top of page

🌐 Quantum Weekly - The Global Signals That Actually Mattered (21 September - 27 September 2026)

Writer: Brian Couzens
Brian Couzens
2 minutes ago
17 min read
Regular front image for Quantum weekly a world alit with PQC and Quantum hubs

The week of 21–27 September was an assurance week. Three independent strands tested the premises cryptographic programmes rest on: a preprint from UC San Diego and Inria forged 1024-bit RSA signatures without factoring the key, public cryptanalysts broke five of China's newly published post-quantum candidate designs within days, and ETSI published guidance treating every stage of the entropy pipeline as untrusted until verified. Around those tests, the compliance and capital frame tightened. FIPS 140-2 validations moved to NIST's Historical list, the three European Supervisory Authorities named quantum as a cryptographic risk to the financial system, Germany selected six consortia for a milestone-gated fault-tolerance competition worth up to €640 million, and Microsoft placed a topological system in front of DARPA's evaluators. Confirmed signals this week came from the United States, China, South Korea, Germany, France, the European Union and Australia, plus a six-consortium supply chain study spanning North America, Europe and Asia.


🇺🇸 United States - FIPS 140-2 Validations Move to Historical: Procurement Standing Ends for Unmigrated Modules

Compliance Deadline / Module Assurance / Procurement Governance

The Detail:NIST's Cryptographic Module Validation Program states that FIPS 140-2 validations move to the Historical list on 21 September 2026. The same NIST project page carries a transition schedule table that lists 22 September 2026 for the same action, a one-day inconsistency in the authoritative source. CMVP states that Historical modules remain supported for purchase and use in existing systems, and that federal agencies decide when to move to FIPS 140-3-only procurement. New FIPS 140-2 submissions closed in April 2022.

This week I published "Demand has a date. Supply has a register." (23 September 2026), which counts sixteen FIPS 140-3 certificates on the CMVP record carrying a post-quantum algorithm family inside the validated boundary as at 21 September, with LMS counted as a post-quantum family. I followed it with "FIPS 140-3 Gap Analysis: What the September Deadline Exposed" (25 September 2026).

Why it matters:Historical status does not switch a module off. It removes the module's standing wherever a contract, policy or regulator references "FIPS validated" for new acquisition. The exposure sits in documents: supplier contracts, security policies and audit evidence that cite FIPS 140-2 certificate numbers now describe a non-current state. Procurement and compliance owners should reconcile every cited certificate number against the CMVP database, require suppliers to state FIPS 140-3 certificate numbers and validated boundaries in writing, and record the 21 or 22 September ambiguity in their evidence file rather than assume one date. A FIPS 140-3 gap analysis is the control that converts this from a vendor assertion into an auditable position. The supply side remains thin: sixteen post-quantum-capable validated modules is a short register for an entire market.


🇨🇳 China - NGCC Round 1 Candidates Face Open Cryptanalysis; Five Designs Reported Broken Within Days

Sovereign Standards / Cryptanalysis at Speed / Algorithm Divergence

The Detail:China's Institute of Commercial Cryptography Standards (ICCS) published the Round 1 candidates of its Next-generation Commercial Cryptographic Algorithms Program (NGCC) on 20 September, one day before this window opened: 34 signature schemes, 41 key encapsulation mechanisms, nine key-exchange protocols and 35 hash functions. The in-window signal is what followed. On 22 September, researchers at the Institute of Software, Chinese Academy of Sciences posted IACR ePrint 2026/2152, reporting explicit collisions for all fixed-output variants of the MoFang hash design and for all three variants of Neulaser, with structural weaknesses in five further submitted hash functions. PostQuantum's count of the public ngcc.dev tracker, run by Finnish cryptographer Markku-Juhani O. Saarinen, recorded 104 findings against 65 of the 119 candidates, across signature, KEM, key-exchange and hash candidates, by the morning of 23 September, the majority implementation defects in submitted reference code found through an AI-assisted sweep, with practical design breaks reported against the Tins and Facto-DSA signature schemes and the MoFang and Neulaser hash functions. None of the candidates is standardised or deployed. ICCS rules exclude algorithms already standardised elsewhere, including ML-KEM and ML-DSA.

