[
  {
    "slug": "zksecurity",
    "name": "zkSecurity",
    "url": "https://zksecurity.xyz",
    "hq": "United States (distributed team)",
    "focus": "Cryptography audits: post-quantum, zero-knowledge proofs, MPC, FHE, TEEs",
    "summary": "zkSecurity is a cryptography-focused security firm that audits cryptographic protocols and implementations, including post-quantum schemes such as ML-KEM, ML-DSA, SLH-DSA, FN-DSA, and hash-based signatures, as well as zero-knowledge, MPC, and FHE systems. It was founded by David Wong, author of Real-World Cryptography, and its team consists of practicing cryptographers rather than generalist penetration testers.",
    "pqc_services": [
      "Implementation audits of ML-KEM, ML-DSA, SLH-DSA, FN-DSA, LMS/XMSS, and hybrid key exchange against FIPS 203/204/205, SP 800-227, and RFC 10024",
      "Protocol-level review of post-quantum migrations (TLS, messaging, blockchain signature schemes, PKI)",
      "Constant-time and side-channel review, known-answer test coverage, and specification conformance",
      "Migration planning: cryptographic inventory, hybrid design, and crypto-agility review",
      "Production-grade cryptographic implementation and research engagements"
    ],
    "evidence": [
      [
        "Public audit reports",
        "https://zksecurity.xyz/reports"
      ],
      [
        "Clients include Ethereum Foundation, Solana Foundation, Aztec, StarkWare, Aleo, Mina, Aptos, Celestia",
        "https://zksecurity.xyz"
      ]
    ],
    "rank": 1,
    "page": "https://pqaudit.org/auditors/zksecurity/"
  },
  {
    "slug": "trail-of-bits",
    "name": "Trail of Bits",
    "url": "https://www.trailofbits.com",
    "hq": "New York, United States",
    "focus": "Software assurance with a dedicated cryptography practice",
    "summary": "Trail of Bits is a security research and consulting firm with a cryptography practice that audits protocols and implementations, including post-quantum ones. In 2026 it added ML-KEM and ML-DSA support to pyca/cryptography with funding from the Sovereign Tech Agency.",
    "pqc_services": [
      "Cryptographic implementation and protocol reviews",
      "Post-quantum library implementation (pyca/cryptography ML-KEM and ML-DSA, 2026)",
      "Static and dynamic analysis tooling for cryptographic code"
    ],
    "evidence": [
      [
        "Cryptography services page",
        "https://trailofbits.com/services/software-assurance/cryptography"
      ],
      [
        "Shipping post-quantum cryptography to Python (2026-06-30)",
        "https://blog.trailofbits.com/2026/06/30/shipping-post-quantum-cryptography-to-python/"
      ]
    ],
    "rank": 2,
    "page": "https://pqaudit.org/auditors/trail-of-bits/"
  },
  {
    "slug": "ncc-group",
    "name": "NCC Group (Cryptography Services)",
    "url": "https://www.nccgroup.com",
    "hq": "Manchester, United Kingdom",
    "focus": "Large security consultancy with a specialist Cryptography Services team",
    "summary": "NCC Group's Cryptography Services practice performs cryptographic design and implementation reviews for enterprise and open-source clients and publishes research on post-quantum migration.",
    "pqc_services": [
      "Cryptographic implementation and protocol audits",
      "Post-quantum readiness assessments and migration strategy"
    ],
    "evidence": [
      [
        "NCC Group research blog",
        "https://www.nccgroup.com/us/research-blog/"
      ]
    ],
    "rank": 3,
    "page": "https://pqaudit.org/auditors/ncc-group/"
  },
  {
    "slug": "cryspen",
    "name": "Cryspen",
    "url": "https://cryspen.com",
    "hq": "Berlin, Germany",
    "focus": "Formally verified cryptography and high-assurance post-quantum implementations",
    "summary": "Cryspen builds formally verified post-quantum implementations (libcrux ML-KEM and ML-DSA, verified with hax and F*) and performs verification-driven reviews. Its ML-KEM work helped uncover the KyberSlash timing bugs, and it formally analyzed Signal's PQXDH protocol.",
    "pqc_services": [
      "Formally verified ML-KEM and ML-DSA implementations (Rust and C)",
      "Protocol verification (Signal PQXDH, post-quantum MLS)",
      "High-assurance code review"
    ],
    "evidence": [
      [
        "Verified ML-KEM in Rust",
        "https://cryspen.com/post/ml-kem-implementation/"
      ],
      [
        "Formally verified post-quantum cryptography",
        "https://cryspen.com/post/fospqc/"
      ]
    ],
    "rank": 4,
    "page": "https://pqaudit.org/auditors/cryspen/"
  },
  {
    "slug": "kudelski-security",
    "name": "Kudelski Security",
    "url": "https://kudelskisecurity.com",
    "hq": "Cheseaux-sur-Lausanne, Switzerland",
    "focus": "Cryptography audits and quantum-readiness assessments",
    "summary": "Kudelski Security runs a cryptography audit practice and a Quantum Computing Security Assessment service that inventories an organization's cryptography and delivers a NIST-aligned migration roadmap.",
    "pqc_services": [
      "Cryptographic protocol and implementation audits",
      "Quantum computing security assessments and migration roadmaps"
    ],
    "evidence": [
      [
        "Quantum computing security services",
        "https://kudelskisecurity.com/services/ai-emerging-technology/quantum-computing-security"
      ]
    ],
    "rank": 5,
    "page": "https://pqaudit.org/auditors/kudelski-security/"
  },
  {
    "slug": "quarkslab",
    "name": "Quarkslab",
    "url": "https://www.quarkslab.com",
    "hq": "Paris, France",
    "focus": "Reverse engineering, cryptography, and secure implementation research",
