Post-Quantum Cryptography (PQC)
Navigate the transition to post-quantum cryptography
Post-quantum transition starts with end-to-end visibility
Managing PQC migration requires clarity across every layer of your technology stack. Modern enterprise environments span hardware, firmware, software, silicon, networking, and broad supply chains. Each carries distinct cryptographic dependencies. Dell helps you identify and secure risks across your environment to build cyber resilience today while preparing for future quantum risks.
A phased, infrastructure-wide approach
Phased delivery
Hybrid cryptographic coexistence
Cryptographic agility by design
A six-layer model for quantum resilience
1. Hardware supply chain and platform integration
Dell works with silicon and component providers to align quantum-resistant trust foundations at the hardware level.
2. Secure manufacturing and code signing
Dell ships The National Institute of Standards and Technology (NIST) SP 800-208 PQC signature algorithms on select platforms to secure firmware signing and prevent attackers from forging update signatures to compromise platform trust. This is the layer that answers "Trust Now, Forge Later", where the risk is a forged firmware update signature rather than decrypted data.
3. Platform root of trust
Dell advances secure boot and firmware verification across the platform trust chain to support post-quantum validation models.
4. Platform software and cryptographic services
Dell is migrating toward PQC-capable libraries and services aligned with the latest validation requirements, supporting ML-KEM and ML-DSA while separately tracking FIPS 140-3 module validations.
5. Secure system communications
Dell embeds cryptographic agility into communication layers, including Transport Layer Security (TLS), identity, and enterprise integration services.
6. Customer workload and data security
Dell extends protection to customer data-at-rest, replication, backup, and key management through hybrid post-quantum deployment models.
Post-quantum migration roadmap
-
Phase 1: Strengthen security hygiene
Establish strong baseline controls, including least privilege, multi-factor authentication (MFA), patch management, and robust classical algorithms such as AES-256 and SHA-384 or higher. -
Phase 2: Inventory cryptographic dependencies
Build a comprehensive cryptographic Bill of Materials (CBOM) to identify where and how public-key cryptography powers applications, devices, and workflows. -
Phase 3: Analyze, prioritize, and plan
Evaluate cryptographic assets and dependencies, prioritized by business criticality, data sensitivity, and required lifespan. -
Phase 4: Migrate with cryptographic agility
Align adoption with technology refresh cycles rather than creating a separate program. Pilot in controlled environments to test performance, interoperability, and manageability. Select platforms supporting in-place algorithm updates and treat hybrid classical-PQC modes as a temporary transition bridge.
Aligned with evolving standards and guidance
PQC continues to evolve through new standards, procurement requirements, and validation pathways. The Dell portfolio directly aligns with these frameworks to maintain continuous compliance.
NIST PQC standards
NIST published three initial post-quantum standards in August 2024: ML-KEM for key establishment (FIPS 203), ML-DSA for digital signatures (FIPS 204), and SLH-DSA for signatures (FIPS 205).
- Phased deployment: Dell is integrating these algorithms across the infrastructure portfolio on a rolling schedule.
- Architecture protection: System design accommodates newly approved algorithms without requiring hardware redesigns.
CNSA 2.0 compliance
Commercial National Security Algorithm (CNSA 2.0) sets official, enforceable government requirements for higher security settings than standard NIST baselines.
- Mandated parameter sets: Systems implement ML-KEM-1024, ML-DSA-87, AES-256, and SHA-384/512, alongside NIST SP 800-208 stateful hash-based signatures for firmware signing.
- Direct engineering: Dell builds hardware directly to these specifications.
- Pure PQC path: CNSA 2.0 eliminates hybrid mode requirements, providing national security customers a direct migration path to pure post-quantum cryptography.
FIPS 140-3 validation
Algorithm support and certified compliance follow separate validation lifecycles.
- Independent tracks: Dell manages algorithm implementation and Federal Information Processing Standards (FIPS) 140-3 module testing on distinct operational tracks.
- In-process validation: Infrastructure can run ML-KEM today while module certifications complete formal testing.
- Audit transparency: Dell provides explicit certificate numbers for compliance audits. When evaluating any vendor, request the certificate number, not the algorithm name.
Regulatory deadlines driving PQC adoption
Compliance timelines depend on the systems used by your organization. Data with a long confidentiality life may currently be at risk. To prevent future decryption of harvested data, migration to PQC should start immediately across frameworks established by NIST.
National security systems
Applies to defense, intelligence, and classified networks.
- January 1, 2027: New system purchases should support post-quantum algorithms (2026 Executive Order; CNSA 2.0).
- December 31, 2030: Systems that cannot support post-quantum updates must be retired or replaced (CNSA 2.0; Committee on National Security Systems Policy 15 [CNSSP 15]).
- December 31, 2031: Post-quantum algorithms are required for all deployments unless granted an official waiver (CNSA 2.0). Pure post-quantum is the objective; hybrid modes are not required.
Federal civilian agencies
Applies to non-defense government departments and civilian contractors.
- December 31, 2030: High-priority systems must use post-quantum key exchange (Executive Order 14412 [EO 14412]; Office of Management and Budget [OMB] Memorandum M-26-15).
- December 31, 2031: High-priority systems must use post-quantum digital signatures (OMB M-26-15).
- December 31, 2035: Civilian agency systems complete full migration (EO 14412; OMB M-26-15). Hybrid architectures and cryptographic agility are explicitly accommodated during transition.
Commercial systems
Applies to private-sector businesses, enterprise infrastructure, and commercial tech.
- 2030: NIST IR 8547 deprecates classical algorithms like RSA and ECC. Organizations may keep deprecated methods active, but leadership assumes operational risk.
- 2035: Regulatory frameworks formally disallow classical algorithms across commercial compliance environments (NIST IR 8547).
- Immediate step: Upgrade baseline encryption to AES-256 and SHA-384 to exceed current minimums and protect long-term data.
Protection across the Dell portfolio
Dell embeds post-quantum cryptography across PCs, servers, storage, networking, and data protection platforms. Protections advance across every infrastructure layer, prioritized by risk, architectural dependency, and implementation readiness.