AWS
AWS services have distinct TLS endpoints and security-policy menus. CloudFront viewer connections, load balancer listeners, and origin connections must be assessed separately.
Evidence to collect
- Record the service, region, listener, hostname, and applied security policy.
- Compare the selected policy with that service’s documented supported key-exchange groups; TLS 1.3 alone is not a PQC claim.
- Check each customer-facing hostname and relevant backend path. Results from one edge location are a point-in-time observation.
- Inventory certificate signatures separately from key exchange. ACM certificate selection is not evidence of an ML-KEM handshake.
Record the scope and result
Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.
Official references
Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.