Post-Quantum Buying Moves From Availability to Proof: What Counted as Evidence in the First Week of September 2026
A ship stays in class only while a classification society such as Lloyd's Register holds a current survey record for it. Class rests on those periodic surveys, so the certificate can fall out of date on the calendar while not a single plate has changed. Marine insurance has worked on that distinction since Lloyd's Register was founded in 1760. The steel is one object, the certificate covering it is another, and only the second has an expiry.
Cryptographic procurement is arriving at the same distinction. In the first week of September 2026 a buyer could assemble four different classes of document about the same market. A certification program had fixed the date on which a whole class of certificates changes status. A vendor had reported a numbered readiness level reached during a live Army exercise. A chipmaker had attached a half-year revenue figure and a product-attributed pipeline to two named post-quantum parts. Three platform vendors had published the days on which their runtimes and signing chains change by default. The documents carry dates spread across July, August and September; what changed in that week is that all four could be put on the table together.
Practical takeaway. For the last two years a post-quantum answer could be a roadmap slide. Each of the four documents below can be requested by name and checked by a reader who was not in the room: a certificate number with its status on a given date, a readiness level with the exercise it was claimed in, a half-year revenue figure the company reported as preliminary and unaudited, and a vendor date that changes an estate whether or not anyone decided anything.
21 September 2026: the CMVP Moves Every FIPS 140-2 Module to the Historical List
The NIST Cryptographic Module Validation Program has said that on 21 September 2026 it will place all FIPS 140-2 validated modules on the Historical List, allowing agencies to continue using those modules for existing systems only. The program's standing description of Historical status is blunter: federal agencies should not include such modules in new systems, though they can be procured for legacy systems.
A module does nothing different on 22 September. A proposal that cites its certificate does. From that day the proposal points at an entry an evaluator reads as legacy, and the phrase "FIPS-validated" carries three questions behind it: which standard, which certificate number, and what status that number holds on the day the proposal is read. Where the answer is a 140-2 number, the follow-up is whether a 140-3 successor exists or where the module sits in the validation queue. The answer is public record either way.
2 September 2026: QuSecure Reports Technical Readiness Level 7 at Project Convergence Capstone 6
On 2 September 2026 QuSecure announced that its QuProtect R3 platform provided quantum-resistant communications, cryptographic agility, and cryptographic discovery and inventory for U.S. Army tactical mission systems at Project Convergence Capstone 6, the capstone experiment for Army Transformation and Training Command, held at the National Training Center at Fort Irwin. The company states that operation by soldiers in real-world conditions brought QuProtect R3 to Technical Readiness Level 7.
That rating is the company's own account of an Army event. The Army has published no rating of its own, and the same release carries ordinary availability language, including the assertion that QuSecure is ready to deploy today. What a buyer can use here is narrower and more durable: the claim is pinned to a named exercise, at a named location, on a named date, which makes it a question a programme office can be asked to answer. Trade reporting of the announcement adds that the platform builds an automated cryptographic bill of materials, detecting non-compliant or quantum-vulnerable algorithms across live mission nodes. An inventory generated inside an exercise is a thing a buyer can ask to see, in a format a second vendor can read. That is the same ground we covered when network monitoring tools began to recognise the cryptography they were being asked to retire: the capability becomes checkable at the moment it produces a file.
6 July and 3 September 2026: SEALSQ Attaches $60 Million of Pipeline to QS7001 and QVault TPM
Availability claims cost nothing to make. A reported revenue figure and a pipeline attribution both carry a company's name and a reporting date. In its preliminary first-half results of 6 July 2026 SEALSQ put unaudited company-wide revenue at approximately $11 million against $5 million a year earlier, reaffirmed full-year guidance of $27 million to $36 million, and described an active pipeline of more than $225 million through 2029, of which more than $60 million is attributed to the QS7001 secure element and the QVault TPM. The $11 million is preliminary and unaudited, and SEALSQ says the completed half-year statements will also be unaudited and may differ materially from these figures. The $60 million is a management estimate of potential opportunities attributed to those two products. It is not booked revenue, and no filing is obliged to confirm it.
