No new movement on NIST PQC standards (FIPS 203/204/205) this week. The three finalized standards — ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205) — remain the active baseline, published August 13, 2024. FIPS 206 (FN-DSA, based on FALCON) remains in draft, with final publication expected late 2026 or early 2027. HQC (selected March 2025 as a code-based alternative key encapsulation mechanism to pair with ML-KEM) is in standardization. NSA CNSA 2.0: no new advisories or timeline updates this week.
| Date | Event | Status |
|---|---|---|
| Aug 13, 2024 | NIST finalizes FIPS 203 (ML-KEM) · FIPS 204 (ML-DSA) · FIPS 205 (SLH-DSA) | ✓ Final |
| Mar 11, 2025 | NIST selects HQC as 5th algorithm — code-based key encapsulation, pairs with ML-KEM | ✓ Selected — in standardization |
| Sep 21, 2026 | FIPS 140-2 → Historical. Only FIPS 140-3 modules satisfy new federal procurement from this date | ⚠ 5 Days |
| Late 2026 / Early 2027 | FIPS 206 (FN-DSA/FALCON) — expected final publication | In draft |
| ~2030 | NIST IR 8547 targets RSA/ECC deprecation. NSA CNSA 2.0 targets full PQC transition for new systems by 2030 | Planning horizon |
Standing position as of this edition: Chrome/Chromium ships X25519+Kyber768 hybrid TLS by default (deployed 2023–2024). OpenSSL 3.5 (April 2025) added full ML-KEM/ML-DSA/SLH-DSA support. Google Cloud making PQC hybrid the default for load balancers from October 2026. None of the 12 tracked network/security vendors (Check Point, Cisco, Fortinet, Palo Alto, VMware, Ivanti, Citrix, F5, SonicWall, Oracle, Arista, Microsoft) issued new PQC or crypto-agility guidance in the coverage window. The vendor survey will report movement here when it happens — not to fill space with standing updates.
The most operationally relevant HNDL point for organizations this week is the one that connects directly to Block 1's deadline: the FIPS 140-2 Historical transition creates a unique window to address HNDL exposure and compliance simultaneously, rather than serially. Here is why they are connected and why sequential replacement is the wrong approach.
This report will not fill this block with vendor press releases when no independently verified milestone has occurred. Hardware progress claims that appear in vendor marketing without third-party technical corroboration are explicitly excluded per this briefing's editorial standards. The next substantive entry here will reference independently analyzed research, not a company's own announcement.
This week's focus: HSM (hardware security module) and key management infrastructure readiness — specifically, the assessment step that prevents organizations from solving the FIPS 140-2 gap with hardware that immediately needs replacing for the PQC transition. The FIPS 140-2 deadline this Monday makes this the most time-sensitive practical step in the current rotation.
▶ HSM / Key Management PQC Readiness Assessment — Do This Before Procuring FIPS 140-3 Replacements
- Inventory every HSM and validated crypto module in scope. List the vendor, model, current FIPS certificate number, and FIPS level (1–4). Verify each certificate's status at csrc.nist.gov/projects/cryptographic-module-validation-program — the CMVP database is authoritative. A two-minute lookup per module removes whole classes of vendor disputes later. Flag every module showing only a FIPS 140-2 certificate with no active 140-3 certificate alongside it.
- For each flagged module, determine the vendor's PQC roadmap commitment before procuring a 140-3 replacement. Ask the vendor two specific questions in writing: (a) Does the current-generation hardware support ML-KEM, ML-DSA, and SLH-DSA (FIPS 203/204/205) via firmware update, or does it require hardware replacement? (b) What is the committed delivery date for a CMVP-validated firmware version carrying these algorithms? If the vendor cannot answer (b) with a specific date and a CMVP certificate number to be assigned, assume hardware replacement will be needed again for the PQC transition — budget accordingly.
