloudflare |
| api.acme-bank.example | TLS 1.2 · ECDHE / ECDSA P-256 | No | — |
| legacy.acme-bank.example | TLS 1.1 · RSA / RSA-1024 | No | — |
| mail.acme-bank.example | STARTTLS · ECDHE / RSA-2048 | No | — |
Your critical path runs through your vendors
We cross the vendors visible on your surface, and the typical ones for your industry, against each manufacturer’s declared post-quantum status. This is what sets your real timeline — and it does not depend on you.
The network edge and the browsers have already solved this. The origin server — yours — is where the migration stalled. Your three hosts without a CDN sit squarely in that 90 % that has not moved.
Cloudflare Radar · Post-Quantum Encryption, 27-Feb-2026.
What we did detect on your surface
This is not a general library: it is your actual inventory, crossed against what each vendor does for you.
Cloudflare enables hybrid key exchange by default, on every plan and on both legs. These two hosts already have it without you doing anything; all that is left is confirming that no restricted cipher-suite configuration in your zone is switching it off.
There is no provider between your server and anyone watching, which is why they remain fully classical. What Cloudflare does or does not do never reaches them: their exposure depends entirely on what you configure.
The vendor library
The typical vendors in your industry, with what you would have to do in each case. Every row carries its source; anything unconfirmed is declared as such.
HSM · appliance and on-premise
| Vendor · product | What you must do | Detail |
|---|---|---|
| Entrust nShield 5s / 5c | Firmware | Firmware v13.8+ (also covers the earlier XC generation). The post-quantum feature ships always on, no separate licence. |
| Entrust nShield Connect XC / Solo XC | Separate licence | Firmware AND a separately purchased PostQuantum licence — unlike the 5 line. |
| Thales Luna 7 (firmware 7.9.0+) | Firmware | Native ML-KEM and ML-DSA from firmware 7.9.0 (Jul-2025) plus client 10.9.0+, on the Luna 7 hardware you already own. |
| Thales Luna 8 | New hardware | Not a firmware upgrade: a hardware replacement (Aug-2026). All certifications restart. This is budget, not a ticket. |
| Utimaco Quantum Protect | Separate licence | Add-on package for u.trust Se-Series and CSe-Series, field-upgradeable without changing hardware. Ships ML-KEM and ML-DSA. |
| Utimaco CP5 / eIDAS | No path | No published post-quantum path. If your use case is eIDAS qualified signing, there is no route with this vendor today. |
Cloud key management
| Vendor · product | What you must do | Detail |
|---|---|---|
| Azure Key Vault · Managed HSM · Cloud HSM | No PQC | No post-quantum, no preview, no announced date. Verified against the API’s actual enum. |
| AWS KMS | Partial | Offers ML-DSA as a signing key type (ML_DSA_44/65/87, since Jun-2025). Does NOT offer ML-KEM as an encapsulation service — AWS’s hybrid lives in the TLS to the API, a different layer. And ML-KEM is precisely what mitigates harvest-now-decrypt-later. |
| AWS CloudHSM | Partial | The vendor contradicts itself: its migration page says ML-DSA is “in preview”; the SDK release notes treat it as available. Ask in writing. |
| Google Cloud KMS | Partial | Post-quantum signing generally available (Jul-2026). The protection level — software only or backed by HSM — remains to be confirmed. |
| IBM z17 (CEX8S) | Firmware | IBM’s documented path to the final standards (FIPS 203/204) runs through z17 with CCA 8.4 firmware. |
| IBM z16 (CEX8S) | Partial | What is documented for z16 is CCA 8.0/8.2 — earlier-round Dilithium and Kyber, pre-standard. Does not satisfy FIPS 203/204. Open question to IBM. |
| IBM Hyper Protect Crypto Services | Deprecated | Its PQC is round-2 Dilithium only, on CEX7S — pre-standard. And the hardware behind it is end-of-life. |
Certificates and PKI
| Vendor · product | What you must do | Detail |
|---|---|---|
| ¿Existe un certificado TLS post-cuántico públicamente confiable? | No path | Not today. The CA/B Forum Baseline Requirements (v2.2.9) allow only RSA and ECDSA. No public authority can issue one even if it wanted to. |
| PKI privada con ML-DSA | Already there | It does exist: DigiCert and Sectigo (on request) and Microsoft AD CS already offer it — valid inside your own organization, not on the public internet. |
| Vigencia de certificados TLS | Dated | A parallel calendar that changes your operations: 100 days from 15-Mar-2027 and 47 days from 15-Mar-2029 (ballot SC-081v3). If your rotation is manual, this hits you before post-quantum does. |
Core banking and payments
| Vendor · product | What you must do | Detail |
|---|---|---|
| Temenos · Finastra · FIS · Fiserv · Flexcube | No statement | Zero occurrences of “quantum” in the FIS Security Statement and in the FY2025 10-K filings of FIS, Fiserv, Visa and Mastercard. |
| SWIFT — Release 8.0 | Dated | Mandatory by end of July 2027, with no upgrade path from 7.7. If you are on 7.7, that jump needs planning of its own. |
| EMVCo | No statement | Formally states it does not expect the threat “until at least 2040 – maybe never”. That is a published position, not silence: know that your card ecosystem thinks this way. |
Browsers
| Vendor · product | What you must do | Detail |
|---|---|---|
| Chrome / Edge 147 | Already there | No longer switchable off. Microsoft, verbatim: “This policy has been removed starting in Microsoft Edge version 147.” The client side stopped being optional. |
CDN and edge
| Vendor | Client → edge | Edge → origin |
|---|---|---|
| Cloudflare | By default | By default |
| Akamai Enhanced TLS | By default | By default since Oct-2025 |
| AWS CloudFront | By default | No confirmed date (checked Aug-2026) |
| Fastly | By default | No specific statement found |
| Azure Front Door | No public statement | No public statement |
| Akamai Standard TLS | Not available at that tier | Not available |
Word traps — the same finding stated backwards
Entrust · «Post-Quantum Option Pack» — It does not deliver the final standards, only the earlier candidates on CodeSafe, with a separate SEE licence. And in its own documentation: “the underlying Security World protection mechanisms still use classical (non post-quantum) crypto” — the Option Pack protects your post-quantum keys with classical cryptography. It is the lab path, not the production one.