It matters here because the parts are named. A product-attributed pipeline says which products a company expects to sell, in units a buyer can put to a competitor and compare. The September entry in the same file is the hardware itself: on 3 September 2026 SEALSQ and wolfSSL announced wolfTPM support for the QVault TPM. SEALSQ describes that part as on track to implement the post-quantum algorithms of the Trusted Computing Group's TPM 2.0 version 1.85 specification in silicon, and reports ML-DSA signing and ML-KEM encapsulation tested on physical hardware. A pipeline attribution and a working software interface are two different kinds of statement about the same part, and a buyer can ask for both.
15 September, 19 October, and IOS XE 26.x: Three Vendor Dates That Move an Estate
The fourth kind of document is a calendar, and it belongs to the vendors. JDK 27 reaches general availability on 15 September 2026 and delivers hybrid post-quantum key exchange for TLS 1.3, with X25519MLKEM768 placed first in the default preference list so that applications gain it without a code change. Microsoft published on 20 August 2026 that the Windows Production PCA 2011 expires on 19 October 2026, that Windows production signing moves to RSA-3072 and SHA-384 later in 2026, and that it moves to post-quantum signing by default in 2027, alongside the practices that will make an application fail on a file Windows itself considers valid. Cisco's IOS XE 26.x supports an ML-KEM-768 hybrid for IKEv2 on production routers once configured.
These changes arrive on the vendor's schedule. We read the Windows timetable in August, and the point holds here: the date is fixed while the algorithm pairing keeps moving, so the testable question is whether an application survives a replacement signing certificate and a SHA-384 signature.
The Federal Calendar These Sit Inside: EO 14412, M-26-15 and the 27 September RFI
The destinations are set. Executive Order 14412, signed 22 June 2026 and published in the Federal Register on 25 June, directs the Office of Management and Budget to issue guidance requiring agency transitions to post-quantum key establishment on high-value assets and high-impact systems by 31 December 2030 and to post-quantum digital signatures by 31 December 2031; national security systems are excluded from that subsection. OMB Memorandum M-26-15, dated 24 June 2026, asks every agency for a migration plan within 120 days, which falls on 22 October 2026, and requires that plan to carry a cryptographic-agility architecture and a third-party coordination plan. The Department of War's request for information on software-only encryption, reported as closing on 27 September 2026, specifies ML-KEM-1024 key transport and asks respondents to work to a 31 December 2029 implementation target. A request for information gathers responses; it imposes no rule.
Read the parameter sets against each other and a seam appears. The commercial default arriving in JDK 27 is built on ML-KEM-768; the defense request asks about ML-KEM-1024. Both are FIPS 203 parameter sets and both are correct for their own purpose, and an organisation that sells into federal and commercial buyers at once now needs a test record for each. The federal migration work we covered in August is where those two lines meet first.
How Quentir Reads It
The shift here is in who carries the burden of proof. Under an availability regime the buyer carries it: the vendor says the product supports ML-KEM, and the buyer has no cheap way to test the claim before signing. The four documents move some of that burden back, in different amounts. Two of them stand outside the sales conversation: the certificate status is published by the validation program, and the platform date sits on the vendor's own support page where developers would notice it moving. The other two carry the company's name. The half-year figure is SEALSQ's own preliminary and unaudited disclosure, published on a reporting date. The readiness level remains the vendor's claim. Its value is that it names an exercise, a location and a date, so the claim has somewhere to be checked.
Nobody wrote a rule requiring vendors to disclose readiness levels or attribute pipeline to post-quantum parts. Buyers began asking questions that only a document could answer, and the market produced documents. The civic consequence is worth naming: hospitals, city governments, water utilities and school districts are being asked to buy cryptographic modernisation on the same terms as a defense prime, without a procurement office that can read a validation certificate. A public record with a date lets a small buyer and a large one ask the identical question and compare the identical answer. A roadmap gets only the large buyer a meeting.
The seam is where this will be tested first. A supplier serving both a federal customer under M-26-15 and a commercial customer running JDK 27 is now holding two parameter sets, two calendars and two definitions of adequate, and the responses to the request for information closing on 27 September will show what the Department of War expects to be possible in software alone.
