A small British engineering firm's equipment testing room in late afternoon, with an IT technician seen from behind connecting two compact computers through a network appliance on a metal workbench. E

Testing post-quantum cryptography with Microsoft, AWS and Google in the UK

8 min read

Microsoft, AWS and Google provide distinct routes for testing certificate signatures, cloud API connections and frontend traffic. UK businesses should choose a pilot around their existing platform and require evidence of negotiation, compatibility and operational cost.

Written by Andrew McLean Studio Director at Disruptive Live

UK small and mid-sized businesses can test post-quantum cryptography through Microsoft AD CS certificate services, AWS service connections and Google Cloud Load Balancing. These address different jobs, including certificate signatures, cloud API connections and application traffic. Start with the platform you already operate and one bounded pilot. Success means proving which cryptographic protection worked, checking compatibility and identifying the parts of your system that the test did not cover.

What a post-quantum pilot means for a UK business

Post-quantum cryptography, or PQC, uses algorithms designed to withstand attacks from future quantum computers. For this decision, separate two tasks. Key establishment protects the secrets used to encrypt a connection; digital signatures establish authenticity. Google’s documentation explains why recorded traffic creates a future decryption risk, while attacks against authentication have a different mechanism. Google’s explanation of the TLS threats

That distinction determines what to test. A business exchanging confidential files needs evidence about its transfer connection. A software supplier testing signed releases needs evidence about signatures and the systems that verify them. Passing either test does not establish that the other task is protected.

Hybrid key exchange combines a conventional mechanism with a post-quantum mechanism. AWS KMS documents a combination of Elliptic Curve Diffie-Hellman and ML-KEM, the Module-Lattice-Based Key-Encapsulation Mechanism. The pilot therefore tests a combined approach rather than simply removing conventional cryptography. AWS KMS hybrid design

For a UK organisation, keep deployment geography and cryptographic coverage as separate acceptance criteria. AWS documents broad regional coverage for KMS and S3, but that does not establish UK data residency for an entire application. Confirm the actual endpoints, storage locations and service dependencies used by the pilot. KMS regional scope, S3 regional scope

A bounded PQC pilot
Choose an existing platform, verify the specific cryptographic protection and compatibility, then record what the pilot did not cover.

Microsoft offers a certificate laboratory

Microsoft AD CS is the clearest supported Microsoft testing route in the supplied documentation. It can use ML-DSA for certification authorities, code-signing certificates, server and client authentication certificates, and certificate-status response signing. Microsoft warns that third-party applications, devices and services may not recognise these certificates. Supported ML-DSA scenarios

Build a separate test hierarchy rather than changing the authority that issues production certificates. The infrastructure administrator owns certificate issuance; application owners must establish whether their software can validate the resulting certificates and chains. Microsoft’s requirements include Cryptography Next Generation key storage providers rather than legacy providers. AD CS requirements and migration limits

Certificate size is a concrete measurement opportunity. Microsoft lists these signature sizes for its supported parameter sets. They describe signatures, not complete certificate sizes or measured network overhead. Microsoft’s parameter-set table

Parameter setSignature size
ML-DSA-442,420 bytes
ML-DSA-653,309 bytes
ML-DSA-874,627 bytes

Do not infer equivalent capabilities across Azure services. Azure App Service documents TLS 1.3 support, but that page does not establish post-quantum key exchange. Azure Key Vault Managed HSM lists RSA, elliptic-curve and symmetric AES key types, with quantum-resistance guidance for AES-256; it does not establish an ML-DSA or ML-KEM testing route. App Service TLS documentation, Managed HSM key documentation

AWS offers API and file-transfer tests

AWS KMS is a useful starting point for an existing AWS application because it provides documented verification evidence. Make a direct API call from a compatible client and inspect the corresponding CloudTrail entry. A hybrid algorithm such as `X25519MLKEM768` in `tlsDetails.keyExchange` establishes what that connection negotiated. AWS notes that `tlsDetails` is absent when another AWS service calls KMS on your behalf. KMS verification details

Amazon S3 provides a storage-transfer test, subject to its endpoint exclusions. However, AWS says S3 CloudTrail events and server access logs do not expose PQ-TLS key-exchange details. Plan suitable client or handshake inspection before treating a successful upload as proof of post-quantum negotiation. S3 support and logging limitations

Secrets Manager supports API-connection tests, while AWS Payment Cryptography documents hybrid TLS for its endpoints and recent SDKs. These are relevant when the application already uses those services; neither is a reason to introduce an otherwise unnecessary dependency. Secrets Manager guidance, Payment Cryptography guidance

For supplier or customer file exchange, Transfer Family offers a different pilot using hybrid SSH key establishment. Its documentation describes SFTP transfers into and out of S3 or Amazon EFS. Confirm availability in the intended Region before including it in a UK deployment design. Transfer Family scope

Record the exact client environment. AWS documents different support paths for Go, Java, JavaScript, Node.js and other runtimes, including reliance on system TLS libraries on some platforms. A result from a developer’s laptop should not be assumed to apply to the production host. AWS client-support matrix

Google offers a frontend connection test

Google Cloud Load Balancing supports the hybrid key-exchange group `X25519MLKEM768` on specified Application Load Balancers and proxy Network Load Balancers. Enable it through the `post-quantum-key-exchange` setting in an SSL policy. The client must advertise both TLS 1.3 and the supported group. Google’s configuration and compatibility requirements

This creates a practical staging test for an existing web application. Compare compatible and incompatible clients, record the negotiated group and test representative corporate network paths. Google states that clients without the required support are unaffected, so a successful connection alone cannot prove that PQC was used. Google’s negotiation behaviour

The documented boundary is the connection from client to load balancer. Assess the backend connection separately. The supplied evidence does not justify describing the whole application path as post-quantum protected. Google’s frontend-only scope

Architecture and responsibilities

Treat each pilot as a test of a defined boundary. The following responsibility map is an editorial proposal based on the documented product scopes.

