Edition #10 closed with three things I said I was watching.
One of them had already happened, three weeks before I sent it.
The Signal
Here is what I wrote on August 16: “As of early 2026, no HSM vendor had completed a FIPS 140-3 Level 3 validation with post-quantum algorithms inside the validated boundary. Banks can be ready and still be blocked by paperwork.”
An HSM, a hardware security module, is the physical box where a bank, a payments network or a certificate authority keeps its private keys. The keys never leave it. Level 3 means opening the box destroys what is inside. For a regulated institution, your bank among them, a key that lives anywhere else is a liability.
On July 29, Thales Trusted Cyber Technologies got that validation. Certificate 5450, module Luna T7, tested on firmware 7.15.1. Three weeks later, on August 19, Crypto4A got one too.
One paragraph on what they hold, because these names are about to be on every vendor page you read. In 2024, NIST, the US body whose approval decides what cryptography a government or a regulated institution is allowed to run, published the replacements for the mathematics a quantum computer would break. Two of them do the everyday work. One agrees on a secret key between two machines that have never met. The other signs, which is how a system proves a message came from where it claims. On a datasheet they appear as ML-KEM and ML-DSA. Certificate 5450 covers both, inside the box.
I missed the first one by eighteen days and published a gap that had already closed.
Now the part that matters more than who was first. Every validated module carries a public document called the Security Policy, and the one behind certificate 5450 runs to eighty-nine pages with its revision history dated on page three. First draft, September 11, 2024. Post-quantum algorithms written into the document, January 14, 2026. Certificate posted, July 29, 2026. Twenty-two months.
Crypto4A gives the same number from the other end. It entered the public queue on March 20, 2025 and came out validated on August 19, 2026. Seventeen months, with a date on each end.
Entrust submitted its own firmware on August 22, 2025 and is still in the queue thirteen months later. The guidance covering modules that run the old and the new cryptography side by side, which is what every migrating institution is building, was clarified on August 19, 2026. For most of the period when companies were being told to plan their migration, the rule they would be audited against was still being written.
That is one clock. Here is the other.
On September 9, an open competition called ECDSA.Fail published its results. The target was the arithmetic step that dominates the cost of the one known method a quantum computer would use to forge signatures on secp256k1, the curve that authorizes Bitcoin and Ethereum transactions. That method has been public since 1994. The estimate of what it would cost to run is the thing that keeps moving.
Anyone could enter, with no entry requirements of any kind, and a public evaluator checked every submission automatically, so nobody had to trust anybody. More than a hundred contributors and their AI agents cut the benchmark score by 86.1% in a matter of months. The paper is signed by people from cryptocurrency foundations and a security auditing firm. Their winning circuit sits more than 50% below the operating point Google reported for its own version, which Google never released.
Two systems for improving cryptography, running in the same month. One is checked by a program in seconds and iterates in public. The other is checked by an accredited laboratory and iterates in years.
The attack side has the fast one.
I spent 25 years watching the date of a technology and the date of an organization drift apart. This is the widest I have seen them. Your migration does not move at the speed of the research. It moves at the speed of the queue that certifies the box your keys live in, and that queue has a floor of a year.
The Application
Cloudflare, both halves of the same network. In February 2026 the company reported that post-quantum key agreement had gone from under 3% of client traffic at the start of 2024 to over 60%. On the other side of its own network, roughly 10% of customer origin servers support the same algorithm, up from under 1% at the start of 2025. The scanner behind that figure tests for support, not preference, so 10% is the optimistic reading. The half that arrived through a browser update is nearly done. The half that requires somebody to change a server is not.
Two certificates, three weeks apart. Thales Trusted Cyber Technologies, July 29, 2026: Luna T7, certificate 5450, Overall Level 3, tested on firmware 7.15.1, with ML-KEM and ML-DSA inside a boundary drawn around the whole PCIe card. Crypto4A, August 19, 2026: certificate 5497, module QASM 1.1 on firmware 5.0.1.158, Overall Level 3, carrying ML-KEM, ML-DSA, LMS and SLH-DSA, and in the public queue since March 20, 2025. Both are real, and each company announced itself as the first.
The Thales upgrade is a firmware load rather than new hardware. The same Security Policy notes what the load does: once the module verifies the new firmware it resets itself and zeroizes every user and every user object it holds. Plan it as a key ceremony with downtime, not a patch window.
Entrust, thirteen months in the queue. Firmware v13.8.0, carrying the same post-quantum algorithms, released August 22, 2025 and submitted for updated Level 3 validation. Still pending. The algorithms have been shipping and usable for a year; the certificate that lets a regulated buyer count them has not arrived.
September 21, 2026, and Executive Order 14412. Every remaining FIPS 140-2 certificate moves to the historical list on September 21, after which US and Canadian federal agencies can no longer accept those modules for protecting sensitive information. The order, signed June 22, 2026, moves key establishment on high-value federal systems by December 31, 2030 and digital signatures by December 31, 2031, and directs the procurement rulemakers to propose a rule requiring federal contractors to meet the post-quantum standards by the end of 2030. That last clause is how this reaches companies that have never sold to a government.
