// DeepFalcon1313 — QUANTUM READINESS & CRYPTO AGILITY WEEKLY BRIEFING | WEEK OF SEPTEMBER 16, 2026
Edition #7  |  Coverage: September 9–16, 2026  |  Sources: NIST CSRC · CMVP · NSA CNSA 2.0 · EncryptionConsulting · MSSP Alert · Safelogic · ComplianceHub · QNSQY Blog · Entangled Future
FREE — PUBLIC BRIEFING
Generated: 2026-09-16  |  Prompt v1.2-DM
Companion: Daily Vuln + Threat Reports (subscriber-gated)
5 Days
FIPS 140-2 → Historical (Sep 21)
3/7
Blocks with Genuine Updates
4/7
Blocks — No Meaningful Movement
3
Daily Report PQC/FIPS Mentions This Week
#7
Edition — Weekly Cadence Since Aug 6
Seven Blocks — Week of September 16, 2026
Block 1 — Standards NIST PQC Standards & Mandate Tracker — FIPS 140-2 → Historical in 5 Days (September 21) Action This Week ▼
⚠ FIPS 140-2 → Historical on September 21, 2026 — this Monday — 5 days away. On that date NIST's CMVP (Cryptographic Module Validation Program) moves every remaining active FIPS 140-2 certificate to Historical status. Historically-listed modules keep running — existing deployments are not revoked — but a Historical certificate can no longer satisfy new federal procurement requirements, FedRAMP authorizations, HIPAA safe harbor decisions, defense contracts, or CMMC assessments. Only FIPS 140-3 validated modules appear on the active validation list from September 21 onwards. This briefing has tracked this deadline for seven consecutive weeks. It is here.

No new movement on NIST PQC standards (FIPS 203/204/205) this week. The three finalized standards — ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205) — remain the active baseline, published August 13, 2024. FIPS 206 (FN-DSA, based on FALCON) remains in draft, with final publication expected late 2026 or early 2027. HQC (selected March 2025 as a code-based alternative key encapsulation mechanism to pair with ML-KEM) is in standardization. NSA CNSA 2.0: no new advisories or timeline updates this week.

DateEventStatus
Aug 13, 2024NIST finalizes FIPS 203 (ML-KEM) · FIPS 204 (ML-DSA) · FIPS 205 (SLH-DSA)✓ Final
Mar 11, 2025NIST selects HQC as 5th algorithm — code-based key encapsulation, pairs with ML-KEM✓ Selected — in standardization
Sep 21, 2026FIPS 140-2 → Historical. Only FIPS 140-3 modules satisfy new federal procurement from this date⚠ 5 Days
Late 2026 / Early 2027FIPS 206 (FN-DSA/FALCON) — expected final publicationIn draft
~2030NIST IR 8547 targets RSA/ECC deprecation. NSA CNSA 2.0 targets full PQC transition for new systems by 2030Planning horizon
Why FIPS 140-2/140-3 connects to PQC migration: FIPS 140-3 is a module validation standard, not a PQC algorithm standard — but it is the prerequisite. FIPS 140-3 (based on ISO/IEC 19790:2012) formally deprecates Triple-DES, SHA-1 for signatures, RSA-1024, and MD5, and adds non-invasive (side-channel) attack security requirements. More importantly: the first FIPS 140-3 validated module carrying all three NIST PQC algorithms (EnQuanta's QuantaCrypt, certificate #5312) supports ML-KEM, ML-DSA, and SLH-DSA and is aligned to CNSA 2.0. Organizations replacing FIPS 140-2 modules should choose hardware and software with PQC algorithm support in the firmware roadmap — or they will replace modules again in 2028-2030 for the PQC transition.
Block 2 — Vendors Vendor Crypto-Agility Moves — No New Announcements This Week No Movement ▼
No new vendor PQC or crypto-agility announcements identified in the September 9–16 sweep window. Last week's significant item — Google Cloud announcing X25519MLKEM768 hybrid key exchange as the default for Cloud Load Balancing in October 2026 — remains the most recent enterprise-scale deployment move. That item was covered in Edition #6.

