Cloudflare plans to become a public certificate authority and start production issuance of post-quantum Merkle Tree Certificates in the first quarter of 2027. Teams planning a post-quantum migration now have an issuer-side date to test web PKI against.
Perspective Coverage
4 publishers
- Builder
- Builder 45%
- Operator
- Operator 45%
- Investor
- Investor 10%
Reality
- Evidence50
- Adoption8
- Hype gap+30
- Incentives
- Insufficient
- Confidence60
NSA has moved its post-quantum deadline for National Security Systems to 2027, two years ahead of Cloudflare, Google and Microsoft, a dev.to post reports. That account is secondhand, so whether suppliers to those systems have to re-plan their migrations depends on what the agency's own statement says.
Reality
- Evidence15
- Adoption
- Insufficient
- Hype gap+55
- Incentives
- Insufficient
- Confidence30
PwC surveyed 3,934 leaders and found 52% rank attacks on AI systems as their biggest cyber preparedness gap. Only 17% place AI risk with the CISO, so in most of the sample the security function does not own the threat it feels least ready for.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 57%
- Investor
- Investor 15%
Reality
- Evidence55
- Adoption35
- Hype gap+15
- Incentives40
- Confidence60
Cloudflare Workers adds five ML-KEM and ML-DSA parameter sets to Web Crypto behind the webcrypto_modern_algorithms flag. Developers can now test post-quantum code against primitives built into the runtime, but they still have to build the protocols on top.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap0
- Incentives55
- Confidence62
Cloudflare has agreed to buy a GlobalSign root and applied to four browser root programs to become a public certificate authority. It has not issued a certificate yet, and its post-quantum certificates are aimed at Chrome's quantum-resistant root store in early 2027.
Reality
- Evidence55
- Adoption5
- Hype gap+20
- Incentives72
- Confidence60
Cloudflare plans to become a public certificate authority and issue post-quantum Merkle Tree Certificates from early 2027. Sites it fronts will manage both kinds from one system, so the planning work falls on old devices that will never add a new root.
Reality
- Evidence45
- Adoption5
- Hype gap+20
- Incentives55
- Confidence42
UC San Diego and INRIA researchers forged RSA signatures on a 1,024-bit key inside a hardware security module after about 4 billion signing requests. The key stayed inside the device throughout, so for custodians the exposure is in signing settings, starting with the FIPS mode the researchers switched off.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence40
Vitalik Buterin says Ethereum's Hegotá upgrade, planned for 2027, is likely the last fork that someone who knew Ethereum in 2015 would recognize. The work he expects to follow has no dates yet, so ETH holders are pricing a long rebuild of the protocol off a single milestone.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives35
- Confidence55
Hybrid ML-KEM is live on google.com and googleapis.com, and Cloud KMS post-quantum algorithms are generally available. The rest of the roadmap is a dated dependency schedule.
Reality
- Evidence60
- Adoption40
- Hype gap+10
- Incentives55
- Confidence65
Generic methods collapse per-type API sprawl, go fix gains four modernizers, and the goroutineleak profile in runtime/pprof is now generally available. GoLand 2026.2 supports all three.
Perspective Coverage
5 publishers
- Builder
- Builder 66%
- Operator
- Operator 34%
- Investor
- Investor 0%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+8
- Incentives45
- Confidence70
The Responsible Fintech Institute has put NIST-standardized signing in front of supervisors from Abu Dhabi, Bhutan and Malta. The code that would let anyone check the work comes later.
Reality
- Evidence45
- Adoption12
- Hype gap+30
- Incentives55
- Confidence62
The construction runs inside today's Script limits, so no soft fork was needed. The cost of quantum defence moves instead onto the individual holder, at $75 to $150 per transaction.
Perspective Coverage
4 publishers
- Builder
- Builder 44%
- Operator
- Operator 34%
- Investor
- Investor 22%
Reality
- Evidence62
- Adoption5
- Hype gap+18
- Incentives50
- Confidence60
The G7 Cyber Security Working Group's June call to action says the quantum threat is off the radar and under-resourced at most organizations, and it hands CISOs the wording to fund a cryptographic inventory this cycle.
Perspective Coverage
5 publishers
- Builder
- Builder 22%
- Operator
- Operator 55%
- Investor
- Investor 23%
Reality
- Evidence72
- Adoption30
- Hype gap+10
- Incentives60
- Confidence68
Cloudflare reports origin handshake retries falling by a factor of fourteen, though its own 30% miss rate cannot produce a 52% baseline. What does transfer is post-quantum key agreement arriving with nobody configuring it.
Reality
- Evidence50
- Adoption60
- Hype gap+25
- Incentives70
- Confidence60
AWS and Microsoft are already shipping ML-KEM hybrid groups, so the question for platform teams is whether the old proxy, SDK and appliance in the path still complete a handshake that got bigger.
Reality
- Evidence40
- Adoption55
- Hype gap+10
- Incentives20
- Confidence45
The iPhone 18 Pro's Reference Image mode binds a photo to the sensor that captured it, then has Apple's cloud develop and sign the finished file. Apple's published account protects the original capture and stops at the edit.
Perspective Coverage
10 publishers
- Builder
- Builder 42%
- Operator
- Operator 45%
- Investor
- Investor 13%
Reality
- Evidence55
- Adoption12
- Hype gap+30
- Incentives65
- Confidence60
Reference mode on the iPhone 18 Pro signs pixels as they leave the sensor and finishes the picture inside Private Cloud Compute, so anyone building a verification pipeline now has an Apple trust root to handle alongside C2PA.
Reality
- Evidence56
- Adoption24
- Hype gap+28
- Incentives72
- Confidence57
The 0.02% timing overhead comes from IonQ's own simulations of 88 memory blocks and magic factories, posted to arXiv. For anyone working through a cryptographic inventory, the readiness deadlines stand where they were.
Reality
- Evidence33
- Adoption
- Insufficient
- Hype gap+35
- Incentives80
- Confidence55
The Joint Committee of the EBA, EIOPA and ESMA handed EU governments an autumn risk update that puts reliance on non-EU ICT, clearing, ratings and foreign-currency funding at the top, with AI-enabled attacks and quantum next.
Reality
- Evidence45
- Adoption30
- Hype gap+30
- Incentives55
- Confidence45
Head of cryptography Yehuda Lindell says hash-based post-quantum signatures may not split across parties. So Coinbase is researching threshold decryption plus a programmable HSM for the $250 billion it custodies.
Reality
- Evidence46
- Adoption18
- Hype gap+24
- Incentives62
- Confidence52
Earlier coverage
- Google certified a quantum attack on elliptic curve cryptography without disclosing the algorithm
Science · September 22, 2026 · 1 publisher
- TigerByte leaves stealth with $3M to bolt packet inspection onto legacy avionics
Security · September 20, 2026 · 1 publisher
- Cloudflare swapped a years-old TLS guess for a daily probe of every origin
Build · September 20, 2026 · 1 publisher
- Seal's only pre-release design review came from the agent that wrote much of its code
Build · September 19, 2026 · 1 publisher
- Upgrading to JDK 27 switches TLS 1.3 handshakes to hybrid post-quantum key exchange
Build · September 18, 2026 · 1 publisher
- DigiCert folds post-quantum migration into the 47-day certificate mandate
Product · September 17, 2026 · 1 publisher
- Microsoft tests post-quantum TLS issuance with seven certificate authorities outside public trust
Product · September 17, 2026 · 1 publisher
- EO 14412 gives US agencies until Dec. 31, 2030 to fix key establishment on high-value assets
Product · September 17, 2026 · 1 publisher
- LGT put hybrid post-quantum key exchange in front of live online banking customers
Product · September 17, 2026 · 1 publisher
- Java 27 couples post-quantum TLS 1.3 to two newly flipped JVM defaults
Build · September 15, 2026 · 4 publishers
- Apple signs iPhone photos inside the camera hardware before software touches the pixels
Security · September 16, 2026 · 1 publisher
- Apple's Reference Image mode signs photos with a key the camera sensor made in the factory
Product · September 16, 2026 · 1 publisher
- Oracle's post-quantum backport reaches JDK 8 and 11 last, in the second half of 2027
Product · September 15, 2026 · 1 publisher
- Fortaegis seats its contract manufacturer and Tokyo Electron's venture arm inside a $50M round
Build · September 14, 2026 · 1 publisher
- Google's own post-quantum deadline runs two years ahead of the NSA's target
Product · September 13, 2026 · 1 publisher
- Opting into quantum-ready Play signing invalidates the SHA-1 in your Android OAuth client
Build · September 12, 2026 · 1 publisher
- More than 100 researchers with AI agents cut Bitcoin's quantum-attack benchmark sevenfold in two months
Invest · September 11, 2026 · 2 publishers
- NIST sets 2030 and 2035 retirement dates for quantum-vulnerable algorithms, raising stakes for banks
Leadership · September 11, 2026 · 1 publisher
- FINMA gives Swiss banks about a year to put a post-quantum plan before the board
Invest · September 11, 2026 · 1 publisher
- Crowdsourced AI agents cut one step of a Bitcoin quantum attack by 86 per cent in about two months
Invest · September 10, 2026 · 1 publisher
- A new IACR estimate sizes the secp256k1 break at 1,450 logical qubits and 40 million Toffoli gates
Security · September 10, 2026 · 1 publisher
- IonQ's compiled secp256k1 break needs twice the qubits of its 2027 machine
Security · September 10, 2026 · 1 publisher
- ISARA's chief executive would scope post-quantum migration by cryptography in live use
Leadership · September 10, 2026 · 1 publisher
- A 2,420-byte DNSSEC signature overruns the UDP buffer DNS software commonly advertises
Build · September 10, 2026 · 1 publisher
- Java 27 makes G1 the collector on the 1-CPU container that used to get Serial
Build · September 10, 2026 · 1 publisher
- Google and Ethereum set 2029 dates one year ahead of NIST's ECDSA deprecation
Invest · September 9, 2026 · 1 publisher
- IonQ credits SkyWater's standard lines with cutting its chip design cycle to two months
Product · September 8, 2026 · 1 publisher
- IonQ's secp256k1 estimate spends 13 physical qubits on every logical one
Build · September 8, 2026 · 1 publisher
- Ethereum's protocol cluster declined 28 of the 62 EIPs proposed for Hegota
Invest · September 7, 2026 · 2 publishers
- The post-quantum signature NIST finalised runs 72 times the bytes of today's ECDSA
Invest · September 4, 2026 · 2 publishers
- World open-sources ProveKit to keep age checks on the user's own phone
Product · September 2, 2026 · 1 publisher
- A quantum-resistant bitcoin spend clears mainnet under today's consensus rules
Product · August 30, 2026 · 1 publisher
- JDK 24 relocates the post-quantum blocker to your key custody plumbing
Build · August 28, 2026 · 1 publisher
- Bitcoin's first post-quantum signature BIP arrives with its tradeoffs already conceded
Invest · August 26, 2026 · 1 publisher
- The quantum race stopped being about money. It now hands boards two dates: 2029 and 2030
Leadership · August 26, 2026 · 1 publisher
- TCG hands hardware buyers a version number: PC Client TPM Profile 1.07
Build · August 25, 2026 · 1 publisher
- Red Hat counted 572 quantum-vulnerable spots in OpenStack. The obstacle is OpenStack's own pins.
Product · August 25, 2026 · 1 publisher
- Ethereum's quantum plan gets a one-way switch: draft EIP would retire BLS for good
Invest · August 25, 2026 · 1 publisher
- TCG writes down what "quantum-safe TPM" means, and buyers finally get a document to argue with
Security · August 24, 2026 · 2 publishers
- Harvest now, decrypt soon: post-quantum migration is a funded program, not a research topic
Leadership · August 21, 2026 · 1 publisher