In February we published the first PQC Vendor Scorecard. It mapped 28 vendors across seven product categories against what CISA says should be deployed now versus what is still transitioning. The point was simple: check what vendors claim against what their endpoints actually negotiate.
Five months later, the landscape moved. Some of it moved a lot. This is the Q2 update.
What changed
Three things compressed the timeline since Q1.
Google Quantum AI published a whitepaper in March demonstrating a 20x reduction in the resources needed to break ECC-256. Fewer than 500,000 physical qubits, runtime in minutes. Combined with Craig Gidney's June 2025 work on RSA-2048 (fewer than one million superconducting qubits), both classical algorithm families are on a shorter path than anyone modeled a year ago. Cloudflare and Google both moved their full PQC targets to 2029.
Executive Order 14412 set binding deadlines for federal high-value and high-impact systems on June 22: key establishment by end of 2030, digital signatures and authentication by end of 2031. Federal contractors must comply with post-quantum FIPS by end of 2030.
And the networking hardware category, which was the weakest enterprise infrastructure category in Q1, had more vendor movement than any other category in the scorecard.
The scorecard
The summary table tracks Q1 to Q2 movement across six categories. One improved, one is new, two are stable, two did not move.
| Category | Q1 | Q2 | Movement | The gap |
|---|---|---|---|---|
| Browsers / CDNs | High | High | Stable | 65%+ of client traffic. ~10% of origins support PQC. |
| Cloud Infrastructure | Medium | Medium | Stable | KMS and edge ready. Databases and M365 still classical. |
| Networking | Fragmented | Converging | Up | Cisco and Palo Alto shipped. Fortinet extends lead. |
| HSM / Key Mgmt | n/a | Mixed | New | Hardware ships PQC. FIPS validation and cloud KMS lag. |
| Databases | None | None | Unchanged | Zero native PQC at any database endpoint. |
| SaaS / Collaboration | None | None | Unchanged | Salesforce published a compliance doc. Endpoints still classical. |
Networking moved fastest
In Q1, Fortinet was the only networking vendor shipping NIST-compliant PQC in the data path. Cisco had a strategy blog. Palo Alto had already shipped PAN-OS 12.1 Orion in August 2025 with all three NIST PQC standards (ML-KEM, ML-DSA, SLH-DSA), quantum-safe VPN tunnels, and a cipher translation proxy that re-encrypts classical traffic into ML-KEM at the network edge. The Q1 scorecard did not reflect this. It has been corrected.
Since Q1: Cisco published a product roadmap with specific firmware versions (FTD 10.5, ASA 9.25) targeting ML-KEM for GA in late 2026, with ML-DSA following in FTD 11.0 in 2027. Fortinet extended its lead with FortiOS 8.0 (PQC SSL deep inspection) and FortiWeb 8.0.3 (ML-KEM and ML-DSA via OpenSSL 3.5).
This is the category to watch. Regulatory pressure plus customer demand plus competitive dynamics produced more movement in five months than the database and SaaS categories have produced since PQC standardization.
The FIPS validation bottleneck
HSM and Key Management enters the scorecard in Q2 because it is the infrastructure layer underneath every other category. A CA cannot issue an ML-DSA certificate if its signing HSM does not support ML-DSA. An enterprise cannot deploy PQC key management if its KMS does not support ML-KEM key types.
Thales (Luna v7.9) and Entrust (nShield v13.8.0) both ship ML-KEM, ML-DSA, and SLH-DSA in production firmware. AWS KMS has ML-KEM and ML-DSA in GA with FIPS 140-3 validated PQC via AWS-LC. Azure Key Vault and Google Cloud KMS are trailing, with partial support or preview only.
The bottleneck is not firmware. It is validation. Combined FIPS 140-3 validation with PQC algorithms averages 500+ days in the current CMVP queue. Until that clears, CAs cannot issue FIPS-validated PQC certificates, and regulated enterprises cannot deploy PQC key management under federal procurement rules. The FIPS 140-2 sunset on September 21, 2026 makes this worse: organizations still on FIPS 140-2 modules face a double migration.
The false floor, with data
In Q1 we argued that widely cited PQC adoption numbers measure CDN posture, not origin-server deployment. Cloudflare validated this directly. They launched origin-server tracking on Radar in February 2026. About 10% of origins support post-quantum key exchange, up from under 1% at the start of 2025. The scanner tests support, not preference, so the negotiated rate is lower. Cloudflare does not publish it. Over 65% of client traffic to the edge is post-quantum encrypted.
The gap between 65% and some fraction of 10% is the false floor. One number counts traffic at the edge. The other counts servers behind it. If your organization reports PQC progress using edge statistics, you are reporting your CDN vendor's posture, not your own.
Databases and SaaS did not move
Zero database vendors deployed PQC to a connection endpoint in Q2. SQL Server, Azure SQL, RDS, Aurora, DynamoDB, MongoDB Atlas, PostgreSQL (managed), Snowflake: all unchanged. The proxy workaround via PQ-TLS-capable load balancers remains the only option.
In SaaS, Salesforce published a PQC compliance document on March 18 covering core services, Commerce Cloud, and Data Cloud. It is behind a login wall. It is the first concrete PQC compliance artifact from a major SaaS vendor. But no ML-KEM at the endpoint.
Zoom shipped post-quantum end-to-end encryption for meetings (ML-KEM-768, Zoom 6.0.10+) in May 2024. This is application-layer E2EE for meeting content, not ML-KEM negotiated in the TLS handshake to zoom.us. The Q1 scorecard missed it and listed Zoom as "no announcements." That was wrong.
Microsoft accelerated its Quantum Safe Program timeline from 2033 to 2029 on June 30, 2026, and shipped TLS hybrid ML-KEM key exchange on Windows 11 and Windows Server 2025 on July 14. The ML-KEM groups are disabled by default and require explicit admin configuration. Teams, Outlook, SharePoint, and OneDrive endpoints are not negotiating PQC today, but the migration target is now public and four years closer than Q1 reported.
ServiceNow, Workday, and Slack remain unchanged. No PQC deployment, no roadmaps.
Download
The full report covers eight categories with updated vendor assessments, comparison tables, a regulatory deadline table (EO 14412, CNSA 2.0, ANSSI 2027, BSI TR-02102, FIPS 140-2 sunset), 25 sources, and a six-question vendor questionnaire for procurement reviews.
Download the [PQ]probe PQC Vendor Scorecard: Q2 2026 Edition
The scorecard tells you where the industry is. [PQ]probe tells you where your organization is, and whether you are getting better or worse. A vendor shipping PQC does not mean your endpoints negotiate it. The only way to know is to probe, track, and measure over time.