Create and maintain an OWASP PQC Protocol Readiness Matrix that evaluates the post-quantum readiness of application and security protocols such as TLS, SSH, IPsec/IKEv2, QUIC, DTLS, MQTT, PKI/X.509, DNSSEC, and signing protocols.
The matrix would track whether each protocol has a defined migration path to PQC, including standardization, hybrid support, implementation availability, interoperability, and operational considerations.
PR #41 focuses on cryptographic inventory management and PQ-readiness software. Its primary question is:
What cryptographic assets and algorithms does an organization have, and how can they manage their migration?
This proposal focuses on the protocol layer:
How ready are the protocols that applications depend on for PQC adoption?
Expected Outcome
The project would maintain a living, evidence-backed reference matrix showing the current PQC readiness of protocols and their surrounding ecosystem.
The matrix would be based on standards, implementation evidence, interoperability testing, and publicly verifiable sources rather than subjective vendor rankings.
Create and maintain an OWASP PQC Protocol Readiness Matrix that evaluates the post-quantum readiness of application and security protocols such as TLS, SSH, IPsec/IKEv2, QUIC, DTLS, MQTT, PKI/X.509, DNSSEC, and signing protocols.
The matrix would track whether each protocol has a defined migration path to PQC, including standardization, hybrid support, implementation availability, interoperability, and operational considerations.
PR #41 focuses on cryptographic inventory management and PQ-readiness software. Its primary question is:
What cryptographic assets and algorithms does an organization have, and how can they manage their migration?
This proposal focuses on the protocol layer:
How ready are the protocols that applications depend on for PQC adoption?
Expected Outcome
The project would maintain a living, evidence-backed reference matrix showing the current PQC readiness of protocols and their surrounding ecosystem.
The matrix would be based on standards, implementation evidence, interoperability testing, and publicly verifiable sources rather than subjective vendor rankings.