// DeepFalcon1313 — Quantum Readiness & Crypto Agility Weekly Briefing | Week of September 30, 2026
Edition #9 · Coverage window: September 24 – September 30, 2026 · Sources: NIST CSRC · NSA · CISA · EU Joint Committee of the ESAs · Cloudflare · IETF · China ICCS / NGCC · Infleqtion · IonQ · PostQuantum.com
FREE — PUBLIC BRIEFING
Published: 2026-09-30
Weekly · Wednesdays
6
Blocks with updates
1
No-movement blocks
7
Total blocks
3
Hard deadlines flagged
93
Days to CNSA 2.0 gate

This Week in One Minute

The most useful news this week came from infrastructure, not standards bodies. Cloudflare published a cluster of post-quantum work: a fix for a design weakness that lets an attacker quietly downgrade post-quantum IPsec tunnels to classical key exchange, an application to become a publicly trusted certificate authority built around compact post-quantum-friendly Merkle Tree Certificates, and new analytics showing whether your own traffic is using hybrid ML-KEM. Its numbers are a good reality check: about 70% of browser traffic it sees is already post-quantum, but only about 15% of the origin servers behind it are.

On the risk side, the EU's three financial supervisors formally warned that encryption-breaking quantum capability could arrive before quantum computers are commercially useful, naming "harvest now, decrypt later" collection as a present-day concern. Hardware news was incremental and mostly vendor-reported; nothing this week changes credible estimates of when RSA or ECC will be broken. NIST was quiet. The NSA CNSA 2.0 procurement gate on January 1, 2027 is now 93 days away.

This week's readiness step: find out whether your VPNs negotiate post-quantum key exchange, and whether that negotiation can be downgraded.

BLOCK 1 NIST PQC Standards & Mandate Tracker No movement3 deadlines ▼

No meaningful movement this week. NIST's PQC project news page shows no new announcements since the May 14 advancement of nine candidates to Round 3 of the additional-signatures process. FIPS 206 (FN-DSA, based on Falcon) and the HQC backup key-encapsulation standard remain pending; NIST has previously indicated a draft HQC standard around 2026 and a final in 2027. No new NSA or CISA PQC guidance was found in the window.

Deadlines on the Board

DeadlineWho it bindsRequirementStatus
Dec 31, 2026EU member statesAdopt national PQC migration strategies / begin transition (NIS Cooperation Group roadmap)92 days · reaffirmed by EU supervisors this week
Jan 1, 2027US National Security Systems (new acquisitions)NSA CNSA 2.0 — new NSS equipment must support approved quantum-resistant algorithms93 days
Mid-2027Swiss financial institutionsFINMA Guidance 05/2026 — adopt PQC strategy and roadmap~9 months
BLOCK 2 Vendor Crypto-Agility Moves Updates ▼

Cloudflare published five post-quantum posts on September 28–29. They are the week's substantive vendor moves; no PQC announcements from the 12 enterprise network/security vendors we track (Check Point, Cisco, Fortinet, Palo Alto Networks, VMware/Broadcom, Ivanti, Citrix, F5, SonicWall, Oracle, Arista, Microsoft) were found in the window.

IPsec quantum-downgrade protection
VENDOR DOCS + IETFCloudflare · Sep 29, 2026

In IKEv2, each side signs only its own outbound messages, not the full exchange. An attacker who can tamper with the handshake can strip the post-quantum option so both ends settle on classical key exchange without noticing. Exploiting this for decryption still needs a quantum computer working in real time during the handshake, so it is not a practical attack today, but it undermines the point of deploying PQ VPNs against future adversaries. Cloudflare co-developed a full-transcript-authentication extension through the IETF IPSECME working group and offers it as an opt-in beta for its IPsec, Magic WAN and Magic Transit customers.

Cloudflare applies to become a public certificate authority — with Merkle Tree Certificates
VENDOR ANNOUNCEMENTCloudflare · Sep 29, 2026

Cloudflare has applied to the Chrome, Apple, Microsoft and Mozilla root programs, is acquiring an established root from GlobalSign for compatibility, and expects its first Merkle Tree Certificates in production in Q1 2027. MTCs address a real post-quantum problem: PQ signatures are large, and a conventional certificate chain full of them bloats every TLS handshake. Issuance will be ACME-based and will require ACME Renewal Information (RFC 9773) support.

