Malaysia Is the Only ASEAN State Rated Tier 1 for Post-Quantum Cryptography Migration Readiness in SITG-Consulting's September 2026 Assessment of the ASEAN-10
Circle's August 31 Disclosure Reads 813 Logical Qubits Off Eigen Labs' ECDSA.fail Leaderboard: What a Google and Stanford Estimate Says a secp256k1 Attack Actually Costs
Circle's August 31 disclosure tells developers that breaking elliptic curve signatures now takes 813 logical qubits, a figure lifted from one axis of Eigen Labs' ECDSA.fail circuit competition. We put it back beside the March 2026 Google, Stanford, and Ethereum Foundation estimate, under 1,200 logical qubits and 90 million Toffoli gates on fewer than half a million physical qubits, and beside Willow's actual 105 physical qubits, to show how a defense buyer should read quantum cryptanalysis headlines while setting a post-quantum migration schedule.
SEALSQ's QVault TPM Puts ML-DSA and ML-KEM in Silicon and wolfSSL's wolfTPM Now Drives It: What the September 3, 2026 Integration Means for Long-Life Defense Platforms
SEALSQ and wolfSSL announced on September 3, 2026 that the wolfTPM stack now drives the QVault TPM, a chip on track to be the first shipping TPM 2.0 device with ML-DSA and ML-KEM in silicon under the Trusted Computing Group's v1.85 specification. We read the integration as a hardware root of trust story for thirty-year defense platforms, where the soldered TPM is the last chip to change, and set out what still stands between this laboratory integration and a post-quantum TPM a program office could specify: an availability date, independent validation and public side-channel scrutiny.
Cloudflare's 2029 Target, HPE's 24 to 48 Months, Dell's 1.2 Million Old Servers and QuSecure's Vendor-Reported TRL 7: Four Post-Quantum Clocks Against EO 14412's 2030 and 2031 Deadlines
Four companies put dates and numbers on the post-quantum migration in the first week of September 2026, and none of them is a government. Cloudflare's roadmap, restated in the German trade press on 4 September, targets completion in 2029; HPE told enterprises on 4 September to plan on 24 to 48 months; Dell told investors on 1 September that 1.2 million of its installed servers are old enough that customers are refreshing them, with security requirements among the reasons; and QuSecure reported on 2 September that its platform ran under soldier operation at a US Army exercise and, by the company's reading, reached Technology Readiness Level 7. Read against Executive Order 14412's 2030 and 2031 federal deadlines, the four give a program office something the policy documents do not: the pace at which suppliers say they can move, and the size of the installed base that has to be carried along.
The four announcements measure different things. Cloudflare's is a post-quantum roadmap with dated milestones, the first of which it has announced support for. HPE's is a lead-time estimate for a large enterprise. Dell's is a count of hardware that customers are replacing whatever the cryptography does. QuSecure's is a readiness level reported by the company from a field exercise. This Monitor reads each one for what it can support, then sets all four beside the federal calendar and beside what the founder of this site wrote about lead times in War on the Rocks in July.
ASD's LATICE Guidance of 20 July 2026 and the NCSC's Workshop Report of 22 July 2026 Both Start With the Cryptographic Inventory, and the EU's End-2030 Date Leaves Little Time to Build One
Three post-quantum migration documents surfaced together on 4 September 2026: the Australian Signals Directorate's LATICE guidance of 20 July, the UK NCSC's report of 22 July on its first industry migration workshop, and an Italian reading of the EU roadmap that sets the end of 2030 for critical infrastructure. ASD and the NCSC both begin with a cryptographic inventory, which ASD says should be started in partial form and maintained over time. The NCSC gives large organizations two to three years for that discovery phase against its 2028, 2031 and 2035 dates, and its workshop found that supplier readiness decides whether a plan can be kept. This Monitor reads what the documents let a program office refuse, and what an inventory cannot answer.
