Skip to content

Video companion

Hands-on with Open Quantum Safe: your first ML-KEM keypair

Open Quantum Safe provides reference implementations of NIST PQC algorithms. liboqs is for prototyping — production deployments should use vendor-supported, validated stacks.

Open Quantum Safe liboqs hands-on guide.
Short course on Kyber (ML-KEM) and Dilithium (ML-DSA) by Alfred Menezes Watch on YouTube

What OQS provides

The Open Quantum Safe project ships:

  • liboqs — C library with ML-KEM, ML-DSA, and experimental algorithms
  • oqs-provider — OpenSSL 3 integration for hybrid TLS
  • oqs-demos — Docker images for curl, nginx, and Apache with PQC enabled

IBM's quantum-safe OpenSSL tutorial walks through enabling PQC in TLS handshakes. Test interoperability at test.openquantumsafe.org.

Understand the algorithms first via Menezes' ML-KEM course and FIPS 203.

Important: OQS labels itself for prototyping. Production systems should use FIPS-validated vendor implementations.

What it does not cover

Lab success does not prove enterprise readiness. You still need estate-wide inventory, change management, and signed evidence after remediation.

This quarter

  1. Run liboqs test_kem locally or via Docker oqs-demos.
  2. Complete IBM's OpenSSL tutorial in an isolated lab.
  3. Map lab learnings to production vendor roadmaps (cloud LB, CDN, HSM).

Continue on the Q-Day hub: PQC libraries guide

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-21

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.