Palo Alto Networks QSS secures FedRAMP approval for quantum-safe tools

Federal agencies can now deploy quantum-safe defenses thanks to Palo Alto Networks achieving FedRAMP Moderate authorization for its Quantum-Safe Security (QSS) solution. This certification confirms QSS meets stringent security standards for sensitive data, enabling adoption of advanced technologies while addressing the December 31, 2030 deadline for transitioning key establishment to post-quantum cryptography. Palo Alto Networks uses existing firewalls as sensors, delivering improvements to an agency’s cryptographic posture from the start without costly new hardware, a fiscally responsible approach to mitigating emerging threats. QSS transforms the network into an automated, real-time cryptographic control point.

Palo Alto Networks QSS Enables PQC Transition by 2031

Executive Order 14412 and subsequent OMB Memorandum M-26-15 mandate federal agencies transition key establishment to PQC by December 31, 2030, and digital signatures by December 31, 2031, shortening the original 2035 target. This certification demonstrates QSS meets stringent security requirements for sensitive, unclassified data, enabling agencies to proactively address these deadlines without disrupting existing infrastructure. Palo Alto Networks’ approach centers on transforming current security investments into a proactive defense against emerging quantum threats.

Traditional cryptographic audits, often conducted annually, provide only a snapshot in time and quickly become outdated; QSS offers continuous, automated discovery and risk assessment. This capability identifies cryptographic weaknesses across diverse systems, including those within complex IoT environments, without requiring additional agent deployments or hardware investments. As the largest standalone cybersecurity provider, the company has embedded this functionality directly into its existing security fabric, creating a real-time cryptographic control point.

The technical architecture of QSS rests on three core pillars: agentless discovery, prioritized risk intelligence, and active inline remediation, Palo Alto Networks says. Agentless discovery utilizes the existing Palo Alto Networks security infrastructure to provide comprehensive visibility into encrypted sessions, certificates, and tunnels, according to the company. This allows the platform to correlate the mathematical strength of ciphers and certificates with asset criticality and data sensitivity, moving beyond simple technical alerts to focus on protecting the most valuable data.

The company urges agencies to “Get Ahead of the Mandate,” and “Stop guessing which digital locks to change first.” For legacy systems unable to natively support PQC, QSS employs Cipher Translation, allowing firewalls to translate weak classical encryption into quantum-safe standards at the network edge. This shields vulnerable assets without requiring costly or time-consuming application code changes, a fiscally responsible approach to PQC migration.

The platform addresses the growing threat of “Harvest Now, Decrypt Later” (HNDL) attacks, where adversaries collect encrypted data with the intention of decrypting it once quantum computers become powerful enough. According to the company, “Quantum-Safe Security transforms your existing infrastructure into a high-fidelity sensor network to neutralize” these risks.

Palo Alto Networks’ commitment extends beyond simply providing a technical solution; it positions itself as a partner in a broader national security initiative. The company states that “The Executive Order on Securing the Nation Against Advanced Cryptographic Attacks confirms that PQC is a national security imperative, not just a compliance requirement.” The FedRAMP Moderate authorization reinforces this position, demonstrating that Palo Alto Networks is helping agencies build a strong security posture.

Founded in 2005 and headquartered in Santa Clara, the company has integrated quantum-safe capabilities across its Firewall and Secure Access Service Edge platforms, and maintains a strategic partnership with IBM to further develop quantum-safe solutions. With one patent family and two publications in the last twelve months, Palo Alto Networks continues to invest in research and development within this critical field, ensuring agencies can modernize with confidence and bridge the gap for unpatchable legacy systems via in-line enforcement.

Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of Rusty Flint

Rusty Flint

Rusty is a quantum science nerd. He's been into academic science all his life, but spent his formative years doing less academic things. Now he turns his attention to write about his passion, the quantum realm. He loves all things Quantum Physics especially. Rusty likes the more esoteric side of Quantum Computing and the Quantum world. Everything from Quantum Entanglement to Quantum Physics. Rusty thinks that we are in the 1950s quantum equivalent of the classical computing world. While other quantum journalists focus on IBM's latest chip or which startup just raised $50 million, Rusty's over here writing 3,000-word deep dives on whether quantum entanglement might explain why you sometimes think about someone right before they text you. (Spoiler: it doesn't, but the exploration is fascinating)

Latest Posts by Rusty Flint: