SEALSQ's 9 September 2026 Interview on Fifteen-to-Twenty-Year Medical Device Lives, and the QS7001 Page That Still Lists Kyber and Dilithium 2
Quentir Medicine Monitor
Evidence-based insights for quantum medicine. Published by Quentir Systems LLC · September 10, 2026.

On 9 September 2026 Carlos Moreira, founder and chief executive of the Nasdaq-listed semiconductor company SEALSQ, described in a published interview a post-quantum exposure specific to connected physical systems, among them medical devices, which he sets alongside the familiar risk of stored data waiting to be decrypted later. His reason rests on an arithmetic any hospital finance office already runs: equipment bought today could remain in service well beyond the transition date NIST has proposed.
Many connected devices stay fifteen or twenty years in service and cannot be swapped out quickly. A draft NIST report proposes that the public-key algorithms those devices ship with become disallowed after 2035, with the weaker parameter sizes deprecated five years earlier. The company's answer is a secure microcontroller called the QS7001, whose product page names medical and healthcare devices as a target market, and whose specification sheet still lists Kyber and Dilithium 2, the names those algorithms carried before NIST standardized them.
What Carlos Moreira Said on 9 September 2026, and Why Fifteen to Twenty Years Is the Number That Matters
The interview was published by Unite.AI on 9 September 2026. Moreira founded WISeKey in 1999 and later created SEALSQ as a separate semiconductor and post-quantum security company. His contribution is a distinction rather than a discovery, and it is worth reporting in his own terms. Harvest-now-decrypt-later, he says, is a real concern, because sensitive information stolen today could be decrypted once large-scale quantum computers exist. Connected physical systems, he continues, present "a different challenge," because "cars, medical devices, industrial controllers and smart infrastructure all need to know whether the code they are running is authentic." The interviewer raised the possibility that this second exposure is the more pressing one; the answer describes what makes it distinct without placing it above the first.
The distinction is worth holding onto, because it splits a hospital's problem in two. One half concerns records at rest, the exposure this Monitor examined when it asked how long a patient record outlives the encryption wrapped around it. The other half concerns the equipment itself: an infusion pump accepting a firmware update, an imaging system authenticating to a network, a bedside monitor deciding whether an instruction it received is genuine. Those decisions are made by silicon, and the silicon is bought once.
Moreira's service-life figure is the load-bearing part. Devices of this kind, he says, "remain in operation for fifteen or twenty years and cannot be replaced or upgraded quickly." Applied to a purchase made in 2026, that range reaches 2041 to 2046. The interview also offers a triage method that survives translation out of vendor language: rank each device by how long it will stay in service, how hard it would be to update or replace, and what the operational consequence would be if its identity or its communications could no longer be trusted. Hospital estates rank badly on all three at once, which is the point.
What the QS7001 Product Page Lists: 80 MHz 32-Bit RISC-V, Kyber 512/768/1024 and Dilithium 2
In the interview Moreira describes the part precisely: the QS7001 "addresses this as a 32-bit secure RISC-V microcontroller with a hardware Root of Trust and cryptographic acceleration. It integrates the NIST-standardized ML-KEM for key establishment and ML-DSA for digital signatures." ML-KEM is the key-establishment mechanism standardized as FIPS 203, and ML-DSA is the signature scheme standardized as FIPS 204.
The company's own QS7001 page describes an 80 MHz 32-bit secured RISC-V CPU with a hardware root of trust, and names its algorithm support as Kyber at parameter sets 512, 768 and 1024 together with Dilithium 2. Kyber and Dilithium are the names those submissions carried through the NIST selection process; ML-KEM and ML-DSA are the names of the standardized versions, which differ from the earlier drafts in specified detail. A page that lists the older names does not by itself establish which version the silicon implements, and a hospital buying a device built on this part has a plain question to put to the manufacturer.
Two further items on that page belong in the same conversation. The Common Criteria EAL5+ evaluation is recorded as in progress, meaning it has been entered rather than completed. The accompanying QVault TPM software stack is described as under development toward future FIPS 140-2 and 140-3 evaluation objectives, which is a stated goal rather than a present status. The page names its medical market explicitly, listing wearables, sensors, imaging systems, diagnostics and connected medical devices among the applications, so the intent to sell into hospitals is the company's own, not an inference drawn here.
Quantum pillar: post-quantum cryptography. Technology readiness: TRL 4 of 9. Rung four on the shared ladder both Evidence Registers use reads "the pieces were put together and tested under laboratory conditions." What supports that here is narrow and specific: the QS7001 is a complete commercial part with a published specification, and it sits inside a Common Criteria EAL5+ evaluation, which is laboratory testing of an assembled product by a licensed evaluator. That evaluation is recorded as in progress, so no passing result is claimed for it, and no independent test report on this part appears in the sources read for this note. Rung six would need a working part carrying a realistic task from end to end, which nothing here demonstrates. This rung describes the microcontroller alone, and the regulatory standing of any medical instrument built on it is a separate question on which this placement makes no claim.
Why NIST IR 8547's 2030 and 2035 Dates Fall Inside an Imaging System's Service Life
The dates come from NIST Internal Report 8547, "Transition to Post-Quantum Cryptography Standards", whose initial public draft was released on 12 November 2024. Its transition tables put ECDSA and RSA at the 112-bit security strength level, which covers RSA-2048 and the P-224 curve, as deprecated after 2030 and disallowed after 2035. At 128 bits of security strength and above, the level that covers the widely deployed P-256 curve, the same families carry no 2030 deprecation and go from acceptable to disallowed after 2035 in a single step. The report gives the two words fixed meanings borrowed from SP 800-131A. Deprecated means the algorithm "may be used, but there is some security risk," and the data owner decides whether to carry it. Disallowed means it "is no longer allowed for the stated purpose," which withdraws the data owner's option to accept that risk.
Set those dates against the service life. A device installed this year on a fifteen-year horizon is still in the building in 2041, six years past the point at which NIST proposes to disallow its original public-key cryptography. On a twenty-year horizon it reaches 2046. Those statuses attach to the uses NIST approves, and they are purpose-specific: the report keeps a legacy-use category covering already-protected information, so a disallowed signature algorithm may still be used to verify an old signature. They do not by themselves make a hospital's installed equipment unlawful in 2036, and this draft sets no purchasing deadline for any health system. What a report of this kind moves is the ground under a procurement conversation, since it tells a manufacturer which algorithms will remain approved for the purposes its customers care about. A hospital planning against an initial public draft is planning against a stated intention, and the service-life arithmetic holds whichever year the final report settles on.
Why Forescout Measured Post-Quantum Key Exchange on 6 Percent of Connected Medical Devices
A vendor interview establishes an argument. A measurement establishes where the estate actually stands. On 24 June 2026 Forescout Research published its measurement of post-quantum adoption by device class, drawn from enterprise assets observed in the company's Device Cloud between August 2025 and April 2026. It counts one narrow thing: the share of devices running an OpenSSH version, 9.x or 10.x, that offers a post-quantum key exchange among its defaults. On that measure connected medical devices reached 6 percent, against 50 percent for ordinary information technology, 28 percent for general connected devices and 16 percent for operational technology. This Monitor's sister lane recorded the same four figures in June. Forescout does not publish the denominator behind the device-class percentages, so the ordering of the four classes is firmer evidence than any one level.
One protocol on one family of software is a long way from a full picture of a device's cryptography, and a hospital should read the figure as a proxy rather than an inventory. It says nothing about how a device authenticates its firmware or verifies a command, which is the exposure the interview describes, so these two lines of evidence sit beside each other without either confirming the other. What the measurement supports is narrow and still worth having: on this one indicator, connected medical devices ranked last of the four classes Forescout observed. One is a vendor's account of where the risk sits, the other an outside count on a single protocol, and a board asking about its own estate needs a third thing that neither supplies, which is an inventory of its own devices.
Five Questions a Hospital Buyer Can Ask Before Signing a Device Contract
Which cryptographic algorithms and parameter sets does this device use today, named as FIPS 203 and FIPS 204 versions where they apply rather than by the Kyber and Dilithium submission names? Can its firmware signing and key establishment be updated in the field after installation, or does a change of algorithm require replacing hardware? What is the manufacturer's stated support horizon for this model, and how does it compare with the 2035 disallowance date? Which independent security evaluations of the underlying secure element are complete, and which are in progress, with the evaluation reference and its date? And where a device cannot be migrated within its service life, what compensating measures does the manufacturer propose for the years between 2035 and the end of that life?
None of those questions needs a quantum specialist to ask or a vendor to grade. Each has a documentary answer that belongs in a procurement file.
How Quentir Reads It
The argument in this interview is sound and the company making it sells the remedy, so both halves deserve stating. The service-life reasoning is correct and it is underused: hospital estates are procured on capital cycles that outrun cryptographic ones, and the mismatch is arithmetic rather than opinion. The specific product claim is where a reader should slow down. A page naming Kyber 512, 768 and 1024 alongside Dilithium 2 while the chief executive names ML-KEM and ML-DSA is a discrepancy that a buyer resolves with one written question to the vendor, and this Monitor makes no finding about which the silicon implements.
This Monitor places the QS7001 at rung four on the evidence available, treats the medical market listing as a stated commercial intent rather than evidence of clinical deployment, and treats the Common Criteria evaluation as pending until the company records it as closed, a security result that would still sit apart from any medical-device regulatory clearance. The datapoint worth carrying forward is the distance between the 6 percent Forescout counted in June and the 2035 date NIST has drafted. Neither figure is a deadline a hospital has been given, and together they describe a purchasing decision that has to be taken years before the question becomes urgent.
Sources
Primary source: Carlos Moreira, founder and chief executive of SEALSQ and founder of WISeKey, in the Unite.AI interview series, 9 September 2026, for the quoted distinction between harvest-now-decrypt-later and connected physical systems, the fifteen-to-twenty-year service life, the three-question device triage and the description of the QS7001 as integrating ML-KEM and ML-DSA. SEALSQ's QS7001 product page supplies the 80 MHz 32-bit RISC-V CPU, the algorithm listing of Kyber 512/768/1024 with Dilithium 2, the Common Criteria EAL5+ evaluation recorded as in progress and the named medical and healthcare applications. NIST Internal Report 8547, initial public draft of 12 November 2024, supplies the transition tables and the definitions of deprecated and disallowed. Forescout Research, 24 June 2026, supplies the device-class figures, the Device Cloud window of August 2025 to April 2026 and the OpenSSH 9.x and 10.x definition of support, and states no denominator. The judgments are this Monitor's own: the TRL 4 placement and its limits, the reading of the Kyber and Dilithium naming as an open question for a buyer rather than a finding about the silicon, the service-life arithmetic reaching 2041 and 2046, the reading of NIST's statuses as purpose-specific rather than a hospital purchasing deadline, and the five procurement questions.