Home icon

Protecting your secrets from tomorrow’s quantum risks

Security Blog



This article explains how AWS Secrets Manager now protects against quantum computing threats using hybrid post-quantum cryptography with ML-KEM key exchange.

  • Secrets Manager supports hybrid post-quantum TLS combining traditional X25519 with ML-KEM algorithm
  • Secrets Manager Agent v2.0.0+, Lambda extension v19+, and CSI Driver v2.0.0+ enable post-quantum TLS by default
  • AWS SDKs for Rust, Go, Node.js, Kotlin, Python, and Java v2 support hybrid post-quantum key exchange with version requirements
  • Verify post-quantum TLS active by checking CloudTrail tlsDetails keyExchange field shows X25519MLKEM768
  • No code changes needed; upgrade client versions to enable protection against harvest now, decrypt later attacks
  • CRYSTALS-Kyber support phasing out in 2026; older SDKs will fall back to traditional TLS

AWS Secrets Manager now provides quantum-resistant encryption for data in transit by default, requiring only client software upgrades to enable protection against future quantum threats.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Apr 14
2026
AWS Secrets Manager now supports hybrid post-quantum TLS to protect secrets from quantum threats
Apr 2
2026
Decoding Realistic Quantum Error Syndrome with Quantum Elements Digital Twins
May 14
2026
Automating post-quantum cryptography readiness using AWS Config
Jun 29
2026
How AWS is helping federal agencies lead in quantum computing and post-quantum security

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.