Standing position as of this edition: Chrome/Chromium ships X25519+Kyber768 hybrid TLS by default (deployed 2023–2024). OpenSSL 3.5 (April 2025) added full ML-KEM/ML-DSA/SLH-DSA support. Google Cloud making PQC hybrid the default for load balancers from October 2026. None of the 12 tracked network/security vendors (Check Point, Cisco, Fortinet, Palo Alto, VMware, Ivanti, Citrix, F5, SonicWall, Oracle, Arista, Microsoft) issued new PQC or crypto-agility guidance in the coverage window. The vendor survey will report movement here when it happens — not to fill space with standing updates.

Block 3 — HNDL "Harvest Now, Decrypt Later" Risk Watch — The FIPS 140-3 Transition Is the Near-Term HNDL Decision Point ▼
No new HNDL-specific threat intelligence or documented adversary collection campaigns published in the September 9–16 window. The structural risk picture is unchanged from prior editions.

The most operationally relevant HNDL point for organizations this week is the one that connects directly to Block 1's deadline: the FIPS 140-2 Historical transition creates a unique window to address HNDL exposure and compliance simultaneously, rather than serially. Here is why they are connected and why sequential replacement is the wrong approach.

The HNDL Exposure Surface
HNDL risk applies specifically to asymmetric key exchange — RSA, ECDH, and related mechanisms. The threat is that encrypted TLS sessions, VPN tunnels, or other asymmetric-key-protected data intercepted today can be stored by a well-resourced adversary and decrypted years from now when a cryptographically relevant quantum computer (CRQC) becomes available. AES-256 symmetric encryption, used for bulk data after key exchange, is not at quantum risk. The risk is in the negotiation step, not the encryption step.
Why FIPS 140-3 Replacement Is the HNDL Decision Point
Many organizations are replacing FIPS 140-2 validated HSMs and crypto modules with FIPS 140-3 validated alternatives right now, to meet the September 21 deadline. This is a one-time hardware/software replacement event with procurement cycles measured in months. If an organization selects a FIPS 140-3 module without verified PQC algorithm support in the firmware roadmap, they will replace those modules again in 2028-2030 when CNSA 2.0 PQC requirements take effect. The right question at procurement is: does this module carry ML-KEM, ML-DSA, and SLH-DSA in current firmware or on a confirmed roadmap?
Expert consensus on CRQC timeline (NIST / Global Risk Institute): 10–20 years from today is the range cited in the most credible independent assessments. Some researchers place it under 10 years; others over 25. No serious researcher claims it is impossible or that the timeline is settled. The reason to begin migration now despite the uncertainty: data with a confidentiality requirement longer than the CRQC timeline is already at harvest risk. For long-lived financial records, health data, government classified material, and national security data, that threshold is already breached — which is why CNSA 2.0 sets 2030 as the new-systems deadline, not 2035.
Block 4 — Quantum Progress Quantum Computing Progress — No New Verified Hardware Milestones This Week No Movement ▼
No new independently verified quantum computing hardware milestones identified in the September 9–16 window. The standing reference point: QuEra Computing demonstrated 96 logical qubits in January 2026 — the largest publicly confirmed logical qubit count as of this edition. Breaking RSA-2048 using Shor's algorithm requires approximately 4,000 error-corrected logical qubits. The gap between current demonstrated capability (96) and cryptographically relevant capability (~4,000) remains substantial.

This report will not fill this block with vendor press releases when no independently verified milestone has occurred. Hardware progress claims that appear in vendor marketing without third-party technical corroboration are explicitly excluded per this briefing's editorial standards. The next substantive entry here will reference independently analyzed research, not a company's own announcement.

Block 5 — This Week's Checklist Practical Focus: HSM and Key Management Migration Planning — Avoid Replacing Hardware Twice Action Item ▼

This week's focus: HSM (hardware security module) and key management infrastructure readiness — specifically, the assessment step that prevents organizations from solving the FIPS 140-2 gap with hardware that immediately needs replacing for the PQC transition. The FIPS 140-2 deadline this Monday makes this the most time-sensitive practical step in the current rotation.

