Home icon

Automating post-quantum cryptography readiness using AWS Config

Security Blog



This article introduces the PQC Readiness Scanner, an automated AWS Config tool for assessing post-quantum cryptography readiness across TLS endpoints.

  • Inventories ALB, NLB, and API Gateway endpoints for PQC migration readiness
  • Classifies endpoints into three tiers based on TLS 1.3 and PQC key exchange support
  • Tier 1: TLS 1.3 only with PQC (optimal, no action needed)
  • Tier 2: TLS 1.2 and 1.3 with PQC (low priority, backward compatible)
  • Tier 3: No PQC support (high priority, requires immediate upgrade)
  • Built using AWS Config conformance packs with Lambda-powered custom rules
  • Supports single-account and multi-account (Organizations) deployment via CloudFormation StackSets
  • Provides continuous monitoring and audit-ready compliance reporting

The scanner automates PQC migration planning by identifying which endpoints need quantum-resistant cryptography upgrades first, reducing manual configuration reviews.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Dec 5
2024
AWS post-quantum cryptography migration plan
Apr 14
2026
AWS Secrets Manager now supports hybrid post-quantum TLS to protect secrets from quantum threats
Nov 11
2025
Accenture and AWS accelerate customer’s post-quantum cryptography journey
Jun 29
2026
How AWS is helping federal agencies lead in quantum computing and post-quantum security

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.