Configuration
Assumptions you can change
The rupture year depends on assumptions, so they are settings rather than constants. Every change re-scores the whole estate through the same engine the API and agent tools use, and the profile is stored with your session.
Survey profile
Midpoint between the conservative and aggressive projections: error correction and logical clock rates improve somewhat faster than the conservative case.
Danger zone
Retire every primitive in this session
Rows are tombstoned rather than deleted so the seal chain remains replayable. This cannot be undone, and it only affects the anonymous scope that owns them.
Algorithm registry
What the engine knows about
| Algorithm | Family | Bits | Attack | PQ | Migrate to |
|---|---|---|---|---|---|
| RSA-1024Below the NIST SP 800-57 floor of 112 bits and already factorable in practice. | rsa | 1024 | shor | no | ML-KEM-768 (FIPS 203) |
| RSA-2048The most widely deployed public-key size. Shor-broken in a cryptographically relevant timeframe. | rsa | 2048 | shor | no | ML-KEM-768 (FIPS 203) |
| RSA-3072Marginally above the NIST 112-bit floor; quantum cost grows superlinearly. | rsa | 3072 | shor | no | ML-KEM-768 (FIPS 203) |
| RSA-4096Largest common RSA modulus; the most expensive classical size to attack and quantum alike. | rsa | 4096 | shor | no | ML-KEM-1024 (FIPS 203) |
| ECDSA-P256Curve25519/P-256 discrete logs are Shor-broken; no ECC curve is quantum safe. | elliptic-curve | 256 | shor | no | ML-DSA-65 (FIPS 204) |
| ECDSA-P384Common in TLS 1.3 certificate chains and code signing roots. | elliptic-curve | 384 | shor | no | ML-DSA-87 (FIPS 204) |
| Ed25519Fast and common for SSH and code signing; still Shor-broken. | elliptic-curve | 256 | shor | no | ML-DSA-65 (FIPS 204) |
| X25519Default TLS 1.3 key exchange group alongside P-256. | elliptic-curve | 255 | shor | no | ML-KEM-768 (FIPS 203) |
| DH-2048Legacy TLS and SFTP key exchange; index calculus and Shor both apply. | finite-field | 2048 | shor | no | ML-KEM-768 (FIPS 203) |
| AES-128-GCMGrover halves the effective security of symmetric primitives to their key length. | symmetric | 128 | grover | no | AES-256-GCM |
| AES-256-GCMRetains 128-bit security against Grover; normally kept as-is. | symmetric | 256 | grover | no | AES-256-GCM (retain) |
| CHACHA20-POLY1305Software-optimized AEAD; Grover-resistant at 256-bit keys. | symmetric | 256 | grover | no | ChaCha20-Poly1305 (retain) |
| SHA-1Collision attacks are practical today; quantum resistance is irrelevant until it is replaced. | hash | 160 | grover | no | SHA-256 |
| SHA-256256-bit preimage resistance falls to 128 bits under Grover, which remains ample. | hash | 256 | grover | no | SHA-256 (retain) |
| SHA-512Wide-pipe hash retained for signatures and long-lived digests. | hash | 512 | grover | no | SHA-512 (retain) |
| ML-KEM-768FIPS 203Module-Lattice-Based Key-Encapsulation Mechanism, NIST PQC standard 1 of 3. | lattice | 768 | none | yes | Deployed |
| ML-KEM-1024FIPS 203Highest security category of FIPS 203. | lattice | 1024 | none | yes | Deployed |
| ML-DSA-65FIPS 204Module-Lattice-Based Digital Signature Algorithm, NIST PQC standard 2 of 3. | lattice | 3309 | none | yes | Deployed |
| ML-DSA-87FIPS 204Largest FIPS 204 signature category. | lattice | 4627 | none | yes | Deployed |
| SLH-DSA-65FIPS 205Stateless hash-based signature; security from preimage resistance rather than lattice problems. | hash-based | 65 | none | yes | Deployed |
| HQC-128Selected by NIST in March 2025 as a backup key-encapsulation mechanism. | code-based | 128 | none | yes | Backup KEM under standardization |
Compliance regimes
Which clock binds you
NIST IR 8547 transition timeline
Quantum-vulnerable algorithms deprecated after 2030 and disallowed after 2035. Applies to all FIPS-approved uses.
NIST IR 8547 ipd, Transition to Post-Quantum Cryptography Standards (Nov 2024)
- 2030 · Quantum-vulnerable algorithms deprecated
- 2035 · Quantum-vulnerable algorithms disallowed
US Executive Order 14412 / OMB M-26-15
High-value assets and high-impact systems move to post-quantum key establishment by end of 2030 and signatures by end of 2031.
Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (22 Jun 2026); OMB M-26-15
- 2030 · High-value assets: post-quantum key establishment
- 2031 · High-impact systems: post-quantum signatures
- 2035 · Remaining systems migrated
CNSA 2.0 (NSA)
Software and firmware signing on PQC by 2025, preferred by 2030, required for new systems by 2033.
NSA Commercial National Security Algorithm Suite 2.0 FAQ (updated Dec 2024)
- 2025 · Software and firmware signing on PQC
- 2030 · PQC preferred
- 2033 · PQC required for new systems
UK NCSC roadmap
Discovery by 2028, priority systems by 2031, full migration by 2035.
UK NCSC, Timelines for migration to post-quantum cryptography
- 2028 · Complete discovery
- 2031 · Priority systems migrated
- 2035 · Full migration
Manifest contract
Copy the reference manifest
label,system,usage,algorithm,deployment,confidentialityYears,dataClass,ownerTeam,notes,cve Payments API TLS certificate,payments-gateway,certificate,RSA-2048,partner-shared,7,regulated,platform,"customer payment flows, 10y retention", Partner SFTP key exchange,partner-sftp,key-establishment,DH-2048,partner-shared,10,confidential,integrations,"quarterly partner statement transfer", Data lake envelope encryption,data-lake,data-at-rest,AES-256-GCM,data-at-rest,12,regulated,data-platform,"column-level keys in KMS", Mobile app pinning cert,mobile,certificate,ECDSA-P256,internet,5,internal,mobile,"issued by internal CA", Okta OIDC signing key,identity,signature,Ed25519,internal,5,internal,identity,"SSO session signing", Release signing key,ci,signature,RSA-4096,internal,7,internal,platform,"notarized binaries",CVE-2021-44228