
Work Here?
PQShield builds cryptographic solutions to guard data against both classical and quantum attacks. It offers PQC software (PQCryptoLib SDK) and hardware IP cores under PQPlatform to accelerate post-quantum algorithms like digital signatures and key exchange. The hardware/software co-design lets integration into secure elements, IoT firmware, servers, and networking gear while hardening against side-channel attacks. Its goal is to help organizations migrate to NIST-standard PQC and future-proof digital infrastructure, serving customers across semiconductors, automotive, aerospace, finance, and government advisory roles.
Industries
Hardware
Enterprise Software
Cybersecurity
Defense
Company Size
51-200
Company Stage
Series B
Total Funding
$64.9M
Headquarters
Oxford, United Kingdom
Founded
2018
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$64.9M
Above
Industry Average
Funded Over
5 Rounds
Industry standards
Health Insurance
Paid Vacation
Paid Holidays
Gym Membership
Stock Options
Flexible Work Hours
Hybrid Work Options
Remote Work Options
Meet the team - Rob Ellison, Sales Director. Topics: Team Date: 10/09/2026 Rob Ellison joined PQShield in April 2026 as Sales Director, bringing extensive embedded business development experience across hardware, software, and semiconductor IP. Having built success as an individual contributor and team leader across startups and large public companies, Rob excels at bridging complex security technology with practical business requirements. Now based in Austin, Texas - by way of Alabama and California - Rob is a key addition to its commercial team. Outside of strengthening cyber resilience with customer stakeholders, he prioritizes health and fitness - spending quality time with his family, and staying active whenever he gets the chance.
PQShield introduces ultra-small post-quantum security tools for embedded devices. 2 mins read PQShield has introduced major upgrades to its UltraPQ Suite, unveiling what it describes as the world's first full-stack post-quantum TLS and a new generation of ultra-compact security libraries designed for memory-constrained embedded systems. The company's latest release centres on PQMicroLib-Core, a quantum-resistant cryptographic library engineered to operate within a footprint of less than 5 KB. The development targets embedded devices used in sectors such as payments, medical technology, industrial control and networking, where RAM can be limited to only a few kilobytes. With post-quantum cryptography (PQC) key sizes significantly larger than those used in traditional schemes - some requiring 30-40 KB of RAM - manufacturers of microcontroller-based products have faced a practical barrier to adopting NIST-standardised PQC algorithms. This is particularly challenging for secure boot, where memory constraints may be as tight as 8-10 KB. PQShield says its upgraded library is the first production-ready implementation capable of meeting these limits, delivering a footprint up to eight times smaller than comparable off-the-shelf or open-source solutions. Crucially, the upgrade can be deployed as a software-only update, allowing existing "brownfield" devices already in the field to adopt PQC without needing hardware redesigns or product recalls. Alongside the library upgrade, PQShield has introduced what it calls the first drop-in post-quantum TLS solution for embedded systems. While the widely used PSA cryptography API was not designed with PQC in mind, PQShield has integrated PQMicroLib-Core with the PSA Certified Crypto API, creating a pathway for manufacturers to implement quantum-secure TLS using familiar, portable interfaces. This combined approach enables embedded developers to upgrade to PQC-based TLS that: * uses standard, portable APIs, * can be added to existing hardware via software updates, * fits within strict memory budgets. The updated suite also addresses new vulnerabilities introduced by larger PQC keys. Bigger key sizes can increase exposure to physical attacks, including differential power analysis and fault injection. PQMicroLib-Core now includes software-level DPA countermeasures designed to shield both new and deployed devices without requiring additional hardware. These defences can also be integrated directly into silicon for future chip designs. The shift to post-quantum cryptography is widely viewed as one of the most significant transitions the cybersecurity sector has faced. PQShield notes that embedded devices pose a particular challenge because of the constraints built into their hardware and the long lifespans of deployed systems. The company is already partnering with major semiconductor manufacturers, including STMicroelectronics, Microchip Technologies, Lattice Semiconductor and IAR Systems, to support wider adoption of ultra-small PQC implementations. PQShield founder and CEO Dr Ali El Kaafarani said: "Post-quantum cryptography is the biggest cybersecurity transition in a generation. It needs to be thorough but also practical, and can't come at the expense of operational efficiency or good performance. We've worked hard to develop implementations for the embedded sector that give manufacturers the security they need with the convenience they want - through software upgrades rather than hardware recalls, and by developing the most lightweight post-quantum cryptography on the market." The upgrades are expected to accelerate PQC adoption in sectors with large numbers of legacy devices and strict memory, power and cost constraints. By offering a software-only migration path, PQShield's approach could help manufacturers meet emerging regulatory requirements and protect long-lived embedded systems against future quantum-enabled threats.
PQShield releases lightweight PQC library for embedded systems. Insider Brief * PQShield announced upgrades to its UltraPQ Suite at Embedded World, introducing an embedded post-quantum cryptography (PQC) library with a memory footprint of under 5KB. * The updated PQMicroLib-Core enables quantum-resistant cryptography and TLS support for memory-constrained embedded devices through software upgrades rather than hardware changes. * The upgrade also adds protections against physical attacks such as differential power analysis and fault injection, addressing new security risks introduced by larger PQC keys. PRESS RELEASE - PQShield, the market leader in post-quantum cryptography (PQC), has announced major upgrades to its UltraPQ Suite, delivering the smallest-ever PQC solution on the embedded market, the world's first full-stack post-quantum TLS, and all-new protections against physical attacks for embedded devices. Announced at Embedded World in Nuremberg, PQShield's upgraded PQMicroLib-Core brings quantum-resistant cryptography to embedded devices with a footprint of less than 5KB - the leanest professional-grade PQC solution for memory-constrained devices. Devices used in payments, medical wearables, industrial control systems and networking infrastructure are designed with extremely limited RAM. Yet new and mandatory PQC keys are heavier than existing cryptography, with some implementations requiring 30-40KB of RAM. That may be manageable in servers and laptops, but for microcontroller-based embedded systems with memory budgets measured in tens of kilobytes, they simply do not fit, or necessitate costly hardware upgrades or performance sacrifices. This challenge is especially acute for secure boot, which runs at the earliest stage of device startup with RAM constraints as severe as 8-10KB for the smallest units. Until now, there has been no practical way to implement NIST-standardized PQC within those limits, especially for the 20 billion "brownfield" devices in the field - already-deployed products that can only be upgraded with software. PQShield's upgraded PQMicroLib-Core is the first practical, production-ready solution that meets those constraints. Its ultra-small 5KB memory footprint - the leanest configuration yet for embedded devices - allows manufacturers to deploy NIST-standardized PQC within their tight RAM budgets without sacrificing performance. It is as much as eight times smaller than other off-the-shelf and open source alternatives. Crucially, it can be integrated into brownfield products as a software-only upgrade. For industrial manufacturers operating at scale, the need to recall or redesign hardware across global device fleets would make the PQC transition commercially unviable. A lightweight, software-based upgrade path preserves product lifecycles and safeguards long-term compliance for long shelf-life products. World-first software stack for TLS and physical attacks. This upgrade improves security for TLS - the protocol that protects communication between devices and the cloud. For the manufacturers of connected embedded devices like payment terminals and wearable medical tech, there hasn't been a clear way to make TLS quantum-secure. The standard cryptography TLS API used for embedded systems, called PSA, wasn't designed to support PQC - but PSA is vital for ease-of-use and universal portability. PQShield has solved this by creating the first full-stack, drop-in PQC solution for embedded TLS. PQMicroLib-Core has also been integrated with the PSA Certified Crypto API, reinforcing its compatibility with industry-standard embedded security frameworks and simplifying adoption for manufacturers building on PSA-based platforms. By combining PQMicroLib-Core with PSA, for the first time manufacturers can now upgrade to quantum-secure TLS that: * Uses standard, portable APIs * Can be added to existing hardware through a software update * Works within the tight memory limits of embedded devices The upgrade also tackles new risks introduced by post-quantum cryptography. Larger PQC keys can make devices more vulnerable to physical attacks such as differential power analysis (DPA) and fault injection. The risk is higher for high-value devices that are physically accessible, such as telecoms and payments infrastructure. Not all products can afford hardware-based protections, and many brownfield devices still need software upgrades to fix this. The upgraded PQMicroLib-Core product protects embedded devices against these physical attacks, with DPA countermeasures integrated at the software level to eliminate the potential of side-channel attacks. This allows already-deployed devices to attain a high level of defence against physical attacks through software alone, and can also be hard-wired into the silicon of chips in production now. PQShield is already working with major chipmakers and embedded systems manufacturers to support the global adoption of ultra-small PQC, including a new collaboration with STMicroelectronics alongside existing collaborations and projects with Microchip Technologies, Lattice Semiconductor, IAR Systems and many others. PQShield CEO and founder Dr Ali El Kaafarani said: "Post-quantum cryptography is the biggest cybersecurity transition in a generation. It needs to be thorough but also practical, and can't come at the expense of operational efficiency or good performance. We've worked hard to develop implementations for the embedded sector that give manufacturers the security they need with the convenience they want - through software upgrades rather than hardware recalls, and by developing the most lightweight post-quantum cryptography on the market." Mohib ur rehman. Mohib has been tech-savvy since his teens, always tearing things apart to see how they worked. His curiosity for cybersecurity and privacy evolved from tinkering with code and hardware to writing about the hidden layers of digital life. Now, he brings that same analytical curiosity to quantum technologies, exploring how they will shape the next frontier of computing. Matt Swayne December 26, 2019 Matt Swayne December 14, 2024 Cierra Choucair November 1, 2024 Kenna Hughes-Castleberry March 24, 2022 James Dargan April 14, 2022 May 28, 2020 April 18, 2022 May 24, 2021 Keep track of everything going on in the Quantum Technology Market. In one place.
PQShield releases 5KB RAM post-quantum cryptography implementation. PQShield released a technical update to its PQMicroLib-Core library, achieving a memory footprint of less than 5KB of RAM. Unveiled at Embedded World 2026 in Nuremberg, this implementation targets memory-constrained embedded devices such as medical wearables, payment terminals, and industrial control systems. The library provides production-ready support for NIST-standardized algorithms, including ML-KEM (FIPS 203) and ML-DSA (FIPS 204), allowing post-quantum cryptography (PQC) to operate within the 8-10KB RAM budgets typical of secure boot processes. The update includes a full-stack, drop-in PQC solution for Transport Layer Security (TLS) compatible with the PSA Certified Crypto API. This integration facilitates quantum-secure communication between connected devices and cloud infrastructure using standardized, portable APIs. To address the physical vulnerabilities introduced by larger PQC keys, the software includes integrated countermeasures against Differential Power Analysis (DPA) and fault injection, enabling side-channel resistance on devices lacking hardware-based cryptographic accelerators. This software-based approach enables the migration of approximately 20 billion "brownfield" devices currently in the field to quantum-resistant standards without requiring hardware replacements. PQShield is collaborating with semiconductor manufacturers including STMicroelectronics, Microchip Technologies, and Lattice Semiconductor to integrate these implementations into existing and future silicon designs. The release follows the initial introduction of the company's UltraPQ Suite, which established the framework for specialized cryptographic tools in resource-limited environments. For technical specifications and evaluation details, consult the official PQShield product page here, and see our previous coverage on the launch of the UltraPQ Suite here. March 9, 2026
Hedged dilithium dis-faulting | eshard Expert Review #6. Welcome back to the Expert Review series, where, together with eShard, Pqshield delve into the dynamic world of cybersecurity to provide unbiased and detailed analyses from seasoned professionals. If you missed its previous edition, check it out here. In this review, Pqshield take a look at a key contribution to CHES 2024 (the 26th edition), entitled Correction Fault Attacks on Randomized CRYSTALS-Dilithium from E. Krahmer, P. Pessl, G. Land and T. Güneysu. This paper addresses fault attacks on the randomized/hedge ML-DSA (CRYSTALS-Dilithium) signature scheme. The work makes a significant contribution by presenting novel fault attacks that threaten the security of ML-DSA, which is of course, the primary algorithm selected by NIST as its post-quantum cryptography standard for digital signatures FIPS-204.