Skip to content
Friday, 9 October 2026
Tenesys AI News
Subscribe

Microsoft urges organizations to start testing post-quantum certificate readiness now

In short: Microsoft published guidance warning that post-quantum cryptography (PQC) planning cannot focus only on encrypted data — authentication systems, certificates, PKI, and hardware security modules also need to be tested for compatibility with new quantum-resistant algorithms. Microsoft launched a PQC TLS Pilot Program on August 27, 2026, letting approved certificate authorities test ML-DSA-87 based post-quantum certificate chains in closed, non-production environments. Seven pilot roots were added from providers including DigiCert, Sectigo, HARICA, and SSL.com, with rolling admissions continuing through the end of 2026. Windows 11 (from the July 28, 2026 updates) now supports evaluating ML-DSA certificates in controlled testing scenarios via Schannel.

Source: Microsoft SecurityMicrosoftOriginal article ↗

This summary was generated automatically by AI from Microsoft Security's publication. It is our own text, not a copy of the original — facts, figures and quotes belong to the source, linked above and below.

What changed?

  • 1Microsoft launched the PQC TLS Pilot Program on August 27, 2026, for certificate authorities in the Microsoft Trusted Root Program
  • 2Pilot uses ML-DSA-87 (Module-Lattice-Based Digital Signature Algorithm) for post-quantum certificate issuance
  • 3Seven pilot roots added: ComSign, DigiCert, HARICA, IdenTrust Services, Sectigo, Shanghai Electronic Certification Authority, SSL.com
  • 4Pilot certificates are not publicly trusted and must not be used in production or on public-facing websites
  • 5Windows 11 support for ML-DSA certificate testing begins with July 28, 2026 updates: KB5101681 (26H1) and KB5101684 (25H2)
  • 6Rolling admissions for the pilot continue through the end of 2026

Why it matters

Post-quantum migration isn't just about encrypting data — it affects every system that issues, validates, stores, or relies on certificates, including larger certificate chains that can impact TLS handshake size, performance, and inspection systems. Security and infrastructure teams running long-lived PKI, VoIP/SIP gateways, or hardware security modules should start inventorying certificate dependencies and vendor roadmaps well before post-quantum authentication becomes mandatory.

What it means for AI agents and contact centers

If your company runs its own PKI, TLS termination for SIP/VoIP trunks, or long-lived telephony/security appliances, this is an early signal to start inventorying certificate dependencies and checking with TLS/certificate vendors about post-quantum roadmaps — not an immediate action item, but worth tracking as larger post-quantum certificates could affect handshake performance on latency-sensitive voice infrastructure.

Sources

  • Microsoft SecurityOfficialPrimary source
    „Post-quantum authentication: Why organizations should start testing certificate ecosystems now“
    8 Oct 2026, 23:44
    Original article →
Published by source
8 Oct 2026, 23:44
Found by our system
9 Oct 2026, 01:39
Summary generated
9 Oct 2026, 01:40

This article was written by AI from the original source. Facts, numbers and prices come from the source; missing values are marked “Not specified”. Legal notice, copyright and privacy

Microsoft urges organizations to start testing post-quantum certificate readiness now · TENESYS AI NEWS