How does Q6of align with CNSA 2.0 and the NSA's quantum-resistant timeline?
Our policy engine ships with a CNSA 2.0 baseline pre-loaded: ML-KEM-768 for key encapsulation, ML-DSA-65 for signatures, and AES-256 / SHA-384 as the symmetric defaults. Customers can tighten the floor to CNSS-recommended curves per asset class, and the control plane exports an evidence trail for every handshake that satisfies a reviewer without a follow-up audit.
What exactly does the FIPS 140-3 Level 2 certificate cover?
The certificate covers our cryptographic module — the HSM-backed key store, the policy enforcement boundary, and the random-bit generator — not the entire SaaS control plane. That boundary is exactly what your auditor will care about; we will share the certificate number and the security policy document on the audit call.
Will a hybrid TLS termination break our existing clients?
No. The agility mesh negotiates hybrid suites (X25519 + ML-KEM-768) by default, so legacy clients continue to negotiate against the classical half. Once the asset hits a "shadow" window of 100% post-quantum negotiation for 14 consecutive days, the classical fallback can be retired on your schedule.
What is the realistic harvest-now-decrypt-later exposure window?
Long-lived data with multi-decade confidentiality value — legal records, genomic data, defense IP, certain financial instruments — is the priority. Our modeling suite, used by the NSA's CSfC program as reference tooling, scores your assets against an adversary-collection probability curve so you can sequence migrations by exposure rather than by alphabet.
What does a migration actually cost, and how do I budget for it?
Our open-source PQC migration cost calculator — now an OWASP reference tool — returns a defensible cost band per asset class within minutes. During the 30-minute audit we walk you through a populated version against your CBOM, with confidence intervals your CFO will accept.