Architecture playbook: crypto-agility for the post-quantum era. Learn more
The MyPQC platform

One platform for the
post-quantum era.

MyPQC is one layered stack. A Crypto Agility Core Engine sits at the foundation. On top of it run four quantum-safe apps and managed PKI and monitoring services. A single API layer opens the whole platform to the enterprise software providers and Tier-1 integrators who build on it. Post-quantum by default, sovereign by design, and agile enough to swap algorithms by policy.

Aligned with NIST FIPS 203 / 204 / 205 · sovereign KAZ options alongside · W3C DID data model (v1.1) · Digital Signature Act 1997

The platform at a glance

Four layers, one sovereign foundation

An API layer for builders, four turnkey quantum-safe apps for users, and managed services for operators. All of it rests on the Crypto Agility Core Engine, which governs which algorithm runs.

MyPQC platform architecture: API layer, ready-to-use PQC apps, managed services, and the Crypto Agility Core Engine

The MyPQC stack. The API layer surfaces the platform to integrators. The ready-to-use apps and managed services sit in the middle. The Crypto Agility Core Engine (risk, agility middleware, PQC orchestration, and policy enforcement) is the foundation everything else builds on.

How the platform is layered

Every layer does one job, cleanly

The crypto-governance foundation stays separate from the apps that use it and the API that exposes it. Each layer can change without breaking the others.

Crypto Agility Core Engine: the foundation

The policy-driven layer beneath everything: crypto-risk assessment, agility middleware, PQC orchestration, and enterprise-wide policy enforcement. A CISO changes the algorithm for a cryptographic purpose from one portal, and every connected system applies it. No application code changes, no redeployment.

Ready-to-use apps

Quantum-safe applications built directly on the core engine: Sovereign PQC Digital ID, Document Signing, and Secure File Sharing & Storage. Quantum-safe Messaging & Video is on the roadmap. Deploy the app suite instead of assembling crypto yourself.

Managed services

Operated capabilities that keep the estate healthy: PQC certificate issuance and management, digital-ID management, and continuous cryptography inventory and monitoring. This is the observability and PKI plane that feeds the core engine what it needs to govern.

API layer

One versioned integration surface for third-party enterprise software providers and Tier-1 system integrators. Partners embed quantum-safe identity, signing, sharing, and crypto-agility into their own products without building cryptography from scratch.

How migration works

Discover → Govern → Prove

MyPQC turns post-quantum migration from a one-off project into a repeatable, auditable program. Visibility first, policy-driven control next, verifiable evidence last.

01

Discover

MCert's containerized, ephemeral scanners find every algorithm, certificate, key, protocol, and crypto library across servers, apps, network devices, containers, and code. Everything is normalized to CycloneDX CBOM/SBOM and scored for quantum risk. You can't migrate what you can't see.

02

Govern

The Crypto Agility Core Engine turns those findings into policy. Bind a cryptographic purpose to an algorithm, schedule a transition with an effective date, and every connected system switches automatically, with no redeploy. The self-describing envelope keeps everything already encrypted or signed verifiable.

03

Prove

Signed, optionally encrypted CBOM and risk reports, plus a tamper-evident audit trail, show exactly which algorithms are in use and how far migration has progressed. The next scan auto-verifies remediation against the live environment.

Why sovereign & standards-based

Aligned with the NIST standards. Sovereign by choice.

MyPQC implements the finalized NIST post-quantum algorithms and offers Malaysian sovereign options alongside them. Crypto-agility means the choice is never locked in. You standardize on open standards and keep the freedom to swap algorithms by policy as guidance evolves.

Aligned with NIST FIPS 203 / 204 / 205. MyPQC implements ML-KEM, ML-DSA, and SLH-DSA, the finalized NIST PQC standards. (Standards alignment, not a FIPS-140 validation claim.)

Sovereign KAZ options alongside. KAZ-SIGN and KAZ-KEM are optional, policy-selectable Malaysian sovereign algorithms offered alongside the NIST standards. They never replace them, and they stay swappable at any time.

Digital Signature Act 1997 alignment. Identity and signing link to an X.509 certificate from an MCMC-licensed CA for legal recognition. This is a deployment capability, not an automatic guarantee.

On a credible timeline. NIST's proposed roadmap (draft IR 8547) would deprecate RSA/ECC around 2030 and disallow them around 2035. "Harvest now, decrypt later" already puts today's encrypted data at risk.

Standards & algorithms

Sovereign KAZ algorithms are optional, policy-selectable, and offered alongside the NIST standards, not instead of them.
PurposeNIST standardSovereign option
Key encapsulationML-KEM · FIPS 203KAZ-KEM (optional)
Digital signaturesML-DSA · FIPS 204KAZ-SIGN (optional)
Hash-based signaturesSLH-DSA · FIPS 205None
Symmetric encryptionAES-256-GCMNone
Crypto inventoryCycloneDX CBOM / SBOMMySEAL / NACSA mapping

Reporting maps to NIST SP 800-131A, MySEAL, NACSA and BNM RMiT, with secure regulator transfer to NACSA and Bank Negara Malaysia. Identity is adapted from the W3C DID data model (v1.1, a Candidate Recommendation).

See the whole platform in action

Get a walkthrough of the layered stack and a quantum-readiness assessment for your organization.