zkAssess scans your code for quantum-vulnerable and classically weak cryptography the same way any cryptographic inventory tool would — except the analysis runs entirely inside your own boundary. No privacy problem, because your source code never leaves your machine or CI runner.
What zkAssess finds, plus your own constraints — legacy clients you can't break, compliance deadlines, risk tolerance — decides which path fits. Most organizations don't choose once; they choose per system.
Roll out the chosen algorithms across your systems — replacing the quantum-vulnerable primitives zkAssess flagged, one system at a time.
Validate the replacement against real traffic and workloads — not just a lab environment — and finalize the migration with a documented, auditable trail.
ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) became official, quantum-resistant replacements for RSA, ECDSA, and Diffie-Hellman.
Existing FIPS 140-2 certificates move to historical status, meaning federal buyers can no longer use them to justify new procurement.
The NSA's Commercial National Security Algorithm Suite 2.0 requires new national security systems to run quantum-resistant algorithms from this date, with full migration mandated by the early 2030s.
NIST's transition guidance deprecates RSA-2048 and comparable elliptic-curve algorithms by 2030, and removes them from federal standards entirely by 2035.
Of human-initiated web traffic through Cloudflare was already using post-quantum key agreement as of late 2025.
Major platforms — Cloudflare, Google Chrome, and Apple iMessage — have shipped hybrid post-quantum protocols to production, not pilot, environments.
Realistic timeline analysts give for a full enterprise cryptographic migration — which is why starting with an inventory now matters more than which algorithm you pick first.
A traditional code scanner needs to read your source to find weak cryptography — which means a vendor, auditor, or automated tool now has full visibility into your codebase, business logic, and anything sensitive it contains.
zkAssess resolves this the same way modern privacy-preserving protocols resolve any "prove a fact without revealing the data" problem: the scan runs inside your own boundary, and only a signed, redacted attestation — the score, which patterns matched, cryptographic proof that each finding is real — ever leaves it. Your code is never the thing that crosses the line.
Every product on this path — zkAssess, Hybrid Post-Quantum Cryptography, Pure Post-Quantum Cryptography — is live today.