- Separate the FIPS 140-3 compliance decision from the PQC migration decision, but link the timelines. You need a FIPS 140-3 certificate for new federal procurements — that is non-negotiable from Monday. You need PQC algorithm support for CNSA 2.0 compliance by approximately 2030. These are different requirements, but the hardware that addresses them should be the same hardware: a FIPS 140-3 validated module on a confirmed PQC firmware roadmap. The first validated module to carry all three PQC algorithms with FIPS 140-3 certification is EnQuanta's QuantaCrypt (CMVP #5312, supporting ML-KEM, ML-DSA, SLH-DSA, aligned to CNSA 2.0). It is not a universal recommendation — evaluate against your specific deployment requirements — but it is the benchmark for what crypto-agile FIPS 140-3 support looks like in practice.
- Map your key management lifecycle to both deadlines. HSMs generate and protect long-lived asymmetric keys — certificate signing keys, TLS private keys, code-signing keys, VPN identity keys. Any private key that will still be in use in 2030 should be on a migration path to ML-DSA or ML-KEM by the time CNSA 2.0 PQC requirements take effect for your sector. Identify which keys those are now, while the HSM replacement exercise gives you the asset map for free.
- For organizations that cannot complete FIPS 140-3 hardware replacement by Monday: the operative guidance from NIST is that existing FIPS 140-2 validated deployments continue to function after September 21 — the Historical designation affects new procurement justification, not existing operations. The practical priority is ensuring that any new procurement after Monday cites a FIPS 140-3 certificate, and that any solicitation response from a vendor referencing a FIPS 140-2 certificate is treated as non-compliant for federal contracts. Existing systems have time; new purchases do not.
Relevance filter applied: every item below connects specifically to the cryptographic/security implication of quantum computing. Items related to quantum computing in other domains (materials science, drug discovery, optimization) are excluded regardless of their significance in those fields.
| Indicator | Signal This Week |
|---|---|
| 1. Research Publication Growth | No meaningfully new cryptanalysis, PQC algorithm design, or quantum factoring/discrete-log papers identified in the September 9–16 window. The underlying research volume trend remains high — NIST's PQC standardization attracted sustained academic output — but no specific paper of note to call out this week. |
| 2. Patent Filings | No PQC-specific patent activity identified in this week's research sweep. No qualifying lattice-based signature, quantum-resistant hardware, or crypto-agility tooling patents surfaced in accessible sources during the coverage window. |
| 3. Startup Funding | No PQC migration tooling, quantum-safe product, or crypto-agility platform funding rounds identified in the September 9–16 window. |
| 4. Product Releases | EnQuanta's QuantaCrypt (CMVP #5312) remains the leading reference point for new product category entrants: a FIPS 140-3 validated software module carrying all three NIST PQC algorithms (ML-KEM, ML-DSA, SLH-DSA) and aligned to CNSA 2.0. Publication date was earlier in 2026; no new entrant at this tier identified this week specifically. The category exists and has its first validated representative — the market is forming. |
| 5. Standards Progress (Non-NIST/NSA) | No new ETSI, ISO, IETF, or industry consortium PQC publications in the September 9–16 window. RFC 10024 (IETF Hybrid TLS 1.3 formalization) was covered in Edition #4 and remains the standing IETF reference. No update to that status this week. |
| 6. Enterprise Adoption | Google Cloud's announced October 2026 deployment of X25519MLKEM768 as the default for Cloud Load Balancing remains the most recent large-scale demand-side adoption signal (covered Edition #6). No new named enterprise adoption announcements this week. The October 2026 date is two weeks away — a brief status update is expected in next week's edition. |
| 7. Regulatory References | No new PQC mentions in financial sector regulatory guidance, insurance requirements, or non-US jurisdiction standards bodies identified in the September 9–16 window. Standing reference: UK NCSC published its PQC migration guidance in 2024; the European Telecommunications Standards Institute (ETSI) has an active QSCH (Quantum Safe Cryptography and Security) technical committee. No new output from either body this week. |
| ★ Frequency in This Service's Daily Reports | 3 mentions in the September 9–16 window, all in the daily vulnerability reports (September 11, 15, and 16). All three references were FIPS 140-2 Historical deadline tracking in the countdown section — not a new CVE or active-exploitation finding. This confirms the deadline's operational prominence in the daily threat surface coverage and is the expected pattern for a compliance deadline in its final week. Count will reset next week once the September 21 date passes. |