Why it matters:Two governance consequences. First, the NGCC will produce a Chinese post-quantum algorithm family that is, by design, outside the NIST set. Organisations with operations or customers in China face a dual-stack obligation, and the preparation is architectural: cryptographic agility that lets a second algorithm family be added without re-engineering applications. I mapped this multipolar standards picture, including China's algorithm call and South Korea's KpqC, in "The State of Post-Quantum Cryptography in 2026: A Global Map of PQC Algorithms and Migration Deadlines" (28 September 2026). Second, the speed. Candidate packages drew reproducible findings within 24 hours, with AI assistance credited on a large share of them. Any proprietary or lightly reviewed algorithm offered by a vendor should now be assumed to face the same scrutiny, and buyers should ask what public analysis a scheme has survived before accepting it into a product roadmap. No finding this week affects ML-KEM or ML-DSA deployments.


🇰🇷 South Korea - SK Telecom and KISTI Link QKD Key Management to a Digital Twin Over ETSI Interfaces

QKD Engineering / Interoperability / Pre-Deployment Validation

The Detail:On 22 September, SK Telecom announced that it had developed, with the Korea Institute of Science and Technology Information (KISTI), a digital twin for validating quantum key distribution networks before physical build. SKT's key management system, implemented as containers orchestrated through Kubernetes, connects in real time with KISTI's QKD simulator through ETSI-compatible interfaces. The simulator models fibre distance, optical loss, detection efficiency and post-processing, and returns key material and system state to the key manager. The system was shown at ECOC 2026 in Málaga on the SK Broadband stand. SKT states this is the first public demonstration of interoperation between an independently developed key management system and QKD simulator. The work was funded under Ministry of Science and ICT programmes.

Why it matters:QKD capital is sunk once fibre and devices are in the ground; configuration errors are expensive to reverse. A digital twin moves design validation earlier, and the use of ETSI interfaces reduces lock-in to a single QKD vendor. The limit is equally clear: a simulator validates topology and key rates, while the physical security of deployed devices still depends on device certification and side-channel evidence. Operators should treat the twin as a design control and keep field acceptance testing as a separate gate. The durable point is architectural: QKD networks are governed at the key management layer.

A korea image of the SK Telecom development

🇺🇸 United States - Microsoft Opens Maryland Quantum Centre and Places a Topological System Under DARPA Evaluation

Independent Evaluation / Federal Benchmarking / Ecosystem Build-Out

The Detail:On 22 September, Microsoft opened a 15,000 square foot quantum research centre in the University of Maryland's Discovery District, marked by a ribbon-cutting with Governor Wes Moore. Microsoft states that DARPA will have full on-site access to its latest topological system, built on the Majorana 2 chip, for independent testing and evaluation, and that Microsoft is among the first companies to advance to the final stage of DARPA's Underexplored Systems for Utility-Scale Quantum Computing programme within the Quantum Benchmarking Initiative. The centre includes partner laboratories and a hardware makerspace with AMD, Bluefors, Intel, IQM, Fermilab, Riverlane and Quantum Motion named as initial partners, alongside Microsoft-funded postdoctoral positions at UMD and an annual workshop series on measurement-based quantum computing.

Why it matters:Topological qubit claims have been contested in the scientific literature. Placing hardware in front of a government test and evaluation team is the correct response to that contest, and it sets a reference point for the market: a roadmap evaluated by an independent assessor carries more evidential weight than one that has not been. Boards and risk committees tracking cryptographically relevant quantum timelines should weight vendor milestones by their verification status, and should expect DARPA's findings, when published, to move estimates in either direction.


🇩🇪 Germany - Six Consortia Selected for a Fault-Tolerance Competition Worth Up to €640 Million

Sovereign Capability / Milestone-Gated Funding / Modality Hedging

The Detail:On 22 September, planqc confirmed that six consortia had been selected for Germany's Quantum Computing Competition, run by the Federal Ministry of Research, Technology and Space (BMFTR) with up to €640 million in planned funding. The target is at least two error-corrected quantum computers at the European technological frontier by 2030. Two consortia were selected for each of three platforms: neutral atoms, trapped ions and superconducting circuits. At least one partner in each consortium must demonstrate a functioning system meeting defined entry criteria by 31 March 2027, with a further selection after 30 months. planqc coordinates LOGIQC, a neutral ytterbium-atom programme with MPQ, LMU, the University of Tübingen, Forschungszentrum Jülich and TOPTICA Photonics.

On 23 September, QUDORA announced that its seven-member NFQC-1k consortium, with a total project volume of approximately €122 million, had been selected on the trapped-ion track. Partners are TU Braunschweig, Leibniz University Hannover, PTB, NXP Semiconductors Germany, Forschungszentrum Jülich and AQT Germany. QUDORA states the target is a demonstrator with at least 1,000 individually addressable physical qubits and at least 50 logical qubits at a logical gate error rate below 0.01%, verified through a Quantum Fourier Transform, plus a QPU pilot line. The consortium has passed the outline phase and now submits its full application. The remaining four consortia were identified in Handelsblatt reporting cited by planqc.

