Sectigo Quantum Ready, Announced September 17, 2026: What Cryptographic Discovery Must Show a Defense Buyer
Quentir Defense Monitor
Evidence-based insights for quantum defense and security. Published by Quentir Systems LLC · October 4, 2026.

A defense organization can replace an encryption library and still have little understanding of the systems that depend on it. An identity service may support depot maintenance, a contractor portal and a planning application. Each owner sees part of that relationship. A migration decision needs the relationships together, including the consequences of changing one component while another remains in service.
That is the procurement problem behind cryptographic discovery. Sectigo announced Quantum Ready on September 17, 2026, offering discovery, dependency mapping and risk prioritization for post-quantum migration. The October 1 coverage appearing in this week's news pool describes that earlier announcement. Its date matters: the new evidence is an announced offering, with early access, and the public release supplies no defense deployment results.
For a buyer, the useful question is whether such a service can turn an incomplete understanding of an estate into a defensible sequence of upgrades. The capability would help protect a force's own digital systems while preserving their availability through change. The work belongs to defensive migration and crypto-agility, with the discovery result judged against what it can actually establish about an organization's dependencies.
What Sectigo's September 17 announcement establishes
The Sectigo release describes a Cryptographic Bill of Materials, or CBOM, and risk assessment using criticality, sensitivity, dependencies and migration complexity. It places discovery and assessment in Quantum Ready and lifecycle execution in Sectigo Certificate Manager. Chief Product Officer Ian Hassard explains the visibility problem; CEO Kevin Weiss describes the company's broader product direction.
That division creates a useful purchasing distinction. A discovered asset has to become a decision someone can implement. Procurement can examine the evidence passed between discovery and change management: what was observed, which service relies on it, which owner accepts the proposed change and how successful replacement will be demonstrated. The presence of a certificate-management platform alongside a discovery product leaves those questions open for evaluation.
The public announcement does not provide a discovery-accuracy benchmark, a representative test estate or a measured reduction in migration effort. Those omissions limit the conclusions available today. An early-access invitation establishes a route to evaluation. It gives a program office no basis for assuming the system has already demonstrated coverage of its particular equipment, applications or supplier relationships.
A practical evaluation would distinguish the number of findings from their usefulness. Hundreds of certificates associated with a single shared service might represent one substantial migration dependency. A small component with a long support life could create a more difficult replacement problem. Counting assets without explaining the service relationships would make these two situations look misleadingly similar.
Why defense buyers need dependency evidence across service boundaries
The defensive value is continuity of trusted services through cryptographic replacement. A force needs to maintain access to its own systems, validate information from suppliers and preserve the ability to authenticate software updates. Migration can affect these functions at different speeds. Understanding their dependencies can help a buyer recognize when a local upgrade depends on another organization's change schedule.
Consider a hypothetical maintenance service shared with a contractor. Its visible certificate might be easy to replace. The client software that accepts it might have a slower update cycle, while a supporting device might require a separate qualification process. An inventory that connects these relationships would support a more credible cost estimate. An inventory that ends at the certificate would leave the buyer to reconstruct them elsewhere.
This is also why crypto-agility has to reach the procurement relationship. A supplier's promise to support new algorithms becomes useful when it identifies the affected product version, the update path and the conditions under which compatibility will be tested. A buyer assessing discovery software would need to see how unsupported or inaccessible components remain visible in the resulting assessment.
Quentir's earlier analysis of how a CBOM supports migration planning explains the dependency-map argument. The new procurement issue is whether a commercial discovery service can populate that map accurately enough to support decisions. A diagram can make relationships easy to understand; its operational value depends on the observations and supplier evidence behind each relationship.
The same reasoning applies to the assessment's lifespan. A new application version, a replaced device or a changed service provider can alter the migration picture. For a defense buyer, an inventory's usefulness therefore depends on how changes appear and how gaps are communicated. A clear statement of what remains unknown can prevent a program from mistaking an attractive dashboard for complete estate coverage.
