top of page


Quantum Weekly 3 -9th August 2026
๐The Global Signals That Actually Mattered (3 - 9 August 2026) Brian C Founder & CEO, SITG-Consulting | Thought Leader & Forensic Strategist Quantum Risk, PQC, ERM, Compliance & Governance | Independent Validation | Board Advisor | Author | Quantum Risk Management 10 August 2026 This week's structural signal was theoretical provenance meeting sovereign procurement, moving on independent clocks. An Amazon Web Services cryptographer posted a preliminary polynomial-time quantum
Brian Couzens
4 days ago12 min read
ย
ย
ย


๐ณ๐ฑ NETHERLANDS PQC SPOTLIGHT: SOME OF EUROPEโS STRONGEST GUIDANCE, BUT STILL NO NATIONAL MANDATE
The Netherlands sits in Tier 2 of SITG-Consultingโs Europeโs Post-Quantum Readiness 2026 assessment. That is an important distinction. The Netherlands has produced some of the strongest practical PQC migration guidance we found anywhere in Europe. But strong guidance is not the same thing as a governed national migration programme. Government Posture: Strong Guidance, No Binding Migration Programme The Dutch position is built around two important pieces of work. The PQC Migra
Brian Couzens
Aug 62 min read
ย
ย
ย


๐ฑ๐น LITHUANIA PQC SPOTLIGHT: THE ONLY EU MEMBER STATE TO REACH TIER 1
Lithuania stands apart in our assessment of post-quantum readiness across the EU-27. It is the only Member State to reach Tier 1, High Confidence. This does not mean Lithuania has completed its PQC migration. It means something more useful at this stage: the country has established publicly verifiable migration machinery, with governance, mandatory actions, implementation dates, inventory requirements and procurement provisions. Government Posture: From Awareness to Execution
Brian Couzens
Aug 52 min read
ย
ย
ย


๐ Quantum Weekly - The Global Signals That Actually Mattered (27 July - 2 August 2026)
Brian C Founder & CEO, SITG-Consulting | Thought Leader & Forensic Strategist Quantum Risk, PQC, ERM, Compliance & Governance | Independent Validation | Board Advisor | Author | Quantum Risk Management 3 August 2026 This week's structural signal was verification, not capability. Anthropic stated its AI model broke a NIST post-quantum signature candidate that had survived two full rounds of accredited human expert review; the algorithm's own developers confirmed the finding an
Brian Couzens
Aug 310 min read
ย
ย
ย


DigiCert's 2026 Quantum Readiness Outlook
Every week I see organisations announcing their Post-Quantum Cryptography strategy. Strategies. Roadmaps. Working groups. Steering committees. Pilot programmes. Then along comes some actual data. DigiCert's 2026 Quantum Readiness Outlook surveyed 1,001 IT and cybersecurity decision-makers across the United States, United Kingdom and Australia. 87% say they are planning, testing or implementing PQC. Only 7% have deployed quantum-safe or hybrid cryptography across most of their
Brian Couzens
Jul 272 min read
ย
ย
ย


๐ Quantum Weekly - The Global Signals That Actually Mattered (20 July - 26 July 2026)
27 July 2026 This week the confirmed signal set was dominated by state and quasi-state actors building coordination infrastructure rather than by vendors announcing capability. Israel opened a funded tender for national quantum R&D infrastructure, the UK's National Cyber Security Centre convened its first joint government-industry PQC migration workshop, and Japan's government-backed research agency launched a fiscal-year-scheduled silicon quantum manufacturing programme. In
Brian Couzens
Jul 279 min read
ย
ย
ย


TLS 1.3 hasn't become TLS 1.4.
It has become less tolerant of the past. This month, the IETF published RFC 9846, which replaces RFC 8446 while keeping the protocol as TLS 1.3. On the surface, it looks like a minor revision. It isn't. One change stands out: Implementations MUST NOT negotiate TLS 1.0 or TLS 1.1. Not "SHOULD NOT." Not "avoid where possible." MUST NOT. That matters because we're reaching a tipping point. For years, organisations carried obsolete cryptography because "it still works." Increasin
Brian Couzens
Jul 252 min read
ย
ย
ย


