top of page


The PQC Baker's Dozen: 13 Mistakes That Derail a Post-Quantum Cryptography Transition
The costliest mistake in a post-quantum cryptography (PQC) transition is made before a single algorithm changes. It is buying a product first. Each mistake below sets out what goes wrong and what to do instead, across PQC and crypto modernisation programmes, with the SITG-Consulting analysis and the primary source behind it. 1. Starting with a PQC product A product cannot tell you where your cryptography sits. Board mandate first, discovery second, vendor fifth. SITG-Consulti
Brian Couzens
9 hours ago3 min read


🌐 Quantum Weekly - The Global Signals That Actually Mattered (28 September - 4 October 2026)
The week of 28 September to 4 October fixed the dates and moved the algorithms. The NSA restated its 2027 and 2030 requirements for National Security Systems, NATO attached quarters to its post-quantum cryptography work, and South Korea's science ministry opened a national migration competition. In the same days, Germany's BSI advised against Classic McEliece for new developments, a web infrastructure operator set out a certificate authority built for post-quantum Merkle Tree
Brian Couzens
13 hours ago23 min read


The Hidden PQC Cost in Quantum M&A
M&A activity is rife in quantum computing. That is fact. What fewer boards are pricing in is the cost of post-quantum cryptography inside those deals. The quantum sector is moving from research-led development towards commercialisation, strategic investment and consolidation. IonQ, for example, reported agreements involving major acquisitions and held $3.3 billion in cash, cash equivalents and investments at the end of 2025. It also completed acquisitions including Oxford Ion
Brian Couzens
2 days ago3 min read


Post Quantum Cryptography: A Practical Introduction for New Graduates and Early‑Stage Partners
Introduce a practical way for new graduates to understand quantum risk and the work behind cryptographic migration. Cryptographic transformation is becoming one of the most significant operational challenges facing organisations that rely on digital trust. The shift to post quantum cryptography is not a theoretical exercise. It is a structured change programme that touches governance, sequencing, supplier dependencies, retention policy, certificate lifecycles and long lived d
Brian Couzens
2 days ago3 min read


Mosca’s Theorem: The Equation That Tells You When to Start Post-Quantum Migration
Post-quantum cryptography is often discussed as a future technical programme. That framing is too comfortable. The question for boards, security leaders and technology executives is not whether a cryptographically relevant quantum computer will arrive on a particular date. The question is whether the organisation’s sensitive data will remain protected for as long as it needs to be, given the time required to change the cryptography that protects it. Michele Mosca’s risk inequ
Brian Couzens
2 days ago4 min read


PQC Governance Digest: Cut-off 2 October 2026
BSI Pulls Back on Classic McEliece as NSA Restates PQC Deadlines A national cryptographic authority has told its constituency to stop building new systems on a post-quantum algorithm that, according to industry reporting, an international standard added only four months ago. On 1 October, Germany's BSI advised that Classic McEliece should not be used for new developments after cryptanalytic advances lowered its assessed security level. The same day, the NSA restated that new
Brian Couzens
3 days ago4 min read


Thematic Reviews and the Governance Visibility Gap in Cryptographic Risk
Compliance frameworks tell organisations what controls to implement. They do not tell leadership whether those controls operate as intended across systems, vendors, and decision chains. This distinction is where governance failures take root, and where a thematic review provides visibility that periodic audits cannot. The gap is structural, not accidental. Audits assess controls against criteria. Thematic reviews examine how a specific risk theme behaves across an organisatio
Brian Couzens
5 days ago4 min read


What Evidence Actually Proves a PQC Migration Is Good
Organisations talk about post-quantum cryptography (PQC) migration as if buying a vendor solution is proof of progress. It is not. Procurement is not evidence. A pilot is not evidence. A press release is not evidence. Good PQC migration is not defined by activity. It is defined by verifiable outcomes. The distinction matters because regulators, auditors and boards are starting to ask a harder question: not whether a migration programme exists, but whether it can prove what it
Brian Couzens
6 days ago5 min read


Why PQC Vendors Are Not the Starting Point for Your Post-Quantum Transition
The Order Matters. Getting It Wrong Is Expensive. A growing number of organisations are beginning their post-quantum cryptography (PQC) transition with a vendor evaluation. They attend a conference, see a product demonstration, receive a pitch deck, and begin a procurement process. This is the wrong sequence. It produces partial coverage, unmanaged dependencies, and a governance gap that widens with every deployment decision made without a baseline. The transition to post-qua
Brian Couzens
6 days ago6 min read


Discovery Is Table Stakes for PQC. A CBOM Is Not Discovery.
PQC discovery is the entry requirement for any post-quantum cryptography (PQC) programme. An organisation that cannot show which cryptography it runs, where it runs and who owns it has no basis for prioritising, sequencing or reporting a migration. A Cryptographic Bill of Materials (CBOM) is often offered as proof that this work has been done. It is a different thing. This article sets out the distinction, the governance consequences of confusing the two and three questions a
Brian Couzens
6 days ago4 min read


