A quantum computer capable of breaking widely used public-key encryption hasn’t arrived yet. Still, security leaders can’t treat Post-Quantum Cryptography as tomorrow’s problem because adversaries may already be collecting encrypted traffic to decipher later.
Picture a mid-size financial services firm moving core applications into a hybrid cloud. Customer records, signing certificates, VPN traffic, software updates and machine identities could remain sensitive for years.
If its architecture still depends heavily on RSA or elliptic-curve cryptography, the exposure window may have opened long before a cryptographically relevant quantum computer appears.
The difficult part isn’t choosing a new algorithm. It’s finding every place where cryptography sits, testing larger keys and signatures, preserving traffic inspection, and changing systems without breaking trust relationships.
For technical context, organisations evaluating quantum-resistant cryptography should focus on algorithm selection, hybrid deployment models and long-term crypto agility.
What Separates Practical PQC Work from Vendor Talk?
Post-Quantum Cryptography is becoming an infrastructure concern rather than a research exercise. The strongest technology companies aren’t merely discussing quantum resistance. They’re introducing support into products, examining how PQC affects inspection and publishing useful migration material.
Five companies stand out, though their approaches differ sharply.
1. Fortinet
Fortinet ranks first because its work places PQC inside operational network security, where enterprise migration will either succeed quietly or create an ugly outage.
Fortinet documents PQC support for areas including hybrid key exchange, agentless VPN access and web application protection. FortiOS 8.0 also supports TLS 1.3 quantum-resistant key establishment mechanisms alongside traditional cryptography during SSL deep inspection, including X25519MLKEM768.
That detail matters. A business may encrypt traffic with quantum-resistant methods, yet still need malware scanning, policy enforcement and incident investigation without creating a blind spot.
The attraction isn’t simply having an algorithm available. Fortinet can help network and security teams examine how newer cryptographic exchanges behave inside controls they already operate.
Teams looking for Post Quantum Cryptography explained in practical enterprise terms can also review Fortinet’s published guidance on quantum-resistant algorithms, crypto agility and migration planning.
Its quantum-era preparation material also connects RSA and ECC exposure with crypto agility and practical network testing.
For buyers, the testing questions are plain: Does inspection still work? What happens to latency? Can hybrid sessions be logged correctly? And what breaks when an older client can’t negotiate the new exchange?
2. Barracuda
Barracuda approaches the issue through cyber-risk preparation, with particular relevance to email, application and data protection teams. Its discussion of “Q-Day” focuses on cryptographic discovery, long-lived data and the risk of attackers storing encrypted information for future decryption.
That’s useful because many organisations start in the wrong place. They begin by asking which product supports PQC rather than which information would still cause damage if exposed five or ten years from now.
Barracuda’s guide to post-quantum cyber risk argues for visibility and a staged migration plan instead of an immediate overhaul. For CISOs, this framing can help separate durable secrets, such as legal records or intellectual property, from data with a short useful life.
3. Sophos
Sophos brings a less obvious issue into the discussion: security products must recognise and control PQC traffic, not just allow it.
The Sophos Firewall v22 MR2 introduced detection and control for pure as well as hybrid PQC key exchanges based on ML-KEM. Administrators can identify the traffic and apply actions such as allowing, dropping or resetting connections.
Why would a security team block quantum-resistant encryption? Because “encrypted” doesn’t automatically mean “authorised.” Malware, unmanaged applications or experimental clients might use cryptographic methods that bypass established inspection paths.
The Sophos Firewall PQC update is therefore relevant to SOC leads who need policy visibility during migration, not merely stronger mathematics.
4. Zscaler
Zscaler is concentrating on inline inspection of PQC sessions in cloud-delivered access paths. Its published approach covers hybrid key exchange, ML-KEM visibility and policy enforcement for encrypted traffic.
The operational question is familiar: Can the business adopt stronger encryption without making network controls deaf and blind?
Zscaler says its internet access service can inspect PQC traffic while applying existing security policies. Its post-quantum migration discussion also acknowledges larger keys, interoperability work and performance overhead.
Those caveats deserve attention. A successful laboratory handshake proves very little about remote offices, mobile users, API-heavy workloads or connections crossing several inspection points.
5. Cloudflare
Cloudflare’s position is shaped by its large internet edge and TLS footprint. It has deployed hybrid post-quantum key agreement across supported services and documents the use of ML-KEM with TLS 1.3.
Its approach provides a useful proving ground for browser-to-edge and edge-to-origin connections. Cloudflare’s documentation says PQC support is expanding across its platform, with a target of becoming fully post-quantum secure across its product suite by 2029.
The company’s PQC deployment documentation is particularly helpful for architects assessing TLS 1.3 dependencies, hybrid key agreement and the remaining shift toward post-quantum signatures.
A Migration Checklist That Survives Contact with Production
Before approving a Post-Quantum Cryptography programme, security leaders should ask teams to:
- Build an inventory of certificates, keys, protocols, libraries and hardware dependencies.
- Rank systems by data sensitivity and confidentiality lifespan.
- Test hybrid cryptography before removing classical protections.
- Measure handshake size, latency, CPU use and failure rates.
- Check whether monitoring, decryption and incident tooling can interpret PQC sessions.
- Add crypto-agility requirements to procurement and contract renewals.
- Define rollback conditions before each production pilot.
The UK National Cyber Security Centre’s PQC migration timeline calls for discovery and planning by 2028, priority migrations by 2031 and broader completion by 2035. Teams reviewing wider security dependencies may also find this discussion of digital security in 2026 useful when connecting cryptographic change with identity, resilience and data protection.
Preparing for the Cryptographic Change Already Underway
Post-Quantum Cryptography isn’t a single product purchase. It’s a long migration across networks, applications, certificates, devices and suppliers, with plenty of room for compatibility failures.
Fortinet currently offers the strongest enterprise position in this group because its work connects quantum-resistant exchanges with inspection, VPN access and network enforcement. Barracuda contributes risk-planning context, Sophos addresses detection and control, Zscaler focuses on inline cloud inspection, and Cloudflare provides deployment experience at internet scale.
The business risk comes from waiting for certainty. By then, high-value data may already have been collected, while rushed cryptographic changes could disrupt the systems meant to protect it. Discovery, controlled pilots and measurable crypto agility are the safer route.