Post-quantum visibility in analytics — and a revealing statistic
VENDOR DOCSCloudflare · Sep 29, 2026

New fields (ClientTLSKeyExchangeGroup, OriginTLSKeyExchangeGroup) show which key-exchange group each connection used. Cloudflare cites roughly 70% of browser-generated traffic using hybrid ML-KEM versus only about 15% of origin connections. The gap is the story: browsers upgraded themselves; the servers enterprises run mostly have not.

"CryptoLabe" — AI-assisted cryptographic inventory
VENDOR-INTERNAL TOOLCloudflare · Sep 29, 2026

Cloudflare described an internal AI tool that discovers cryptographic use across code, configuration and dependencies as part of its target of full post-quantum readiness by 2029. Its practical advice is worth repeating: do not start by trying to find every use of cryptography; start with critical systems and validate findings with owning teams. The tool itself is not publicly available.

BLOCK 3 "Harvest Now, Decrypt Later" Risk Watch Updates ▼
EU financial supervisors: the threat may arrive before quantum computers are commercially useful
REGULATOR REPORTJoint Committee of the EBA, EIOPA and ESMA · Autumn 2026 Risks & Vulnerabilities update · Sep 23, 2026

The three European Supervisory Authorities warned that quantum computing could weaken cryptography that financial institutions rely on at scale, and that encryption-breaking capability could materialise before any viable commercial quantum application. They named harvest-now-decrypt-later collection explicitly, and pointed to the NIS Cooperation Group's call for member states to adopt PQC migration strategies by the end of 2026. Coverage also noted that about 6 million bitcoin sit in addresses with exposed public keys — an illustration of long-lived exposure, not a near-term prediction.

Why it matters: this moves HNDL from a security-team talking point into supervisory language. Expect EU-regulated banks, insurers and custodians — and their suppliers — to be asked for PQC plans in upcoming supervisory cycles, alongside the Swiss FINMA mid-2027 roadmap requirement.

Sector urgency this week: financial services (EU and Switzerland) moved up; no new sector-specific signals for healthcare, government or critical infrastructure were found.

BLOCK 4 Quantum Computing Progress, Contextualized Updates ▼

Bottom line: nothing this week changes credible estimates of when a cryptographically relevant quantum computer will exist. The progress is real but incremental, and most of it is vendor-reported.

ClaimWhat was claimedWhat is verifiedCrypto relevance
Infleqtion — 30 logical qubits (Sep 24–27)30 entangled logical qubits encoded in 80 neutral atomsVENDOR ONLYUses a distance-2 code that detects but cannot correct errors, relies on discarding flagged runs, and has no paper yetLow. Error detection with post-selection does not scale to the long computations code-breaking needs.
IonQ — real-time decoder on a laptop CPU (Sep 23)An Apple M4 Max decoded a simulated 408-logical-qubit machine in real timePREPRINTarXiv 2608.25027, simulation only — no data from real qubitsLow–moderate. Shows the classical decoding side is tractable; the quantum hardware remains the bottleneck.
QEC "classical loop" matures (synthesis, Sep 27)Several vendors now publish error-correction interfaces with measured latenciesVENDOR-MEASUREDQblox + Riverlane reported ~10 µs loops at distance 7 with emulated qubits (Sep 11)Moderate. 10 µs reaction time is an assumption in the best-known RSA-2048 cost estimate; meeting it in emulation removes one engineering unknown, not the qubit-count gap.
BLOCK 5 Practical Readiness Checklist — This Week: VPN & IPsec Post-Quantum Readiness Action ▼

VPN tunnels carry exactly the kind of long-lived, high-value traffic that harvest-now-decrypt-later targets, and this week's IPsec downgrade disclosure shows that "supports PQC" and "always uses PQC" are not the same thing. This is an afternoon's work for most admins.

