The Post-Quantum Cryptography Alliance PQC Readiness Tracking Working Group is a community driven effort to collect, verify and publish information about devices and software that need to be updated to remain secure when post-quantum computers can factor (break) classical asymmetric cryptography.
- Working Group Mailing List: https://lists.pqca.org/g/wg-readiness-tracking
- GitHub Repository: https://github.com/PQCA/wg-readiness-tracking
- Meeting Cadence: Every 2 weeks @ 9am US/Pacific time, beginning May 21, 2026 meeting link
- Cryptographic Libraries - Tracking PQC readiness for cryptography libraries and tools
- HSMs - Hardware Security Modules
- Web Browsers - Tracking PQC support in major web browsers
- Cloudflare PQC Tracker
- PKI Consortium Tracker - Outdated, but potentially useful
- Focus first on Harvest Now Decrypt Later (HNDL) / Store Now Decrypt Later (SNDL) first by protecting key exchanges.
- As Post-quantum secure key encapsulation is deployed, start working on signature algorithm updates.
- Lead with discovery and inventory. Without basic cryptographic hygiene, you cannot make fully informed decisions about where to focus.
- As your inventory improves work on cryptographic agility. To the extent possible use libraries like Tink that support multiple keysets and can substantially de-risk and ease transitions.
- For use cases that rely on TLS for transport security and signing, if you cannot move to TLS 1.3 with downgrade protections, you do not have a reliable path to PQC. If you rely on the WebPKI for public trust (use public CAs), plan to move to Merkle Tree Certificates. For private PKIs, plan to move to ML-DSA signatures in X.509.
CISA offers a good general PQC risk management framework
It is acceptable to use AI tools to help gather information, but contributors must self-review their changes before opening a PR. Contributors are also encouraged to disclose any AI tools used, to help maintain transparency.
To make it easy to contribute and consume readiness information, Markdown tables are used based on the Proposed tracking template.
The initial focus of the working group is to refine the format and processes for vetting and approving information using the Cryptographic Library tracker