NQM-aligned India's PQC migration platform · by V Innovation Labs

India's shield against the quantum threat

KavachQ helps Indian banks, NBFCs, and Critical Information Infrastructure operators discover their cryptographic estate, score quantum risk, and migrate to NIST post-quantum algorithms — aligned with the DST National Quantum Mission Task Force roadmap.

2029
CII readiness target
2033
Enterprise target
L1–L4
Assurance levels
₹6,003Cr
NQM budget

Built around the standards India's regulators are aligning to

NIST FIPS 203 · ML-KEM NIST FIPS 204 · ML-DSA NIST FIPS 205 · SLH-DSA DST National Quantum Mission CycloneDX 1.6 CBOM Mosca's inequality Harvest-now, decrypt-later NQM Task Force roadmap
The platform

One platform for the whole migration journey

From "we don't know what crypto we run" to a board-ready, DST-aligned migration plan — KavachQ takes you the whole way.

Step 01 · Discover

See every certificate, algorithm, and key parameter you run

KavachQ builds a Cryptographic Bill of Materials (CBOM) across your estate — TLS endpoints, certificates, and protocols, plus any CBOM you already hold — so quantum-vulnerable cryptography stops hiding in plain sight.

Scan a domain free
Step 02 · Score

Know which assets are exposed first

Every asset gets a 0–100 quantum-risk score and a T1–T4 tier — algorithm strength, exposure, and harvest-now risk. A single, ranked risk register tells you exactly what to fix first — not a flat list of findings.

Try the live risk model
Step 03 · Plan

Sequence the move — with crypto-agility built in

Generate a phased, impact-aware migration to ML-KEM, ML-DSA, and SLH-DSA — mapped to the apps each change touches. Designed so the next algorithm swap is a config change, not a project.

Explore the roadmap
Step 04 · Report

Board-ready, DST-aligned evidence

Export a board pack tagged to DST/NQM milestones and the relevant RBI / SEBI / CERT-In references — the kind of evidence a board, a regulator, and an auditor all accept.

See the framework
kavachq scan --host bank.example.in
› negotiating TLS handshake…
cipher ECDHE-RSA-AES256-GCM-SHA384
key-exch X25519 ⚠ quantum-vulnerable
cert-sig RSA-2048 ⚠ harvest-now risk
› mapping to CBOM (CycloneDX 1.6)…
verdict PQC readiness 12 / 100
recommend ML-KEM-768 + ML-DSA-65
payments-api · RSA-204892
core-banking · 3DES88
vpn-gw · ECDH-P25664
archive · AES-25618
RANKED BY QUANTUM-RISK SCORE · T1–T4
  1. Inventory frozenCBOM baseline · 1,284 assets
  2. Pilot ML-KEM-768TLS termination · staging
  3. Hybrid rolloutX25519 + ML-KEM · production
  4. Signatures → ML-DSA-65code-sign + mTLS
  5. Decommission RSA/ECCcrypto-agility verified
BOARD PACK · DST / NQMCBOM ✓
T1 · Critical12
T2 · High34
T3 · Medium88
T4 · Low210
Exported · tagged to DST/NQM milestones · PDF + CycloneDX

Product screens are illustrative.

Inside the product

Not a mockup. The working console.

The walkthrough above is illustrative. These are the actual KavachQ console screens — captured on a demo tenant, with illustrative numbers and client identifiers blurred or omitted. Real client estates never leave your environment.

KavachQ · Cryptographic inventory
KavachQ console — cryptographic inventory dashboard: high-risk crypto objects, PQC-ready share, total assets, and algorithm families ranked by severity.
Cryptographic inventory. Every certificate and algorithm across your estate — deduplicated, severity-ranked, and mapped to its PQC replacement and Indian regulatory exposure.
KavachQ · CBOM map
KavachQ console — CBOM map plotting each estate asset as a node coloured by quantum risk: vulnerable, weakened, or quantum-safe.
The estate as a CBOM. Each asset plotted by quantum risk — vulnerable, weakened, or already quantum-safe.
KavachQ · Dependency graph
KavachQ console — crypto dependency graph linking application risk tiers to the vulnerable algorithm families they depend on.
Crypto dependency graph. Which applications, grouped by risk tier, lean on which quantum-vulnerable algorithm families.