Forescout Finds Post-Quantum Key Exchange on More Than 19 Million of 160 Million SSH Servers, With OT at 16 Percent and Medical Devices at 6 Percent
Forescout's Vedere Labs measured post-quantum key exchange across more than 160 million internet-facing SSH hosts: support grew 72 percent in a year, to more than 19 million servers, with Forescout attributing most of the growth to OpenSSH upgrades. The same measurement puts operational technology at 16 percent, medical devices at 6 percent, and embedded Dropbear stacks at 3 percent. We read the two-speed migration as a capability question for the long-lived equipment defense estates run on, and what crypto-agility clauses should demand of 2027 contracts.
MIT and Google Cryptographers Refute Daniel Simon's Claimed Quantum Attack on the Lattice Problems Behind ML-KEM
A Task Force for the Ciphertext Already on Deposit
The U.S. Treasury has launched a Quantum-Readiness Task Force to move the financial sector onto post-quantum cryptography, anchored to Executive Order 14412 and its 2030 and 2031 federal deadlines. We read the announcement through the threat it exists to counter, harvest now, decrypt later collection against long-lived financial data, and list the checkpoints that would show a coordination body turning into an enforceable migration calendar.
The Imported Key Travels in a Quantum-Resistant Envelope
Google Cloud has opened a preview of quantum-resistant key import in Cloud KMS, wrapping customer key material in ML-KEM and X-Wing envelopes designed to resist known classical and quantum attacks on a recorded transfer. We read what the release means for harvest now, decrypt later exposure, why the wrapped key is the densest target that attack pattern has, and what still separates a preview label from a bring your own key mandate a program office can rely on.
The Post-Quantum Migration Reaches the Silicon Layer
In one August week, a Wuhan university team released a 28-nanometer post-quantum cryptography chip with a naval research institute in the room, and a Canada-Taiwan consortium validated a compute-in-memory rival for the same NIST algorithms. A close look at what a hardware root of trust means for forces whose platforms outlive their ciphers, and at the evaluation gates still standing between both chips and a program office.
Lazarus Fits Its Zero-Day With a Post-Quantum Key Exchange
Check Point Research found the North Korea-linked Lazarus Group using a Kyber-based key-encapsulation step to protect delivery of a privilege-escalation payload inside a Windows zero-day chain aimed at aerospace and defense targets. The post-quantum scheme from which the ML-KEM standard was derived has now surfaced as an offensive tool.
Sixty Hours of AI Cryptanalysis Retired the Hawk Signature Scheme
An Anthropic frontier model found a hidden lattice symmetry that roughly halves the lattice dimension needed to attack Hawk, and the team withdrew the scheme from NIST's process a day later. AI-assisted cryptanalysis is now a working method, with direct consequences for post-quantum cryptography buyers and the case for crypto-agility.
Cloud KMS Makes Post-Quantum Signing a Systems Test
Cloud KMS support for post-quantum digital signatures turns algorithm availability into a test of firmware signing, roots of trust, and cryptographic interoperability.
AI Cryptanalysis Changes Post-Quantum Assurance
AI cryptanalysis found an end-to-end weakness in a HAWK research parameter set, shifting post-quantum assurance toward reproducible evidence and independent cryptographic validation.
Hong Kong’s Quantum Readiness Score Makes the Work Visible
Hong Kong’s new quantum preparedness index turns a distant concern into a measurable program, while cryptographic inventory and operational pilots determine whether the score represents real progress.
The CBOM Turns Post-Quantum Migration Into a Map
A cryptographic bill of materials turns hidden algorithms and trust relationships into a working map for post-quantum migration and supplier planning.
One Million Noisy Qubits Reprice the Attack on RSA-2048
A Google Quantum AI paper cut the projected hardware cost of breaking RSA-2048 by a factor of twenty. Here is what the new estimate means for harvest now, decrypt later and the arithmetic of your post-quantum migration deadline.