Here are sample output from show commands that can be used to verify PQC configuration.
Device# show crypto session detail
Crypto session current status
Code: C - IKE Configuration mode, D - Dead Peer Detection
K - Keepalives, N - NAT-traversal, T - cTCP encapsulation
X - IKE Extended Authentication, F - IKE Fragmentation
R - IKE Auto Reconnect, U - IKE Dynamic Route Update
S - SIP VPN, E - Stronger IKE Encryption Enforced
Interface: Tunnel0
Profile: IKEv2_PROFILE
Uptime: 00:00:06
Session status: UP-ACTIVE
Peer: 10.0.149.217 port 500 fvrf: (none) ivrf: (none)
Phase1_id: 10.0.149.217
Desc: (none)
Session ID: 1
IKEv2 SA: local 10.0.149.203/500 remote 10.0.149.217/500 Active
Capabilities:U connid:1 lifetime:23:59:54
IPSEC FLOW: permit ip 0.0.0.0/0.0.0.0 0.0.0.0/0.0.0.0
Active SAs: 2, origin: crypto map
Inbound: #pkts dec'ed 0 drop 0 life (KB/Sec) KB Vol Rekey Disabled/113
Outbound: #pkts enc'ed 0 drop 0 life (KB/Sec) KB Vol Rekey Disabled/113
Device# show crypto ike sa
IPv4 Crypto IKEv2 SA
Tunnel-id Local Remote fvrf/ivrf Status
1 10.0.149.203/500 10.0.149.217/500 none/none READY
Encr: AES-CBC, keysize: 256, PRF: SHA512, Hash: SHA512, DH Grp:16, Auth sign: PSK, Auth verify: PSK
PQC Key Exchange: ML-KEM-1024
Life/Active Time: 86400/46 sec
CE id: 0, Session-id: 1
Local spi: 344F7AC6A1758651 Remote spi: 8FCCD7B55AB5B9A9
IPv6 Crypto IKEv2 SA
Device# show crypto ike sa detailed
IPv4 Crypto IKEv2 SA
Tunnel-id Local Remote fvrf/ivrf Status
1 10.0.149.203/500 10.0.149.217/500 none/none READY
Encr: AES-CBC, keysize: 256, PRF: SHA512, Hash: SHA512, DH Grp:16, Auth sign: PSK, Auth verify: PSK
PQC Key Exchange: ML-KEM-1024
Life/Active Time: 86400/48 sec
CE id: 0, Session-id: 1
Local spi: 344F7AC6A1758651 Remote spi: 8FCCD7B55AB5B9A9
Status Description: Negotiation done
Local id: 10.0.149.203
Remote id: 10.0.149.217
Local req msg id: 3 Remote req msg id: 0
Local next msg id: 3 Remote next msg id: 0
Local req queued: 3 Remote req queued: 0
Local window: 20 Remote window: 20
DPD configured for 0 seconds, retry 0
Fragmentation not configured.
Quantum-safe Encryption using PQC: ML-KEM-1024
Dynamic Route Update: enabled
Extended Authentication not configured.
NAT-T is not detected
Cisco Trust Security SGT is disabled
Initiator of SA : Yes
PEER TYPE: IOS-XE
IPv6 Crypto IKEv2 SA