AI & Security Β· Post-Quantum Security
Protect data in transit today with NetScaler hybrid post-quantum encryption, and get a clear quantum-readiness plan for your Citrix environment.
Post-quantum cryptography (PQC) uses algorithms designed to resist attacks from future quantum computers. It matters now because attackers can record encrypted traffic today and decrypt it later, once quantum computers mature. NIST standardized ML-KEM in FIPS 203 in 2024, and its migration timeline targets 2030 and 2035 for moving off today's public-key algorithms.
NetScaler 14.1 supports hybrid post-quantum key exchange, combining X25519 with ML-KEM-768 on TLS 1.3. Altanora assesses your NetScaler estate, upgrades it and enables PQC safely.
Sources: Citrix and NetScaler announcements, July 2025; NIST.
From inventory to protected traffic.
Inventory NetScaler builds, certificates, ciphers and TLS versions across your estate.
Move to a supported NetScaler 14.1 build, with Citrix Aidrien helping map builds to known CVEs.
Turn on X25519 + ML-KEM-768 on TLS 1.3 front ends, and test clients before rollout.
Measure the impact of new key exchange on appliance capacity before enabling it at scale.
A quantum-readiness roadmap your auditors and leadership can follow.
Patching, certificate management and 24/7 monitoring with Managed NetScaler.
Classic TLS vs NetScaler hybrid post-quantum key exchange.
| Classic TLS key exchange | NetScaler hybrid PQC | |
|---|---|---|
| Algorithm | Elliptic curve (for example, X25519) | X25519 combined with ML-KEM-768 |
| Harvest-now, decrypt-later risk | Exposed to future quantum attacks | Protected by a post-quantum algorithm |
| Protocol | TLS 1.2 or 1.3 | TLS 1.3 |
| Compatibility | Universal | Falls back to classic key exchange for older clients |
Hybrid PQC applies to the NetScaler TLS front end. We confirm client support in testing.
Citrix-funded security work delivered by Altanora.
Canadian manufacturer
deviceTRUST
pilot and Zero Trust roadmap delivered as part of a Citrix-funded security health check.
Altanora client engagement
Seagate
100%
secure access coverage after replacing VPN with Citrix Zero Trust access.
Canadian public sector
Protected B
Citrix delivered on sovereign Canadian infrastructure, only through Altanora.
Altanora
From Our Clients
βEvery interaction with Altanora has consistently exceeded my expectations. Their deep technical expertise, combined with a comprehensive understanding of our business challenges, allows them to deliver practical solutions and reliably meet their commitments.βFrederic St-Jean, Director of Information Technology
2026 Citrix Evangelist Partner of the Year and a Citrix Platinum Partner since 2006, with 70+ certified engineers across North America.
We design, upgrade and run NetScaler for enterprises across North America.
PQC readiness can be included in a Citrix-funded security health check through Citrix Funded Pro Services.
We tell you what's protected today and what's still on Citrix's roadmap.
Attackers capture encrypted traffic today and store it, expecting to decrypt it later with a quantum computer. Data that must stay confidential for years is most at risk.
Yes. NetScaler 14.1 supports hybrid post-quantum key exchange, combining X25519 with ML-KEM-768, on TLS 1.3 front-end connections. It became generally available in August 2025.
ML-KEM is the module-lattice key encapsulation mechanism standardized by NIST in FIPS 203. NetScaler pairs it with X25519 so connections stay secure even if one algorithm is broken.
Post-quantum key exchange adds processing work, so we test capacity on your appliances before enabling it broadly.
Today, PQC in the Citrix stack is on the NetScaler TLS front end. Secure HDX uses AES-256-GCM encryption. We track Citrix's roadmap and will tell you when more components add PQC.
Eligible customers can include a PQC readiness assessment in a Citrix-funded security health check. We confirm eligibility with Citrix first.
Talk to us about a NetScaler PQC readiness check.
Book a PQC Readiness Check