Why it matters:The structure is the signal. Germany is buying against measurable entry criteria and down-selecting on evidence. The NFQC-1k specification, which pairs a logical qubit count with a logical gate error threshold and a named verification circuit, is a usable template for any buyer who needs to define what a "logical qubit" claim must include. The pilot line and the presence of NXP signal that sovereign fabrication is part of the ask from the outset.


🇺🇸 🇫🇷 United States / France - Researchers Forge 1024-bit RSA Signatures Without Factoring the Key

Classical Cryptanalysis / HSM Assurance / RSA Retirement

The Detail:IACR ePrint 2026/2131, "Forging 1024-bit RSA signatures in nearly SNFS time", by Laura Shea, Miro Haller, Adam Suhl and Nadia Heninger of UC San Diego and Emmanuel Thomé of Inria Nancy, was approved and listed publicly on 22 September. The authors implement a 2007 algorithm by Joux, Naccache and Thomé that forges RSA signatures after temporary access to a raw RSA signing or decryption oracle, without factoring the modulus. The attack took 1,380 CPU core-years over five calendar months and 2^32 oracle queries; after precomputation, any chosen signature can be forged offline in 180 core-years. The authors used a hardware security module as the signing oracle, impersonating it through black-box API interactions without extracting the key, and note that blind RSA schemes also provide such an oracle. They conclude that the concrete security of RSA with a signing oracle is 15 to 30 bits lower than factoring-based estimates for 1024-bit to 4096-bit keys, and that even 4096-bit RSA does not appear to meet a 128-bit security level in this attack model. The paper is a preprint. The attack requires an unpadded oracle; standard PKCS#1 v1.5 and PSS signing interfaces do not generally expose one.

Why it matters:The case for retiring RSA now carries classical evidence as well as quantum evidence, and the authors say so. The immediate control is interface exposure, ahead of key length: which HSMs, key management services and protocols expose raw RSA operations, such as the unpadded RSA mechanism in PKCS#11, and to whom. Key owners should inventory permitted mechanisms per key, restrict raw RSA to documented and justified uses, and treat blind RSA deployments as in scope for review. This is a cryptographic lifecycle finding, and it belongs in the same migration plan as PQC.

Pictorial of the breakage stats for RSA 1024

🇪🇺 European Union - ESAs Name Quantum as a Cryptographic Risk in Their Autumn Financial Stability Update

Supervisory Signal / Financial Stability / Timing Risk

The Detail:On 23 September, the European Supervisory Authorities (EBA, EIOPA and ESMA) published their Joint Committee Autumn 2026 update on risks and vulnerabilities, naming external dependencies, emerging technologies and private credit as key vulnerabilities for the EU financial system. The update states that quantum computing could undermine cryptography systems widely used to secure communications, transactions, databases and blockchains, and that these risks could materialise faster than any commercially viable application. The ESAs call on supervisors and market participants to strengthen preparedness for risks arising from the rapid development of AI and quantum computing. The findings were presented to the Financial Stability Table of the EU Economic and Financial Committee on 10 September.

Why it matters:A sentence in a Joint Committee risk update is how a topic enters supervisory dialogue. The timing argument matters: the ESAs are telling firms not to calibrate cryptographic risk to the commercial maturity of quantum computing. EU financial entities already operate under DORA's ICT risk management requirements, which include documented cryptographic controls, so the question supervisors will reasonably ask is whether those controls include a quantum transition plan with owners and dates. Boards should expect that question in the next supervisory cycle and should be able to show a cyber risk and resilience position that answers it with evidence rather than intent.


🌐 Global - Six Industry Consortia Map Quantum Supply Chains: 90% of Firms Rely on a Foreign Supplier

Supply Chain Dependency / Export Control Exposure / Provenance

The Detail:On 23 September, at Quantum World Congress, QED-C, the European Quantum Industry Consortium (QuIC), Quantum Industry Canada, UKQuantum, Japan's Q-STAR and the Korea Quantum Industry Association released the Global Quantum Supply Chain report, with engagement across India's quantum ecosystem. The survey covered 160 companies headquartered in 15 countries, reporting suppliers in 36 countries, customers in 49 and manufacturing in 25. 90% reported at least one foreign supplier and 74% at least one foreign customer, with a median of three supplier countries and three customer countries. The United States, Germany, the United Kingdom, Canada and Japan were the locations named for both suppliers and customers with the highest frequency. The survey ran in March and April 2026; no respondent was headquartered in China, although China appeared as a named supplier or customer location.

