Cost engine · free, no signup

PQC Cost Calculator

Post-quantum TLS is slower and heavier than what you run today. This tells you what that costs on your traffic, in dollars, before you commit to it.

Who it's for

Network and infrastructure leads, and CISOs sizing PQC across a TLS-heavy estate.

The problem

Vendors quote percentages on a benchmark you can't inspect. Nobody tells you what the percentage means on your bill.

What you get

A dollar figure from handshakes we measured daily on real hardware, plus the arithmetic that produced it.

Run date
2026-08-22
Commit
Host
Xeon Platinum 8259CL @ 2.50GHz
liboqs
0.15.0
Architectures
aarch64 · x86_64
Pricing
AWS list, editable
No signup. Every input is in the URL — the link is the scenario.
1

What are you comparing?

Pick the key exchange you run today and the one you are considering. Every timing here is measured on real hardware — not modelled, not vendor-supplied.

CPU architectureMeasured
Chosen once — the timings and the pricing lookup both use it.
2

How much traffic do you handle?

Only handshakes that run a full key exchange cost anything — resumed sessions skip it entirely. This is the biggest lever on the figure in step 4.

Workload archetypePublic default
Real production case study — the most defensible single figure in this list.
Handshakes / secondYour input
The default is a cited industry example, not you. Change it.
Session reuse %Public default
Reuse hides this cost; churn exposes it.
Kotak Mahindra Bank — up to 1,500 transactions/sec at peak (AWS Industries case study) (2026-08-16)One bank's one product mix in production, not a sector norm. Vendor benchmarks reach far higher — Infosys Finacle/IBM published 29,010 effective tx/sec — but those are stress tests, not steady state.Cloudflare TLS Post-Quantum Experiment — ~53% of connections were resumptions (mobile ~25%, desktop 40–70%) (2026-08-16)#unverified-current — the experiment predates this by several years and TLS 1.3 resumption behaviour has likely shifted. Real and cited, but due a refresh.
3

What do you pay for compute and bandwidth?

Defaults are AWS list prices. If you have negotiated rates, put them in — the answer moves with them. Press Enter or Calculate to apply.

$ / vCPU-hourPublic default
$ / GB egressPublic default
Over what periodYour input
The figures below match the inputs above.
AWS c7i.xlarge on-demand, Linux, us-east-1 — $0.179/hr ÷ 4 vCPU (2026-08-16)Third-party aggregator mirroring AWS published pricing; AWS's own page is JS-rendered. Re-verify against your negotiated rate — pricing pages move without notice.AWS data transfer out to internet — $0.09/GB up to 10TB, after a 100GB/month free allowance (2026-08-16)Tiers down to $0.05/GB above 150TB; some regions start higher. AWS only — GCP and Azure are not sourced and are not assumed equivalent.
4

What it costs

Your traffic, your rates, our measurements.

Moving to X25519 + ML-KEM-768 · 1 month
$181per month

more than X25519, at 705 full handshakes/sec — 1.85B handshakes over 1 month.

$11.94 today against $193 after — a 16.16× change.

Recurring, not one-off
$181/month

This is an ongoing operating cost for as long as the traffic runs, not a migration project fee.

Per million handshakes
$0.0977

The unit figure — multiply by your own volume if you would rather not trust the archetype.

As a share of the classical bill
1516%

What the same traffic costs you today, versus after.

What drives the difference

CPU time0%Extra microseconds per handshake, billed as compute.−$0.4633
Bytes on the wire100%A bigger key exchange, billed as egress.$182

Every suite you selected

SuiteHandshakeBytes outvs classicalCPUEgressTotal / 1 month×
X25519Classical286.1 µs32 Bbaseline$6.60$5.34$11.941.00×
X25519 + ML-KEM-768Hybrid266.1 µs1.09 KB7.0%$6.14$187$19316.16×

How that number is worked out

No model, no hidden coefficient. Four multiplications, and you can check every one.

  1. 1Count the handshakes that actually happen1,500/sec minus the 53% that resume an existing session leaves 705/sec doing a real key exchange.
  2. 2Multiply by what one handshake costs in CPUWe measured 266.1 µs median against 286.1 µs for classical. The difference × your handshakes × your $/vCPU-hour.
  3. 3Multiply by what one handshake costs on the wire1.09 KB leaves your server per handshake instead of 32 B. That extra × your handshakes × your $/GB egress. Outbound only — inbound is free.
  4. 4Add the two, over your chosen periodAcross 1 month. That is the figure in step 4, and the split between the two terms is the bar above it.

