Post-quantum cryptography news
What changed in post-quantum cryptography, who it affects, and what to do about it. Standards, mandates, breaks, and shipping implementations, read against the primary source.
October 2026
TLS draft pairs ML-KEM-1024 with X448
A new individual Internet-Draft proposes MLKEM1024X448 for TLS 1.3, DTLS 1.3 and QUIC. Its 1,624-byte key shares target a higher security level, but it has no IETF adoption, codepoint or deployment status.
4 min readNSA turns the 2027 PQC deadline into a procurement gate
The NSA's new post-quantum resource hub puts two near-term gates in one place: new commercial national-security systems must support quantum-resistant algorithms from 2027, while legacy systems that cannot support them are to be phased out by 2030.
4 min readIETF tightens KEM-only authentication for LAKE
Revision 01 of the IETF LAKE authentication draft specifies a five-message, three-secret KEM handshake for constrained systems and tightens the rules around key binding, freshness and when authentication completes.
4 min read
September 2026
IETF holds standalone ML-KEM TLS draft for review
The RFC Editor has paused the standalone ML-KEM-for-TLS draft while IETF process complaints are reviewed. The hold delays publication but does not revoke hybrid RFC 10024 or establish a cryptographic flaw.
4 min readOpenSSL 4.1 beta speeds ML-KEM and ML-DSA
OpenSSL 4.1.0-beta1 adds architecture-specific ML-KEM and ML-DSA paths for Power, IBM Z and x86-64, moving PQC performance testing from generic support claims to real CPU fleets.
4 min readIETF draft brings post-quantum crypto to EAP-TLS
A new standards-track IETF draft applies post-quantum TLS to EAP-TLS, EAP-TTLS, PEAP and TEAP, while confronting the certificate-size problem that enterprise authentication cannot ignore.
4 min readoqs-provider 0.12.0-rc2 fixes key-handling bugs
The new oqs-provider release candidate packages fixes for use-after-free, hybrid-key length validation, RSA reconstruction overflow, and allocation cleanup.
5 min readJava 27 puts hybrid post-quantum TLS on the default path
Java 27 adds hybrid ML-KEM key exchange to TLS 1.3 by default, changes ML-KEM and ML-DSA private-key encodings, and speeds both algorithms on AVX-512 systems.
4 min readCloudflare brings ML-DSA validation to DNSSEC
Cloudflare's 1.1.1.1 now validates ML-DSA DNSSEC signatures. Larger responses and downgrade protection show why the trust chain still matters.
4 min readThe quantum claim that put lattice security in question
A quantum algorithm raised an unsettling question about lattice security. Twelve days later came a refutation. Here is what failed, and why it is a relief.
5 min readGo 1.27 puts ML-DSA into TLS and X.509
Go 1.27 brings ML-DSA signatures to X.509 and TLS 1.3. What Go teams can use now, how FIPS module support differs, and what to test.
3 min readCISA and G7 issue joint call to action on PQC
On September 3, 2026, CISA and the G7 Cyber Security Working Group published a jointly signed statement, co-signed by the UK, France, Germany, Canada, Japan and Italy's national cyber agencies, telling organizations they can no longer treat post-quantum migration as a future problem. It sets no new date and no new algorithm requirement. What is new is that seven governments signed the same page, which is a different kind of pressure than one more national deadline.
4 min read
August 2026
GSA starts post-quantum overhaul of federal PIV badges
GSA is moving on two fronts at once: an interagency working group met for the first time on August 12, 2026 to plan post-quantum identity and access management across the federal government, and its physical access control testing lab is adding post-quantum algorithms to the program that certifies PIV badge readers and door controllers. Both trace back to the same document, OMB's June memo on executing Executive Order 14412, and both point at the same design choice: a dual-stack PIV card that keeps its classical keys while it grows post-quantum ones.
4 min readFirst FIPS 140-3 Level 3 HSM validated for ML-KEM, ML-DSA
NIST's Cryptographic Module Validation Program listed certificate 5497 on August 19, 2026: Crypto4A's QASM module, validated at FIPS 140-3 Security Level 3, natively implementing ML-KEM, ML-DSA, SLH-DSA, and LMS alongside AES, SHA, and RSA. Crypto4A and the press covering it call it the first PQC-capable hardware security module to clear Level 3. Whether or not it is the first, the certificate is real, and it answers a question that has been open since 2024: can you buy a validated HSM to actually run these algorithms in.
