QUANTUM INTEL6
[Quantum Computing]Google demonstrates 1,000-qubit processor milestone
CNSA 2.0178d
Q-Day~1274d
UNDERSTANDING THE QUANTUM RISK

Why quantum computers
break today’s encryption

Almost all encryption on the internet relies on math that quantum computers will be able to undo. This page explains the threat in plain language — and shows exactly what PQScore checks when it scores your domain.

⛛ THE CORE THREAT — “HARVEST NOW, DECRYPT LATER”

An adversary doesn’t need a quantum computer today to threaten you today. They can record your encrypted traffic now — customer data, financial transactions, internal communications — and simply store it.

When a sufficiently powerful quantum computer arrives (estimated around 2030), that stored traffic gets decrypted retroactively. Anything with a long shelf life — health records, trade secrets, state data — is already at risk the moment it’s sent.

THE CLOCK

A threat with deadlines

Q-Day — the point where quantum computers can break RSA and elliptic-curve cryptography — is estimated between 2028 and 2035. Regulators aren’t waiting: migration mandates are already on the calendar.

Jun 2026
DORA
EU · Financial
Dec 2026
NIS2 / COM(2026)13
EU
Jan 2027
CNSA 2.0
USA · National Security
Dec 2028
NCSC PQC
UK
Dec 2030
OMB M-23-02
USA · Federal
THE METHODOLOGY

What we test

Every scan runs 11 checks against your domain — across TLS, DNS and email. Each check carries a weight that reflects how much it matters for quantum resistance. Together they sum to 100, your PQScore.

Key Exchange30
Certificate Signature25
DNSSEC15
Certificate Hygiene8
Email Encryption (STARTTLS)4
Legacy TLS Protocols4
Weak Cipher Suites3
HTTP Strict Transport Security3
DKIM Email Signing4
DMARC Policy2
SPF Record2
🔑

Key Exchange

30 pts
WHAT IT IS
How your server and a visitor agree on a secret encryption key when a secure connection opens.
WHY IT MATTERS
ECDHE and RSA key exchange are broken by Shor’s algorithm on a quantum computer. Traffic captured today can be decrypted later — the “Harvest Now, Decrypt Later” attack.
HOW TO FIX
Deploy hybrid key exchange (X25519 + ML-KEM-768). Available in OpenSSL 3.2+, recent Nginx, and most major CDNs.
📜

Certificate Signature

25 pts
WHAT IT IS
The algorithm used to sign your domain’s TLS certificate — the proof that you are really you.
WHY IT MATTERS
RSA and ECDSA signatures can be forged by a quantum computer, letting an attacker impersonate your domain.
HOW TO FIX
Move to ML-DSA-65 (FIPS 204) once your CA supports it. Interim step: prefer ECDSA P-384 over P-256.
🌐

DNSSEC

15 pts
WHAT IT IS
Cryptographic signatures on your DNS records that prove they haven’t been tampered with.
WHY IT MATTERS
Without DNSSEC, attackers can redirect your domain to a fake server — a real risk today, not only after Q-Day.
HOW TO FIX
Enable DNSSEC at your registrar (one click on Cloudflare/Route53). Prefer Ed25519/Ed448 signing.
📅

Certificate Hygiene

8 pts
WHAT IT IS
How much life your current TLS certificate has left.
WHY IT MATTERS
An expired certificate blocks visitors outright. Frequent renewal is also your chance to adopt PQC certificates.
HOW TO FIX
Automate renewal (Let’s Encrypt + certbot) and use each renewal to upgrade the signature algorithm.
✉️

Email Encryption (STARTTLS)

4 pts
WHAT IT IS
Whether your mail server offers to encrypt email while it travels between servers.
WHY IT MATTERS
Without STARTTLS, mail between servers can travel in plaintext and be intercepted.
HOW TO FIX
Enable STARTTLS on your MX server and enforce it with MTA-STS to block downgrade attacks.
🧱

Legacy TLS Protocols

4 pts
WHAT IT IS
Whether your server still accepts the obsolete TLS 1.0 / 1.1 protocols.
WHY IT MATTERS
TLS 1.0/1.1 carry known flaws (POODLE, BEAST) and are banned by PCI DSS and modern frameworks.
HOW TO FIX
Disable TLS 1.0 and 1.1. Serve only TLS 1.2 and TLS 1.3.
🔓

Weak Cipher Suites

3 pts
WHAT IT IS
Encryption algorithms in your config that are already considered cryptographically weak.
WHY IT MATTERS
RC4, 3DES and NULL ciphers can be broken with classical computers today — quantum makes it worse.
HOW TO FIX
Remove RC4, 3DES, NULL, EXPORT and anonymous cipher suites from your TLS configuration.
🛡️

HTTP Strict Transport Security

3 pts
WHAT IT IS
A header telling browsers to always reach your site over HTTPS.
WHY IT MATTERS
Without HSTS, attackers can downgrade visitors to unencrypted HTTP (SSL stripping).
HOW TO FIX
Send Strict-Transport-Security with a long max-age, includeSubDomains, and preload.
🖋️

DKIM Email Signing

4 pts
WHAT IT IS
The algorithm used to cryptographically sign the email your domain sends.
WHY IT MATTERS
RSA DKIM signatures are quantum-vulnerable — a quantum attacker could forge your mail, enabling phishing at scale.
HOW TO FIX
Rotate the DKIM key to Ed25519 as an interim step; watch IETF for PQ-DKIM standardisation.
📨

DMARC Policy

2 pts
WHAT IT IS
A policy telling receivers what to do with mail that fails SPF/DKIM checks.
WHY IT MATTERS
Without a strict DMARC policy, anyone can send email pretending to be your domain.
HOW TO FIX
Publish a DMARC record with p=reject and a reporting address.
📋

SPF Record

2 pts
WHAT IT IS
A DNS record listing which servers may send email for your domain.
WHY IT MATTERS
Without SPF, anyone can send mail claiming to come from your domain.
HOW TO FIX
Publish an SPF record ending in -all (hard fail) listing only your authorised senders.

We also gather SSH and API-endpoint signals for the detailed report, but those don’t affect the numeric score — only the 11 weighted checks above do.

READING YOUR SCORE

From 100 down

Every domain starts at 100. Each weakness subtracts a share of its check’s weight — a fully quantum-vulnerable key exchange costs the most, a missing SPF record the least. The result lands in one of four risk bands.

Low
80–100
Quantum-ready or close. Maintain and monitor.
Medium
55–79
Some progress, but key gaps remain. Plan the migration.
High
30–54
Significant exposure. Begin migration now.
Critical
0–29
Severe gaps. Adversaries can harvest your traffic today.

See where your domain stands

Run a free scan and get your PQScore, a sector benchmark, and a prioritised migration roadmap — in about a minute.