TigerTrust supports NIST-standardized post-quantum algorithms end-to-end — issuance, storage, deployment, and lifecycle management — and gives you the tools to plan a migration from RSA/ECDSA at your own pace. The goal is crypto-agility: swap algorithms without swapping platforms.

What it is

You run readiness assessments against your existing certificates to score their quantum vulnerability, issue PQC (or hybrid classical + PQC) certificates from your internal CA, and track migration progress through structured migration plans. The existing renewal engine handles PQC certificates the same way it handles classical ones.

When to use it

  • Assess your current inventory for long-lived RSA or ECDSA certificates that are at elevated risk.
  • Issue hybrid certificates (classical + PQC signature) so existing clients keep working while adding PQC protection.
  • Track a fleet-wide algorithm migration from planning through rollout to completion.
  • Demonstrate to auditors that you have a documented post-quantum migration program.

Supported algorithms

AlgorithmNIST standardType
ML-DSA-44, ML-DSA-65, ML-DSA-87FIPS 204Signature (formerly CRYSTALS-Dilithium)
ML-KEM-512, ML-KEM-768, ML-KEM-1024FIPS 203Key encapsulation (formerly CRYSTALS-Kyber)
SLH-DSA-SHA2-128sFIPS 205Signature (stateless hash-based)
Falcon-512DraftSignature (smaller than ML-DSA)
ML-DSA-65 is the recommended default for new signature certificates. Hybrid certificates set hybridClassicalAlg (for example, ECDSA-P256) alongside the PQC algorithm so that classical clients can verify the certificate today.

Set it up

1

Run a readiness assessment

Go to PQC > Assessments and click Assess readiness. Select one or more certificates. TigerTrust scores each certificate 0–100 based on key algorithm vulnerability, key size, hash algorithm, and remaining validity.
2

Review high-risk certificates

Filter to high or critical risk. Each assessment returns a recommended target algorithm and an estimated migration duration.
3

Create a migration plan

Click Create migration plan from the assessment results. Select the target algorithm, security level (1, 3, or 5), and the certificates in scope. TigerTrust tracks the plan through phases: planningpilotrolloutcomplete.
4

Issue PQC certificates

Go to PQC > Certificates and click Register PQC certificate. Choose the algorithm, enter the common name, and optionally set a classical algorithm for a hybrid certificate. The internal CA issues the certificate using the PQC algorithm.
5

Advance the plan

As you migrate batches of certificates, click Advance phase on the migration plan to move from pilot to rollout and track overall progress.

What you’ll see

PQC > Assessments shows risk scores for assessed certificates with color-coded risk levels. PQC > Migration plans lists active plans with phase, progress percentage, target algorithm, and rollback plan. PQC certificates appear in your main Certificates inventory alongside classical ones, tagged with their algorithm.
PQC certificates are larger than classical ones. An ML-DSA-65 signature is roughly 3.3 KB versus about 256 bytes for ECDSA-P256. Verify that your load balancers, browsers, and TLS terminators handle the size increase before flipping production traffic. Test in staging first.

Migration playbook

1

Inventory

Run assessments across every certificate in scope. Filter high/critical risk into an initial batch.
2

Pilot

Migrate non-production workloads first using hybrid certificates so classical clients keep working.
3

Client compatibility

Test browsers, tools, HSMs, and TLS terminators against the larger PQC key material.
4

Rollout

Progressively renew production certificates onto the target algorithm. The renewal engine handles PQC certificates natively.
5

Retire classical

Once client coverage is complete, drop the classical half of hybrid certificates.

Certificate Authorities

Configure your internal CA to issue PQC certificates.

Renewal automation

Renewals seamlessly cross the classical to PQC boundary.