Thales CipherTrust Manager · «soporta PQC» — It is only ML-KEM as TLS key agreement. It neither creates nor manages post-quantum keys: it protects the transport to the manager, not what the manager holds.
Azure · «quantum-resistant» — It appears in marketing material without matching any function available in Key Vault, Managed HSM or Cloud HSM. There is no preview and no date.
Status as declared by each manufacturer in public sources, with the date consulted. A “no date” does not mean the vendor is not working on it: it means you cannot plan against anything.
HNDL index + CRQC scenarios
Banking = high confidentiality horizon. The HNDL index combines sector with observed exposure:
| If the threat arrives in | Probability | What it means for you |
|---|---|---|
| 5 years · 2031 | ~15 % | Your migration is half done. Four years with a live threat while you migrate. |
| 10 years · 2036 | 28–49 % | Your migration just finished. Everything harvested before is still readable. |
| 15 years · 2041 | ≥ 51 % | Protected from then on; not what left before 2035. |
| 20 years · 2046 | ≥ 69 % | Protected. |
Global Risk Institute · Quantum Threat Timeline Report 2025 (7th edition, March 2026, 26 experts). Aggregate probability that a computer able to factor 2048 bits in under 24 hours exists.
Source limits: Small sample with varying composition year to year; probability bins are not uniform. The 2019–2021 surveys gave a higher probability for the same horizon.
Global Q-Ready score
Weighted mean of the dimensions measurable at the External tier:
| Dimension | Weight | 0–100 |
|---|---|---|
| Certificates / public PKI | 40% | 40 |
| Surface & hygiene | 25% | 52 |
| HNDL posture (time) | 25% | 15 |
| Edge TLS PQC | 10% | 40 |
Roadmap
30 days · Hygiene & visibility
| Action | Effort | Cost |
|---|---|---|
| Inventory public certificates and CT hostnames | hours | no cost |
| Force TLS 1.3 and disable TLS 1.1 on the legacy host | hours | no cost |
| Replace the RSA-1024 certificate | hours | no cost |
| Publish security.txt with a contact channel | minutes | no cost |
90 days · Hybrid where it is missing
| Action | Effort | Cost |
|---|---|---|
| Enable X25519MLKEM768 on the three hosts with no CDN (api, legacy, mail): OpenSSL 3.5+ or your server’s equivalent | days | no cost |
| Check that no cipher-suite restriction is disabling the hybrid Cloudflare already brings on www and online | minutes | no cost |
| Consolidate wildcards and retire orphan hostnames | days | no cost |
| Name a crypto-agility owner and define key rotation | days | no cost |
365 days · Interior
| Action | Effort | Cost |
|---|---|---|
| Cryptographic inventory of internal systems (CBOM) | weeks | needs budget |
| Post-quantum plan with HSM and key-management vendors | weeks | needs budget |
| Migrate signatures to ML-DSA where the vendor already supports it | weeks | needs budget |
| Quarterly re-scan | — | subscription |
The “no cost” actions require no purchase: they are your own team’s work with tools you already have. None of them is “flip a toggle on Cloudflare”: on hosts already behind Cloudflare the hybrid ships on by default, and there is nothing to enable.
Visibility gaps
The External tier does not observe the interior. These gaps close with Assisted (uploads + integrations) and Enterprise (partner):
- gapHSM/KMS inventory and internal keys
- gapApps, VPN and internal mTLS
- gapEncrypted databases and backups
- gapVendor PQC roadmaps
Appendix · methodology & limits
Public-surface evidence only: Certificate Transparency, DNS resolution, TLS probe (ClientHello with hybrid groups), public trust chain and light OSINT. No exploits, no aggressive port-scan, identified User-Agent. Not a certification and no substitute for a formal internal review.
Rosetta seal
Each report is sealed with the hash of the evidence JSON. In production it anchors to the Evidence Ledger (here, a sample, unanchored).
rosettaq-archive/v2 · sample · not anchored