top of page


🇳🇱 NETHERLANDS PQC SPOTLIGHT: SOME OF EUROPE’S STRONGEST GUIDANCE, BUT STILL NO NATIONAL MANDATE
The Netherlands sits in Tier 2 of SITG-Consulting’s Europe’s Post-Quantum Readiness 2026 assessment. That is an important distinction. The Netherlands has produced some of the strongest practical PQC migration guidance we found anywhere in Europe. But strong guidance is not the same thing as a governed national migration programme. Government Posture: Strong Guidance, No Binding Migration Programme The Dutch position is built around two important pieces of work. The PQC Migra
Brian Couzens
Aug 62 min read
Â
Â
Â


🇱🇹 LITHUANIA PQC SPOTLIGHT: THE ONLY EU MEMBER STATE TO REACH TIER 1
Lithuania stands apart in our assessment of post-quantum readiness across the EU-27. It is the only Member State to reach Tier 1, High Confidence. This does not mean Lithuania has completed its PQC migration. It means something more useful at this stage: the country has established publicly verifiable migration machinery, with governance, mandatory actions, implementation dates, inventory requirements and procurement provisions. Government Posture: From Awareness to Execution
Brian Couzens
Aug 52 min read
Â
Â
Â


NORWAY PQC SPOTLIGHT: EARLY QUANTUM TRANSITION, NO NATIONAL MANDATE
Norway’s digital ecosystem is one of the most mature and trusted in Europe. The country is now entering an early but serious quantum-transition phase. The government has begun developing a national quantum technology strategy for publication in 2026, supported by the Research Council of Norway, Innovation Norway and the Norwegian National Security Authority (NSM). Investment is also increasing, including NOK 244 million awarded to four national quantum research centres. NSM’s
Brian Couzens
Aug 22 min read
Â
Â
Â


CRYPTOANALYSIS: LET ME EXPLAIN THIS FFS
The sensational headlines surrounding Anthropic’s AI work on HAWK reveal a fundamental misunderstanding of how global cybersecurity actually operates: cryptanalysis is not a panic event; it is the continuous quality-control engine of the digital world. The framing that "AI broke post-quantum security and everything is collapsing" is pure noise. Here is the reality. 1. This Is an Ongoing Discipline Run by Dedicated Teams Cryptanalysis isn't something that happens once in a blu
Brian Couzens
Aug 12 min read
Â
Â
Â


CUBA PQC SPOTLIGHT: STATE‑CENTRIC CYBERSECURITY, ZERO PQC READINESS
Cuba operates one of the most state‑controlled cybersecurity regimes in the Western Hemisphere. Its legal architecture is built on Decreto 360/2019, Decreto‑Ley 35/2021, and Resolution 105/2021, all of which focus on ICT security, cyberspace defence, telecom control, and mandatory incident reporting - none of which contain PQC migration, crypto‑agility, or quantum‑risk provisions. Government Posture: Strong Control, No Quantum Strategy Cuba’s cybersecurity model is centralise
Brian Couzens
Aug 12 min read
Â
Â
Â


🇦🇪 UAE PQC Spotlight: High-Value Targets Meet Global Leadership in Quantum Readiness
The UAE is a high-maturity digital state with world-class infrastructure, aggressive AI adoption, and strong cybersecurity regulation. Recognizing its exposure as a global hub, the UAE moved decisively into action. In late November 2025, the UAE Cybersecurity Council approved the National Encryption Policy and Executive Regulation No. 71 of 2024, legally mandating Post-Quantum Cryptography (PQC) migration. Government Posture: Global Pioneer in Mandatory Migration The UAE's di
Brian Couzens
Jul 302 min read
Â
Â
Â