Why it matters:Sovereign programmes such as Germany's competition and US foundry investment sit on an industry in which nine in ten firms depend on a foreign supplier. That is a provenance and continuity risk as well as a trade statistic. Buyers of quantum hardware and quantum-safe equipment should require component provenance disclosure, identify single-country dependencies for cryogenics, lasers and control electronics, and model export-control scenarios before committing to multi-year programmes. The same discipline organisations are learning to apply through cryptographic bills of materials applies to the hardware stack. I set out the supplier questions this raises in "Stop Buying Cryptographic Debt for PQC" (21 September 2026).


🇦🇺 Australia - QuintessenceLabs Adds Cryptographic Asset Management and a PQC Readiness Assessment

Discovery Tooling / Vendor Convergence / Independence

The Detail:On 23 September, Canberra-based QuintessenceLabs announced TSF Sentry Cryptographic Asset Management and a Post-Quantum Cryptography Readiness Assessment at Quantum World Congress in College Park, Maryland. The company states that TSF Sentry provides continuous visibility of where cryptography is used across an enterprise and links findings to the applications and systems that need remediation, and that the readiness assessment provides a structured, risk-based blueprint for prioritising the transition.

Why it matters:A key management and quantum random number vendor is moving upstream into discovery and assessment. That is commercially rational and it is now the pattern across the sector. It raises an independence question buyers should answer explicitly: when the party that assesses readiness also sells the remediation, the assessment's scope and findings need separate validation. Separate the diagnostic from the supply decision.


🇪🇺 Europe - ETSI Publishes QRNG Implementation Guidance and Introduces "Entropy Zero Trust"

Entropy Assurance / Standards / Lifecycle Controls

The Detail:On 24 September, ETSI announced Technical Report ETSI TR 104 171, implementation guidance for quantum random number generators. ETSI states that while QRNG output may appear statistically random, an adversary with relevant side-information can introduce exploitable predictability. The report covers the QRNG lifecycle: modelling and validating the quantum entropy source, randomness extraction, monitoring entropy quality in operation, detecting drift, bias and hardware failure, protection against tampering and side-channel attack, securing the path from entropy source to consuming application, and the provenance, attestation and auditability needed to show outputs remain trustworthy. It introduces "Entropy Zero Trust" (EZT), under which no part of the entropy pipeline is trusted without verification, and proposes a common basis for comparing implementations by trust level, throughput, power, size, weight, interfaces and scalability. Mark Pecen, Chair of ETSI TC Quantum, stated that secure randomness rests on the integrity of the entire implementation. ETSI lists attestation and logging protocols, stronger certification models and guidance on combining QRNGs with PQC as future standardisation priorities.

Why it matters:Every post-quantum key is only as strong as the randomness that generated it, and entropy is the least audited dependency in the stack. ETSI has now put in writing what procurement teams should have been demanding: a "quantum" label on a random number generator is a physics claim, not an assurance claim. Buyers should require documented min-entropy estimation, continuous health testing, conditioning design, tamper evidence and attestation from source to application, and should apply the same questions to classical entropy sources. This is squarely the territory of quantum trust and PQC assurance: verifying that the controls behind a claim exist and operate.

The ETSI Logo world

🇺🇸 United States - Infleqtion Reports 30 Entangled Logical Qubits From 80 Physical Qubits

Fault Tolerance / Vendor Claims / Metric Definition

The Detail:On 24 September, Infleqtion (NYSE: INFQ) announced that it had entangled 30 logical qubits using 80 physical qubits on its Sqale neutral-atom platform. Infleqtion claims this makes it the first neutral-atom company to reach 30 logical qubits on a commercial system. The company states that the result used a logical entangling operation discovered with AI assistance that halves the physical gates required for a key operation, that the experiment executed approximately 1,000 physical operations, and that the result was confirmed by a signal approximately 1,000 times stronger than underlying noise. Infleqtion reports three customers for logical qubit circuits on Sqale, including the Wellcome Leap Quantum for Bio programme, and restates roadmap targets of 100 logical qubits in 2028 and 1,000 by 2030, which its release classifies as forward-looking statements. The release points to a company blog write-up; no peer-reviewed paper is cited.

