OWASP / OWASP/quantum-security-project

Proposal: PQC Protocol Readiness Matrix

Open
#46 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
No language data
Stars
99
Forks
32
PR merge metrics
No merged PRs in 30d

Description

Create and maintain an OWASP PQC Protocol Readiness Matrix that evaluates the post-quantum readiness of application and security protocols such as TLS, SSH, IPsec/IKEv2, QUIC, DTLS, MQTT, PKI/X.509, DNSSEC, and signing protocols.

The matrix would track whether each protocol has a defined migration path to PQC, including standardization, hybrid support, implementation availability, interoperability, and operational considerations.

PR #41 focuses on cryptographic inventory management and PQ-readiness software. Its primary question is:

What cryptographic assets and algorithms does an organization have, and how can they manage their migration?

This proposal focuses on the protocol layer:

How ready are the protocols that applications depend on for PQC adoption?

Expected Outcome

The project would maintain a living, evidence-backed reference matrix showing the current PQC readiness of protocols and their surrounding ecosystem.

The matrix would be based on standards, implementation evidence, interoperability testing, and publicly verifiable sources rather than subjective vendor rankings.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the issue's listed protocols and its criteria: standardization, hybrid support, implementation availability, interoperability, and operations. Review the cited PR #41 for the boundary between protocol readiness and cryptographic inventory work. Done means a living, evidence-backed matrix covering the proposed protocol scope with publicly verifiable sources.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, documentation, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.