PQC Governance Digest: Cut off 25 September 2026
The FIPS 140-2 sunset landed. The ESAs named quantum as a systemic risk. ETSI told the industry its entropy pipeline is not to be trusted. Three signals, three continents, one theme: the compliance clock is no longer counting down. It is running. FIPS 140-2 Goes Historical: The Last Fallback Disappears Standards / Regulator | North America | 21 September 2026 #FIPS140 #CNSA2 #CMMC #CryptoCompliance The Detail On 21 September 2026, NIST's Cryptographic Module Validation Progra
Brian Couzens
Sep 295 min read


🌐 Quantum Weekly - The Global Signals That Actually Mattered (21 September - 27 September 2026)
The week of 21–27 September was an assurance week. Three independent strands tested the premises cryptographic programmes rest on: a preprint from UC San Diego and Inria forged 1024-bit RSA signatures without factoring the key, public cryptanalysts broke five of China's newly published post-quantum candidate designs within days, and ETSI published guidance treating every stage of the entropy pipeline as untrusted until verified. Around those tests, the compliance and capital
Brian Couzens
Sep 2917 min read


Beyond the Hype: A Vendor-Neutral Framework for Your First PQC Hybrid Pilot
Key Takeaways: A full-estate Post-Quantum Cryptography (PQC) migration introduces unacceptable operational risk and unknown dependencies. A bounded PQC hybrid pilot isolates variables, captures decision-grade evidence, and proves rollback capabilities. Successful pilots require a complete Cryptographic Bill of Materials (CBOM) for the specific scope, an authenticated architecture, and a strict evidence contract. Governance gates must mandate three clear outcomes: Expand, Paus
Brian Couzens
Sep 283 min read


The State of Post-Quantum Cryptography in 2026: A Global Map of PQC Algorithms and Migration Deadlines
Post-quantum cryptography (PQC) has crossed an important line: it is no longer a research topic but a compliance deadline. As of September 2026, the algorithms are standardized, national migration timelines are published across five continents, and the main risk has shifted from "will the math hold?" to "will your organization migrate in time?" This article maps the current global state of PQC: the algorithms, the country-by-country deadlines, and the uncomfortable adoption g
Brian Couzens
Sep 283 min read


Malaysia Achieves Tier 1 Status in Post-Quantum Cryptography Readiness
On 15 September 2026, Malaysia's National Security Council (Majlis Keselamatan Negara), an agency of the Prime Minister's Department, confirmed Malaysia as the only ASEAN member state at Tier 1 for post-quantum cryptography migration readiness. The assessment behind that finding is SITG-Consulting's ASEAN Post-Quantum Cryptography Readiness 2026: An Empirical Assessment of the ASEAN-10, published on 1 September. The statement and the report were reported by: Bernama, Malaysia
Brian Couzens
Sep 273 min read


Post-Quantum Cryptography in Plain English: The Backfill Session at the MY Digital Trust Summit 2026
At the MY Digital Trust Summit 2026 in Kuala Lumpur, a speaker could not make the morning session. We were asked to fill fifteen minutes on post-quantum cryptography (PQC) for a non-specialist audience, at short notice. No slides. No preparation. Just a stand-up talk for three hundred people, from an ASEAN perspective, in plain English. We call it the backfill session. Watch the full talk Watch on YouTube: Post-Quantum Cryptography in Plain English — MY Digital Trust Summit 2
Brian Couzens
Sep 252 min read


FIPS 140-3 Gap Analysis: What the September Deadline Exposed
On 21 September 2026, NIST's Cryptographic Module Validation Programme moved all remaining FIPS 140-2 certificates to historical status. The date had been signposted for years. The preparation, across a significant number of regulated organisations, had not kept pace. Historical status does not mean the modules stop functioning. It means they no longer satisfy federal procurement requirements and, by extension, the compliance expectations of any regulated sector that referenc
Brian Couzens
Sep 254 min read


Demand has a date. Supply has a register.
Author: Brian Couzens Publish date: 23 September 2026 Where post-quantum migration stands in September 2026 As at 21 September 2026, sixteen FIPS 140-3 certificates on the NIST Cryptographic Module Validation Program record carry a post-quantum algorithm family inside the validated boundary. That count treats LMS, the stateful hash-based signature scheme standardised in NIST SP 800-208, as a post-quantum family. It is a count of validated post-quantum capability, not a count
Brian Couzens
Sep 238 min read


Stop Buying Cryptographic Debt for PQC
A proposed post-quantum semiconductor and cybersecurity centre in Switzerland offers a useful warning for every organisation purchasing technology today. Post-quantum cryptography is no longer only an algorithm-selection exercise. It is becoming a question of procurement, product lifecycles, hardware dependency, supplier assurance and digital sovereignty. The central issue is simple: Can the systems being purchased today remain secure when their current cryptography is no lon
Brian Couzens
Sep 214 min read


🌐 Quantum Weekly - The Global Signals That Actually Mattered (14 September - 20 September 2026)
Brian C Founder & CEO, SITG-Consulting | Thought Leader & Forensic Strategist Quantum Risk, PQC, ERM, Compliance & Governance | Independent Validation | Board Advisor | Author | Quantum Risk Management 21 September 2026 This week, quantum moved from research infrastructure into sovereign industrial policy. The United States committed over $2.2 billion in combined federal and private capital to quantum manufacturing and fault-tolerant development, NVIDIA launched the orchestra
Brian Couzens
Sep 2113 min read
All Posts
bottom of page
