During presentation author discusses concept and building blocks used while building cryptographic module supporting hybrid, quantum-safe TLS v1.3 key exchange. Author provides a recepie to make the construction FIPS-certifiable, even before post-quantum KEMs are FIPS-approved.