Microsoft Tells Enterprises: Start Testing PKI, HSMs and Appliances for Post-Quantum Authentication
Microsoft has published new guidance urging organizations to start testing their certificate infrastructure for post-quantum authentication, warning that the transition touches far more than cryptographic algorithms — it reaches into public key infrastructure (PKI), hardware security modules (HSMs), security appliances, applications, devices, and every process that keeps digital trust working.
Why it matters
The core risk driving this push is "harvest now, decrypt later": encrypted traffic intercepted today could be decrypted years from now once sufficiently powerful quantum computers exist. That means the certificates and private keys protecting that traffic need to become quantum-resistant well before the threat fully materializes.
Microsoft's own research found that many organizations know where their TLS traffic flows, but lack a complete map of their certificate dependencies. The concern isn't a new malware campaign — it's infrastructure readiness. Swapping out a signature algorithm is the easy part; the hard part is confirming that years of accumulated PKI deployments, legacy devices, operational technology, custom applications, and third-party integrations can actually handle the change without breaking.
Post-quantum certificates and certificate chains are also larger than their classical counterparts, which can affect connection setup, storage, transmission limits, and network inspection tooling. That's why Microsoft is stressing that HSM providers and security appliance vendors need to be part of the migration conversation from day one — not bolted on afterward.
Microsoft's PQC TLS Pilot
Microsoft launched its Post-Quantum Cryptography TLS Pilot Program on August 27, 2026, allowing certificate authorities in good standing with the Microsoft Trusted Root Program to test certificate issuance using ML-DSA-87, a quantum-resistant digital signature algorithm. The latest release added seven pilot roots, operated by ComSign, DigiCert, HARICA, IdenTrust, Sectigo, Shanghai Electronic Certification Authority, and SSL.com. Admissions remain open through the end of 2026 via the Trusted Root Program portal.
Crucially, these pilot certificates are not publicly trusted. Microsoft is restricting their use to closed environments, custom applications, and enterprise testbeds — explicitly excluding production trust and public-facing websites. On supported, correctly configured Windows 11 systems, pilot testing becomes available with the July 2026 updates, and ML-DSA certificates can work with Schannel in supported scenarios, though administrators still need to confirm platform requirements before testing.
The rest of the ecosystem is moving too
Microsoft's pilot is one piece of a broader, uneven transition. Let's Encrypt is exploring Merkle Tree Certificates for public-web authentication, Cloudflare has been testing its own post-quantum certificate authority, Google has rolled out software-based quantum-safe digital signatures through Cloud KMS (with hardware-backed support planned separately), and OpenSSL has been shipping post-quantum performance improvements. Each of these efforts addresses a different slice of the problem — none of them, on its own, means an organization is ready.
What to do now
- Inventory everything certificate-dependent. Map public and private trust relationships, and flag equipment with long upgrade cycles — embedded devices, OT, and legacy appliances are the likely failure points.
- Ask your vendors directly. Certificate authorities, HSM vendors, software suppliers, and platform vendors should be able to state their post-quantum roadmap and whether they support pilot testing — don't assume universal readiness.
- Test the full certificate lifecycle, not just the algorithm: issuance, distribution, validation, renewal, and ongoing management all depend on linked systems that can fail independently of the cryptography itself.
- Treat pilot certificates as test tools, not production replacements. They exist to surface failures in a controlled setting.
- Build a multi-year program with named owners, documented dependencies, and modernization priorities driven by what testing actually finds — not a one-time project with a single deadline.
The goal, as Microsoft frames it, is to find the failures now — in a lab, with a pilot certificate — rather than later, when quantum-resistant authentication becomes a hard deployment requirement.
