top of page

From Standards to Stress Tests: PQC Migration Enters Its Operational Phase

Writer: Brian Couzens
Brian Couzens
3 days ago
3 min read
image showing all the new rules ruptured by standards


The week of 18 September 2026 marked a shift. Post-quantum cryptography is no longer confined to policy papers and vendor roadmaps. Two events, separated by 11,000 kilometres, demonstrated that regulators and standards bodies are now testing whether organisations can execute the migration they have been told to plan.


The Global Quantum Drill: Dubai Puts PQC Under Pressure

On 17-18 September, the International Telecommunication Union and the UAE Cybersecurity Council ran the Global Quantum Drill at GISEC 2026 in Dubai. This was not a conference panel. It was a hands-on exercise forcing participants, with industry support from AWS, Fortinet, Honeywell, Cisco and Google Cloud, to work through two operational scenarios: one testing supervisory decision-making when quantum risk hits the incident queue, the other requiring participants to identify where cryptographic security assumptions fail during implementation.

The significance is in the format. When the ITU shifts from publishing recommendations to running timed exercises, it signals that the multilateral community considers the theoretical phase over. Organisations that have not moved beyond awareness-raising are now measurably behind the bodies setting the pace.

Washington Convenes Before the Deadline

On 16 September, the US General Services Administration convened its 2026 Post-Quantum Cryptography Summit, a federal-only event drawing speakers from OMB, NIST, CISA, the Department of War and the Office of the National Cyber Director. The timing was deliberate: Executive Order 14412's 90-day deadline for federal agencies to submit PQC migration plans to OMB falls days later, around 20-21 September. The FIPS 140-2 certificate sunset follows on 21 September, removing the last remnant of pre-FIPS 140-3 validation from federal procurement.

For organisations in the federal supply chain, the convergence of these deadlines is not incidental. When agencies submit their migration plans, the cryptographic requirements will flow into contracts, procurement vehicles and vendor assessments. The GSA has already signalled it will update federal identity and physical access control infrastructure for quantum resistance.

Europe Clarifies Its Roadmap

On 14 September, the Netherlands, co-chairing the NIS Cooperation Group's PQC work stream, published the FAQ on the EU roadmap to quantum-safe cryptography. This document addresses the questions Member States and their regulated sectors have been raising since the European Commission published its coordinated implementation roadmap in June 2025: how to estimate quantum risk, how to prioritise migration, when hybrid cryptographic schemes are appropriate, and what national roadmaps should contain.

The FAQ arrived the same week ENISA launched the Cyber Resilience Act Single Reporting Platform, bringing the CRA's vulnerability-reporting obligations into force. While the CRA is not PQC-specific, it creates the regulatory framework under which cryptographic vulnerabilities, including quantum-related risks, will be reported and tracked across the EU product ecosystem.

What This Means for Organisations That Have Not Started

The gap between organisations that are executing PQC migration and those still evaluating it widened this week. The IETF advanced ML-KEM for TLS 1.3 to the RFC Editor Queue on 17 September, the final stage before publication. When that RFC lands, every TLS implementation will have a standards-compliant path to post-quantum key agreement. Organisations waiting for "the standard" will have run out of reasons to wait.

The pattern across jurisdictions is consistent. The US is enforcing through executive order deadlines and procurement reform. The EU is clarifying implementation through its NIS Cooperation Group and enforcing product-level obligations through the CRA. The UAE is running operational stress tests with multilateral backing. India and Latin America returned no new signals this week, but India's SEBI Chairman called for cryptographic inventories on 10 September and Brazil's ICP-Brasil PQC working group deliverables are due within days.

The window for treating PQC as a future problem is closing. The organisations and jurisdictions that moved early are now testing their implementations. Those that have not begun are accumulating compliance risk with every passing week.



SITG-Consulting provides independent advisory on post-quantum cryptography migration, cryptographic governance and quantum risk assurance. For more information, visit SITG-Consulting Quantum Trust and PQC Assurance Services.


 
 
 

Comments


bottom of page