The handshake timings are measured. Everything else is either a public figure we cite or a number you typed. Nothing is interpolated — there is no value between two of our runs.

Sources

Every figure this page depends on. The first entry changes with your selection.

Reference list
Kotak Mahindra Bank — up to 1,500 transactions/sec at peak (AWS Industries case study) (2026-08-16)One bank's one product mix in production, not a sector norm. Vendor benchmarks reach far higher — Infosys Finacle/IBM published 29,010 effective tx/sec — but those are stress tests, not steady state.AWS API Gateway default account throttle: 10,000 req/sec sustained (upper bound); small/mid SaaS API rate limits ~8–10 req/sec (lower-bound proxy) (2026-08-16)#unverified — no authoritative 'typical' figure exists. These are a platform ceiling and a rate-limit proxy, not measurements of anyone's actual traffic. Enter your own number.Istio scale test — 1,000 services, 2,000 pods, 70,000 mesh-wide requests/sec (2026-08-16)Istio's own scale test, not a typical deployment. Evidence that internal mesh traffic routinely exceeds edge traffic by 1–3 orders of magnitude — not a figure to adopt unedited.Cloudflare TLS Post-Quantum Experiment — ~53% of connections were resumptions (mobile ~25%, desktop 40–70%) (2026-08-16)#unverified-current — the experiment predates this by several years and TLS 1.3 resumption behaviour has likely shifted. Real and cited, but due a refresh.AWS c7i.xlarge on-demand, Linux, us-east-1 — $0.179/hr ÷ 4 vCPU (2026-08-16)Third-party aggregator mirroring AWS published pricing; AWS's own page is JS-rendered. Re-verify against your negotiated rate — pricing pages move without notice.AWS data transfer out to internet — $0.09/GB up to 10TB, after a 100GB/month free allowance (2026-08-16)Tiers down to $0.05/GB above 150TB; some regions start higher. AWS only — GCP and Azure are not sourced and are not assumed equivalent.Q-Shield methodology — how these handshakes are measured, and what they are not (2026-08-16)Q-Shield benchmark source and every committed result file (2026-08-16)
Opening scenario

Bank core-banking gateway · 53% session reuse · one month

The figures the calculator starts on, rendered statically. Everything above moves them.

SuiteHandshakeBytes outCPU $/moEgress $/moTotal $/mo×
X25519 + ML-KEM-768266.1 µs1.09 KB$6.14$187$19316.16×
P-256 + ML-KEM-768215.0 µs1.13 KB$4.96$192$19716.53×
ML-KEM-76861.4 µs1.06 KB$1.42$182$18315.32×
X25519286.1 µs32 B$6.60$5.34$11.941.00×
What this is, and what it is notEverything else Q-Advantage publishes reports a measurement. This page computes — it multiplies measured handshake costs by traffic volumes and cloud rates to produce a figure nobody measured. That is arithmetic over cited inputs, not a model with hidden coefficients, and every input carries a tag saying whether it is measured, a public default, a bounded estimate, or yours.

It covers the TLS key exchange only — no certificate-chain signing, no packet-level effects, AWS list pricing. A real estate has negotiated rates, its own session-reuse behaviour, and a certificate chain that matters. This gets you the shape and the order of magnitude. It does not replace measuring your own.
The number above is the easy half

Now do it against your actual infrastructure.

This page prices one key exchange against one set of assumptions. A migration decision needs the rest of it: which of your endpoints are actually negotiating what, how much of your traffic resumes rather than handshakes, what your certificate chain does to the picture, and where the cost lands across a whole estate rather than a single gateway.

Your endpoints, measured

We measure what your estate actually negotiates today, rather than assuming one uniform baseline across every endpoint.

Your real traffic profile

Session-reuse rates and handshake volumes taken from your own telemetry, not an industry archetype we had to cite because we did not know you.

The whole cost, not the wire

Certificate reissuance, HSM headroom, and the internal service-mesh multiplier that usually dwarfs the edge — priced together.

We do not sell migration tooling and we do not resell anyone’s PQC product. We measure, and we tell you what the measurements mean for your bill — which is the only reason to trust a number that came from a vendor’s competitor or from us.