๐ฐ๐ท South Korea PQC Spotlight: High Capability, Master Plan in Motion, Mandates Not Yet Issued
South Korea is a global semiconductor and technology powerhouse. It does not have a CNSA style, economy wide crypto retirement deadline, but it does have a government backed PQC Master Plan, sector wide pilots, and a national playbook aimed at transforming the countryโs cryptographic infrastructure by 2035. Industry is still moving faster than regulation, but the state is not passive. Korea is building a phased and coordinated PQC transition. Government Posture: Master Plan a
Brian Couzens
Jul 222 min read
ย
ย
ย


NZ SPOTLIGHT: The Quiet Five Eyes Laggard With One WorldโClass PQC Contribution
NewโฏZealand is the only Five Eyes member with no PQC retirement deadline. Conservative and advisory in posture, yet home to one of the globally significant contributors to MLโDSA. This is NZโs real PQC position. Government posture: NZISM v3.8 (Sept 2024), Section 2.4 requires agencies to inventory cryptographic assets, monitor GCSB updates, and prepare migration plans. No PQC algorithms are approved, and no deadline exists for retiring RSA, DH, ECDH or ECDSA. GSMAโs 2025 tra
Brian Couzens
Jul 221 min read
ย
ย
ย


๐ Quantum Weekly - The Global Signals That Actually Mattered (13 July - 19 July 2026)
Brian C Founder & CEO, SITG-Consulting | Thought Leader & Forensic Strategist Quantum Risk, PQC, ERM, Compliance & Governance | Independent Validation | Board Advisor | Author | Quantum Risk Management July 20, 2026 This week the ecosystem moved from announcement to institutionalisation across three separate layers: standards, manufacturing and procurement. A code-based post-quantum algorithm reached ISO standardisation, giving the PQC landscape a second formal standards trac
Brian Couzens
Jul 2012 min read
ย
ย
ย


Quantum Is No Longer a Cyber Risk. It's a Fiduciary Duty.
Buried in a legal update this week was a signal that should concern every Board. Lawyers are now being trained on post-quantum cryptography, quantum evidence, AI-quantum convergence and Q-Day. Think about that. The legal profession is preparing for the consequences. Is your Board? Now imagine the cross-examination. "When did you become aware that quantum computing would eventually render your cryptography obsolete?" "You knew your regulators had already issued migration guida
Brian Couzens
Jul 191 min read
ย
ย
ย


Malaysia - Southeast Asiaโs Quantum Risk Front Runner -PQC - ๐ฒ๐พ SPOTLIGHT:
Malaysia has quietly become ASEANโs most assertive mover on quantum risk and PQC. Not the most advanced, not the most resourced, but the most coordinated, the most visible, and the first to publish a national PQC roadmap. This is why Malaysia now sits in the regional spotlight. 1. First in ASEAN with a National PQC Roadmap Malaysia is the only ASEAN member with a formal PQC transition roadmap. It is structured, time bounded, and aligned with NISTโs migration track. Core pilla
Brian Couzens
Jul 192 min read
ย
ย
ย
FIPs140-3 A Thematic Review
A half-year read on where FIPS 140-3 validation actually stands. Between January and mid-July 2026, 30 new FIPS 140-3 certificates were issued or announced across non-hyperscaler, non-tier-1 vendors, spanning HSMs, authentication, cryptographic libraries, edge/IoT and embedded modules. With FIPS 140-2 fully retiring on 21 September 2026, this is no longer a future consideration. It's active, measurable, and already reshaping vendor selection. This SITG-Consulting Thematic Rev
Brian Couzens
Jul 181 min read
ย
ย
ย
An Analysis of ASD's PQC Vendor Approach.
One supplier can destroy five years of post-quantum planning. Not through incompetence. Through dependency. The conversation around post-quantum cryptography still revolves around algorithms, migration plans and technical roadmaps. That misses the point. Modern organisations no longer control much of their own cryptography. It sits inside cloud platforms, software, managed services, operational technology and hardware supplied by third parties. Your programme cannot move fast
Brian Couzens
Jul 161 min read
ย
ย
ย