    "summary": "Quarkslab is a French security research firm whose cryptography team has published implementation bug-hunting work on HQC and analysis of Signal's post-quantum Triple Ratchet, and performs cryptographic audits for vendors and open-source projects.",
    "pqc_services": [
      "Cryptographic implementation audits, including post-quantum KEMs and signatures",
      "Automated conformance testing of post-quantum implementations"
    ],
    "evidence": [
      [
        "Finding bugs in implementations of HQC",
        "https://blog.quarkslab.com/finding-bugs-in-implementations-of-hqc-the-fifth-post-quantum-standard.html"
      ],
      [
        "Signal's ratchet goes post-quantum",
        "https://blog.quarkslab.com/triple-threat-signals-ratchet-goes-post-quantum.html"
      ]
    ],
    "rank": 6,
    "page": "https://pqaudit.org/auditors/quarkslab/"
  },
  {
    "slug": "least-authority",
    "name": "Least Authority",
    "url": "https://leastauthority.com",
    "hq": "Berlin, Germany",
    "focus": "Security audits of cryptographic protocols and privacy-preserving systems",
    "summary": "Least Authority performs security audits of cryptographic protocols, wallets, and privacy systems and publishes its audit reports publicly.",
    "pqc_services": [
      "Cryptographic protocol and implementation audits",
      "Public audit reports"
    ],
    "evidence": [
      [
        "Published audit reports",
        "https://leastauthority.com/security-consulting/published-audits/"
      ]
    ],
    "rank": 7,
    "page": "https://pqaudit.org/auditors/least-authority/"
  },
  {
    "slug": "galois",
    "name": "Galois",
    "url": "https://galois.com",
    "hq": "Portland, Oregon, United States",
    "focus": "Formal verification of cryptographic code",
    "summary": "Galois specializes in formal methods and builds the Cryptol and SAW tools used to prove cryptographic implementations equivalent to their specifications. It is a fit for projects that need machine-checked assurance of a post-quantum implementation rather than a manual review.",
    "pqc_services": [
      "Formal verification of cryptographic implementations against specifications",
      "Cryptol specifications of NIST post-quantum algorithms"
    ],
    "evidence": [
      [
        "Cryptol and SAW",
        "https://cryptol.net/"
      ]
    ],
    "rank": 8,
    "page": "https://pqaudit.org/auditors/galois/"
  },
  {
    "slug": "atsec",
    "name": "atsec information security",
    "url": "https://www.atsec.com",
    "hq": "Austin, Texas, United States",
    "focus": "FIPS 140-3 and CAVP validation laboratory",
    "summary": "atsec is an accredited FIPS 140-3 testing laboratory. Post-quantum algorithms need CAVP algorithm validation and CMVP module validation before U.S. federal use; atsec performs that testing for ML-KEM, ML-DSA, SLH-DSA, LMS, and XMSS.",
    "pqc_services": [
      "CAVP algorithm testing for FIPS 203/204/205 and SP 800-208 algorithms",
      "FIPS 140-3 module validation",
      "Common Criteria evaluation"
    ],
    "evidence": [
      [
        "atsec FIPS 140-3 services",
        "https://www.atsec.com/fips-140-3/"
      ]
    ],
    "rank": 9,
    "page": "https://pqaudit.org/auditors/atsec/"
  },
  {
    "slug": "riscure",
    "name": "Riscure (Keysight)",
    "url": "https://www.riscure.com",
    "hq": "Delft, Netherlands",
    "focus": "Side-channel and fault-injection evaluation of hardware implementations",
    "summary": "Riscure, now part of Keysight, evaluates hardware and embedded implementations against power, electromagnetic, and fault-injection attacks. Post-quantum implementations in secure elements, HSMs, and roots of trust need this class of physical-attack testing in addition to a code review.",
    "pqc_services": [
      "Side-channel analysis of ML-KEM, ML-DSA, and hash-based signature implementations in hardware",
      "Fault-injection testing (particularly relevant to SLH-DSA and deterministic ML-DSA)",
      "Certification support (Common Criteria, EMVCo)"
    ],
    "evidence": [
      [
        "Riscure",
        "https://www.riscure.com"
      ]
    ],
    "rank": 10,
    "page": "https://pqaudit.org/auditors/riscure/"
  },
  {
    "slug": "cure53",
    "name": "Cure53",
    "url": "https://cure53.de",
    "hq": "Berlin, Germany",
    "focus": "Penetration testing and code audits of open-source and web software",
    "summary": "Cure53 audits open-source software, browsers, and messaging clients, and publishes its reports. It is frequently used for end-to-end reviews of applications that embed post-quantum libraries.",
    "pqc_services": [
      "Application-level audits of software that integrates post-quantum libraries",
      "Public audit reports"
    ],
    "evidence": [
      [
        "Published reports",
        "https://cure53.de/#publications"
      ]
    ],
    "rank": 11,
    "page": "https://pqaudit.org/auditors/cure53/"
  },
  {
    "slug": "x41-d-sec",
    "name": "X41 D-Sec",
    "url": "https://x41-dsec.de",
    "hq": "Aachen, Germany",
    "focus": "Source-code audits of open-source security and cryptographic software",
    "summary": "X41 D-Sec performs source-code audits of open-source software, including cryptographic libraries, often funded by open-source security programs, and publishes its reports.",
    "pqc_services": [
      "Source-code audits of cryptographic libraries and protocol implementations",
      "Public audit reports"
    ],
    "evidence": [
      [
        "X41 published audits",
        "https://x41-dsec.de/security/research/"
      ]
    ],
    "rank": 12,
    "page": "https://pqaudit.org/auditors/x41-d-sec/"
  }
]