Crypto libraries · HSM / KMS · Cloud & CDN

Amazon Web Services

AWS is rolling hybrid ML-KEM transport protection across service endpoints; customer-held PQC signing keys are not generally available across KMS.

ShippingVerified through 2026-09-06
Products

Verified capability

3 records
Crypto libraries

AWS-LC

Shipping
ML-KEM
Implemented in the open-source cryptographic library
Scope
Library capability; downstream service enablement varies
CAWS-LC post-quantum implementation notesChecked 2026-09-06
Open first-party evidence
HSM / KMS

Managed key services

Partial
PQC-protected API transport
Hybrid ML-KEM in TLS to KMS endpoints
PQC customer signing keys
Not generally available
CAWS post-quantum migration planChecked 2026-09-06
Open first-party evidence

Do not infer: That keys managed for you are post-quantum key types — the protected item is the connection.

Cloud & CDN

AWS service endpoints

Partial
Hybrid TLS to service endpoints
Rolling out across services
Full-estate completion
Published multi-year migration plan, no single GA date
CAWS post-quantum migration planChecked 2026-09-06
Open first-party evidence
Roadmap explorer

Published milestones

1 dated steps
  1. 2025
    statementC

    Multi-year migration plan published

    AWS describes staged endpoint deployment and application testing without claiming one estate-wide completion date.

    AWS post-quantum cryptography
Compare OpenSSLCompare GoogleCompare OpenSSHCompare SignalCompare ThalesCompare Infineon