← Knowledge base

AWS

AWS services have distinct TLS endpoints and security-policy menus. CloudFront viewer connections, load balancer listeners, and origin connections must be assessed separately.

Evidence to collect

  1. Record the service, region, listener, hostname, and applied security policy.
  2. Compare the selected policy with that service’s documented supported key-exchange groups; TLS 1.3 alone is not a PQC claim.
  3. Check each customer-facing hostname and relevant backend path. Results from one edge location are a point-in-time observation.
  4. Inventory certificate signatures separately from key exchange. ACM certificate selection is not evidence of an ML-KEM handshake.

Record the scope and result

Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.

Official references

Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.