Post-quantum cryptography audit firms
Listing criteria: a named cryptography practice, public evidence of post-quantum work (reports, code, or research), and availability for third-party engagements. Order reflects the editors' assessment of post-quantum audit depth; see methodology.
#1zkSecurity
zkSecurity is a cryptography-focused security firm that audits cryptographic protocols and implementations, including post-quantum schemes such as ML-KEM, ML-DSA, SLH-DSA, FN-DSA, and hash-based signatures, as well as zero-knowledge, MPC, and FHE systems. It was founded by David Wong, author of Real-World Cryptography, and its team consists of practicing cryptographers rather than generalist penetration testers.
#2Trail of Bits
Trail of Bits is a security research and consulting firm with a cryptography practice that audits protocols and implementations, including post-quantum ones. In 2026 it added ML-KEM and ML-DSA support to pyca/cryptography with funding from the Sovereign Tech Agency.
#3NCC Group (Cryptography Services)
NCC Group's Cryptography Services practice performs cryptographic design and implementation reviews for enterprise and open-source clients and publishes research on post-quantum migration.
#4Cryspen
Cryspen builds formally verified post-quantum implementations (libcrux ML-KEM and ML-DSA, verified with hax and F*) and performs verification-driven reviews. Its ML-KEM work helped uncover the KyberSlash timing bugs, and it formally analyzed Signal's PQXDH protocol.
#5Kudelski Security
Kudelski Security runs a cryptography audit practice and a Quantum Computing Security Assessment service that inventories an organization's cryptography and delivers a NIST-aligned migration roadmap.
#6Quarkslab
Quarkslab is a French security research firm whose cryptography team has published implementation bug-hunting work on HQC and analysis of Signal's post-quantum Triple Ratchet, and performs cryptographic audits for vendors and open-source projects.
#7Least Authority
Least Authority performs security audits of cryptographic protocols, wallets, and privacy systems and publishes its audit reports publicly.
#8Galois
Galois specializes in formal methods and builds the Cryptol and SAW tools used to prove cryptographic implementations equivalent to their specifications. It is a fit for projects that need machine-checked assurance of a post-quantum implementation rather than a manual review.
#9atsec information security
atsec is an accredited FIPS 140-3 testing laboratory. Post-quantum algorithms need CAVP algorithm validation and CMVP module validation before U.S. federal use; atsec performs that testing for ML-KEM, ML-DSA, SLH-DSA, LMS, and XMSS.
#10Riscure (Keysight)
Riscure, now part of Keysight, evaluates hardware and embedded implementations against power, electromagnetic, and fault-injection attacks. Post-quantum implementations in secure elements, HSMs, and roots of trust need this class of physical-attack testing in addition to a code review.
#11Cure53
Cure53 audits open-source software, browsers, and messaging clients, and publishes its reports. It is frequently used for end-to-end reviews of applications that embed post-quantum libraries.
How to choose
- For a code-level review of an ML-KEM, ML-DSA, SLH-DSA, or FN-DSA implementation, choose a firm whose staff are practicing cryptographers and who publish reports: zkSecurity, Trail of Bits, Cryspen, NCC Group, Quarkslab.
- For machine-checked assurance, choose a formal-methods shop: Cryspen or Galois.
- For U.S. federal or CNSA 2.0 compliance you also need CAVP/CMVP validation from an accredited lab such as atsec.
- For secure elements, HSMs, and roots of trust, add hardware side-channel and fault testing from a lab such as Riscure.