  1. List every tunnel. Site-to-site IPsec, remote-access VPN (IPsec or SSL/TLS), cloud interconnects and SD-WAN overlays. Note vendor, firmware version and who owns each.
  2. Check PQC support per product. Look in vendor release notes for ML-KEM / hybrid key exchange in IKEv2 (RFC 9370 additional key exchanges) or in TLS-based VPNs. Record: supported / roadmap / unknown.
  3. Check what is actually negotiated. Supported is not the same as used. Pull IKE logs or tunnel status on one test tunnel and confirm which key-exchange groups were agreed.
  4. Ask about downgrade protection. For each vendor: "If an attacker strips the PQ proposal, does the tunnel fail or fall back silently?" Where your policy allows, require PQ key exchange rather than offering it as optional, on tunnels carrying long-lived sensitive data.
  5. Prioritise by data lifetime, not traffic volume. Tunnels carrying data that must stay confidential for 10+ years (HR, legal, health, financial, government) move first.
  6. Put it in the record. Add the results to your crypto inventory and into renewal/RFP questions for VPN and SD-WAN vendors.

Rotation note: previous editions covered FIPS 140-2 → 140-3 transition, HSM/key-management migration planning and post-transition actions; VPN/IPsec has not been this block's focus before.

BLOCK 6 This Week's Log Log ▼
Window
September 24 – 30, 2026 (7 days since Edition #8)
Changed since last week
Cloudflare PQ cluster (IPsec downgrade fix, CA application with MTCs, PQ analytics, AI inventory tool); EU ESAs Joint Committee HNDL warning; China's NGCC Round 1 candidates publicly attacked (104 findings, five designs broken); incremental QEC hardware and decoder claims.
Checked, nothing new
NIST CSRC PQC news; NSA CNSA 2.0 pages; CISA PQC guidance; the 12 tracked enterprise network/security vendors; browser vendors' PQC rollouts; AWS/Azure/Google Cloud PQC announcements; PQC patent activity.
Countdown
CNSA 2.0 new-NSS acquisition gate: 93 days (Jan 1, 2027).
Method notes
Hardware claims labelled vendor-only / preprint / verified. The EU supervisors' report is dated September 23, the day before this window opened; it is included because it was not covered in Edition #8's published summary. Our own daily-report mention count (Block 7) is based on report titles and summaries in the site search index plus the full text of today's two reports.
Corrections
None this week.
BLOCK 7 Momentum Indicators Updates ▼

Every row below is filtered for relevance to cryptography — quantum news without a cryptographic or security implication is excluded.

#IndicatorThis week
1Research publicationsUnusually intense public cryptanalysis: within three days of China's Next-generation Commercial Cryptographic Algorithms (NGCC) programme publishing 119 Round 1 candidates on Sep 20, researchers logged 104 findings against 65 of them and practically broke five designs (two signature schemes, a trapdoor-recovery break and two hash functions); one hash break is on IACR ePrint (Sep 22). Notably, one researcher reported using AI assistance to find 53 implementation issues in a day.
2Patent filingsNo meaningful signal this week.
3Startup fundingNo verified PQC-specific funding round found in the window.
4New product categories / entrantsA major CDN applying to become a publicly trusted CA specifically to deploy post-quantum-friendly Merkle Tree Certificates (Q1 2027) — a new category of PQ entrant in the WebPKI. (Details in Block 2.)
5Standards progress (non-NIST)IETF IPSECME: full-transcript authentication extension for IKEv2 progressing toward RFC. China ICCS NGCC Round 1 under public review — a separate national PQC track that multinationals operating in China will need to support alongside NIST algorithms.
6Enterprise adoptionCloudflare telemetry: ~70% of browser traffic uses hybrid ML-KEM, ~15% of origin servers do — the demand side (server estates) lags the client side badly. Cloudflare itself targets full PQ readiness by 2029.
7Regulatory references (beyond NIST/CNSA)EU Joint Committee of EBA/EIOPA/ESMA autumn risk update names quantum and HNDL risk for financial institutions (Sep 23). FINMA mid-2027 roadmap requirement remains the most concrete financial-sector deadline.
★Frequency in DeepFalcon threat/vuln reports (last 7 days)0 mentions. No quantum/PQC references in daily report titles or summaries from Sep 23–30, or in the full text of today's two reports. (Last week's FIPS 140-2 references were a validation-programme deadline, not PQC.)