
Post-quantum email security advances on two IETF tracks
Two August 18 milestones advanced composite ML-KEM for CMS and a CNSA 2.0 S/MIME profile—useful signals for planning, not final standards.
Read postResource archive
Technical explainers, migration notes, and operating guidance for teams preparing post-quantum cryptography work.
The Blog collects technical explainers, migration notes, and operating guidance for teams planning post-quantum cryptography work. Start with the core pages below if you are building an inventory or preparing an internal migration brief.
Research notes and case studies are published only after review for factual accuracy, customer confidentiality, and export-control sensitivity. Press releases and approved media facts are kept separate in the Newsroom.
Latest analysis
29 published briefs for migration planning.

Two August 18 milestones advanced composite ML-KEM for CMS and a CNSA 2.0 S/MIME profile—useful signals for planning, not final standards.
Read post
Coinbase’s custody plan and Ethereum’s public post-quantum roadmap point to the same bottleneck: coordinated key, wallet and protocol migration—not the search for one new signature algorithm.
Read post
Cloudflare now supports ML-DSA certificates on the edge-to-origin hop. The operational lesson is that key agreement, authentication and downgrade resistance must be measured as separate controls.
Read post
FINMA’s survey of 60 Swiss financial institutions found broad awareness but little execution. Its new guidance points to board-approved strategy, a living cryptographic inventory and a PQC roadmap by mid-2027.
Read post
05
Recent quantum news points in one direction: useful scientific workloads, national infrastructure programmes, and enterprise PQC timelines are moving together. Security teams should turn that signal into crypto-agility work now.
Read post
06
IBM, Oak Ridge, and Cleveland Clinic showed quantum computing moving into applied scientific work. Microsoft moved its quantum-safe security timeline to 2029. Together, the message is simple: security teams should stop treating PQC as distant.
Read post
07
Google and Cloudflare have pulled their post-quantum migration targets toward 2029. The lesson for enterprises is not panic; it is that authentication, signing, and crypto inventory need executive attention now.
Read post
08
Browsers, Apple platforms, Java, OpenSSL-based stacks, and CDNs are moving hybrid post-quantum TLS from experiments toward defaults. The new operational question is whether teams can measure coverage.
Read post
09
NIST draft SP 800-230 adds smaller, faster SLH-DSA parameter sets for sign-once, verify-many workflows. The catch is operational: each signing key has a strict signature limit.
Read post
10
NIST moved nine additional post-quantum signature candidates into Round 3 in May 2026. That is algorithm diversity planning, not a pause button for ML-DSA and SLH-DSA migration.
Read post