Key Concepts
Cryptographic Risk Classification
Quantum-Safe Security performs a risk assessment for each asset it discovers. Based
on cryptography observed in sessions, tunnels, and certificates, the app classifies
each asset into one of three Cryptography Risk categories:
Data Exposure Risk—Identifies sessions using algorithms or protocols
deprecated by the National Institute of Standards and Technology (NIST).
Quantum-Secure—Identifies assets already using NIST-approved PQC algorithms
or hybrid PQC algorithms.
The Quantum-Safe Security app continuously monitors cryptographic usage across the
enterprise to ensure the accuracy of cryptographic risk and help you track the
effectiveness of mitigation actions.
The following table lists the specific data sources and cryptographic
attributes used to evaluate cryptographic risk exposure. This list is not
exhaustive.
Cryptographic Risk Classification Mapping
| Data Source | Metadata Inspected |
| Sessions |
- Protocol
- Elliptical Curve
- Key Exchange Algorithm
- Encryption Algorithm
- Authentication Algorithm
|
| Certificates |
- Certificate Key Algorithm
- Key Size
- Certificate Signing Algorithm
|
| Tunnels |
- IKE Protocol
- Elliptical Curve
- Key Exchange Algorithm
- Encryption Algorithm
- Authentication Algorithm
|
Asset Criticality
Asset criticality refers to how important an asset is to your organization's
operations. You can rate assets as
High or
Standard business impact.
High
business impact typically applies to assets that handle sensitive data, must protect
data over long periods, are subject to regulatory requirements, or would cause
significant operational disruption if compromised. It also applies to assets with
the greatest exposure to
Harvest Now, Decrypt Later or other
threats.
You can define rules that automatically assign
High business
impact to applications or user devices based on App-ID categories or user groups, or
manually assign a rating to individual assets. Classifying assets by criticality
gives you a more accurate view of risk and lets you filter and prioritize assets for
remediation using the
Business Impact filter. For more
information, see
Configure Asset Criticality.
Once you configure criticality, the Overview
dashboard surfaces critical asset data directly in the cryptographic risk chart.
The inner donut ring and Critical Data center total let you
assess which risk categories contain the highest concentration of business-critical
assets without leaving the dashboard.
Quantum Readiness
Quantum Readiness reflects the capability of an asset to support PQC, which depends
on its specific hardware and software attributes. An asset is Quantum Ready when its
underlying hardware or software supports quantum-resistant algorithms, even if they
are not in use. An asset is Quantum Safe if its hardware or software actively uses
PQC or hybrid PQC that complies with NIST or other PQC standards.
While Quantum Readiness is a fixed attribute—an asset either has PQC capability or
not—your configuration can determine what state the asset is in. For example,
enabling PQC for SSL/TLS sessions ensures that quantum-ready assets negotiate
quantum-safe sessions. The app provides recommendations for modernizing assets that
are Not Ready and migrating Ready assets to PQC.
When asset context is lacking, the app cannot provide a
definitive status of Quantum Readiness. In this case, if a single PQC key exchange
is observed for the asset over the selected time period, the app infers that the
asset is Quantum Ready.
Cipher Translation Proxy
To secure legacy systems or IoT devices that cannot be upgraded, the app recommends
that you enable
cipher translation. Cipher translation is
the process of intercepting network traffic secured with classical encryption (like
RSA or ECDHE) and re-encrypting it in real-time using quantum-safe algorithms (like
ML-KEM) at the network edge. Hybrid post-quantum (PQ) key exchange enables this
process.
NGFWs running PAN-OS 12.1 or later versions act as the inline proxy, upgrading the
security of sessions. Communications between the parties is secure as long as at
least one of the two mechanisms—classical or PQC—remains uncompromised. Cipher
translation protects against the Harvest Now, Decrypt Later threat, does not require
upgrades or other changes to the endpoint, and facilitates a gradual transition to
PQC without disrupting business operations.
Cipher translation operates in two modes. In
forward proxy mode, the NGFW protects outbound sessions from legacy
clients or IoT devices that cannot use PQC — the device connects to the NGFW using
classical TLS, and the NGFW re-encrypts the traffic using PQC for the outbound
connection. In
inbound inspection mode, the NGFW protects inbound sessions
to legacy application servers — an internet client connects to the NGFW using PQC,
and the NGFW establishes a classical TLS session to the internal server. In both
modes, neither endpoint requires changes. For details, see
Quantum-Safe Cipher Translation.