🇨🇴 Colombia PQC Spotlight: Early Stage Readiness, Digital Signature Reform, Sector Exposure
Colombia is in the early stage of PQC adoption. The country faces elevated quantum risk due to heavy reliance on classical cryptography across financial services, government platforms, and telecom networks. Movement has begun through digital signature reform and initial alignment with NIST standards, but Colombia has no national PQC roadmap yet. Government Posture: Digital Signature Reform Colombia’s digital signature law, Law 527 of 1999, is being updated to include post qua
Brian Couzens
Jul 272 min read
Â
Â
Â


DigiCert's 2026 Quantum Readiness Outlook
Every week I see organisations announcing their Post-Quantum Cryptography strategy. Strategies. Roadmaps. Working groups. Steering committees. Pilot programmes. Then along comes some actual data. DigiCert's 2026 Quantum Readiness Outlook surveyed 1,001 IT and cybersecurity decision-makers across the United States, United Kingdom and Australia. 87% say they are planning, testing or implementing PQC. Only 7% have deployed quantum-safe or hybrid cryptography across most of their
Brian Couzens
Jul 272 min read
Â
Â
Â


🇹🇼 Taiwan PQC Spotlight: Semiconductor Security, National Defense, Quiet Infrastructure Uplift
Taiwan is advancing PQC through semiconductor security requirements, national defense modernization, and selective government upgrades. It does not publish loud quantum strategies, but it is quietly building one of the most security driven PQC environments in Asia due to geopolitical exposure and its central role in global chip supply chains. Government Posture: Security Driven PQC Adoption The Executive Yuan and National Science and Technology Council treat quantum risk as
Brian Couzens
Jul 262 min read
Â
Â
Â


TLS 1.3 hasn't become TLS 1.4.
It has become less tolerant of the past. This month, the IETF published RFC 9846, which replaces RFC 8446 while keeping the protocol as TLS 1.3. On the surface, it looks like a minor revision. It isn't. One change stands out: Implementations MUST NOT negotiate TLS 1.0 or TLS 1.1. Not "SHOULD NOT." Not "avoid where possible." MUST NOT. That matters because we're reaching a tipping point. For years, organisations carried obsolete cryptography because "it still works." Increasin
Brian Couzens
Jul 252 min read
Â
Â
Â


🇮🇳 India PQC Spotlight: National Quantum Mission, Sovereign Algorithms, Accelerated Infrastructure
India is emerging as Asia’s most assertive sovereign adopter of Post Quantum Cryptography. Under the National Quantum Mission and MeitY’s PQC Task Force, the country is driving a three phase migration plan backed by domestic testing and procurement requirements. PQC has moved from research into a core element of digital sovereignty and critical infrastructure security. Government Posture: NQM Steering and Indigenous Sovereignty DST, MeitY, C DOT, CERT In, and DSCI lead a dua
Brian Couzens
Jul 242 min read
Â
Â
Â


FIPS 140-3 Gap Analysis: fix the module before the lab, not after
For many years we have run cryptographic module readiness reviews inside larger governance and assurance engagements. It was never a named line item. It was the work done before a vendor spent money at a testing laboratory, so the money was not wasted. We have now formalised it as a defined service: the SITG FIPS 140-3 Gap Analysis. The context is a hard deadline. FIPS 140-2 certificates sunset on 21 September 2026 and move to the Historical List. From that date, a module wit
Brian Couzens
Jul 232 min read
Â
Â
Â


🇸🇬 Singapore PQC Spotlight: Strategy, Deployment, & Timelines
Singapore is Asia's most operationally advanced PQC adopter. With a unified strategy, live quantum safe networks, and proactive regulators, PQC has moved from theory to structured deployment. Government Posture: Centralised & Risk-Based Leadership: Strategy led jointly by CSA, National Quantum Office, MAS, and IMDA. Standards: PQC is the primary migration path, aligned with NIST FIPS 203, 204, and 205. Core Milestones: End 2025: CII operators must complete full crypto invento
Brian Couzens
Jul 232 min read
Â
Â
Â