The White House Quantum Summit wasnโt the story.
Americaโs transition from quantum strategy to quantum execution was. In the span of three weeks, the United States compressed years of quantum policy into a coordinated national programme: Executive Order 14412 accelerating Post-Quantum Cryptography (PQC) migration Executive Order 14413 strengthening the national quantum innovation ecosystem The Department of Defense PQC Strategy OMB M-26-15 defining a structured federal migration roadmap QuantumEAGLe aligning government and
Brian Couzens
Jul 152 min read
ย
ย
ย


The PQC Gap Nobody Has Named: Why Discovery and Posture Management Are Not Enough
July 12, 2026 The quantum threat isn't coming. It is already in your infrastructure. PQC Discovery and PQC Posture Management are maturing fast, but neither can deliver a governed, evidence-driven transformation. The missing capability is Transition Orchestration: the programme architecture that validates and proves every cryptographic decision. If your organization cannot prove every decision it makes, it does not control its cryptographic estate. It merely tracks it. Hard T
Brian Couzens
Jul 124 min read
ย
ย
ย
FINMA Quantum Computing PQC Guidance
FINMA's new guidance on Quantum Computing is welcome. It sends an important signal. Quantum risk is no longer a theoretical technology discussion. It is a governance and operational resilience issue that financial institutions are expected to address now. I agree with the direction of travel. Board-approved strategies, risk analysis, cryptographic inventories, crypto-agility and supplier management all deserve attention. However, I was struck by how extraordinarily light the
Brian Couzens
Jul 121 min read
ย
ย
ย


BREAKING: Quantum Just Got Secure-by-Design - And Silicon Is Moving First
๐จ BREAKING: Quantum Just Got Secure-by-Design - And Silicon Is Moving First The last 24 hours in PQC and quantum have been louder than anyone expected. ๐ฅ Europe may have just fired the starting gun on secure-by-design quantum hardware. ๐ช๐บ SEALSQ and Quobly signed a $5M deal to embed post-quantum cryptography directly into Quoblyโs silicon quantum processors. ๐ค Not PQC at the application layer. โ Not PQC wrapped around the cloud. โ๏ธ PQC integrated into the cryogenic contr
Brian Couzens
Jul 112 min read
ย
ย
ย


๐จ ๐๐๐๐๐๐๐๐: ๐๐ฎ๐๐ง๐ญ๐ฎ๐ฆ ๐๐ฎ๐ฌ๐ญ ๐๐จ๐ญ ๐๐๐๐ฎ๐ซ๐-๐๐ฒ-๐๐๐ฌ๐ข๐ ๐ง - ๐๐ง๐ ๐๐ข๐ฅ๐ข๐๐จ๐ง ๐๐ฌ ๐๐จ๐ฏ๐ข๐ง๐ ๐ ๐ข๐ซ๐ฌ๐ญ โก
The last 24 hours in PQC and quantum have been louder than anyone expected. ๐ฅ Europe may have just fired the starting gun on secure-by-design quantum hardware. ๐ช๐บ SEALSQ and Quobly signed a $5M deal to embed post-quantum cryptography directly into Quoblyโs silicon quantum processors. ๐ค Not PQC at the application layer. โ Not PQC wrapped around the cloud. โ๏ธ PQC integrated into the cryogenic control electronics themselves. ๐ง Weโre talking about Cryo-CMOS ASICs with PQC ac
Brian Couzens
Jul 112 min read
ย
ย
ย


CBOM: The Difference Between Discovery and Intelligence
The Missing Discipline The post-quantum conversation has a numbers problem. Vendors love to say they have found millions of cryptographic assets. That sounds serious. It sounds comprehensive. It sounds like the sort of number a board should pay attention to. But in most environments, that number is doing a lot of rhetorical work. What organisations usually have are millions of cryptographic instances. The same library. The same certificate. The same key store. The same implem
Brian Couzens
Jul 85 min read
ย
ย
ย
bottom of page