The Noise
“First post-quantum HSM,” from two companies, three weeks apart, both telling the truth.
Thales says it is first with the complete set the NSA requires for national security systems. Crypto4A says it is first with every post-quantum algorithm NIST has standardized. Those are different lists. NIST’s includes a third signature scheme, SLH-DSA, and the algorithm table in the Thales Security Policy does not carry it. The Crypto4A table carries all twelve of its parameter sets. Each company drew the line where its own product ended.
Now read further into either document, because on this they agree. Both say the module does not establish its own keys with a post-quantum mechanism, and both offer that function to an application built on top, under the same NIST implementation guidance. For their own key agreement, both use elliptic curve and RSA.
Two vendors, two countries, two certificates, the same sentence. The classical mathematics still running inside the hardware validated to replace it.
None of that makes either certificate less real. The boxes do what the documents say. The documents say more than the announcements did, and they are free.
The Question
Somewhere in your organization there are hardware security modules holding keys, and somebody knows which ones and who sold them.
Of every supplier who has told you they are post-quantum ready, how many gave you a module certificate number and a date?
Count how many people you have to ask before anyone can answer.
Now What?
Five moves, and each one will make a seller uncomfortable.
Ask for the CMVP certificate number in writing, not the word “validated.” Every number resolves to a public entry at csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules/search. Then go one click further. The row itself gives you the module name, the vendor and the date, and often nothing else; the document hanging off it, called the Security Policy, is where the security level appears, along with the exact firmware version that was tested and the list of algorithms the validation actually covers. A supplier can hand you a real certificate number for a module whose validated version is two firmware releases behind the one they installed for you. NIST’s own guidance is to ask the vendor for a signed letter naming the certificate number and then check that letter against the entry. If the two do not match, what you were offered is not a validated module. A vendor who has the number sends it in an hour. A vendor who sends a paragraph instead has answered you.
Ask which algorithms the certificate covers, one by one. Two vendors called themselves first this summer and both were right, because each counted a different list. “Full post-quantum support” resolves to a table in the Security Policy with names in it. Read the table. If the scheme your auditor will ask about is missing from it, the word on the datasheet does not help you.
Check the queue for the ones who do not have it yet. NIST publishes a Modules In Process list at csrc.nist.gov/projects/cryptographic-module-validation-program/modules-in-process. If a supplier tells you their certificate is coming, that list says whether they are in the queue at all, and at which stage. Being absent from it while promising a date is the answer to a question you did not have to ask.
Split your key inventory by what a firmware update can fix. Some current-generation modules take post-quantum algorithms through an in-field upgrade. Others need physical replacement, and hardware replacement runs on procurement lead times, not on security timelines. Which of your boxes is in which group decides whether your 2030 is comfortable or impossible.
Put the validation date in the contract you sign this year. Any HSM or key management renewal signed now will still be running in 2030. Make the vendor commit to a date for the module certificate covering post-quantum algorithms, with a remedy if it slips. They will push back, and the push back is the information.
What I’m Watching
The OMB guidance, due September 20. Executive Order 14412 gave the Office of Management and Budget until that date to publish how agencies should inventory their cryptographic assets and hit the 2030 and 2031 deadlines. It lands the day before the 140-2 certificates go historical. The guidance on how to migrate and the expiry of what you were migrating from arrive in the same weekend.
The queue itself as a number. Over the next year, how many Level 3 modules with post-quantum algorithms inside the boundary actually receive certificates. Two arrived three weeks apart this summer. That count is the real capacity of the migration, and unlike every roadmap in this field, it is published.
Open competitions on machine-checkable problems. The ECDSA.Fail organizers argue their method generalizes to any problem where an evaluator can verify a submission automatically. If that holds, the next place it shows up is a problem someone thought was safely hard because only a few labs were working on it.
This is the Javier D’Ovidio Newsletter. Emerging tech without the hype. Real signals for strategic decisions.
If this edition helped you see something you were not seeing before, forward it to one leader who needs to be in the conversation.
Subscribe at newsletter.javierdovidio.com so you catch the next edition. Follow Javier D’Ovidio on LinkedIn for daily signals on the convergence.
Javier D’Ovidio Javier D’Ovidio Newsletter
How I make this
The judgment in this newsletter is mine. Every edition is the output of a framework I have built over 25 years in technology. I map what is happening across five forces. Then I filter signal from noise, and run each thing through one question: how does this serve life.
I use AI as a tool in that process. It helps me sweep sources across the five forces and draft. It does not decide anything. I choose the topic. I verify every figure and claim against primary sources before it goes out. I call what is signal and what is noise, and that call rests on having watched several technology waves arrive and get dismissed. I edit every edition against my own writing standards. The framework and the final call are mine, and I am accountable for every claim here.
That is the point of this newsletter. AI is a tool a person uses. The person stays responsible for what it produces.