Why it matters:Logical qubit counts are becoming the headline metric, and their definitions are not standardised: error detection versus correction, code distance, post-selection and logical error rate all change what a number means. Set against Germany's NFQC-1k specification this week, which pairs a logical count with a logical gate error threshold and a named verification circuit, the gap in disclosure is visible. Anyone using vendor announcements to inform cryptographic risk timelines should require the logical error rate, code parameters and rejection rate behind each count before updating an estimate.


🇺🇸 United States - DigiCert and Quantum XChange Push PQC Management Into Enterprise and Public-Sector Buying Channels

Procurement Channels / Cryptographic Inventory / Evidence of Progress

The Detail:On 22 September, Quantum XChange announced that Carahsoft will act as its Master Government Aggregator, making its Phio TX cryptographic management platform available to the US public sector through Carahsoft's reseller partners and the TIPS, OMNIA Partners and The Quilt contract vehicles. Quantum XChange states that Phio TX supports PQC, QKD and classical encryption under unified policy control, with FIPS 140-3 and FIPS 203 validation.

On 24 September, DigiCert announced general availability of DigiCert Quantum Central within its DigiCert ONE platform, following a July preview. DigiCert states the product consolidates cryptographic inventory from network scans, certificate lifecycle platforms, key vaults, CSV uploads and software or cryptographic bills of materials; applies organisation-defined policies; raises remediation changes through workflows including Jira; and exports inventory as cryptographic bills of materials for audit. DigiCert cites its 2026 Quantum Readiness Outlook: 87% of organisations planning, testing or implementing PQC, and 7% having deployed quantum-safe or hybrid cryptography.

Why it matters:DigiCert's own figures describe the problem precisely: an 80-point gap between intent and deployment. Tooling closes part of it. It does not decide who owns a finding, what risk appetite a policy encodes, or whether the evidence produced would satisfy an auditor. Contract vehicles shorten public-sector buying cycles, which moves the constraint from procurement to governance capacity. Organisations adopting these platforms should define ownership, policy baselines and acceptance criteria before the first scan. A PQC Discovery Sprint is designed to set that frame first. For organisations moving from inventory to deployment, I published a bounded, evidence-gated approach in "Beyond the Hype: A Vendor-Neutral Framework for Your First PQC Hybrid Pilot" (28 September 2026). Vendor validation claims, including the Phio TX FIPS statements, should be checked against CMVP and CAVP records by certificate number.


🌐 Global Sweep - The Assumptions Layer Under Test

Ecosystem / Capital Markets / PQC Infrastructure / Hardware Architecture / Sovereign Security

The Detail:

  • Cryptographic assumptions were tested from three directions in the same week: classical cryptanalysis of RSA with a signing oracle (UC San Diego and Inria), open cryptanalysis of China's NGCC candidates (Chinese Academy of Sciences researchers, ngcc.dev contributors), and ETSI's formal position that entropy pipelines must be verified end to end.

  • Compliance and supervisory pressure hardened: FIPS 140-2 validations moved to NIST's Historical list, and the EBA, EIOPA and ESMA named quantum cryptographic risk in a financial stability document.

  • Capital and evaluation became evidence-gated: Germany's up to €640 million competition down-selects on entry criteria; DARPA received on-site access to Microsoft's topological system; Infleqtion's 30-logical-qubit claim arrived without a cited peer-reviewed paper.

  • PQC management tooling moved into buying channels: DigiCert Quantum Central general availability, Quantum XChange through Carahsoft contract vehicles, and QuintessenceLabs adding discovery and readiness assessment.

  • QKD engineering shifted towards interoperability and pre-deployment validation: SK Telecom and KISTI over ETSI interfaces.

  • Supply chain interdependence was quantified by six industry consortia: 90% of 160 surveyed quantum firms depend on at least one foreign supplier.

  • Regions checked with no confirmed in-window signal sectioned this week: United Kingdom, Canada, Japan, India, Singapore, Taiwan, the GCC (Qatar, UAE, Saudi Arabia, Bahrain, Kuwait, Oman), Africa (South Africa, Nigeria, Kenya, Ghana), Latin America (Brazil, Chile, Mexico, Colombia), the Netherlands, Finland, Sweden, Denmark, Spain and Italy. UK, Canadian, Japanese and Danish items appeared in secondary coverage during the window but were not verified to a primary source in time for this edition. India participated in the supply chain study only.