3 min readExecutive Order 14412 sets a 2030 federal PQC deadline
Executive Order 14412, signed on June 22, 2026, gives the federal post-quantum migration dates that agencies have to plan against: key establishment by December 31, 2030 and digital signatures by December 31, 2031 for High Value Assets and high impact systems. It also directs the FAR Council to propose a rule carrying the same 2030 requirement to covered contractors. Here is what the order obliges, when each clock runs out, and which parts reach past the federal perimeter.
6 min readLazarus used ML-KEM to hide a Windows zero-day
Check Point Research disclosed that the North Korea-linked Lazarus Group used ML-KEM, the NIST-standardized post-quantum key encapsulation mechanism, to protect the delivery channel for a Windows kernel zero-day (CVE-2026-68820) in its Operation Dream Job campaign against defense and aviation firms. Microsoft patched the flaw in its August 2026 Patch Tuesday release, the only bug that month it flagged as actively exploited. The notable part is not quantum computers, it is that a well-reviewed, standardized primitive is now common enough that attackers reach for it too.
4 min readPost-quantum TLS 1.3 hybrid is now RFC 10024
The IETF has published RFC 10024, formally standardizing X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024 as hybrid post-quantum key agreement mechanisms for TLS 1.3. The three groups replace the long-running draft-ietf-tls-ecdhe-mlkem specification that browsers and libraries were already shipping as a de facto default. Here is what the RFC locks in, and what it still leaves for a separate migration.
4 min readCloudflare adds post-quantum authentication to origins
Cloudflare now supports post-quantum authentication between its edge and your origin server: Authenticated Origin Pulls and Custom Origin Trust Store both accept ML-DSA (FIPS 204) certificates. Paired with the X25519MLKEM768 key exchange already running on that hop, this is the first mainstream path to a fully post-quantum CDN-to-origin connection, not just the browser-to-edge leg.
3 min readAI-found flaw sinks HAWK, a NIST PQC candidate
On July 28, 2026, Anthropic disclosed that its Claude Mythos Preview model found a structural weakness in HAWK, a lattice-based signature scheme in the third round of NIST's additional-signatures process. The flaw cut the estimated key-recovery cost for the smallest parameter set by roughly a million times, and the HAWK team withdrew the candidate days later. None of NIST's finalized standards, ML-KEM, ML-DSA, and SLH-DSA, are affected.
4 min readGo 1.27 brings post-quantum signatures to the stdlib
Go 1.27, released this month, adds a crypto/mldsa package implementing ML-DSA (FIPS 204), plus ML-DSA support in crypto/x509 and crypto/tls. Post-quantum signatures are no longer a third-party dependency for Go services, they are a standard-library import. Here is what shipped and what it means for the migration.
3 min readHow much of the web already uses post-quantum TLS
By late 2025, around 43% of human web connections to Cloudflare were already using hybrid post-quantum key agreement, and X25519MLKEM768 is on by default in every major browser. The browser-to-edge hop is largely migrated. The unfinished half is origins, authentication, and your own stack. Here is where the line actually is.
3 min readHow ML-KEM became the browser default, release by release
Chrome has negotiated hybrid post-quantum key agreement by default since version 131 in November 2024, migrating from a pre-standard Kyber draft to the finalized X25519MLKEM768. The other major browsers and libraries followed. Here is how the switch happened, and what the hybrid does and does not protect.
3 min readNIST's 2030 and 2035 deadlines for legacy cryptography
NIST's transition report, IR 8547, names the dates the whole migration is timed against: today's public-key algorithms deprecated after 2030 and disallowed after 2035. Those are not distant abstractions, they are a schedule you have to work backwards from. Here is what the deadlines say and what they mean.
3 min readCISA's 2026 SBOM minimum elements: what changed, and why
CISA, with the NSA, FBI, and international partners, replaced the 2021 NTIA baseline for what a software bill of materials must contain. The new floor asks for cryptographic hashes on every component, a signature on the SBOM itself, full transitive-dependency depth, and machine-processable identifiers, and it applies to open-source, AI software, and SaaS. Here is what changed, why it was done, and why it lands next to the cryptographic bill of materials we build.
6 min read