Adversaries are not waiting for quantum computers to exist. They are capturing encrypted traffic right now, storing it, and waiting for the day a quantum computer can unlock it. Security teams call this a harvest now, decrypt later attacks, and it is already underway against corporate networks, cloud gateways, and mobile traffic. Every message your organization sends today without quantum resistant encryption is a message an attacker may already be holding for later.
This is not a distant risk to plan for eventually. Patient records, trade communications, government instructions, and privileged legal conversations often stay sensitive for five, ten, or fifteen years. If that data is captured today in a form a quantum computer can later break, the damage happens the day it is decrypted.
In August 2024, NIST finalized its first post-quantum standards, including FIPS 203 (ML-KEM) for key encapsulation. Since then, secure communication providers have moved at very different speeds. Some have deployed these standards in production today. Others still describe them as a research interest or a roadmap item. That gap matters immediately, not eventually, because the traffic those providers protect right now is what is being harvested.
What to look for beyond the algorithm name
Not every post quantum claim protects you the same way. The questions separate real protection from a talking point:
- Is it running in production today, or is it a plan? A NIST approved algorithm sitting inside a research partnership is not protecting a single message yet.
- Is it the default, or does someone have to turn it on? Optional modes only protect the organizations that know to enable them, and most never do.
The providers
NetSfere: ML KEM 1024 running in production today
NetSfere has deployed NIST's FIPS 203 standard using ML KEM 1024, the highest strength parameter set, across its enterprise messaging platform. It runs today, for every message, not as an optional switch. NetSfere combines this with a hybrid classical plus post quantum design: session keys are derived from both a classical key agreement and an ML KEM shared secret, so a weakness discovered in one algorithm family still leaves the other contributing security. Message payloads are then encrypted with AES 256, and forward secrecy rotates session keys so a future credential compromise cannot unlock past conversations.
This sits inside a broader enterprise control layer: SCIM provisioning, SSO/SAML authentication, centralized administrative policy, audit logging, and HIPAA Business Associate Agreement support for covered healthcare entities. NetSfere also maintains FedRAMP Ready status and compliance mapping across HIPAA, FINRA, GDPR, NIS2/KRITIS, DPDP, and MAS TRM, aimed at the industries where harvest now, decrypt later risk is highest: healthcare, banking, government, and legal services. NetSfere documents this architecture in detail in its quantum resilient encryption overview.
Signal: Triple Ratchet, already rolling out
Signal, the protocol behind the Signal app, WhatsApp, and Google Messages RCS encryption, added post quantum protection in stages. It first introduced PQXDH for quantum resistant initial key agreement, then layered in the Sparse Post Quantum Ratchet, combined with its existing Double Ratchet into what Signal calls a Triple Ratchet. The rollout needs no user action; conversations migrate automatically as clients update. Signal remains consumer focused and open source, without the tenant administration, compliance tooling, or audit controls enterprises require.
Apple iMessage: PQ3 at consumer scale
Apple's PQ3 protocol layers post quantum key material into iMessage's existing key exchange, rekeying periodically to balance message size against security. It was one of the earliest large scale consumer deployments of post quantum messaging security. Like Signal, iMessage is a consumer platform. It does not offer the IT administration, audit logging, or archiving controls enterprises look for in a business communication system.
Mattermost: NIST algorithms behind a premium tier
Mattermost, the open source, self hosted collaboration platform common in DevOps environments, added support for NIST post quantum algorithms inside its Enterprise Advanced tier. It has also partnered with Qrypt to bring quantum secure end to end encryption, built on Qrypt's BLAST protocol and a NIST certified quantum entropy source, into the platform. Because this sits in a premium tier rather than the base product, an organization has to specifically adopt Enterprise Advanced to get it, which means many existing Mattermost deployments are not protected yet.
AWS Wickr: quantum resistant key exchange as an option
Wickr, AWS's encrypted collaboration platform for regulated industries, offers quantum resistant key exchange as an available mode rather than a default setting. Healthcare and other regulated customers can turn it on today. It runs on AWS LC, AWS's FIPS 140-3 validated cryptographic library and the first open source crypto module to include ML KEM in that validation, so the underlying infrastructure is strong even though activation is opt in.
Threema: a research partnership, not yet a shipped algorithm
Threema, the metadata-minimizing messenger whose cryptographers co-developed two of the original NIST PQC standards, has partnered with IBM to chart its quantum-secure roadmap. As of this writing, that is a research collaboration, not a deployed post quantum algorithm in the shipping app. That puts Threema earlier on the adoption curve than the providers above, despite its strong reputation on other security fronts.
Wire: crypto agile architecture, algorithm not yet confirmed shipped
Wire builds its collaboration platform on the Messaging Layer Security standard, designed with crypto agility in mind so it can absorb post quantum algorithms without a ground up redesign. Wire's zero trust, zero knowledge model is a strong foundation, but there is no confirmed, shipped post quantum algorithm in production as of this writing, a real gap next to providers that already have one running.
At a glance
| Provider | Algorithm | Status | Default or opt in | Enterprise controls |
|---|---|---|---|---|
| NetSfere | ML KEM 1024 (FIPS 203), hybrid classical + PQC | Shipped, platform wide | Default | Full: SCIM, SSO/SAML, HIPAA BAA, audit logging, FedRAMP Ready |
| Signal | PQXDH + SPQR (Triple Ratchet) | Shipped, rolling out | Default (automatic) | Minimal, consumer app |
| Apple iMessage | PQ3 | Shipped | Default | Minimal, consumer app |
| Mattermost | NIST ML KEM/ML DSA (via Qrypt) | Shipped, Enterprise Advanced tier | Opt in, tier gated | Yes, self hosted |
| AWS Wickr | ML KEM (via AWS LC) | Shipped, available mode | Opt in | Yes |
| Threema | Under research with IBM | Research phase | Not applicable | Limited enterprise tooling |
| Wire | MLS (crypto agile) | Architecture ready, algorithm not confirmed shipped | Not applicable | Yes |
The takeaway
Quantum resistant encryption is not something to revisit later. The traffic moving across your messaging platform today is what an adversary may already be storing for a future attack. NetSfere was among the first enterprise communication platform to deploy NIST FIPS 203 ML-KEM 1024, the highest security level defined in the standard, across its platform. Built on a crypto-agile architecture, NetSfere is designed to seamlessly adopt future cryptographic standards without requiring organizations to replace or redesign their communication infrastructure.
Beyond quantum-resilient encryption, NetSfere delivers the enterprise capabilities organizations rely on to protect their most sensitive communications, including end-to-end encrypted messaging, secure voice and video, enterprise file sharing, comprehensive administrative controls, audit logging, and compliance support for highly regulated industries.
Whether you're protecting healthcare records, financial transactions, government communications, intellectual property, or other long-lived sensitive information, NetSfere helps organizations address today's cybersecurity threats while preparing for tomorrow's cryptographic challenges
Frequently Asked Questions
Is post quantum risk already active, or is it years away?
How do I tell a real quantum resistant deployment from a roadmap announcement?
Is optional post quantum protection enough for a regulated organization?
Why does the ML KEM 1024 matter when comparing vendors?
Does a hybrid classical plus post quantum design weaken security compared to post quantum only?
Is post quantum risk already active, or is it years away?
How do I tell a real quantum resistant deployment from a roadmap announcement?
Is optional post quantum protection enough for a regulated organization?
Why does the ML KEM 1024 matter when comparing vendors?
Does a hybrid classical plus post quantum design weaken security compared to post quantum only?
