top of page

PQC Governance Digest: 9 Oct 2026

Writer: Brian Couzens
Brian Couzens
2 minutes ago
4 min read
PQC Governance Digest, cut-off 9 October 2026: map highlighting the US and EU with GAO, Europol, Microsoft and IETF signals

PQC Governance Digest: Cut-off 9 October 2026

The US Government Accountability Office has put a number on federal PQC readiness: none of 24 major agencies had fully carried out three initial steps, namely inventory, funding and testing. Europol told organisations not to wait for certainty on quantum timing, and Microsoft and the IETF moved certificate infrastructure forward. Four signals cleared verification. Four regions returned null.


1. United States: GAO Sets the Federal Baseline

Theme tags: Government audit | Cryptographic inventory | Transition funding

The Detail

GAO released GAO-27-108740 on 6 October 2026. It assessed the 24 Chief Financial Officers Act agencies against three practices: a prioritised inventory of systems with vulnerable cryptography, the funding needed to transition priority systems, and PQC testing in agency environments. None fully addressed all three. GAO attributes the gaps in part to a lack of cryptography expertise, of inventory and funding processes, and of testing plans.

This is the public version of a sensitive report issued in September 2025, which made 89 recommendations across 23 agencies. The Department of the Interior did not respond.

Why It Matters

The findings predate OMB M-26-15 (24 June 2026), whose agency PQC migration plans are due by 22 October 2026. Read the report as the baseline those plans start from, not as a verdict on them. Suppliers to federal agencies may find inventory and funding questions reaching them through GAO's follow-up. Our full analysis is in None of 24: The GAO Audit of Federal PQC Readiness.


2. Europe: Europol Rejects Waiting for Certainty

Theme tags: EU agency | Harvest-now-decrypt-later | Crypto-agility

The Detail

On 7 October 2026 Europol published two reports: "Quantum computing and cryptocurrencies: Bridging technical expertise and decision-making" and "Harvest now, decrypt later". Its announcement states that "[t]he timing of these capabilities remains uncertain. However, this should not be the main concern", that "adapting systems and coordinating security upgrades will take time", and that "crypto-agility should be pursued proactively". Press coverage reports that the cryptocurrency report, from Europol's European Cybercrime Centre (EC3), identifies wallets rather than blockchains as the primary point of exposure.

Why It Matters

Europol removes timing uncertainty as a reason to defer. Proactive crypto-agility is an architecture and ownership question: which systems can change algorithms without re-engineering, and who takes that decision. That is the scope of cryptographic agility services.


3. Certificate Infrastructure: Microsoft Guidance and the IETF Composite KEM Draft

Theme tags: ML-DSA-87 | ML-KEM | X.509 PKI | Vendor readiness

The Detail

On 8 October 2026 the Microsoft Security Blog published guidance urging organisations to test their certificate ecosystems for post-quantum authentication. It centres on the PQC TLS Pilot Program, launched on 27 August 2026 under the Trusted Root Program, in which seven CAs (ComSign, DigiCert, HARICA, IdenTrust Services, Sectigo, Shanghai Electronic Certification Authority and SSL.com) operate ML-DSA-87 pilot roots for non-production testing. Supported Windows 11 systems can evaluate ML-DSA certificates in pilot scenarios from the 28 July 2026 updates. Microsoft's six steps begin with inventorying certificate-dependent systems and include assessing CA, PKI, HSM and platform vendor readiness.

On 6 October 2026 the IETF LAMPS Working Group published revision 22 of draft-ietf-lamps-pq-composite-kem, which defines composite keys combining ML-KEM with RSA-OAEP, ECDH, X25519 or X448 for X.509. It is in IESG Evaluation for Proposed Standard and has enough positions to pass.

Why It Matters

Authentication is where dependency chains run deepest: certificates, trust anchors, HSMs, firmware and platform support must move together. Microsoft supplies a test environment; the IETF draft is the developing encoding specification. Vendor readiness should be established with evidence, which a PQC readiness assessment is designed to test.

Strategic Implications

Each of this week's signals assumes a current cryptographic inventory. It is the first of GAO's three practices and the first of Microsoft's six steps, and proactive crypto-agility cannot be planned without it. Organisations that have not started should map their cryptographic dependencies before selecting tools or vendors; a PQC Discovery Sprint is built for that first step.

Forward watch: OMB M-26-15 migration plans are due by 22 October 2026. The ETSI Security Conference runs 19 to 22 October; outcomes fall in the 17 to 23 October window. SAMA's reported cryptographic inventory deadline is 31 December 2026.


Global Sweep

North America: GAO and Microsoft (Sections 1 and 3).

Europe: Europol (Section 2).

Global: IETF composite KEM draft (Section 3). Standards watch: IETF PQUIP's "Adapting Constrained Devices for Post-Quantum Cryptography" (revision 07, 8 October 2026) is in IESG Evaluation for Informational RFC, with a 22 October telechat. IETF Datatracker

India and South Asia: Null. RBI's Q-SAFE expert committee issued no output in the window.

Asia-Pacific: Null.

Latin America: Null.

Africa and Middle East: Null. SAMA Circular 482021280 (27 August 2026) falls outside the window.


What Was NOT Missed

183 endpoints listed across seven regions, 131 opened, fallback searches on 38, and 53 central bank and supervisor speeches searched. Seven borderline items were excluded. GAO and Europol were added during revalidation.


Previous Editions

For independent, evidence-based validation of your PQC programme, see Quantum Trust & PQC Assurance Services.


Disclaimer

This digest is produced by SITG-Consulting for informational purposes. It reflects publicly available material verified at primary sources where accessible within the stated date window; points drawn from secondary sources are attributed in the text. It does not constitute legal, regulatory, or investment advice. Inclusion or exclusion of any item reflects editorial judgement against the published methodology, not an assessment of its importance to any specific organisation. Errors identified after publication are applied as lessons to future editions, not as corrections to published posts.


 
 
 

Comments


bottom of page