News desk
What moved in post-quantum standards, policy and industry between 3 September to 7 October 2026. Curated by hand, short on purpose, linked to primary sources.
Updated 7 October 2026
GAO: none of 24 major US agencies fully ready for the PQC transition
The Government Accountability Office assessed the 24 CFO Act agencies against three preparatory practices: a prioritized cryptographic inventory, a migration funding estimate, and PQC testing plans. None fully addressed all three. The sensitive version of the report made 89 recommendations to 23 agencies.
Why it mattersThe bottleneck is inventory, funding and expertise, not the algorithms. Banks face the same three gaps.
Learn the background: Five-layer discovery: network, code, cert, dependency, runtime, The US timeline: EO 14412, CNSA 2.0, IR 8547
Dutch cabinet sends a government-wide quantum strategy to parliament
The Netherlands published its Rijksbrede Quantumstrategie, aiming to lead in quantum technology and be resilient to its risks by 2035. As summarized by PostQuantum.com, the document sets PQC milestones for central government: high-risk systems migrated by end of 2030, medium-risk systems by end of 2035.
Why it mattersAnother EU member state turning the EU coordinated roadmap into dated national milestones.
Learn the background: EU and global timelines: NIS CG, DORA, G7
Cloudflare Workers adds ML-KEM and ML-DSA to Web Crypto
Workers now offers opt-in native Web Crypto support for ML-KEM and ML-DSA, behind a compatibility flag while the Web Crypto specification for these algorithms is still moving.
Why it mattersDevelopers can prototype PQC at the application layer without bundling their own implementations.
Learn the background: ML-KEM and FIPS 203, ML-DSA (FIPS 204)
BSI advises against Classic McEliece in new developments
After several 2026 cryptanalysis papers lowered key-recovery estimates, Germany's BSI says Classic McEliece should no longer be used for new applications and points to FrodoKEM, ML-KEM, or HQC once standardized. Hybrid deployments still keep at least classical security. BSI reaffirms completing PQC key agreement migration by 2031.
Why it mattersA live example of why hybrid mode and crypto-agility are the default advice: ML-KEM and HQC are not affected.
Learn the background: Hash-based and code-based intuition, Crypto-agility: provider models and testability
Cloudflare plans a public CA issuing free Merkle Tree Certificates
During its Birthday Week, Cloudflare announced plans to become a public certificate authority whose certificates are Merkle Tree Certificates, aimed at post-quantum authentication without large handshake costs. It also added post-quantum key exchange visibility to its analytics and described IKEv2 downgrade protection for post-quantum IPsec.
Why it mattersCertificate chain size is the hard part of PQ authentication on the web. MTCs are the leading answer.
Learn the background: OCSP/CRL impact and Merkle Tree Certificates, Certificate chain bloat
NATO publishes its first Quantum Technology Roadmap
The public summary lists adoption of post-quantum cryptography standards as ongoing work, an update to NATO's action plan on the quantum threat to cryptography due in Q3 2027, and an industry readiness study on quantum-resistant solutions due in Q2 2027.
Why it mattersDefence supply chains will start asking vendors for PQC readiness evidence.
Learn the background: Supply chain and governance: vendor lock-in, RACI, KPIs
China's next-generation crypto candidates draw public cryptanalysis within days
China's Institute of Commercial Cryptography Standards published 119 first-round candidates for its NGCC program on 20 September. Within three days, public reviewers had logged 104 findings against 65 candidates, including practical breaks of five designs (figures as summarized by PostQuantum.com).
Why it mattersOpen review breaks young designs fast. The same pattern ended SIKE and Rainbow.
Learn the background: SIKE and Rainbow: two real collapses, two versions of the same lesson
All FIPS 140-2 certificates move to the CMVP Historical list
NIST's transition schedule moved every FIPS 140-2 validation to the Historical list. Modules can still be used in existing systems, but new procurements should require FIPS 140-3.
Why it mattersHSM refresh and PQC readiness now land in the same procurement cycle.
Learn the background: CAVP, CMVP and production support: the general discipline, HSM validation reality: CAVP vs CMVP
Apple Root Program sets out its post-quantum position
Apple announced a draft policy for Merkle Tree Certificates in TLS (three cosignatures including ML-DSA and ECDSA, 7-day maximum validity, annual audits, operator applications expected from late summer 2027) and will accept composite ML-DSA root certificates for S/MIME.
Why it mattersBrowser and OS root programs decide when PQ certificates become real. Two of them now point to MTCs.
Learn the background: OCSP/CRL impact and Merkle Tree Certificates, S/MIME and code signing: a different lifetime logic
RSA-896 factored on classical GPUs, with Claude porting CADO-NFS
Stephen Weis factored the 270-digit RSA-896 challenge with the General Number Field Sieve. Claude ported CADO-NFS to GPUs and orchestrated the run on up to 2,048 idle GPUs: about 10 days, roughly 30 GPU-years. This is a classical result, not a quantum one.
Why it mattersIt does not threaten RSA-2048, but RSA-1024 keys are within reach of data-center GPU fleets.
Learn the background: Shor, Grover and resource estimates
G7 Cybersecurity Working Group issues a call to action on PQC
The G7 working group urges governments and organizations to begin the transition to post-quantum cryptography as soon as possible, noting that the timeline for a capable quantum computer is uncertain but recent advances suggest one may be built.
Why it mattersA coordinated signal from G7 cyber agencies, published by ANSSI.
Learn the background: Financial sector guidance: Europol, BIS, X9.146
Curated by hand. Every item links its primary source; where we relied on a secondary summary, it is named.