Quantum Readiness & Crypto Agility Weekly Briefing
87% Planning, Only 7% Deployed: The PKI Gap; FIPS 140-2 Sunset 19 Days

Edition #5  ·  Week of September 2, 2026  ·  Free & Public  ·  deepfalcon1313.com
// QUANTUM READINESS
Generated: 2026-09-02  ·  Prompt v1.2-DM
FIPS 203/204/205 in force · RFC 10024 Standards Track · HQC pending
87% vs 7%
Planning vs Deployed (DigiCert Survey)
19 Days
FIPS 140-2 → Historical
15–50×
ML-DSA Cert Size vs Classical
Root-First
PKI Migration Sequencing
5
Edition This Week
19days remaining
FIPS 140-2 transitions to Historical status on September 21, 2026. New implementations and procurements should already be targeting FIPS 140-3. Organizations should not initiate new FIPS 140-2 validations after this date and should document their transition path. Three regulatory deadlines converge in this window: FIPS 140-2 Historical (September 21), the EU's national PQC strategy milestone (Q4 2026), and the NSA CNSA 2.0 software/firmware signing acquisition gate (end of 2026).
This week's headline: 87% of organizations planning PQC — only 7% have actually deployed it across most of their certificate estate. DigiCert's July 2026 enterprise survey found that intent vastly outpaces execution. The primary bottleneck is not algorithm selection — it's PKI migration. ML-DSA signatures are 15 to 50 times larger than the classical signatures they replace, and certificate chains must migrate root-first. Continuous cryptographic discovery — not algorithm choice — is identified as the mandatory first step. This edition's Block 5 focus addresses the PKI migration challenge directly.
Block 1 NIST PQC Standards & Mandate Tracker
FIPS 140-2: 19 Days3 Deadlines Converging
Sep 21
FIPS 140-2 → Historical
19 days
Q4 2026
EU National PQC
Strategy Milestone
End 2026
NSA CNSA 2.0
Acquisition Gate
FIPS 203 (ML-KEM)Finalized August 13, 2024 — Implements. Foundation for TLS hybrid key exchange, VPN, and data-at-rest key establishment.
FIPS 204 (ML-DSA)Finalized August 13, 2024 — Implements. Digital signatures. ML-DSA signatures are 15–50× larger than RSA/ECDSA — the primary PKI migration constraint.
FIPS 205 (SLH-DSA)Finalized August 13, 2024 — Implements. Hash-based signature fallback. More conservative mathematical foundation than ML-DSA for defense-in-depth.
FIPS 206 (FN-DSA)Draft — Pending. Compact lattice-based signatures (FALCON-derived). Finalization expected 2026-2027.
HQC (Code-based KEM)Selected March 2025 — FIPS Pending (~2027). Backup KEM to ML-KEM. Different mathematical basis for algorithm diversity.
RFC 10024Published August 2026 — Standards Track. Hybrid PQ/T TLS 1.3: X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024. See Edition #4.
FIPS 140-2 → HistoricalSeptember 21, 2026 — 19 days. New procurements and implementations should target FIPS 140-3. Existing validated modules remain valid; new validations should not be initiated against FIPS 140-2 after this date.
CNSA 2.0 (NSS)Software/firmware signing: ML-DSA (or LMS/XMSS) acquisition gate end-2026. Network encryption: ML-KEM by 2026–2030. Classical algorithms retired by 2030–2033. National Security System operators in scope.
EU PQC StrategyQ4 2026 national PQC strategy milestone for EU member states. Member states expected to publish or update national quantum-safe cryptography transition plans. Cross-border digital service providers operating in the EU should monitor national-level guidance publication.
HAWK AlgorithmWithdrawn July 28-29, 2026 — Anthropic Claude Mythos Preview identified nontrivial automorphism halving effective key strength. FIPS 203/204/205 unaffected.
Block 2 Vendor Crypto-Agility Moves
CloudflareML-KEM hybrid TLS default — over 50% of human web traffic uses post-quantum key agreement. Post-quantum origin authentication (CDN-to-origin) delivery in the mid-2026 window. Merkle Tree Certificates: mid-2027. Full SASE-suite PQC coverage by early 2028.
DigiCertNow issuing hybrid and PQC X.509 certificates. July 2026 enterprise survey: 87% of organizations planning or piloting PQC; only 7% have deployed quantum-safe cryptography across most of their certificate estate. PKI identified as the primary deployment bottleneck, not algorithm choice.
Google / ChromeML-KEM hybrid TLS default in Chrome. 2029 full PQC migration deadline across Google infrastructure. Google Cloud PQC migration tooling available for enterprise customers. Co-author of RFC 10024 hybrid TLS standardization.
AWSHybrid post-quantum TLS at AWS KMS since 2024. AWS Kampanakis co-authored RFC 10024. Enterprise PQC migration guidance and tooling available.
ApplePQ3 in iMessage since iOS 17.4 (2024). iOS 26 completed remaining PQC integration. Certificate validation infrastructure compatible with hybrid and PQC certificates from DigiCert/Entrust.
OpenSSLOpenSSL 3.5 (April 2025): native ML-KEM and ML-DSA without OQS provider. Teams on OpenSSL 3.4 or earlier should plan upgrade before pursuing FIPS 140-3-bound PQC workloads.
HSM VendorsAWS CloudHSM, Azure Dedicated HSM, Thales Luna, Entrust nShield, Utimaco, Marvell LiquidHSM, Fortanix DSM, and HashiCorp Vault HSM are the eight major HSM platforms with active PQC integration roadmaps. Confirm ML-KEM and ML-DSA support timelines with your HSM vendor as part of PKI migration planning.
Block 3 "Harvest Now, Decrypt Later" (HNDL) Risk Watch
API Key Theft Now Extends Risk