🇰🇷 South Korea PQC Spotlight: High Capability, Master Plan in Motion, Mandates Not Yet Issued
South Korea is a global semiconductor and technology powerhouse. It does not have a CNSA style, economy wide crypto retirement deadline, but it does have a government backed PQC Master Plan, sector wide pilots, and a national playbook aimed at transforming the country’s cryptographic infrastructure by 2035. Industry is still moving faster than regulation, but the state is not passive. Korea is building a phased and coordinated PQC transition. Government Posture: Master Plan a
Brian Couzens
Jul 222 min read
Â
Â
Â


NZ SPOTLIGHT: The Quiet Five Eyes Laggard With One World‑Class PQC Contribution
New Zealand is the only Five Eyes member with no PQC retirement deadline. Conservative and advisory in posture, yet home to one of the globally significant contributors to ML‑DSA. This is NZ’s real PQC position. Government posture: NZISM v3.8 (Sept 2024), Section 2.4 requires agencies to inventory cryptographic assets, monitor GCSB updates, and prepare migration plans. No PQC algorithms are approved, and no deadline exists for retiring RSA, DH, ECDH or ECDSA. GSMA’s 2025 tra
Brian Couzens
Jul 221 min read
Â
Â
Â


Quantum Is No Longer a Cyber Risk. It's a Fiduciary Duty.
Buried in a legal update this week was a signal that should concern every Board. Lawyers are now being trained on post-quantum cryptography, quantum evidence, AI-quantum convergence and Q-Day. Think about that. The legal profession is preparing for the consequences. Is your Board? Now imagine the cross-examination. "When did you become aware that quantum computing would eventually render your cryptography obsolete?" "You knew your regulators had already issued migration guida
Brian Couzens
Jul 191 min read
Â
Â
Â


Malaysia - Southeast Asia’s Quantum Risk Front Runner -PQC - 🇲🇾 SPOTLIGHT:
Malaysia has quietly become ASEAN’s most assertive mover on quantum risk and PQC. Not the most advanced, not the most resourced, but the most coordinated, the most visible, and the first to publish a national PQC roadmap. This is why Malaysia now sits in the regional spotlight. 1. First in ASEAN with a National PQC Roadmap Malaysia is the only ASEAN member with a formal PQC transition roadmap. It is structured, time bounded, and aligned with NIST’s migration track. Core pilla
Brian Couzens
Jul 192 min read
Â
Â
Â
FIPs140-3 A Thematic Review
A half-year read on where FIPS 140-3 validation actually stands. Between January and mid-July 2026, 30 new FIPS 140-3 certificates were issued or announced across non-hyperscaler, non-tier-1 vendors, spanning HSMs, authentication, cryptographic libraries, edge/IoT and embedded modules. With FIPS 140-2 fully retiring on 21 September 2026, this is no longer a future consideration. It's active, measurable, and already reshaping vendor selection. This SITG-Consulting Thematic Rev
Brian Couzens
Jul 181 min read
Â
Â
Â
An Analysis of ASD's PQC Vendor Approach.
One supplier can destroy five years of post-quantum planning. Not through incompetence. Through dependency. The conversation around post-quantum cryptography still revolves around algorithms, migration plans and technical roadmaps. That misses the point. Modern organisations no longer control much of their own cryptography. It sits inside cloud platforms, software, managed services, operational technology and hardware supplied by third parties. Your programme cannot move fast
Brian Couzens
Jul 161 min read
Â
Â
Â


Kudankulam Shows Why Critical Infrastructure Security Is a Governance Problem, Not Just a Cybersecurity Problemcff
Sensitive documents reportedly linked to India's Kudankulam Nuclear Power Plant have been exposed following a ransomware attack affecting a contractor. According to Reuters, the leaked material includes engineering drawings, supplier information and inspection records, while there is currently no evidence that reactor control systems themselves were compromised. That distinction matters. Too often, critical infrastructure security is viewed through the lens of perimeter defen
Brian Couzens
Jul 151 min read
Â
Â
Â
bottom of page