  • Malaysia and wider ASEAN: no new in-window government signal. On 24 September I delivered a plain-English PQC talk at the MY Digital Trust Summit 2026 in Kuala Lumpur (write-up and recording, 25 September 2026), and I published a note on the Malaysian National Security Council's 15 September citation of SITG-Consulting's ASEAN post-quantum readiness assessment (post, 27 September 2026). The Council statement itself predates this window.

Why it matters:Algorithm selection is settled for NIST-aligned estates. What moved this week is everything around it: whether the old algorithms are as strong as assumed, whether new ones survive contact with public analysis, whether the randomness feeding them is verified, and whether the compliance record that describes them is current. That shifts the centre of gravity of PQC programmes from migration logistics to assurance. Organisations that can evidence their cryptographic controls will absorb these shocks as updates. Organisations that cannot will absorb them as findings.


🔮 SITG-Consulting COMMENT - THE WEEK'S REAL SIGNAL

The real signal this week is that the assumptions layer broke in public, three times, in five days.

RSA's security has been priced on the cost of factoring. The UC San Diego and Inria preprint shows that, where an attacker can reach a raw signing oracle, that price is 15 to 30 bits too generous. Nobody's TLS certificate is at risk from this paper. The governance lesson is sharper than the cryptographic one: security was assumed at the algorithm level and lost at the interface level. Key inventories typically record algorithm and key length. Few record which mechanisms each key is permitted to perform, and for whom.

China's NGCC shows the other end of the lifecycle. New algorithms entered public review and five designs were reported broken inside two days, with AI-assisted analysis producing reproducible findings at a pace no committee process was designed for. For organisations with Chinese exposure, the consequence is structural: a second post-quantum algorithm family is coming, and agility is the only preparation that scales. For other organisations, the consequence is procedural: any proprietary algorithm a supplier proposes now has a public benchmark for how quickly weak designs fail.

ETSI's EZT closes the triangle. It is the first formal statement from a European standards body that randomness is a supply chain with stages, each requiring verification. Entropy provenance has been the blind spot of quantum-safe procurement; it no longer has the excuse of being unaddressed.

The compliance frame moved in step. FIPS 140-2 validations went Historical, and NIST's own transition page carries two different dates for it. The ESAs told EU financial firms that quantum cryptographic risk may arrive before quantum computing is commercially useful. Germany priced fault tolerance against measurable entry criteria while a US vendor announced a logical qubit count without a cited peer-reviewed paper.

The board-level implication: cryptographic risk can no longer be managed as an algorithm choice. It has to be managed as a set of evidenced controls across interfaces, entropy, algorithm lifecycle, validation status and supplier claims. That is what the Quantum Cryptographic Assurance Standard (QCAS) is built to test. The question for this quarter is not whether an organisation has a PQC plan. It is whether it can prove its current cryptography does what it claims.


⚠️ Important - What Was NOT Missed

  • No credible evidence of near-term cryptographically relevant quantum advantage. The RSA signature forgery result is classical, requires a raw signing oracle, and does not affect padded PKCS#1 v1.5 or PSS signing interfaces.

  • No finding against China's NGCC candidates affects ML-KEM or ML-DSA. None of the 119 candidates is standardised or deployed.

  • ICCS published the NGCC Round 1 candidate list on 20 September, outside this window. It appears above as context only; the in-window signal is the public cryptanalysis that followed from 21 September.

  • The US Department of Energy's SCAC quantum computing roadmap ("Path to an Integrated Quantum Future") was published on energy.gov on 17 September. Fermilab republished it on 25 September. The primary date is outside this window, so it is excluded.

  • Japan's Shunkai neutral-atom system at the Institute for Molecular Science drew wide coverage on 24 September. Its operational announcement dates to August, outside this window, so it is excluded.

  • The Apple Root Program's post-quantum certificate policy position, reported as posted on 21 September, is excluded from this edition pending confirmation against the primary source. It will be assessed next week.

  • IACR ePrint 2026/2131 was received on 20 September and approved for public listing on 22 September. It is treated as in-window on its public listing date.

  • The Quantum Innovation Summit in Dubai and the European Commission's QCI Days in Padua both run from 28 to 30 September, after this window closes. Both fall into next week's edition.


⚠️ Disclaimer

This newsletter is produced by SITG-Consulting for informational purposes only. It does not constitute professional advice, whether legal, technical, regulatory, or otherwise. The content reflects publicly available information and the author's independent analysis as of the date of publication. Readers should verify all claims independently and seek qualified professional counsel before making decisions based on this material. SITG-Consulting accepts no liability for actions taken or not taken based on the contents of this newsletter.





The SITG-Consulting Board Room

 
 
 

Comments


bottom of page