Every system you run needs new cryptography. Nobody has priced it.
Independent measurement of what post-quantum encryption actually costs — across implementations, protocols and processors. Latency, throughput, bytes on the wire, and the dollars behind them, so the migration can be budgeted instead of estimated.
Hybrid X25519MLKEM768 against classical X25519 — 36.5× the wire cost, paid on every connection, forever.
We measure, track, rate, and price.
Four instruments, one rule: every number links to the run or the source that produced it.
Every NIST-standardized algorithm, daily, on real x86 and ARM silicon — composed into full TLS and SSH handshakes, not primitives in a box.
Open Q-Shield →Weekly posture of named institutions. Where key exchange has moved, where authentication hasn't, and how far apart the two have drifted.
Not yet publishedA rating of named vendor implementations against criteria published before any verdict exists. Rated parties get no influence over the result.
Criteria published firstWhat the handshake delta actually costs across an estate: connections per second, session reuse, bytes on the wire — converted to dollars.
Open the calculator →Quick comparisons.
The questions people actually arrive with, each opening the live compare view with both algorithms already loaded.
What turning on post-quantum key exchange costs per handshake, in time and in bytes.
A 6,972× signing gap between two schemes NIST approved on the same day.
Moving from level 3 to level 5: the price of the upgrade in latency and key size.
The same primitive costs different amounts depending on the protocol wrapped around it.
The gap, ranked.
Same host, same harness, every night. Re-run it yourself — the harness is public.
Read this firstThis run carried 6.9% CPU steal on a burstable instance, which inflates the classical baseline and compresses every timing delta above. Timing deltas move run to run. The byte counts do not. Read the wire column as the durable number and the timing column as a distribution, not a verdict.
“What does moving to post-quantum encryption cost the business?”The only question left — and nobody neutral has answered it.
This is not one migration. It is every TLS endpoint, every internal PKI, every database connection, every VPN tunnel, every code-signing key, every API gateway, every blockchain and the wallets and validators on it, and every device shipping today with a ten-year field life — each on a different clock, with no central operator and no single switch to throw.
And it arrives as two separate bills, neither of which has been published. The one-time one: discovery, engineering hours, certificate reissuance, hardware security module refresh, validation cycles. Then the permanent one — larger handshakes and larger signatures, paid on every connection, every day, indefinitely, in latency, in connections per core, in bytes on the wire, and in the hardware you buy sooner than you planned to.
So the return on any of it is currently unknowable. Vendors quote the slice they sell. Academic cycle counts don’t compose into an invoice. We measure the inputs and publish them — so your ROI is a calculation, not a guess.
The analysis behind the numbers.
Written for the people who have to justify the decision to someone else.
All posts →One email a week. Numbers first.
What post-quantum is costing the systems you’re responsible for, and what changed this week — measured, sourced, and short enough to read before the meeting you’ll need it for.
Free. Unsubscribe anytime. Security leaders · investors · researchers.