Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fortanix’s response to quantum-computing threats combines post-quantum cryptography (PQC) support in its Data Security Manager (DSM) with a discovery and migration-planning tool called PQC Central. The approach is intended to help organizations identify exposure to vulnerable cryptography and plan a transition; it does not establish that Fortanix has demonstrated protection against a cryptographically capable quantum computer.

Why quantum computing puts some encryption at risk

Quantum algorithms such as Shor’s could threaten widely used public-key cryptography, including RSA and elliptic-curve cryptography (ECC). That creates a risk for sensitive information that must remain confidential for years: an attacker could collect encrypted data now and try to decrypt it later, a strategy often called “harvest now, decrypt later.”

The practical priority is therefore not simply whether an organization uses RSA or ECC, but where it uses them and how long the protected information needs to stay secret. Fortanix’s solution guidance frames PQC migration as an organizational program involving cryptographic inventory, system changes, and people and process planning—not a one-time algorithm switch.

Which algorithms and capabilities Fortanix says DSM supports

In a February 2025 announcement, Fortanix said it had added PQC capabilities to Fortanix Data Security Manager. The company’s listed set includes ML-KEM (formerly CRYSTALS-Kyber), ML-DSA (formerly CRYSTALS-Dilithium), Leighton-Micali Signature (LMS), eXtended Merkle Signature Scheme (XMSS), Advanced Encryption Standard (AES), and Secure Hash Algorithm (SHA). Fortanix said the capabilities address quantum and advanced-AI threats and support the Commercial National Security Algorithm Suite (CNSA) 2.0.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Algorithm or family Role in the announced set
ML-KEM NIST-standardized key encapsulation mechanism for establishing shared keys.
ML-DSA NIST-standardized digital-signature algorithm.
LMS and XMSS Hash-based digital-signature schemes for signature use cases.
AES and SHA Symmetric encryption and hashing capabilities listed by Fortanix; they are not the same kind of public-key algorithm as ML-KEM or ML-DSA.

The names and support described here reflect Fortanix’s February 2025 announcement. The announcement does not, by itself, specify which algorithms are enabled in every deployment or how each organization should configure them.

What PQC Central does

Announced on June 24, 2025, PQC Central is embedded in Fortanix Key Insight. Fortanix describes it as a way to move from finding cryptographic exposure to planning and tracking a transition. Its workflow has three stages:

  1. Discovery: scan systems and services for cryptographic use, map dependencies, and catalog assets using algorithms vulnerable to quantum attacks.
  2. Risk assessment: identify vulnerable keys and calculate a cryptographic-readiness score.
  3. PQC transition: track readiness across environments and build a prioritized roadmap, including integrations with ServiceNow or Jira.

The migration work is then carried out through Data Security Manager, Fortanix’s encryption and key-management service. PQC Central is therefore a planning and tracking component of a broader platform, not an encryption algorithm in its own right.

What Fortanix’s 2026 entropy update adds

On March 11, 2026, Fortanix announced multi-sourced quantum entropy in DSM. The capability integrates independent, physics-based entropy from Qrypt and Quantum Dice into key-generation workflows. Fortanix positions this as a way to diversify the root of trust, and says it includes immutable logging, audit support, software-defined crypto agility, and no required hardware change. These are vendor claims; organizations evaluating the capability should confirm deployment details and evidence during procurement. Entropy sourcing addresses the provenance and diversity of randomness used in key generation; it does not replace the need to inventory vulnerable algorithms or plan a PQC migration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do organizations need to replace RSA and ECC now?

The announcements do not establish a universal cutover date or say every RSA and ECC use must be replaced immediately. They do support starting with an inventory, especially for systems protecting data whose confidentiality must last many years. A staged migration can help teams understand where changes are needed and prioritize work before making algorithm or system changes.

  • Find exposure: locate RSA and ECC use across applications, services, keys, and dependencies.
  • Prioritize by consequence: focus first on sensitive information with long confidentiality requirements and systems whose dependencies make migration complex.
  • Plan for integration: assess how new algorithms fit key management, HSMs, applications, and operational processes rather than treating PQC as a single software toggle.
  • Track readiness: use a roadmap to coordinate changes across environments and teams.

Fortanix’s February 2025 announcement cited 2030 as an initial-adoption target based on NIST expectations and 2035 as a full phase-out target based on U.S. requirements for migration away from legacy algorithms. These are targets cited by Fortanix, not a guarantee that every organization or system will follow the same schedule. Teams should verify the requirements applicable to their jurisdiction and sector.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to compare when evaluating Fortanix or another PQC approach

Algorithm support alone is not enough to assess migration readiness. Compare the capabilities that determine whether an organization can find, prioritize, deploy, and govern changes:

  • How deeply the platform inventories cryptographic use and maps dependencies.
  • Which NIST-standardized algorithms it supports and how it handles transitions between classical and post-quantum cryptography.
  • How it integrates with key management, HSMs, and existing applications.
  • How upgrades and crypto-agility are managed across the organization.
  • Whether the deployment model—SaaS, on-premises, or hybrid—fits the environment.
  • What audit and compliance evidence is available.
  • How migration workflows connect to IT-operations systems such as ServiceNow or Jira.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.