A preliminary ePrint draft claims a polynomial-time quantum algorithm for the Dihedral Coset Problem, which published reductions connect to the lattice assumptions behind ML-KEM and ML-DSA. The proof is unverified and the paper attacks no concrete parameter set. The operational question is answerable today: which assets depend on a lattice assumption as their only post-quantum mechanism.
An AI-found attack ended a third-round NIST signature candidate in a day. Migration planning holds up when you can swap an algorithm quickly, and that starts with knowing which ones run where.
A press release called Classic McEliece the first post-quantum algorithm to reach ISO standardization. The same June 2026 amendment to ISO/IEC 18033-2 standardized three key encapsulation mechanisms, ML-KEM, FrodoKEM, and Classic McEliece, so McEliece is the first code-based algorithm ISO has standardized, not the first post-quantum one. NIST and ISO now point to different code-based algorithms, one more field the inventory has to record, while a scan still finds almost no code-based key exchange on the wire.
The second quarterly scorecard tracks what moved since February. Networking had the most vendor movement of any category, HSM and key management enters as a new category, and the FIPS 140-3 validation queue turns out to be the binding constraint rather than firmware. Databases and SaaS did not move at all.
A peer-reviewed Nature critique by physicist Henry Legg reopened the debate over when a quantum computer will break RSA. The hardware timeline changes nothing about your deadline: regulators already fixed the compliance dates, and the harvest-now-decrypt-later window is already open. The only number that responds to work is your origin key exchange, measured per scan against 2030.
Forescout reports nearly 90% of SSH servers still lack post-quantum key exchange. The fair practitioner question is what the real threat is. Three threat categories run on three clocks, and only harvest-now-decrypt-later is already running, which is why every deadline puts key exchange first.
Executive Order 14412 makes the US civilian post-quantum deadline binding: federal high-value and high-impact systems must adopt PQC for key establishment by the end of 2030 and for digital signatures by 2031. The year between the two dates is the part worth reading closely, because a system can be on pace for one deadline and behind on the other at the same moment.
ANSSI stops certifying security products without PQC in 2027. Certification tests the product. It does not show what deployed servers negotiate, and almost none negotiate PQC today.
Let's Encrypt has committed to Merkle Tree Certificates for post-quantum authentication while identifying hybrid key exchange as the near-term priority for server operators. A review of the two functions, their timelines, and what each implies for measurement.
With the final announcement of RFC 9964, formerly draft-ietf-cose-dilithium, ML-DSA serializations for JOSE and COSE just landed. It has raised a question whether leaf certificate in the current scan data presents any insights into classical signatures. Looking at a sample of 100K certificates with a recorded signature algorithm, none yet were ML-DSA or SLH-DSA. RSA signs roughly four out of five of them, with SHA256-RSA alone accounting for 80K, and ECDSA covers most of what remains.
Filippo Valsorda argued last week that AES-128 holds up against quantum computers. [PQ]probe scan data adds the empirical layer: AES-128-only hosts have deployed hybrid PQC key exchange at roughly 8 times the rate of AES-256-only hosts. They upgraded the cipher and left the key exchange alone. Audit checklists treating AES-256 as a quantum-preparedness criterion check the cipher when the quantum threat is on the key exchange.
Filippo Valsorda has reversed his position on hybrid signatures: pure ML-DSA-44 is fine for sigs, hybrid stays for KEX, non-PQ KEX is a potential active compromise. The shift puts BSI's hybrid mandate and the new Geomys/OpenSSH posture on a collision course. Scanners will need to report against both.
Both combine X25519 and ML-KEM-768 with identical wire sizes. The combiners differ. Vendor documentation routinely treats them as synonyms. Treating them that way in a migration plan is a defect.
Classical TLS 1.3 is 4 to 6 KB. Hybrid key exchange plus ML-DSA certificates is 15 to 20 KB. That gap crosses IW10, QUIC 3x amplification, and DNSSEC boundaries. Reference tables plus a calculator for your specific stack.
Microsoft Security published a Cryptographic Posture Management framework that organizes PQC work across code, network, runtime, and storage. The network-domain starter steps give you inventory of where encrypted sessions live. A companion layer answers what those sessions are negotiating, and that pairing is where a migration plan comes together.
Sectigo announced Private PQC on April 14, issuing ML-DSA-signed certificates from a private CA. ML-DSA defends signature authentication. Harvest-now-decrypt-later is addressed by ML-KEM in the handshake. Both belong on the migration plan; knowing which layer each covers keeps the scoping honest.
Germany’s Quantum Computing Competition funds neutral-atom consortia targeting 4,000 qubits by 2030. The Oratomic/Caltech estimates put ECC-256 at risk from approximately 26,000 neutral-atom qubits. One scaling step apart.
A new paper finds structural gaps in the formal verification behind libcrux, the ML-KEM library used by Signal, Google, Firefox, and the Linux Foundation. The proofs are real. They cover less than procurement language suggests.
Two papers from Oratomic/Caltech and Google Quantum AI confirm ECC-256 breaks one to two orders of magnitude faster than RSA-2048. The most modern cryptographic deployments are the most exposed.
Google committed to completing PQC migration by 2029, well ahead of regulatory deadlines. Their acceleration matches what we see in deployment: the tooling works, hybrid PQC is a config change on most cloud infrastructure, and the real bottleneck is inventory, not research.
China will finalize independent PQC standards by 2029 on structureless lattice math, diverging from NIST. Organizations with cross-jurisdictional exposure now face parallel migration tracks.
Aer Lingus gets a B from SSL Labs and an F from pqprobe. Both grades are correct. They answer different questions, and the gap between them is where the real risk lives.
A researcher confident enough to put a hard date on Shor’s algorithm doesn’t know the protocol it breaks. The gap between theoretical physics and operational security is where risk lives.
IBM published a quantum-centric supercomputing blueprint. Qutwo signed enterprise orchestration deals. These are not physics experiments. They are procurement decisions.
More than 90% of origin servers negotiate zero post-quantum key exchange. The IETF is debating the 2035 destination. Most organizations haven’t met the 2027 starting line.
COM(2026) 13 adds the first explicit PQC requirement to EU law. BSI wrote the guidance and co-chaired the EU roadmap. We scanned bsi.bund.de. No post-quantum key exchange.
Three days after we argued that edge PQC numbers create a false floor, Cloudflare launched origin-server tracking on Radar. The gap narrowed from 60% vs 1% to 60% vs some-fraction-of-10%. Still enormous. Still the most important number in PQC.
A group of engineering professors and PQC hardware executives have announced their "apocalypse" algorithm breaks RSA-2048 in 11 hours. However, it failed initial scrutiny, which reveals how commercial incentives threaten to distort PQC migration.
Google won’t add post-quantum X.509 certificates to the Chrome Root Store. Instead, Chrome is building Merkle Tree Certificates — and the migration target just moved for everyone.
Which of your vendors are actually shipping post-quantum cryptography? We mapped 28+ vendors across seven categories and checked announcements against TLS handshakes.
Australia’s Signals Directorate published a quantum primer with no qubit estimates. That tells you everything about what actually matters for PQC migration.
BSI published 70 pages of post-quantum guidance. Four years later, 28 out of 150 companies responded to a survey about what they’d done. The manual was never the problem.