(CRYSTALS-Dilithium). ML-DSA offers two signing modes: a deterministic variant and a "hedged" variant that introduces fresh randomness in each signature generation. The hedged mode was made the default in order to increase robustness against physical attacks, such as differential fault attacks, which proved devastating for the deterministic mode. This paper challenges the perceived security of the hedged mode by introducing a powerful attack strategy that the authors summarize as "fault, then correct". Let's dive in... Its Expert Review The paper's core methodology involves the idea of an adversary first injecting a single, targeted fault during the signing process, to obtain a faulty and thus invalid signature. The attacker then leverages the public verification algorithm to computationally correct the faulty signature until it is accepted as valid. A successful correction reveals information about a secret intermediate value used during the signing process. By repeating this process, an attacker can collect enough information to solve for a portion of the secret key that is sufficient to forge legitimate signatures for any message. The authors present two distinct attacks based on this principle. The first, the Skipping Fault Correction Attack, is a generalization of a previously known instruction-skipping fault attack. The authors adapt it to defeat the randomized signing mode by faulting a key addition that combines a secret component with a random one, and then using the correction method to find the missing secret value in order to recover the key. The second attack targets a computation involving only public data; the generation of a large public parameter from its small public seed. The attack injects a fault into this public parameter and uses the correction strategy to recover a secret random value that was used during that specific signing session, ultimately revealing the signer's secret key. This paper is significant because it demonstrates that the fault attack surface of ML-DSA is broader than previously understood, extending far beyond operations on secret, side-channel sensitive data. The attack on the public parameter is particularly dangerous. While fault attacks on public parameters are known for older cryptosystems, this is a novel vector for modern lattice-based signatures and challenges common assumptions about implementation security. Furthermore, the research shows that the attacks can be modified to circumvent popular countermeasures like shuffling, albeit with a moderate increase in the number of required signatures. This forces a re-evaluation of protection strategies, as developers can no longer assume that using the randomized mode and applying standard countermeasures provides a sufficient level of fault robustness. Which new insights have been contributed, and how significant are they? The main insight is that the correction fault attack method is a versatile and powerful technique for exploiting faults in both the deterministic and hedged versions of ML-DSA. The work provides a significant new perspective by demonstrating that the fault attack surface extends to operations, such as public parameter generation, that are not sensitive to side-channel attacks and therefore might be left unprotected. It also shows that simply switching to the randomized signing mode does not provide sufficient fault robustness. The authors' analysis of how these attacks can bypass countermeasures, such as shuffling, highlights the need for a more careful and holistic approach to designing hardened implementations. The attacks are demonstrated to be highly practical. The authors verified their findings using both simulated faults and real-world experiments, successfully inducing faults with clock glitches on an ARM-based microcontroller. The required number of faulty signatures is strikingly low. For the ML-DSA-44 parameter set (Dilithium2), the authors show the skipping fault attack can recover the key with 1024 faulty signatures, while the attack on the public parameter, when combined with lattice-reduction techniques, requires only 512 faulty signatures. The fault models are realistic. The first attack requires an instruction skip, a well-established technique. The second requires inducing a known perturbation at a specific location in the public parameter, which, while requiring more precision, was successfully achieved in their practical experiments. The paper reveals that implementations of ML-DSA that are susceptible to fault injection may already be vulnerable, even if they correctly implement the NIST-recommended randomized mode. Since the protection of public data generation has not been a primary focus, this work introduces a new and urgent consideration for any security evaluation of a device implementing ML-DSA. This research will undoubtedly drive new efforts to design more comprehensive and efficient fault countermeasures for lattice-based cryptography. The impact will certainly be felt in the immediate future! Stay tuned for more reviews of other groundbreaking articles as Pqshield delve deeper into the advancements and challenges in the field of cryptography. The journey towards securing its digital infrastructure is ongoing, and Pqshield is committed to bringing you the latest insights and analyses from the forefront of cryptographic research.
Find jobs on Simplify and start your career today
Industries
Hardware
Enterprise Software
Cybersecurity
Defense
Company Size
51-200
Company Stage
Series B
Total Funding
$64.9M
Headquarters
Oxford, United Kingdom
Founded
2018
Find jobs on Simplify and start your career today