FINMA 05/2026 A post-quantum roadmap by mid-2027: what it asks →
Cryptographic inventory & post-quantum readiness
You can’t migrate the cryptography you can’t see.
Post Quantum Leap finds every certificate, protocol and cipher in your infrastructure, grades them against your policy, and helps you plan the move to post-quantum. Built for the security, PKI and compliance teams responsible for getting there.
- Managed · your cloud · on-prem
- Active TLS scanning
The hostnames are invented, the pattern is real: four of these five endpoints use a key exchange that a quantum computer will break. Today, all five look healthy.
Why now
Are you already too late?
Attackers record encrypted traffic today and decrypt it once a quantum computer can. This is called harvest now, decrypt later. Whether that makes you late already is arithmetic, not opinion. Three numbers, your numbers:
Data you encrypt today still needs protection in 2041, 6 years after the quantum computer you just assumed. On your own numbers, you are 6 years too late.
What your regulator actually requires, and by when →
Nobody knows the arrival year: the US Office of Management and Budget confirmed in writing in June 2026 that no cryptographically relevant quantum computer is known to exist. That is why the third slider is yours to set. The other two are the ones you control.
Behind this sit real deadlines from the EU, Germany’s BSI and a US executive order, and FINMA’s guidance for the Swiss institutions it supervises.
The full picture, with sources →Migration reality
Post-quantum certificates are not a drop-in replacement.
A signature that fits in 64 bytes today takes thousands of bytes post-quantum, on every certificate and in every handshake.
Signature sizes from NIST FIPS 204; multiples relative to ECDSA P-256. A certificate chain carries several signatures and public keys, so the bytes multiply before they travel.
The question is not whether the network can carry the bytes. It is which endpoints, appliances and embedded clients cannot, and what every renewal touches. That is an inventory question.
See what a scan findsWhat it does
From “we think we know” to a plan you can act on.
Discover
Find every endpoint, and the keys a network scan cannot see
Network scans read the full TLS handshake of more than 40 kinds of service, from web and mail to databases and remote desktop.
- Sweeps whole network ranges, works through your proxies, and can take its targets from a DNS zone file
- Where a scan cannot see inside a machine, a host scanner for Linux, Windows or macOS finds certificate stores, key files, SSH keys and keystores. No private key ever leaves the machine
- A remote engine inside a DMZ or isolated segment connects out to Post Quantum Leap, so no inbound firewall rule is needed. Host scanners there report through it
- Import certificate files, a CBOM or a host list. Enter by hand what no scan can reach, such as an HSM
Inventory
One inventory for endpoints, certificates and keys
Everything sits in one place to search, filter and export, instead of several tools that each hold part of the answer.
- Keys are graded too: by default, a post-quantum key gets an A and a strong classical key a B
- See how many endpoints share a certificate before you replace it
- Trust chains are checked against the public CA stores, and every certificate keeps its history
- Filter by SAN, issuing CA, extended key usage, forward secrecy and more, and export any view to Excel or a CycloneDX CBOM
Grade and report
Your policy, and the frameworks you are measured on
Start from a built-in policy (strict post-quantum, or SSL Labs compatible) and change any single rule. A change re-grades everything at once, without a new scan.
- Eleven framework reports: NIST PQC, CNSA 2.0, BSI TR-02102, NIST IR 8547, PCI DSS 4.0, FIPS 140-3, ANSSI, MAS TRM, DORA, FINMA 05/2026, and our own harvest-now-decrypt-later view
- Reports apply each framework’s own rules, not your policy, and name the rule behind every verdict, one row per endpoint
- A quantum-safe key exchange in front of a classical certificate does not count as ready
- Each report says what it cannot check. FIPS 140-3, for example, cannot confirm CMVP module validation
- Every weakness comes with a recommended fix, and every report exports to Excel or PDF
Plan
Decide what moves when, and who is responsible
Group the findings into pieces of work, put them into dated waves, and give each wave an owner. Post Quantum Leap can draft the order, most exposed first. Nothing changes until you accept it.
- Write rules such as “RSA 2048 or weaker on the perimeter”. Matching hosts join after every scan
- See where one change fixes many findings, such as one issuing CA behind many endpoints
- Check how far the plan lowers your exposure against the risk appetite you set. The model is our own, and its years are estimates
- Take the plan to your board as an editable PowerPoint deck
Proof
Don’t take our word for it.
A real scan, of this website
This is Post Quantum Leap scanning this very website, and reporting the hybrid post-quantum key exchange it negotiated.
Dependencies
See what actually depends on what
An interactive graph of services, protocols, cipher suites and algorithms for any target, coloured by post-quantum rating. Click a node and the whole chain around it lights up.
- Every node shows its post-quantum rating and the estimated year its algorithm stops being safe
- It turns “we should migrate” into “migrating this affects these four services”
Dashboards you can drill into
No number has to be taken on trust: click any tile, bar or row and you see the endpoints it counted.
Why Post Quantum Leap
Why teams pick it.
It runs where your policy says it must
A complete map of your weakest cryptography is sensitive by definition, so you decide where it runs, up to fully air-gapped on your own hardware.
The policy is yours
Grading presets you can override algorithm by algorithm, not a vendor opinion baked into a score. Policies genuinely differ: Canton Bern, for instance, mandates FrodoKEM and Classic McEliece rather than ML-KEM.
Governance is built in
Owners, criticality and your own fields sit on the endpoint and survive every certificate renewal. Every change is recorded, three roles apply everywhere, and people sign in with Entra ID, OpenID Connect or a passkey.
Built in Switzerland
Post Quantum Leap is developed and supported by a Swiss company. The product, the people behind it and the support all sit under Swiss jurisdiction.
How it runs, and where
One container, one database, running where you choose.
- 01
Point it at your infrastructure
Paste a list of targets, import certificates as PEM or CBOM, or let a network sweep find them. Add host scanners where the network cannot reach.
- 02
Let it scan
Scans run in the background, on your schedule and in your timezone, with speed settings that keep intrusion detection quiet. Progress shows in the top bar.
- 03
Plan and track the migration
Dated waves with an owner each, a prioritised list of what to fix first, and your posture over time.
The architecture and the three deployment models have their own page:
Architecture and deployment options →Request a live demo
See it live, then try it yourself.
Around 30 to 45 minutes, online. We drive: nothing to install, no environment to prepare, no data needed from you. We walk through discovery, the inventory, the crypto graph, compliance reporting and planning on a full demo installation, then spend most of the time on whatever is closest to your situation.
If you want to keep going after that, we can give you a login to a demo tenant, or set you up with a local install so you can try it against your own infrastructure.
- What you get
- A straight answer on whether Post Quantum Leap fits your infrastructure, including when it does not.
- Prefer email
- info@postquantumleap.com
Request received.
We have emailed you a confirmation and will reply within one working day with a few suggested times. If nothing arrives, write to info@postquantumleap.com.