Red Hat uses a 3-step strategy to help enterprises establish operational resilience before classical encryption fails.
Step 1: PQC modernization
We are building standard, quantum-resistant algorithms (QRAs) directly into the core of our platform ecosystem. Red Hat® Enterprise Linux® 10 includes default hybrid-PQC capabilities for secure sockets layers (SSL), alongside National Institute of Standards and Technology’s (NIST) standardized algorithms:
- FIPS 203: (ML-KEM, formerly Crystals-Kyber) for secure key encapsulation.
- FIPS 204: (ML-DSA, formerly Crystals-Dilithium) for digital signatures.
- FIPS 205: (SLH-DSA, formerly SPHINCS+) for stateless hash-based signatures.
Deploying these algorithms is difficult due to complex open source dependencies. Red Hat is using its leadership in upstream communities to help prepare core standards like SSL and X.509 for the quantum era. To accommodate what is expected to be a complex transition period, hybrid protocols and mixed-mode operations are provided whenever they support such modes.
Quantum safety is not merely about having algorithms present; it's about effectively using them to protect your assets. Red Hat is driving PQC adoption across its layered portfolio to provide libraries, applications, and tools that are quantum-resistant.
- Red Hat Enterprise Linux 10 has already been released with NIST-standard QRAs, default hybrid-PQC for SSL, and other core capabilities.
- Red Hat OpenShift® serves as a self-contained, hybrid cloud foundation that lets you consistently run and protect your most critical workloads.
- Red Hat is supporting PQC in key application libraries and runtimes, including Python, Go, and Java.
- Red Hat Advanced Developer Suite is preparing to deliver PQC for key components of the software supply chain, including trusted artifacts, signing, and verification.
- Red Hat is investing and accelerating PQC for Red Hat identity platforms—including Identity Management in Red Hat Enterprise Linux, Red Hat Certificate System, and Red Hat Directory Server—to build a quantum-ready trust basis.
As Red Hat makes quantum resistance available, it will inform customers through product tagging, individual component tagging, and cryptographic bills of materials (CBOMs). A CBOM is an inventory of all cryptographic assets and dependencies within an application, helping security teams track what needs to be modernized.
Figure 2. Q-Day preparation roadmap.
| Yesterday | Today | Tomorrow | Future |
| Traditional cryptography; no quantum-resistant algorithms available. | Includes available QRAs and PQC functions. Not available for all applications. Classical by default with configurable use of available QRAs. | QRAs and PQC functions by default where available, configurable classical where needed. | Classical algorithms and functions will be marked as deprecated with eventual removal. Capabilities and mechanisms to be resistant to downgrade attacks. |
Classical |
PQ-capable |
PQ-ready |
Deprecation and removal |
Step 2: Cryptographic agility
PQC migration is qualitatively different from either past cryptographic updates or IT modernizations: It’s a must-succeed, novel synthesis of both. Achieving the necessary agility requires organizations to map how platforms exchange cryptographic keys.
This process begins with a clear inventory of your software assets. It starts with the basics: inventory and risk management. Once inventory information is complete and checked for accuracy, optimization and management work can begin.
Red Hat tools can help automate this process: Red Hat Lightspeed telemetry platforms are integrating cryptographic discovery and Red Hat Ansible® Automation Platform can apply general-purpose system automation to the discovery process. This facilitates modernization and builds the foundation for future enterprise agility.
Adopting PQC may motivate organizations to focus on fundamental enterprise agility, but there are many other reasons to do so:
- Artificial intelligence and agentic systems will rely on nonhuman identity and specialized authentication and authorization systems.
- Software-defined IT systems with a higher dynamic nature require frequent use of independent cryptographic trust and trust anchor systems.
- Cybersecurity risks, particularly in supply chains, are rapidly increasing and the industry is responding with wider use of cryptographically secured or organized digital assets.
Step 3: Cryptographic posture management
Enterprise governance is at the heart of cryptographic posture, assessing the state and actively managing the use of cryptography within an organization. Assessment and management needs to outlast PQC migration and remain relevant even after migration to QRAs is complete. CBOMs will provide an invaluable tool for exchanging posture information across applications, teams, and vendor ecosystems—and to your Chief Information Security Officer (CISO) for effective policy definition and management.
Figure 3: Example cryptographic discovery scan results from Red Hat Ansible Automation Platform over a set of hosts.