▶ HSM / Key Management PQC Readiness Assessment — Do This Before Procuring FIPS 140-3 Replacements

  1. Inventory every HSM and validated crypto module in scope. List the vendor, model, current FIPS certificate number, and FIPS level (1–4). Verify each certificate's status at csrc.nist.gov/projects/cryptographic-module-validation-program — the CMVP database is authoritative. A two-minute lookup per module removes whole classes of vendor disputes later. Flag every module showing only a FIPS 140-2 certificate with no active 140-3 certificate alongside it.
  2. For each flagged module, determine the vendor's PQC roadmap commitment before procuring a 140-3 replacement. Ask the vendor two specific questions in writing: (a) Does the current-generation hardware support ML-KEM, ML-DSA, and SLH-DSA (FIPS 203/204/205) via firmware update, or does it require hardware replacement? (b) What is the committed delivery date for a CMVP-validated firmware version carrying these algorithms? If the vendor cannot answer (b) with a specific date and a CMVP certificate number to be assigned, assume hardware replacement will be needed again for the PQC transition — budget accordingly.
  3. Separate the FIPS 140-3 compliance decision from the PQC migration decision, but link the timelines. You need a FIPS 140-3 certificate for new federal procurements — that is non-negotiable from Monday. You need PQC algorithm support for CNSA 2.0 compliance by approximately 2030. These are different requirements, but the hardware that addresses them should be the same hardware: a FIPS 140-3 validated module on a confirmed PQC firmware roadmap. The first validated module to carry all three PQC algorithms with FIPS 140-3 certification is EnQuanta's QuantaCrypt (CMVP #5312, supporting ML-KEM, ML-DSA, SLH-DSA, aligned to CNSA 2.0). It is not a universal recommendation — evaluate against your specific deployment requirements — but it is the benchmark for what crypto-agile FIPS 140-3 support looks like in practice.
  4. Map your key management lifecycle to both deadlines. HSMs generate and protect long-lived asymmetric keys — certificate signing keys, TLS private keys, code-signing keys, VPN identity keys. Any private key that will still be in use in 2030 should be on a migration path to ML-DSA or ML-KEM by the time CNSA 2.0 PQC requirements take effect for your sector. Identify which keys those are now, while the HSM replacement exercise gives you the asset map for free.
  5. For organizations that cannot complete FIPS 140-3 hardware replacement by Monday: the operative guidance from NIST is that existing FIPS 140-2 validated deployments continue to function after September 21 — the Historical designation affects new procurement justification, not existing operations. The practical priority is ensuring that any new procurement after Monday cites a FIPS 140-3 certificate, and that any solicitation response from a vendor referencing a FIPS 140-2 certificate is treated as non-compliant for federal contracts. Existing systems have time; new purchases do not.
Block 5 rotation log — covered so far: (Ed.1) Crypto inventory methodology · (Ed.2) TLS 1.3 + hybrid PQC adoption · (Ed.3) CA and certificate lifecycle readiness · (Ed.4) RFC 10024 hybrid TLS — IETF formalization context · (Ed.5) Vendor PQC-readiness questionnaire framework · (Ed.6) FIPS 140-2/140-3 procurement checklist · (Ed.7) HSM / key management migration planning [this edition]
Block 6 — Week's Log This Week's Research Log — September 9–16, 2026 ▼
September 16, 2026 — Edition #7 Sources checked this cycle (all 8 mandatory sources): NIST CSRC PQC project page ✓ · NSA CNSA 2.0 advisories ✓ · CISA PQC guidance ✓ · Browser vendor engineering blogs (Chrome, Firefox, Safari) ✓ · Cloud provider blogs (AWS, Azure, Google Cloud) ✓ · 12 tracked network/security vendors ✓ · Quantum research outlets (IBM Quantum, Google Quantum AI, IEEE Spectrum, Ars Technica) ✓ · General PQC/HNDL/crypto-agility search for September 9–16 window ✓
Blocks with genuine new content this edition: Block 1 (Standards): FIPS 140-2 Historical deadline in 5 days — the week's primary operational item. No new NIST standard publications or NSA CNSA 2.0 updates. Block 3 (HNDL): No new threat intelligence; contextual analysis of FIPS 140-3 transition as HNDL decision point. Block 5 (Checklist): HSM/key management migration planning — rotation item. Block 7 (Momentum Indicators): Self-referential signal confirmed (3 mentions in daily reports this week).
Blocks with no meaningful movement (stated plainly, not padded): Block 2 (Vendors): No new announcements. Vendor sweep clean across all 12 tracked names. Block 4 (Quantum Progress): No new independently verified hardware milestones. Standing reference: QuEra 96 logical qubits (January 2026) remains the most recent confirmed figure. Block 7 partial rows: 5 of 8 momentum indicators showed no qualifying signal this week (stated in each row).
Corrections from prior editions: None. No corrections to report.
Self-referential note (Block 7 preview): The daily vulnerability report referenced FIPS 140-2 Historical (September 21 deadline) in 3 consecutive reports this week — September 11, 15, and 16 — all in the deadline countdown tracking section. This consistent cross-pillar reference confirms the deadline's operational prominence in the service's daily threat surface coverage.
Block 7 — Momentum Momentum Indicators — Weekly PQC Maturity Signal Dashboard ▼