Quantum pillar: post-quantum cryptography (migration and crypto-agility). Use posture: defensive. Technology readiness: not applicable. This product announcement supplies no validation result that would place the offered discovery capability on the readiness ladder.
How NCSC's 2028 milestone changes the value of discovery
The UK NCSC migration timeline calls for discovery and an initial migration plan by 2028, the highest-priority migration activities by 2031, and completion by 2035. It addresses large organizations, critical infrastructure and bespoke IT. Its guidance also recognizes long-lived hardware, supplier dependencies and the need to preserve continuity during migration.
These milestones make discovery an investment input. A program office needs enough understanding to allocate engineering effort and align replacements with support arrangements. Buying visibility without a route into planning could consume the preparation period while leaving the expensive decisions unresolved. Buying a prioritization score without understanding its inputs could shift attention toward the components the tool can most easily observe.
For a defense acquisition team, priority can involve several different clocks. Information may need confidentiality beyond the lifetime of the system that stores it. A platform's physical service life may exceed the support period for one embedded component. A contractor's release schedule may determine when interoperability can be assessed. These are analytical considerations for comparing migration options, rather than measured features of Sectigo's offering.
The 2028 target also raises a resourcing question. Someone has to resolve findings that automation cannot settle. Supplier engagement, architectural review and acceptance testing require people with authority and time. A procurement proposal becomes easier to assess when it estimates that work alongside the software deployment, because a discovery tool can reveal unresolved decisions faster than an organization can close them.
The defense-specific benefit would be earlier visibility of an upgrade dependency that threatens service continuity. Whether that benefit appears in practice depends on the estate's access constraints, the quality of supplier information and the buyer's ability to act on the findings. A demonstration in ordinary enterprise IT would need additional evidence before supporting a claim about long-lived defense equipment.
NIST separates discovery from interoperability testing
The NIST NCCoE migration project organizes work around cryptographic discovery and interoperability testing. Discovery examines where cryptography protects information and systems; interoperability work examines how implementations function together. Its public materials include preliminary practice-guide volumes and contributions from technology suppliers and government organizations.
This provides a useful evaluation structure. An inventory can identify a dependency that needs replacement. Separate testing has to establish whether the proposed replacement works with the surrounding systems. A successful discovery exercise would therefore justify confidence in the assessment it produced. Confidence in a migrated service would require evidence about the subsequent implementation and its behavior.
A buyer could compare a candidate tool's findings with an independently understood evaluation estate. The important result would include missed components and ambiguous dependencies, with enough explanation to understand why they were missed. That comparison would help establish where the tool reduces manual effort and where architecture review or supplier confirmation still carries the assessment.
Exportability also affects the ability to compare products over time. If a buyer can carry asset identifiers, dependency findings and uncertainty into another assessment process, it can examine changes without rebuilding its understanding from the beginning. A proprietary score with opaque inputs could make that comparison harder. A procurement team would need an explanation of how findings remain intelligible outside the original dashboard, including how a later reviewer can distinguish an observed relationship from one supplied by an application owner.
The resulting map is itself consequential information. It can describe trust relationships, software dependencies and service owners. A procurement evaluation therefore has reason to examine where assessment data is processed, how access is controlled and how the buyer can retain usable results when the engagement ends. These are properties of the proposed service arrangement that require their own evidence.
Today's public development supports considering a new commercial option for the discovery stage of post-quantum migration. A defense program office could use an evaluation to establish estate coverage, the reliability of dependency findings and the effort required to turn them into accepted changes. Those results would give the buyer a basis for comparing the offering with its existing tools and manual assessment process.
Sources
Primary source: Sectigo corporate announcement, September 17, 2026, including Ian Hassard and Kevin Weiss. Context: UK NCSC migration timelines and NIST NCCoE migration project. Buyer analysis and hypothetical examples are Quentir analysis.