PQSecScan PQC by MiraeStudio.id

How ready is your server for quantum computers?

Each check is compared with its reference value. The sample below is the real result for our own site, miraestudio.id, with its PDF report.

Request form

Reads only the server's first reply. No login, nothing on the server changes.

Checks

No access code yet? Ask on WhatsApp

Understanding your result

Quantum computers don't threaten all of cryptography, and not every fix can be made today. This section explains what each row on the result sheet means, and why. As of October 2026; full sources are on the method page.

What gets checked

Every row

When a browser opens an HTTPS site, three things happen in a fraction of a second:

  1. The browser and server agree on a secret key through a key exchange. The PQ key exchange row checks this step.
  2. The server shows its certificate, a signed digital ID card. The Certificate row checks what kind of signature it uses.
  3. Data travels locked with AES, which stays safe.

Quantum computers threaten steps 1 and 2. The TLS versions row checks that the server speaks TLS 1.3, the only version where post-quantum key exchange exists. The SSH row checks the server's remote-login door, which uses the same cryptography.

What quantum computers break

Rows Key exchange, Certificate

Shor's algorithm (1994) breaks RSA and ECC alike, whatever the key size, given a large enough quantum computer. Grover's algorithm (1996) only speeds up key guessing, so AES-256 stays as strong as 128 bits: still impossible to guess.

AlgorithmFateWhat to do
RSA, ECC (ECDH, X25519)BrokenMove to ML-KEM, hybrid first
RSA, ECDSA signaturesBrokenMove to ML-DSA or SLH-DSA
AES-256, ChaCha20SafeNo change needed
SHA-256, SHA-3Safe, slightly weakenedSHA-384 or higher for the long term

Because Shor breaks RSA and ECC alike, SecScan gives every classical certificate the same score. RSA-4096 is no more quantum-resistant than ECDSA.

Harvest now, decrypt later

Row Key exchange

An attacker can record encrypted traffic today and keep it until a large enough quantum computer exists. Medical records, population data and financial data that must stay secret for years are already at risk. That is why key exchange carries the largest weight: the recording can happen today, and so can the fix.

Signatures are different. Old signatures can't be forged after the fact, so the threat only becomes real once a quantum computer exists. Devices that stay in service for many years, such as cars, satellites and industrial machines, still need post-quantum signatures from the factory.

Mosca's inequality: if how long data must stay secret, plus how long migration takes (usually 5–15 years), is longer than the time left before quantum computers arrive, you are already late.

How close Q-Day is

No quantum computer can break RSA or ECC yet. But the estimated resources needed keep falling:

WhenWhoTargetPhysical qubits
2019Gidney & Ekerå (Google)RSA-2048~20 million
May 2025Gidney (Google)RSA-2048< 1 million
Feb 2026Iceberg QuantumRSA-2048< 100,000
Mar 2026Google Quantum AI et al.ECC-256< 500,000

The last two figures come from simulations that assume hardware more advanced than today's. The best machines of 2026 have about 50–100 logical qubits, while ECC-256 needs about 1,200. The gap is still wide, but it is closing faster than expected.

Treat "quantum computer breaks RSA" headlines with care: the largest number Shor's algorithm has factored so far is 21.

The replacements are standardised

Rows Key exchange, Certificate

Post-quantum cryptography (PQC) is new mathematics that stays hard for quantum computers. It runs on ordinary computers and phones through software updates. NIST published it in August 2024 after an open eight-year competition.

NameStandardOld nameFor
ML-KEMFIPS 203KyberKey exchange
ML-DSAFIPS 204DilithiumSignatures
SLH-DSAFIPS 205SPHINCS+Backup signatures

What runs today is hybrid: X25519MLKEM768 fits the old lock and the new lock together, so an attacker has to open both. Chrome, Edge, Firefox and Safari already use it automatically, as do OpenSSL 3.5+, Go 1.24+ and Cloudflare. A server that accepts it gets full marks on the key exchange row.

Why the certificate row still shows L

Row Certificate

Almost every public site today gets an L on the certificate row, including the sample above. That isn't the owner's fault: no public CA issues ML-DSA certificates for the web yet, and browsers don't accept them. So the highest score a public site can reach today is 92.

The main problem is size. One HTTPS handshake carries about five signatures:

AlgorithmPublic key (bytes)Signature (bytes)
ECDSA P-25664~64–72
RSA-2048256256
ML-DSA-441,3122,420
ML-DSA-651,9523,309

The fix in preparation is called Merkle Tree Certificates: many certificates are signed together with a single signature. Let's Encrypt is trialling it in late 2026 and aims for production in 2027; Cloudflare starts issuing PQC certificates in 2027.

Deadlines

  • NIST IR 8547 (draft): RSA-2048 and equivalents deprecated after 2030; all RSA and ECC disallowed after 2035.
  • United States: Executive Order 14412 (June 2026) sets PQC key exchange by 31 December 2030 and PQC signatures by 31 December 2031 for high-value systems.
  • EU and UK: critical infrastructure around 2030–2031, done by 2035.
  • Indonesia: BSSN published its Post-Quantum Cryptography Migration Guide v1.0 (December 2025), recommends ML-KEM-1024 and ML-DSA-87 in hybrid mode, and is drafting a national roadmap through a task force (2026). The official list of approved cryptographic algorithms does not include PQC yet.

Common misconceptions

  • Quantum computers break all encryption.Only public-key cryptography (RSA, ECC) breaks. AES-256 and SHA-256 stay safe.
  • PQC needs a quantum computer.PQC is ordinary software and already runs in your browser.
  • Just raise RSA to 4096 bits.Shor still breaks it; a bigger key only adds a little work.
  • AES-256 has to be replaced too.No. What changes is how keys are exchanged and how identity is proven.
  • PQC certificates already work on the web.Not yet. Web PQC certificates start in 2027.
  • It's decades away, no rush.Data recorded today can be opened later, and migration takes 5–15 years.

Fixing the findings

Every row

No PQ key exchange. Update the TLS stack. OpenSSL 3.5+ and Go 1.24+ already offer X25519MLKEM768; Caddy 2.10+ turns it on with no configuration. For nginx with OpenSSL 3.5+:

ssl_protocols TLSv1.3;
ssl_ecdh_curve X25519MLKEM768:X25519:prime256v1;

TLS 1.2 or older still enabled. Turn off TLS 1.0 and 1.1 now. Turn off TLS 1.2 once you are sure no old clients still need it.

SSH without PQ KEX, or with an RSA host key. Upgrade to OpenSSH 9.9+ for mlkem768x25519-sha256, remove the RSA host key, or close SSH to the internet and reach it through a VPN.

Classical certificate. Public sites can't fix this yet. Make sure automated certificate issuance (ACME) can switch algorithms, keep an inventory of your certificates, and ask your CA about its PQC plans.