Standards reference
What the standards actually say
Every technical claim on this site traces back to a published standard or to vendor documentation. These pages summarise the standards that matter for VPN migration, quote them where quoting is clearer than paraphrasing, and link directly to the source.
All standards pages
- FIPS 203final
ML-KEM and FIPS 203: what a VPN team actually needs to know
What ML-KEM standardises, which parameter sets exist, and what its arrival does and does not change for an enterprise VPN estate.
National Institute of Standards and Technology · last reviewed
- RFC 7296, RFC 8784, RFC 9242, RFC 9370final
IKEv2 post-quantum migration: which mechanism applies to which tunnel
The three IKEv2 mechanisms relevant to post-quantum migration, how they differ, and how to decide which one applies to a given tunnel.
Internet Engineering Task Force · last reviewed
- RFC 9370final
Hybrid key establishment and why it is the default migration target
Why enterprise VPN migrations combine a classical and a post-quantum key exchange rather than replacing one with the other, and what that costs operationally.
Internet Engineering Task Force · last reviewed
Standards say what is possible. An assessment says what is possible here.
The gap between a published standard and a specific gateway on a specific release is where migration programmes actually live.