Our Signature Report: the PQC Migration Roadmap works the same calendar from the other end, taking the dates an organisation cannot move and setting the artifact to hold against each of them, from the certificate number to the test record for a replacement signing certificate. It is also in the All-access membership alongside the earlier editions these dates connect to, which is the argument for the membership: the calendar keeps moving, and the archive is where the previous moves are kept. The public analysis here stays open to anyone starting from the beginning.
The next checkable item is close. On 22 October 2026 every agency plan under M-26-15 is due, and the plans are where the cryptographic-agility architecture either has an owner or does not. Whether any of them is published, and in how much detail, is the thing to look for six weeks from now.
Published intelligence, built to inform your own decisions. Published: 3 September 2026.
Sources: National Institute of Standards and Technology, Cryptographic Module Validation Program, sections "Applicability of Validated Modules" and the validated-modules Historical List description, for the 21 September 2026 move of all FIPS 140-2 validated modules to the Historical List and the "existing systems only" and "should not include these in new systems" language; program page checked 3 September 2026. QuSecure, "QuSecure Delivers Field-Ready Post-Quantum Cryptography and Crypto-Agility for U.S. Army at Project Convergence Capstone 6", Business Wire, 2 September 2026, for Technical Readiness Level 7, Project Convergence Capstone 6, the National Training Center at Fort Irwin, the capabilities described and the "ready to deploy today" language; the readiness level is the company's statement about an Army event and the Army has published no rating of its own. Quantum Computing Report, "QuSecure Achieves TRL-7 at U.S. Army Project Convergence Capstone 6 for QuProtect R3", 2 September 2026, for the automated cryptographic bill of materials detecting non-compliant or quantum-vulnerable algorithms across live mission nodes. SEALSQ Corp, "SEALSQ Corp Reports Preliminary H1 2026 Results; Revenue up 120%, FY 2026 Guidance Reaffirmed", GlobeNewswire, 6 July 2026, for the approximately $11 million preliminary unaudited company-wide first-half revenue against $5 million a year earlier, the reaffirmed $27 million to $36 million full-year guidance, and the management-estimated pipeline of more than $225 million through 2029 including more than $60 million attributed to QS7001 and QVault TPM; the pipeline is an estimate of potential opportunities, not booked revenue. SEALSQ and wolfSSL, "SEALSQ Announces wolfTPM Support for Its Post-Quantum TPM Technology", newswire release carried 3 September 2026, for the QVault TPM, TPM 2.0 version 1.85, and the ML-DSA and ML-KEM testing on physical hardware. OpenJDK, JDK 27 project schedule, for general availability on 15 September 2026, and JEP 527, for hybrid post-quantum key exchange in TLS 1.3 with X25519MLKEM768 first in the default preference list and no application code change. Microsoft, "Next generation code signing", 20 August 2026, for the 19 October 2026 expiry of the Windows Production PCA 2011, the move to RSA-3072 and SHA-384 later in 2026, post-quantum signing by default in 2027, and the practices that break validation. Cisco, post-quantum cryptography for IKEv2 sessions, IOS XE configuration documentation, for the ML-KEM-768 hybrid on production routers. Executive Order 14412, signed 22 June 2026 and published in the Federal Register on 25 June 2026 as document 2026-12909, for the direction to the Office of Management and Budget, the 31 December 2030 and 31 December 2031 dates, and the exclusion of national security systems from that subsection. Office of Management and Budget, Memorandum M-26-15, 24 June 2026, for the 120-day agency migration plan deadline falling on 22 October 2026 and the required cryptographic-agility architecture and third-party coordination plan. ExecutiveGov, reporting of the Department of War request for information on software-only post-quantum encryption, 1 September 2026, for the 27 September 2026 response date, the ML-KEM-1024 key transport specification and the 31 December 2029 implementation target; the underlying SAM.gov notice is not anonymously fetchable, and a request for information gathers responses rather than imposing a rule. Lloyd's Register, "Our history" and "LR Classification", for the 1760 founding and for classification as periodic survey and verification against class rules. Public pages checked 3 September 2026.
Published intelligence, built to inform your own decisions. Published: September 4, 2026.