This week's primary threat intelligence finding adds a new dimension to HNDL risk: CVE-2026-0768 in Langflow is being exploited to harvest OpenAI API keys and AWS credentials stored in AI orchestration environments. This is distinct from traditional HNDL — instead of harvesting encrypted network traffic to decrypt later, attackers are stealing the API keys and service credentials that provide access to the AI service and its stored data. Organizations using AI application frameworks to process sensitive data now face two HNDL-adjacent risks: (1) the classical HNDL risk on the data in transit, and (2) immediate credential theft enabling direct access to the AI service's data pipeline. Protecting AI infrastructure credentials with ML-KEM-secured key management is an emerging operational necessity, not just a compliance requirement.

Internet PQC Adoption State (2026 Measurement Study)
49.3% Hybrid/Partial
0%50% Hybrid (partial) · 50.7% Fully Vulnerable100%
DigiCert enterprise gap87% planning or piloting PQC — only 7% deployed across most of certificate estate. The planning-to-deployment gap is widening as complexity becomes clear. PKI migration — not algorithm selection — is the bottleneck that is slowing enterprise deployment.
Certificate size constraintML-DSA signatures are 15–50× larger than RSA/ECDSA. Certificate chains grow proportionally. TLS handshakes carry larger certificate payloads. Intermediaries (load balancers, WAFs, CDN edges) must be verified for support before migrating certificate chains.
TLS 1.2 legacy gapTLS 1.2 cannot support RFC 10024 hybrid PQC key exchange. Organizations with TLS 1.2-only endpoints remain fully HNDL-exposed on those connections regardless of other PQC progress. TLS 1.3 migration is a prerequisite.
Block 4 Quantum Computing Progress, Contextualized
Q-Day estimateCryptographically relevant quantum computers remain 5–15+ years away in mainstream expert assessments. HNDL attacks are active now and do not require a quantum computer — only that harvested data is held until quantum capability arrives. No new significant hardware announcements this week.
Why migrate nowData encrypted today with classical algorithms is being harvested now. When CRQCs arrive, that captured data becomes decryptable. Sensitive data with a 5–15 year confidentiality horizon is already at risk. The migration window closes as quantum hardware matures.
Algorithm securityML-KEM, ML-DSA, and SLH-DSA security remains sound — no known quantum attack on FIPS 203/204/205. The April 2024 Chen lattice algorithm concern was refuted by subsequent independent analysis. The HAWK withdrawal (Edition #3, July 2026) demonstrates NIST's ongoing vigilance — the three core standards are unaffected.
Timeline contextDigiCert's data (87% planning, 7% deployed) suggests that at current deployment rates, full enterprise PKI migration will not complete before Q-Day estimates at the conservative end. The math reinforces the urgency of moving from planning to execution this quarter, not next year.
Block 5 Practical Readiness Checklist — This Week's Focus: PKI Migration Planning Rate-Limiting Step Identified

This week's focus: DigiCert's survey identifies PKI — not algorithm choice — as the primary deployment bottleneck. The root-first migration sequencing requirement and ML-DSA certificate size constraints are the operational barriers that are slowing the 87% from joining the 7%. This checklist addresses those barriers directly.

