Skip to main content

Understand solutions for post-quantum computing

To enable cryptographic agility across your enterprise, DigiCert​​®​​ supports the post-quantum cryptography (PQC) standards that can be incorporated in your key pairs and certificates.

Notice

DigiCert Quantum Central is now in preview

Explore the free preview of DigiCert​​®​​ Quantum Central and see how it helps you discover cryptographic assets, prioritize migration risk, manage remediation, and demonstrate quantum readiness. To sign-up and try it now, visit our website.

DigiCert solutions that support PQC

DigiCert ONE services support the following types of PQC solutions:

Table 1. DigiCert solutions for PQC

Solutions

DigiCert​​®​​ services

Issuance of pure PQC (ML-DSA) certificates

Private CA

Delivery of pure PQC (ML-DSA) certificates

Device Trust

Trust Lifecycle

Sign software and verify hash commands using PQC algorithms

Software Trust

Batch issuance support for pure PQC certificates

Device Trust

Trust Lifecycle

Automated certificate lifecycle management of ML-DSA certificates

Trust Lifecycle

Discover certificates and endpoints vulnerable to quantum cryptography

Trust Lifecycle

Quantum Central

Generate ML-DSA key pairs to create a CSR and send a CSR to a PKI over EST or SCEP, all through a free-to-download CLI

DigiCert TrustEdge

C-SDK embedded security toolkit with support for ML-KEM, ML-DSA, TLS 1.3, and FIPS 140-3 certified crypto

DigiCert TrustCore SDK

Test issues of PQC certificates, including ones with algorithms not yet supported by the CA/Browser forum, on a free playground for testing algorithms

DigiCert Labs


Supported PQC algorithms

DigiCert supports private certificates with ML-DSA, SLH-DSA, and ML-KEM algorithms, depending on the service. At the current time, CertCentral doesn’t issue public CA certificates with these algorithms.

  • ML‑DSA provides digital signatures using lattice‑based assumptions, which offers authenticity and non‑repudiation.

  • ML‑KEM lets one party (initiator) generate a public/private key pair. The responder uses the public key to derive a shared secret and a ciphertext, which the initiator de-capsulates to recover the same secret. Use this key encryption method as a quantum defense version of TLS/SSL for secure websites.

  • SLH-DSA applies lightweight hash-based techniques to ensure security while optimizing performance, making it ideal for resource-constrained environments.

Table 2. PQC algorithms that DigiCert supports for private certificates

DigiCert service

ML-DSA

SLH-DSA

ML-KEM

Private CA

1

--

Device Trust

1

--

Document Trust

--

--

--

Software Trust2

1

--

DigiCert TrustCore SDK

DigiCert TrustEdge

Trust Lifecycle

1

--


1 PQC-enabled HSM is available in the United States data centers only.

2 Online Certificate Status Protocol (OCSP) support for ML-DSA isn’t defined in a Requests for Comments (RFC) yet.

Supported key sizes per signing algorithm

DigiCert® Private CA issues and manages private certificates for PQC with the following key sizes:

Table 3. Key sizes per signing algorithm key type

Signing algorithm

Key size

ML-DSA

ML-DSA-44

ML-DSA-65

ML-DSA-87

SLH-DSA

SLH-DSA SHA2-128f

SLH-DSA SHA2-128s

SLH-DSA SHA2-192f

SLH-DSA SHA2-192s

SLH-DSA SHA2-256f

SLH-DSA SHA2-256s

SLH-DSA SHAKE-128f

SLH-DSA SHAKE-128s

SLH-DSA SHAKE-192f

SLH-DSA SHAKE-192s

SLH-DSA SHAKE-256f

SLH-DSA SHAKE-256s


Supported key sizes per encapsulation (key exchange) algorithm

DigiCert® Private CA supports PQC key encapsulation with the following key sizes:

Table 4. Key sizes per encapsulation algorithm key type

Encapsulation algorithm

Key size

ML-KEM

ML-KEM-512

ML-KEM-768

ML-KEM-1024