Captured from the working KavachQ console on a demo tenant · illustrative data · client identities blurred or omitted.

Mosca's inequality, live

If X + Y > Z, your data is already at risk

Drag the sliders. X — how long this data must stay secret. Y — how long migration takes. Z — when a cryptographically-relevant quantum computer arrives.

X · Data shelf life7yrs

Years this data must remain confidential after it is created.

Y · Migration time4yrs

Realistic time to discover, refactor, and roll out PQC at scale.

Z · CRQC arrival10yrs

Conservative estimates place a CRQC in the early-2030s.

7+4=11 vs Z =10
At risk

X + Y exceeds Z — your shelf-life data is exposed before migration finishes. Move from awareness to inventory in the next 6–9 months.

Try it live

The cryptographic sandbox

Run a hybrid-PQC or NIST post-quantum handshake and watch the negotiation, step by step.

The clock is running

India has set the clock.
The migration takes years, not months.

Days
Hours
Minutes
Seconds

Advisory target — DST National Quantum Mission Task Force roadmap: CII to reach full PQC by 2029. Not a regulatory deadline.

The NQM Task Force sets advisory targets for Critical Information Infrastructure to reach post-quantum resiliency by 2029, and enterprises by 2033. Adversaries are already harvesting encrypted traffic to decrypt later. Starting discovery today is the only way to finish in time.

01

The harvest-now threat is real

Adversaries are intercepting and storing encrypted traffic today. Data with long-term sensitivity (financial, health, defence) is already compromised in principle. Quantum-safe migration cannot wait.

02

Quantum advantage is approaching

Google's Willow chip achieved below-threshold error correction in 2024. IBM, Microsoft, and others have published credible roadmaps to fault-tolerant systems within this decade.

03

India has published a clear roadmap

The NQM Task Force sets advisory targets for CII to reach full post-quantum resiliency by 2029, and enterprises by 2033. Migration takes years, not months. Delay now means compressed timelines later.

04

Industrial quantum is here

Quantum computing is already optimising supply chains, accelerating drug discovery, and transforming financial modelling. India's quantum industry is growing across computing, security, and sensing.

National Quantum Mission

Four pillars of India's quantum strategy

India's NQM — approved in 2023 with ₹6,003.65 crore — anchors research across four IIT/IISc hubs. KavachQ focuses on the cryptography that protects everything built on top.

01

Quantum Computing

Superconducting, photonic, and trapped-ion processors across four IIT/IISc thematic hubs.

4 RESEARCH HUBS
02

Quantum Communication

Satellite-based QKD, trusted-node architecture, and a sovereign communication backbone.

NATIONAL QKD NETWORK
03

Quantum Sensing

Precision magnetometers, gravimeters, and optical atomic clocks for defence and navigation.

DEFENCE + CIVIL
04

Quantum Materials

Semiconductors, topological insulators, and superconductors — the foundational hardware layer.

MATERIALS FOCUS
State quantum policies

States leading India's quantum ambition

Beyond the NQM, four Indian states have launched quantum-technology policies with infrastructure, funding, and talent programmes.

ANDHRA PRADESH

Amaravati Quantum Valley

$1B target by 2029

India's first dedicated quantum technology park. 50 acres in Amaravati. IBM 156-qubit (Heron) system. AP Quantum Computing Policy 2025–30. Plans to train 3.5M students by 2035.

KARNATAKA

Karnataka Quantum Mission

₹1,000 Cr

Launched 2025, targeting a $20 billion quantum economy by 2035. Coordinated through KITS (Karnataka Innovation & Technology Society) and a state Quantum Task Force.