Run a cryptographic inventory — this is the mandatory first step
The Encryption Consulting 2026 PQC migration guide identifies continuous cryptographic discovery as the mandatory prerequisite to everything else. You cannot migrate what you haven't inventoried. Tools: NIST's NCCoE PQC migration project provides reference architectures; enterprise tools from SafeLogic, QNSP, and similar vendors automate discovery. Know where RSA and ECDSA are in use before selecting a migration path.
Understand the root-first sequencing requirement
PKI certificate chains must migrate root-first — you cannot issue ML-DSA leaf certificates from a classical root CA. The migration path: (1) Establish or procure a PQC root CA, (2) Issue PQC intermediate CAs, (3) Begin issuing hybrid or PQC leaf certificates. Skipping the sequencing and issuing PQC certificates from classical roots produces an inconsistent chain. Work with DigiCert, Entrust, or your internal CA team to plan the root migration first.
Audit intermediary support for larger certificate sizes before migrating
ML-DSA signatures are 15–50× larger than RSA/ECDSA. Before issuing any PQC certificates, verify that all TLS intermediaries — load balancers, WAFs, API gateways, CDN edge nodes — can handle the larger certificate payloads. A TLS handshake with a full ML-DSA chain will be rejected by intermediaries with hardcoded certificate size limits. This audit prevents a production outage caused by a PQC migration.
Confirm HSM roadmap for PQC algorithm support
If your PKI relies on Hardware Security Modules (HSMs), confirm your HSM vendor's timeline for ML-KEM and ML-DSA support. Eight major HSM platforms (AWS CloudHSM, Azure Dedicated HSM, Thales Luna, Entrust nShield, Utimaco, Marvell LiquidHSM, Fortanix DSM, HashiCorp Vault HSM) have active roadmaps — request written confirmation of ML-KEM and ML-DSA support dates, not just roadmap references. HSM lag is a common blocker that is not discovered until late in the migration planning process.
Plan hybrid certificates as the transition vehicle
Hybrid certificates containing both classical and PQC keys allow a gradual transition — clients that support PQC use the PQC key; classical clients fall back to the classical key. DigiCert and Entrust now issue hybrid certificates. Hybrid certificates are larger than either pure classical or pure PQC certificates — factor this into your intermediary size audit. Hybrid certificates are the right vehicle for the transition period, not the final state.
Block 6 This Week's Log — Edition #5
Sep 2, 2026DigiCert July 2026 enterprise survey published. 87% of organizations planning or piloting PQC; only 7% have deployed quantum-safe cryptography across most of their certificate estate. PKI is the rate-limiting step. ML-DSA signature size (15–50× larger) is the primary certificate chain constraint. Root-first migration sequencing required. (Source: Encryption Consulting / DigiCert)
Sep 2, 2026Three regulatory deadlines converging Q4 2026: FIPS 140-2 Historical (September 21), EU national PQC strategy milestone (Q4 2026), NSA CNSA 2.0 acquisition gate (end-2026). First multi-deadline convergence since FIPS 203/204/205 finalization.
Sep 2, 2026AI infrastructure credential theft creates new HNDL-adjacent risk vector. CVE-2026-0768 Langflow exploitation (this week's threat intel primary) demonstrates attackers systematically targeting AI application frameworks to harvest OpenAI API keys and AWS credentials. AI infrastructure credential protection is emerging as a PQC-adjacent operational concern. (Source: VulnCheck / DeepFalcon1313 threat intel Sep 2)
Aug 26, 2026[Edition #4] RFC 10024 published. IETF formally standardizes hybrid PQ/T TLS 1.3: X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024. Standards Track.
Aug 19, 2026[Edition #3] HAWK algorithm withdrawn from NIST Round 3. AI-discovered nontrivial automorphism. FIPS 203/204/205 unaffected.
Block 7 Momentum Indicators

Momentum indicators track PQC migration maturity signals across the public internet, the vendor ecosystem, and this publication's own archive.

7%
Enterprise organizations with PQC deployed across most of their certificate estate (DigiCert July 2026 survey). The gap between the 87% planning and the 7% deployed is this quarter's primary story.
>50%
Cloudflare human web traffic using post-quantum key agreement — the clearest single indicator of real-world deployment at scale, driven by infrastructure-layer adoption rather than enterprise certificate migration.
19 Days
FIPS 140-2 Historical transition — September 21, 2026. Organizations still initiating FIPS 140-2 validations should stop. New procurements should specify FIPS 140-3.
4 steady
ML-KEM references in the DeepFalcon1313 threat intelligence archive — unchanged from Edition #4. This week's reports (PaperCut, ShieldBreak, Langflow) have no direct PQC angles. The archive count will grow when the next ML-KEM-adjacent threat intelligence finding surfaces.
The 87% vs 7% gap is this edition's defining data point. Enterprise intent to adopt PQC is nearly universal — nearly nine in ten organizations are planning or actively piloting. But only one in fourteen has actually deployed quantum-safe cryptography across most of their certificate estate. The gap is operational, not strategic. Organizations know they need to migrate. The bottleneck is the execution complexity of PKI root-first sequencing, certificate size impacts, HSM readiness, and intermediary compatibility — the exact issues this edition's Block 5 addresses. The organizations that will complete migration before Q-Day are those that have already started the cryptographic inventory and root CA planning now.