Navigation

Get in touch
Logo
News

PQC testing

PQC ready? Test first. Trust second.

Whether new cryptography works in your environment cannot be judged by the algorithm’s name. We build a clearly scoped test path and check clients, gateways, applications and HSMs together. You receive measurements and a well-founded recommendation for the next step.

woman in white long sleeve shirt using black laptop computer — illustrative image
Reproducible test environment · Planning and implementation by OTOKO®

Your brief for OTOKO®

What we take care of for you.

Several TLS endpoints, proxies and security devices can sit between the client and the application. We record where cryptography ends and begins again. A successful test between just two libraries says little about this overall path. The environment therefore reflects the decisive components and configurations. Tests with simulators are reported separately from tests on the intended hardware; the two answer different questions.

The possible scope of services

  • Select representative systems and connection paths
  • Build a test environment with documented component versions
  • Measure compatibility, error behavior and performance
  • Examine packet, storage and format limits
  • Document the approval recommendation and follow-up work

We define the specific scope, your involvement and the acceptance criteria before the start.

Technology explained clearly

How we carry out the task.

01

Examine larger artifacts in practice

New algorithms can bring different key, signature and message lengths. We measure connection setup, memory requirements and processing in the specific profile. Fragmentation, parser limits and timeouts can cause problems along the way. Alongside normal operation, we look at load peaks, dropped connections and incompatible counterparts. Measurement results are compared with the previous algorithm, including measurement conditions and variance. A single successful handshake is not proof of performance.

02

A test report must enable a decision

The report names working combinations, observed errors and the limits of its findings. This results in follow-up work, required updates and conditions for pilot operation. Acceptance requires reproducible tests and documented configurations. To get started, a network and system sketch, device versions and a realistic transaction profile are helpful.

Meeting room at the OTOKO® Cologne office

A verifiable result

What you keep working with.

  1. Reproducible test environment
  2. Compatibility and performance report
  3. Approval criteria with open action items

The handover brings together implementation and documentation. Together, we review the agreed cases and record any remaining tasks.

Your project in detail

Prove PQC capability in your environment.

We build tests for specific combinations of products, libraries and protocols. The goal is a reliable assessment of what works, what limits exist and what needs to be adjusted before a production rollout.

Distinguish functional testing from interoperability

A local test can confirm that a library performs an operation. Interoperability additionally requires that another involved component processes the result correctly. We therefore document both sides, versions, parameters and the formats used.

Test cases cover successful operations and expected rejections. Unsupported algorithms, corrupted objects and conflicting configurations should result in understandable errors. This prevents a demonstration with an ideal configuration from being interpreted as general readiness for deployment.

Measure the impact on runtime and infrastructure

Changed key, signature or message formats can affect storage, transmission and processing. We measure using your representative workload rather than just comparing isolated individual calls. Proxies, gateways and resource-constrained devices are also part of the chain under consideration.

Results are handed over with a reproducible configuration and known limits. This leads to concrete measures: updating a library, adapting the data format, checking capacity or postponing a deployment for now. The recommendation distinguishes technical feasibility, operational suitability and approvals that are still outstanding.

Illustrative project scenario

How the service helps in everyday use.

Example: A client communicates with a service through a gateway. In the lab, the new combination works directly, but not through the gateway. We isolate the cause, document the affected version and test an adjusted configuration before recommending the solution for other systems.

This example explains a possible process and is not a customer reference.

Before the first step

Your questions about PQC testing.

Can the test safely be carried out directly in production?

Not as a general rule. We start with a suitable test environment and agree on later production pilots, including monitoring and a fallback path.

Does a passed lab test prove readiness for production?

It provides evidence for the scope that was tested. Production load, operating procedures and differing counterparts must also be taken into account.

Your project

Which task would you like to solve?

Describe your situation and the desired result. The selected service will be included in the contact request.

Request this service

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.