PQC Governance Digest: Cut off 25 September 2026

The FIPS 140-2 sunset landed. The ESAs named quantum as a systemic risk. ETSI told the industry its entropy pipeline is not to be trusted. Three signals, three continents, one theme: the compliance clock is no longer counting down. It is running.
FIPS 140-2 Goes Historical: The Last Fallback Disappears
Standards / Regulator | North America | 21 September 2026
The Detail
On 21 September 2026, NIST's Cryptographic Module Validation Program moved every remaining FIPS 140-2 certificate to Historical status. The transition had been signalled for years; now it is done. Federal agencies should not include Historical modules in new procurements.
The timing compresses what was already a tight sequence. CMMC Level 2 enforcement begins on 10 November 2026, seven weeks from the sunset date. The CNSA 2.0 acquisition gate falls on 1 January 2027, 102 days later. Any organisation selling cryptographic products or services to US federal buyers now operates on a single validation standard: FIPS 140-3.
A Historical certificate is not a revocation. The modules keep running. But in a CMMC assessment or a federal procurement review, a Historical certificate invites questions, and questions risk becoming findings.
Why It Matters
This is not a policy announcement. It is a policy consequence. The fallback position for organisations that had not yet completed FIPS 140-3 validation has been removed. The procurement chain from vendor to integrator to agency must now demonstrate active FIPS 140-3 certificates tied to specific cryptographic module versions in production. For defence contractors, the seven-week gap between the FIPS 140-2 sunset and CMMC Level 2 enforcement is the tightest compliance window of the year.
ESAs Flag Quantum as a Systemic Risk to EU Financial Cryptography
Central Bank / Supervisor | Europe | 23 September 2026
The Detail
The Joint Committee of the European Supervisory Authorities (EBA, ESMA, EIOPA) published its Autumn 2026 risk update (JC_2026_29) on 23 September. For the first time, the joint risk assessment explicitly names quantum computing as a threat to the cryptographic foundations of the EU financial system.
The language is direct: quantum computing "could undermine cryptography systems widely used to secure communications, transactions, databases, and blockchains." The ESAs call on stakeholders to strengthen preparedness for risks arising from the rapid development of AI and quantum computing.
No specific PQC migration timeline is mandated. No technical standard is referenced. The signal is supervisory posture, not prescriptive regulation.
Why It Matters
The ESAs do not write risk assessments for academic interest. When all three supervisory authorities name quantum as a systemic risk in the same document, it establishes an expectation. Regulated financial institutions across banking, securities, and insurance should anticipate that quantum readiness will feature in upcoming DORA compliance assessments and supervisory dialogues.
The absence of a prescribed timeline is itself instructive. It places the burden on firms to demonstrate proactive preparedness rather than waiting for a mandate. Organisations that have not begun a cryptographic inventory will find this statement cited in future supervisory correspondence.
ETSI Introduces Entropy Zero Trust for Quantum Random Number Generators
Standards / Regulator | Global | 24 September 2026
The Detail
ETSI published TR 104 171 V1.1.1 on 24 September, the first standards-body guidance dedicated to the security of quantum random number generators across their full lifecycle.
The report covers quantum entropy-source validation, randomness extraction, operational monitoring for entropy degradation, bias detection, hardware failure modes, tamper protection, side-channel attack mitigation, and output provenance through the supply chain.
The centrepiece is a concept ETSI calls Entropy Zero Trust: every stage of the entropy pipeline is treated as potentially vulnerable rather than assuming that any individual component can be inherently trusted. The framework applies from the quantum source through the hardware platform, interfaces, operational monitoring, and shared computing environments.
Why It Matters
Entropy quality is the foundation every PQC algorithm stands on. A quantum random number generator that passes statistical tests but leaks side-channel information, or whose entropy degrades under operational stress, renders ML-KEM key generation and ML-DSA signing deterministic and exploitable. The algorithm is correct; the input is compromised.
This guidance fills a gap that the PQC standards themselves do not address. FIPS 203 and FIPS 204 specify algorithms, not the quality of the randomness fed into them. TR 104 171 provides the audit framework for the layer beneath: the entropy pipeline that supplies every key, every nonce, every signature.
Organisations procuring QRNG hardware, or building systems that depend on quantum-derived randomness, now have a standards reference to write into procurement specifications and audit checklists.
Global Sweep
North America: The FIPS 140-2 sunset is the headline. CMMC Level 2 enforcement follows on 10 November. OMB M-26-15 agency migration plans remain due in approximately 30 days. No new executive directives this window.
Europe: The ESAs' Autumn 2026 risk update (JC_2026_29) marks the first joint supervisory authority statement explicitly naming quantum computing as a cryptographic threat to the EU financial system. No ENISA or EC instruments this window.
India and South Asia: No in-window governance signals. RBI Deputy Governor Murmu's call for quantum-proofing India's payment systems (11 September) was logged as a background addition during this scan. No formal RBI circular has followed.
Asia-Pacific: Quiet window. Japan, Singapore, South Korea, and Australia produced no new PQC governance instruments in the 18-25 September period.
Latin America: Null. No qualifying signals detected.
Africa and Middle East: Null for new instruments. GISEC 2026 material was logged in the prior weekly run.
Global (standards bodies): ETSI TR 104 171 is the standout. No new IETF RFCs, ITU-T recommendations, or ISO/IEC publications in the PQC or quantum security space this window.
SITG-Consulting Comment
Three signals from three different governance tiers landed in the same week, and each operates at a different layer of the cryptographic stack. NIST removed the FIPS 140-2 fallback at the validation layer. The ESAs elevated quantum risk at the supervisory layer. ETSI addressed the entropy layer beneath the algorithms themselves.
The pattern is convergence without coordination. No single body orchestrated this sequence. But taken together, the week of 18-25 September 2026 tightened the compliance environment at every level that matters: the modules organisations deploy, the supervisory expectations they face, and the randomness their cryptographic operations depend on.
For any organisation running a PQC migration programme, the immediate action items are clear. Verify that cryptographic modules hold active FIPS 140-3 certificates. Begin documenting quantum readiness for DORA supervisory dialogues. And audit the entropy pipeline, because the strongest algorithm built on compromised randomness protects nothing.
What Was NOT Missed
The following items appeared in search results but fall outside the 18-25 September 2026 window or do not qualify as governance signals:
NIST PQC round 3 candidate announcements and Apple corecrypto updates referenced in several outlets were from May 2026
Korea Science Ministry PQC training programme was June 2026
UAE Crypto Discovery Platform coverage (Computer Weekly) dated to June 2026
WISeKey/OISTE.ORG PQC Root of Trust announcement (25 September) was logged in the compliance matrix as a vendor deployment signal but excluded from PQC Governance Digest candidates as it lacks a governance or regulatory dimension
Disclaimer
This edition of the PQC Governance Digest is produced by SITG-Consulting for informational purposes. It does not constitute legal, regulatory, or technical advice. Readers should verify all cited sources independently and consult qualified professionals before making compliance or procurement decisions. Signal dates and document references were verified against primary sources at the time of publication.
SITG-Consulting | PQC Governance Digest | Cut-off 25 September 2026




Comments