Forum Discussion
[New Release] Detect non-compliant post-quantum cryptography cloud resources
Encrypted traffic captured today can be stored and decrypted later once quantum computing matures. This is a threat known as Harvest-Now-Decrypt-Later (HNDL). Organizations relying on outdated Transport Layer Security (TLS) configurations or non-quantum-safe encryption are exposed to this risk without even knowing it.
Tenable One Cloud Exposure now helps customers detect non-compliant post-quantum cryptography (PQC) cloud resources to support future compliance regulations. With this, four new properties have been added to the Network Endpoint profile for HTTPS-supported endpoints: SSL/TLS Versions, SSL/TLS Cipher Suites, SSL/TLS PQC Support, and SSL/TLS Key Exchange Groups. The Network Endpoint profile also now lists every cipher a server supports, not just what's actively in use. The enhancement allows teams to:
- Gain visibility into quantum-readiness: See which endpoints already support post-quantum cryptography and which don't, so you can prioritize upgrades ahead of emerging compliance mandates. Get all non-PQC-r resources listed in one query.
- Identify weak encryption faster: Surface outdated TLS versions and vulnerable cipher suites across your environment without manual audits or separate scanning tools.
- Reduce HNDL exposure: Proactively harden key exchange methods and ciphers before intercepted traffic becomes a future liability.
- Gain compliance evidence: This allows customers in regulated industries such as healthcare and financial services to easily prove compliance as quantum computing matures.
To find these resources in your cloud environment, go to Tenable One Cloud Exposure and filter or query “non-ready PQC resources” using the Network Endpoint page or Explorer.