MAHARASHTRA

Quantum Corridor

₹20 Cr (Phase 1)

MoU with IonQ and Scandian AB for a quantum R&D corridor. 50,000 quantum-skilled engineers target. IBM partnership for workforce training. Three-phase rollout through 2030.

TAMIL NADU

Quantum Hardware Access

State-backed

First state to provide students and startups real quantum hardware access. XeedQ 4-qubit computer. Q-CTRL partnership for engineering curriculum. Quantum strategy working group.

Free · no sign-in · seconds

Is your website quantum-safe?

Scan any domain's live TLS handshake for quantum-vulnerable certificates — and get its post-quantum readiness score instantly.

We only read what's publicly negotiated in a TLS handshake — no login, nothing stored.

Your toolkit

From understanding to operational readiness

A complete journey — executive education, live scanning, maturity assessment, and migration planning.

Why trust KavachQ

Credibility, not claims

We're an early team, so here's exactly what we stand on today.

Standards-first

Built around NIST FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) — the algorithms India's regulators are aligning to.

NQM-aligned

Aligned to the DST National Quantum Mission roadmap and its migration milestones.

Indian, by design

Built by V Innovation Labs in India, for India's BFSI and Critical Information Infrastructure.

Open & auditable

CBOM output in open CycloneDX 1.6 — portable evidence your own auditors can reproduce, with no lock-in.

About V Innovation Labs Become a design partner
Questions, answered

Post-quantum cryptography in India — the essentials

Straight answers to what BFSI and Critical Information Infrastructure teams ask most about PQC migration.

What is post-quantum cryptography (PQC)?
Post-quantum cryptography (PQC) is a family of encryption and digital-signature algorithms designed to stay secure against attacks from both classical and quantum computers. In August 2024 the US NIST finalised the first three standards — ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) — and India's National Quantum Mission Task Force roadmap aligns to them.
Why do Indian banks and BFSI need to migrate to PQC now?
A cryptographically-relevant quantum computer could break the RSA and ECC encryption that secures today's banking, UPI and payment systems. Adversaries can already harvest now and decrypt later — capturing encrypted data today to decrypt once quantum computers mature. Because migration takes years, India's DST Task Force recommends Critical Information Infrastructure reach full PQC adoption by 2029 and other enterprises by 2033.
What is the DST / National Quantum Mission PQC deadline for India?
The DST Task Force report Quantum-Safe Ecosystem in India — Roadmap to Quantum Resiliency (May 2026), under the ₹6,003.65-crore National Quantum Mission, sets advisory migration targets: Critical Information Infrastructure should reach full PQC by 2029, and other enterprises by 2033. The roadmap is advisory — enforcement rests with sector regulators such as RBI, SEBI, IRDAI and CERT-In. See the full India roadmap →
What is the difference between PQC and QKD?
Post-quantum cryptography (PQC) is software — quantum-resistant algorithms that run on existing hardware and replace RSA and ECC. Quantum key distribution (QKD) is hardware — it uses quantum physics to exchange keys over dedicated fibre or satellite links. For most BFSI and enterprise migration, NIST PQC is the practical, standards-based path; QKD is complementary for specific high-assurance links. Read the full PQC vs QKD comparison →
How do I check whether my organisation is quantum-safe?
Start with KavachQ's free quantum-risk scan — it inspects your domain's live TLS handshake for quantum-vulnerable certificates and returns a post-quantum readiness score in seconds. For a full picture, the KavachQ platform builds a Cryptographic Bill of Materials (CBOM), scores each asset 0–100 and tiers it T1–T4 — weighing algorithm strength, exposure, and harvest-now risk — and produces a phased migration plan tagged to DST/NQM milestones. Take the maturity scan →
Get started

Navigate the quantum transition

Understand the landscape. Assess your exposure. Build a board-ready, DST-aligned action plan. KavachQ takes you from awareness to operational readiness.