Preparing for the Quantum Era
Seclore’s Commitment to Post-Quantum Security

The Quantum Threat: Why This Matters Now
Quantum computing is advancing from theoretical promise to engineering reality. While large-scale, fault-tolerant quantum computers capable of breaking today’s public-key cryptography do not yet exist, the trajectory is clear enough that governments, standards bodies, and enterprises worldwide are no longer asking if this will happen, but when.
The concern isn’t only about the future. It’s about the present. Adversaries can capture encrypted data today and simply store it, waiting for the day quantum computing makes decryption feasible — a strategy widely known as “harvest now, decrypt later” (HNDL). For any organization that handles sensitive, long-lived, or regulated data, that means the quantum threat is already actionable, even before a quantum computer capable of breaking encryption is built. As the next section explains, parts of Seclore’s architecture already narrow this exposure.
Recognizing this, the National Institute of Standards and Technology (NIST) finalized its first set of post-quantum cryptography (PQC) standards in August 2024 — FIPS 203, 204, and 205 — establishing quantum-resistant alternatives to the algorithms that have underpinned digital security for decades. The U.S. National Security Agency’s Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) has set a parallel expectation, calling for migration away from classical public-key algorithms over the coming years. Regulators, industry consortia, and technology vendors across the globe are aligning around this shift.
Seclore views this not as a distant compliance milestone, but as a defining moment for how sensitive data is protected — and we are preparing accordingly.
The Strength We’re Already Building From
Not every part of this transition starts from zero.
Two things about how Seclore is architected today already narrow the exposure this threat creates.
Quantum computers threaten public-key (asymmetric) algorithms like RSA and ECC — the kind of cryptography quantum algorithms can break directly. Symmetric encryption such as AES-256, already used to protect file content, is a different story: it is widely regarded as quantum-resistant at this key length, and is itself one of the algorithms named in the U.S. government’s own CNSA 2.0 post-quantum suite.
Encryption keys are also never stored with the protected document itself — they are managed and served separately. Capturing an encrypted file alone, the basis of a harvest-now-decrypt-later attack, does not by itself hand an attacker the key needed to decrypt it.
Together, this means the work ahead is targeted, not foundational: hardening key exchange and management, not rebuilding content protection from scratch.
AES-256 already protects file content
Symmetric encryption such as AES-256 is a different target from RSA and ECC and is widely regarded as quantum-resistant at this key length.
Keys remain separate from protected files
Capturing an encrypted document alone does not hand an attacker the key needed to decrypt it.
Our Position on Post-Quantum Cryptography
Seclore’s position is straightforward: the transition to quantum-resistant cryptography is a “when,” not an “if,” and we are treating it as a strategic priority today rather than waiting for the threat to fully materialize.
We believe organizations that wait for certainty before acting will find themselves reacting under pressure, on someone else’s timeline. Our approach instead is proactive and structured, built on the principle that the systems protecting our customers’ most sensitive data should be able to evolve as cryptographic standards evolve — without requiring disruptive re-architecture every time the underlying algorithms change.
That principle — widely known in the industry as crypto-agility — means designing our platform so that cryptographic algorithms are modular, upgradeable components rather than fixed, load-bearing assumptions. This is the foundation of how we are approaching the quantum transition, and it reflects a broader philosophy that has guided our security architecture from the outset — anticipate change, and build for it, rather than retrofit around it.

Our PQC Readiness Framework
Seclore’s post-quantum readiness effort is organized around a clear framework with executive sponsorship and cross-functional ownership spanning engineering, security, and product leadership. That framework rests on four pillars.
Governance
We have established a dedicated program to oversee our quantum-readiness strategy, ensuring that decisions about cryptographic architecture are made deliberately, with accountability, and with visibility at the leadership level — not left to individual teams to solve in isolation.
Assessment
A comprehensive review of where and how cryptography is used across our platform is underway. This discovery work allows us to plan a migration that is thorough and sequenced by risk and impact, rather than ad hoc.
Standards alignment
We are committed to adopting algorithms standardized by NIST — including ML-KEM for key establishment and ML-DSA and SLH-DSA for digital signatures — as the foundation of our long-term cryptographic architecture. Aligning with open, vetted, globally recognized standards ensures our approach is interoperable, auditable, and built on the strongest available consensus of the cryptographic community, rather than proprietary or unproven alternatives.
Hybrid-first transition
Where appropriate, we favor hybrid cryptographic schemes that combine classical and post-quantum algorithms during the transition period. This is a deliberate defense-in-depth choice: it allows us to adopt quantum-resistant protection early while maintaining the interoperability and assurance of proven classical methods, giving customers the benefit of both as the ecosystem matures.
Roadmap & Milestones
Our quantum-readiness roadmap is structured in phases, each building on the last, and is aligned with the broader timelines established by NIST and CNSA 2.0 for the industry-wide transition.
We are pacing this roadmap deliberately: closely enough to industry guidance to demonstrate diligence and urgency, while allowing the flexibility to incorporate refinements as standards, tooling, and best practices mature. Our goal is to be ahead of the curve, not merely compliant with it. These milestones reflect our current planning and may be adjusted as standards, technology, and the broader ecosystem continue to evolve.

What This Means for Our Customers
For our customers, the most important commitment we can make is this: protecting your data against the quantum threat is something we are actively executing on today, not a promise deferred to the future. Our roadmap is built to close the exposure window well ahead of when large-scale quantum decryption becomes a practical reality, and the transition to post-quantum cryptography will be managed on your behalf, without requiring disruptive action on your part.
Our platform’s crypto-agile design means this evolution happens beneath the surface of the product experience you already rely on. You do not need to re-architect your own systems or workflows, and we will not force disruptive, unplanned upgrades — any updates to Seclore components will be delivered through normal update channels, on a timeline that respects your own deployment needs. This also means files you’ve already protected do not need to be re-protected or re-keyed: their content is already secured with AES-256, and our architecture is designed so that upgrading how keys are exchanged does not require touching files that are already protected. As our roadmap progresses, we will keep you informed of milestones relevant to your own risk and audit processes.
This confidence is reinforced by the architecture covered above: a future quantum-capable adversary would still need to separately compromise the key exchange, a materially narrower target than the document itself. Security has always been a shared responsibility, and quantum readiness is no exception — we see our role as absorbing as much of that complexity as possible, so you can focus on your business rather than the mechanics of cryptographic migration.
Industry Engagement & Thought Leadership
Seclore does not view quantum readiness as a challenge to solve alone. We are actively engaging with the broader cryptographic and standards community — monitoring guidance from NIST, NSA, and other standards bodies, and working with technology partners across the ecosystem, including cloud providers, HSM vendors, and cryptographic library maintainers, to ensure our approach remains current and interoperable as the landscape evolves.
We also see it as our responsibility to contribute to the industry conversation — sharing our perspective through articles like this one, and through ongoing dialogue with customers, partners, and the security community, so that the transition to a quantum-resistant future is one the industry navigates together.

A Continued Commitment
The shift to post-quantum cryptography will unfold over years, not months, and the standards and best practices guiding it will continue to mature. Seclore’s commitment is to remain proactive, not reactive, as that landscape evolves — treating quantum readiness not as a single project with an end date, but as an ongoing discipline built into how we design, operate, and evolve our platform.
We welcome the opportunity to discuss our quantum-readiness program in more depth with customers and partners. If you have questions about how this roadmap intersects with your own security and compliance requirements, we encourage you to reach out to your Seclore account team or contact us directly.