Relevance filter applied: every item below connects specifically to the cryptographic/security implication of quantum computing. Items related to quantum computing in other domains (materials science, drug discovery, optimization) are excluded regardless of their significance in those fields.

IndicatorSignal This Week
1. Research Publication GrowthNo meaningfully new cryptanalysis, PQC algorithm design, or quantum factoring/discrete-log papers identified in the September 9–16 window. The underlying research volume trend remains high — NIST's PQC standardization attracted sustained academic output — but no specific paper of note to call out this week.
2. Patent FilingsNo PQC-specific patent activity identified in this week's research sweep. No qualifying lattice-based signature, quantum-resistant hardware, or crypto-agility tooling patents surfaced in accessible sources during the coverage window.
3. Startup FundingNo PQC migration tooling, quantum-safe product, or crypto-agility platform funding rounds identified in the September 9–16 window.
4. Product ReleasesEnQuanta's QuantaCrypt (CMVP #5312) remains the leading reference point for new product category entrants: a FIPS 140-3 validated software module carrying all three NIST PQC algorithms (ML-KEM, ML-DSA, SLH-DSA) and aligned to CNSA 2.0. Publication date was earlier in 2026; no new entrant at this tier identified this week specifically. The category exists and has its first validated representative — the market is forming.
5. Standards Progress (Non-NIST/NSA)No new ETSI, ISO, IETF, or industry consortium PQC publications in the September 9–16 window. RFC 10024 (IETF Hybrid TLS 1.3 formalization) was covered in Edition #4 and remains the standing IETF reference. No update to that status this week.
6. Enterprise AdoptionGoogle Cloud's announced October 2026 deployment of X25519MLKEM768 as the default for Cloud Load Balancing remains the most recent large-scale demand-side adoption signal (covered Edition #6). No new named enterprise adoption announcements this week. The October 2026 date is two weeks away — a brief status update is expected in next week's edition.
7. Regulatory ReferencesNo new PQC mentions in financial sector regulatory guidance, insurance requirements, or non-US jurisdiction standards bodies identified in the September 9–16 window. Standing reference: UK NCSC published its PQC migration guidance in 2024; the European Telecommunications Standards Institute (ETSI) has an active QSCH (Quantum Safe Cryptography and Security) technical committee. No new output from either body this week.
★ Frequency in This Service's Daily Reports3 mentions in the September 9–16 window, all in the daily vulnerability reports (September 11, 15, and 16). All three references were FIPS 140-2 Historical deadline tracking in the countdown section — not a new CVE or active-exploitation finding. This confirms the deadline's operational prominence in the daily threat surface coverage and is the expected pattern for a compliance deadline in its final week. Count will reset next week once the September 21 date passes.