Mental model
You (this course’s primary learner) already know smart-card-based signing infrastructure (QSCD, Qualified Signature Creation Device) thanks to your eIDAS/CAdES/e-signature background; this lesson does not explain “what a smart card is” but the specific constraints PQC brings to this environment. There are two real constraints: storage (the card’s limited memory) and transmission (the size limits of the APDU protocol between card and reader).
The real effect of the sizes: storage and transmission
Recall the ML-DSA and SLH-DSA sizes from M4: an ML-DSA-65 signature is 3309 BSOURCED, and an SLH-DSA-SHA2-128s signature is 7856 BSOURCED. These are tens or even hundreds of times a classical RSA-2048 (256 BDERIVED) or ECDSA-P256 (64-72 BDERIVED) signature.
This size difference hits the smart card world in two concrete places. The first is storage: the card’s EEPROM must hold the private key and, if needed, the certificate chain, and on classical cards that space may be limited to a few tens of kilobytes. The second, less known but at least as important, is transmission: commands between card and reader (APDUs, Application Protocol Data Units) work in two standard modes under ISO/IEC 7816-4: short APDUs (at most 256 BSOURCED per command/response) and extended APDUs (up to 65535 BSOURCED). The SLH-DSA-SHA2-128s signature is far above the short APDU limit; to carry it, the reader and card must support extended APDUs. This is not a small technical detail to ignore: older readers still common in the field and some operating system drivers may not fully support extended APDUs; when planning a PQC signing pilot, this should be one of the first items the inventory checks.
There is movement on the hardware side, but its rationale should not be overstated
Concrete evidence that these constraints are not abstract: IDEMIA announced a partnership with GlobalFoundries moving its smart card chips to 28nm, GF 28ESF3 platformSOURCED technology, entering mass production in 2026. But it matters not to make this claim more certain than it is: the press material gives no concrete mechanism for why the move suits PQC (for example “X times more RAM”); it only says 28nm technology is “particularly suited to implementing quantum-resistant solutions”, without justification. It is a real sign that the smart card industry takes PQC seriously, but not specific enough to present as “here is the proven technical rationale”; keep that difference (real investment, no stated mechanism) clear for a hostile architect.
An honest gap: applet and pilot data is not public today
While preparing this lesson, we searched for which vendors actually have a working ML-DSA or SLH-DSA signing applet and what state the eIDAS QSCD certification process is in for PQC: the public announcements of major smart card and chip manufacturers such as IDEMIA, Thales, Giesecke+Devrient and Infineon, GlobalPlatform’s applet standardization work, and ETSI/eIDAS trust-list announcements were checked. The result is clear: no public, concrete, verifiable vendor, applet or pilot data was found today. The only thing found is preparation on the hardware side (the 28nm move above); on the software and certification side (which card operating system, which applet, which QSCD certificate) there is no concrete public source.
This is a live application of one of this course’s principles: when you find a gap, say so openly, including what was searched, instead of inventing figures. When explaining this to a bank architect or an auditor, the right sentence is: “The hardware side (chip capacity) is preparing for PQC, and we have concrete evidence; on the software and certification side we checked [sources X, Y, Z] and found no public vendor claim; that is itself a risk signal, and we should monitor this area regularly with dogrula.” Another example of “we don’t know” being more trustworthy than “everything is ready”.