Post-quantum PKI and cryptographic agility

Prepare your PKI for the post-quantum transition.

NIST standardized ML-DSA in FIPS 204 for post-quantum digital signatures. SecuriTLS supports ML-DSA alongside RSA and elliptic curve cryptography so private PKI teams can begin testing migration paths before quantum-resistant signatures become an urgent requirement.

Create ML-DSA certificate authorities and leaf certificates, build mixed-algorithm hierarchies, and manage lifecycle, revocation, storage, custody, deployment, validation, and audit workflows from the same platform.

RSAEstablished
ECModern
ML-DSAPost-quantum
Why post-quantum readiness matters

Cryptographic migration takes longer than generating a new key.

NIST says organizations should begin migrating systems to quantum-resistant cryptography. PKI migration requires inventory, compatibility testing, trust-chain design, lifecycle operations, deployment changes, and validation across the systems that consume certificates.

Start compatibility testing now

Identify applications, libraries, devices, and services that can consume ML-DSA keys and certificates before migration becomes time-sensitive.

Keep existing algorithms available

RSA and EC remain important for compatibility. Crypto agility means being able to operate multiple algorithms while migration is underway.

Automate the operational layer

A new signature algorithm still needs issuance, renewal, revocation, deployment, validation, storage, custody, and audit workflows.

Supported algorithms

One lifecycle across RSA, EC, and ML-DSA.

RSA

2048, 3072, and 4096-bit keys with SHA-256, SHA-384, and SHA-512 signature hashes.

Elliptic Curve

P-256, P-384, and P-521 keys with supported SHA-2 signature hashes.

ML-DSA

ML-DSA-44, ML-DSA-65, and ML-DSA-87 parameter sets for post-quantum digital signatures.

Migration strategy

Use mixed-algorithm hierarchies to test realistic transition paths.

The subject public-key algorithm and issuer signing algorithm do not have to be the same. SecuriTLS supports mixed-algorithm private PKI paths so you can test how different trust chains behave across your infrastructure.

1

Inventory consumers

Find the services, devices, libraries, and automation that depend on your certificate formats and signature algorithms.

2

Build an ML-DSA test hierarchy

Create post-quantum CAs or leaves alongside RSA and EC and validate application compatibility.

3

Automate rotation and deployment

Treat cryptographic migration as a lifecycle operation rather than a one-time certificate-generation project.

NIST standardization

ML-DSA is standardized in FIPS 204.

FIPS 204 specifies ML-DSA for generating and verifying digital signatures and states that ML-DSA is believed secure even against adversaries with a large-scale quantum computer.