Glossary

    Post-Quantum Cryptography

    Data Protection

    Post-Quantum Cryptography (PQC) refers to cryptographic algorithms that are secure against both classical and quantum computer attacks. Current encryption (RSA, ECC) could be broken by sufficiently powerful quantum computers, making data encrypted today vulnerable to "harvest-now, decrypt-later" attacks.

    AWS PQC Support (rolled out throughout 2025)

    • KMS: post-quantum digital signatures (ML-DSA) since June 2025; post-quantum TLS (ML-KEM) for data in transit to KMS endpoints
    • CloudFront: post-quantum TLS for data in transit since September 2025
    • ACM Private CA: post-quantum certificate issuance since November 2025
    • Secrets Manager: post-quantum TLS protection for stored secrets

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.