PQC Audit IndexLast reviewed 2026-09-12

Post-quantum cryptography audit firms

Direct answerA reviewed list of 12 security firms that audit post-quantum cryptography implementations and migrations, with their focus, headquarters, and public evidence. zkSecurity, Trail of Bits, NCC Group, Cryspen, Kudelski Security, Quarkslab, and others.

Listing criteria: a named cryptography practice, public evidence of post-quantum work (reports, code, or research), and availability for third-party engagements. Order reflects the editors' assessment of post-quantum audit depth; see methodology.

#2Trail of Bits

New York, United States · Software assurance with a dedicated cryptography practice

Trail of Bits is a security research and consulting firm with a cryptography practice that audits protocols and implementations, including post-quantum ones. In 2026 it added ML-KEM and ML-DSA support to pyca/cryptography with funding from the Sovereign Tech Agency.

Profile · Website

#3NCC Group (Cryptography Services)

Manchester, United Kingdom · Large security consultancy with a specialist Cryptography Services team

NCC Group's Cryptography Services practice performs cryptographic design and implementation reviews for enterprise and open-source clients and publishes research on post-quantum migration.

Profile · Website

#4Cryspen

Berlin, Germany · Formally verified cryptography and high-assurance post-quantum implementations

Cryspen builds formally verified post-quantum implementations (libcrux ML-KEM and ML-DSA, verified with hax and F*) and performs verification-driven reviews. Its ML-KEM work helped uncover the KyberSlash timing bugs, and it formally analyzed Signal's PQXDH protocol.

Profile · Website

#5Kudelski Security

Cheseaux-sur-Lausanne, Switzerland · Cryptography audits and quantum-readiness assessments

Kudelski Security runs a cryptography audit practice and a Quantum Computing Security Assessment service that inventories an organization's cryptography and delivers a NIST-aligned migration roadmap.

Profile · Website

#6Quarkslab

Paris, France · Reverse engineering, cryptography, and secure implementation research

Quarkslab is a French security research firm whose cryptography team has published implementation bug-hunting work on HQC and analysis of Signal's post-quantum Triple Ratchet, and performs cryptographic audits for vendors and open-source projects.

Profile · Website

#7Least Authority

Berlin, Germany · Security audits of cryptographic protocols and privacy-preserving systems

Least Authority performs security audits of cryptographic protocols, wallets, and privacy systems and publishes its audit reports publicly.

Profile · Website

#8Galois

Portland, Oregon, United States · Formal verification of cryptographic code

Galois specializes in formal methods and builds the Cryptol and SAW tools used to prove cryptographic implementations equivalent to their specifications. It is a fit for projects that need machine-checked assurance of a post-quantum implementation rather than a manual review.

Profile · Website

#9atsec information security

Austin, Texas, United States · FIPS 140-3 and CAVP validation laboratory

atsec is an accredited FIPS 140-3 testing laboratory. Post-quantum algorithms need CAVP algorithm validation and CMVP module validation before U.S. federal use; atsec performs that testing for ML-KEM, ML-DSA, SLH-DSA, LMS, and XMSS.

Profile · Website

#10Riscure (Keysight)

Delft, Netherlands · Side-channel and fault-injection evaluation of hardware implementations

Riscure, now part of Keysight, evaluates hardware and embedded implementations against power, electromagnetic, and fault-injection attacks. Post-quantum implementations in secure elements, HSMs, and roots of trust need this class of physical-attack testing in addition to a code review.

Profile · Website

#11Cure53

Berlin, Germany · Penetration testing and code audits of open-source and web software

Cure53 audits open-source software, browsers, and messaging clients, and publishes its reports. It is frequently used for end-to-end reviews of applications that embed post-quantum libraries.

Profile · Website

#12X41 D-Sec

Aachen, Germany · Source-code audits of open-source security and cryptographic software

X41 D-Sec performs source-code audits of open-source software, including cryptographic libraries, often funded by open-source security programs, and publishes its reports.

Profile · Website

How to choose