Why Collatz Labs

The post-quantum transition isn't a thought experiment. It's already in production.

We follow the same practical path the industry has already converged on — not a hypothetical one.

The Threat Is Timed, Not Theoretical

Data encrypted today can be decrypted later. That attack is already running.

Adversaries don't need a working quantum computer today to profit from one tomorrow. They can capture encrypted traffic and backups now, store them, and decrypt them once a large enough quantum computer exists — an approach security researchers call "harvest now, decrypt later." Any data that needs to stay confidential for years — health records, financial data, trade secrets, government communications — is exposed to this today, not someday.

August 2024

NIST finalizes the first Post-Quantum Cryptography standards

ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) became official, quantum-resistant replacements for RSA, ECDSA, and Diffie-Hellman.

September 2026

Older FIPS validation retires

Existing FIPS 140-2 certificates move to historical status, meaning federal buyers can no longer use them to justify new procurement.

January 2027

CNSA 2.0 procurement gate opens

The NSA's Commercial National Security Algorithm Suite 2.0 requires new national security systems to run quantum-resistant algorithms from this date, with full migration mandated by the early 2030s.

2030 – 2035

Quantum-vulnerable algorithms are retired

NIST's transition guidance deprecates RSA-2048 and comparable elliptic-curve algorithms by 2030, and removes them from federal standards entirely by 2035.

Not Hypothetical — Already Shipping

The industry stopped debating this and started deploying it.

This isn't a future roadmap borrowed from a whitepaper. Hybrid post-quantum key exchange — classical and quantum-resistant algorithms running together — is already protecting production traffic at internet scale.

50%+

Of human-initiated web traffic through Cloudflare was already using post-quantum key agreement as of late 2025.

3

Major platforms — Cloudflare, Google Chrome, and Apple iMessage — have shipped hybrid post-quantum protocols to production, not pilot, environments.

5–15yr

Realistic timeline analysts give for a full enterprise cryptographic migration — which is why starting with an inventory now matters more than which algorithm you pick first.

Breaking: The Timeline Just Moved

New research suggests Q-Day could arrive years earlier than planned.

Estimates for how many qubits it takes to break RSA-2048 and elliptic-curve cryptography keep dropping. Work from 2024–2025 cut the figure from roughly 20 million qubits down to around 1 million; a newer proposal using a neutral-atom architecture paired with more efficient error-correcting codes pushes the estimate down again — into the 10,000-to-26,000 range for breaking P-256 and RSA-2048, in days to months rather than years.

Current experimental hardware has already demonstrated over 6,000 coherent neutral atoms — not yet computation-ready, but no longer a distant target. In response, Google moved its own cryptographic migration deadline up to 2029, years earlier than the 2031–2035 window most of the industry had planned around, and is now treating migration of entire public key infrastructures — not just key exchange algorithms — as urgent.

The threat timeline isn't fixed. It moves whenever the underlying math does — which is exactly why zkAssess starts with an inventory today, not a migration scheduled for a decade out.

Further reading: Q-Day Moved Closer: PQC Migration Timelines Just Shifted Left — AQtive Guard, April 2026.

Our Path — Grounded, Not Guesswork

The steps every credible migration takes, in the order that actually works.

Security agencies and standards bodies are consistent on this: migration starts with a cryptographic inventory, not an algorithm purchase. We follow that order, and we solve the part most inventories get wrong — doing it without exposing your code.

01
Live

Analyze — with a zero-knowledge assessment

zkAssess scans your code for quantum-vulnerable and classically weak cryptography the same way any cryptographic inventory tool would — except the analysis runs entirely inside your own boundary. No privacy problem, because your source code never leaves your machine or CI runner.

  • Deterministic, versioned pattern detection — reproducible, not a judgment call
  • Redacted, signed attestation only — never the underlying code
  • Score mapped to the compliance profile you actually answer to
02
Live

Decide — Hybrid Post-Quantum Cryptography or Pure Post-Quantum Cryptography

What zkAssess finds, plus your own constraints — legacy clients you can't break, compliance deadlines, risk tolerance — decides which path fits. Most organizations don't choose once; they choose per system.

03
Live

Replace

Roll out the chosen algorithms across your systems — replacing the quantum-vulnerable primitives zkAssess flagged, one system at a time.

  • Staged rollout, matched to the path chosen in step two
  • No quantum-vulnerable primitive left unaccounted for
04
Live

Test and finalize

Validate the replacement against real traffic and workloads — not just a lab environment — and finalize the migration with a documented, auditable trail.

  • Compatibility testing against clients that don't yet support Post-Quantum Cryptography
  • Sign-off against the same compliance profile zkAssess scored against
Hybrid vs. Pure Post-Quantum Cryptography

Neither is universally "right." The findings and the constraints decide.

This is the same choice enterprises deploying Post-Quantum Cryptography today are actually making, not a simplified marketing binary.

ConsiderationHybrid Post-Quantum CryptographyPure Post-Quantum Cryptography
How it works Classical (e.g. ECDH) and post-quantum (ML-KEM) algorithms run side by side; a session is only broken if both fail. Quantum-resistant algorithms replace classical ones outright — no classical fallback.
Best fit Public-facing infrastructure and systems that must stay compatible with clients that don't support Post-Quantum Cryptography yet. New systems, and regimes such as CNSA 2.0 that plan to require quantum-resistant-only algorithms.
Who's shipped it Cloudflare, Google Chrome, and Apple iMessage already run hybrid key exchange in production. Expected as the endpoint of most migration roadmaps once compatibility constraints are gone.
Trade-off Larger handshake sizes and two algorithms to maintain, in exchange for a safer transition. Simpler long-term footprint, but no fallback if a client or dependency can't yet support it.
Why Start With Zero-Knowledge Assessment

You can't fix what you haven't inventoried. You shouldn't have to expose your code to find out.

The privacy problem most scanners create

A traditional code scanner needs to read your source to find weak cryptography — which means a vendor, auditor, or automated tool now has full visibility into your codebase, business logic, and anything sensitive it contains.

zkAssess resolves this the same way modern privacy-preserving protocols resolve any "prove a fact without revealing the data" problem: the scan runs inside your own boundary, and only a signed, redacted attestation — the score, which patterns matched, cryptographic proof that each finding is real — ever leaves it. Your code is never the thing that crosses the line.

Get Started

Start with the inventory. Everything else follows from it.

Every product on this path — zkAssess, Hybrid Post-Quantum Cryptography, Pure Post-Quantum Cryptography — is live today.