PilotBoundary being testedSuggested ownerEvidence to retain
Microsoft AD CSCertificate issuance and signature validationCertificate administrator and application ownerTest chain, validation results and incompatible applications
AWS KMSClient-to-KMS API connectionApplication developer and cloud administratorClient configuration and CloudTrail key-exchange record
Amazon S3Client-to-supported-S3-endpoint connectionApplication or storage teamEndpoint type and client-side negotiation evidence
AWS Transfer FamilySFTP client-to-service SSH connectionFile-transfer administrator and trading partnerClient compatibility and negotiated key exchange
Google Cloud Load BalancingClient-to-load-balancer TLS connectionPlatform engineer and application ownerSSL policy and observed client negotiation

The product boundaries and verification limits come from Microsoft AD CS, AWS KMS, Amazon S3, AWS Transfer Family and Google Cloud Load Balancing.

Ask an external IT provider to deliver these records alongside its configuration work. “PQC enabled” is too vague an acceptance statement.

Pricing and the cost of a useful pilot

The supplied evidence contains no verified GBP prices or PQC-specific surcharges. A defensible budget therefore needs current service pricing or a scoped quotation rather than an invented licence comparison.

For a UK quotation, request GBP amounts, VAT treatment, billing commitments and a defined teardown date. Separate ordinary service charges from engineering and support work.

Cost componentWhat to include in the estimate
Test environmentServer licensing, compute, storage or load-balancer resources required by the chosen design
Application changesRuntime updates, HTTP-client configuration and regression testing
Network testingOffice, remote-access and proxy paths used by staff or applications
Specialist supportCertificate expertise, troubleshooting and documented handover
ClosureConfiguration rollback, resource deletion and retained test evidence

These are budgeting categories, not published supplier charges. AWS specifically identifies larger handshake messages and potential interference from proxies or deep-packet-inspection firewalls, which makes network troubleshooting a reasonable item to scope. AWS KMS performance guidance

Editorial analysis

For an existing AWS application, our preferred first experiment is a direct KMS call because its documented logging provides a clear way to verify negotiation. For an application already behind a supported Google load balancer, test the frontend policy and client behaviour. For a Windows certificate estate, use a parallel AD CS laboratory to discover validation failures before considering operational change.

These are recommendations about testability and existing skills, not a ranking of cryptographic strength. The evidence supports different capabilities, so a single vendor score would conceal the decision.

Give the pilot a written acceptance condition before implementation. Require evidence of the algorithm used, successful representative transactions, recorded compatibility failures, performance against an agreed baseline and a tested route back to the previous configuration. Use synthetic data until those conditions are met.

Sources

Data & Insights

ML-DSA signature sizes supported by Microsoft AD CS

Signature sizes increase across the supported parameter sets; these figures are not complete certificate sizes or network benchmarks.

ML-DSA signature sizes supported by Microsoft AD CSSignature sizes increase across the supported parameter sets; these figures are not complete certificate sizes or network benchmarks.01,0002,0003,0004,0005,000ML-DSA-44ML-DSA-44ML-DSA-65ML-DSA-65ML-DSA-87ML-DSA-87ML-DSA-44, Signature size in bytes: 2,420ML-DSA-65, Signature size in bytes: 3,309ML-DSA-87, Signature size in bytes: 4,627
View the data
ML-DSA signature sizes supported by Microsoft AD CS
CategorySignature size in bytes
ML-DSA-442,420
ML-DSA-653,309
ML-DSA-874,627
Source: Microsoft Learn

Frequently Asked Questions

Does TLS 1.3 automatically mean a connection is post-quantum?

No. Google requires a client to support both TLS 1.3 and `X25519MLKEM768` for its documented hybrid negotiation. Record the key-exchange group rather than relying on the TLS version alone. Google TLS requirements

Can we convert our existing Microsoft certificate authority?

Microsoft says ML-DSA certification authorities must be newly installed and do not support in-place migration. Build a parallel hierarchy and test the applications that rely on its certificates. Microsoft migration requirements

Which AWS service makes a successful test easiest to demonstrate?

For a direct application call, AWS KMS offers documented CloudTrail evidence through `tlsDetails.keyExchange`. That makes it a useful first pilot, provided the application uses a compatible client and the relevant log field is present. KMS verification guidance

Does Google’s load-balancer setting protect the backend connection?

The cited documentation limits post-quantum key exchange to frontend connections between clients and load balancers. Test and document the load-balancer-to-backend connection separately. Google connection scope

Does post-quantum TLS change how stored data is encrypted?

The transport feature itself protects the connection. AWS KMS explicitly distinguishes hybrid TLS from encryption performed under KMS keys, so assess storage encryption and key management as separate controls. KMS encryption boundary

Can a small business run a pilot without dedicated cryptography staff?

A bounded application or connection test can be assigned to an existing developer or IT provider, with specialist help for certificate infrastructure or difficult compatibility failures. Require evidence from the actual deployment environment because AWS documents significant differences between client runtimes and operating systems. AWS SDK requirements