Image 1 of 1
Signature Brief 2026.9 — October 19 Comes Before 2030
Quentir Signature Brief 2026.9 — October 19 Comes Before 2030. The September 2026 edition, on the post-quantum procurement calendar: six dates between September 11 and October 22, 2026 that change what your estate does and what your procurement paper claims, laid against the federal and EU policy destinations they sit inside.
The six dates. September 11: the EU Cyber Resilience Act’s reporting duty applies (24 hours, 72 hours, 14 days). September 15: JDK 27 ships hybrid post-quantum key exchange first in its default TLS 1.3 preference list. September 21: every remaining FIPS 140-2 certificate moves to the CMVP Historical List. September 27: the Department of War closes a request for software-only encryption specified at ML-KEM-1024. October 19: the Windows Production PCA 2011 signing certificate expires, the first step to post-quantum signing by default in 2027. October 22: every federal agency’s migration plan is due under OMB M-26-15.
What you get. A 16-page board-ready brief: the calendar table with the artifact to ask for before each date; the mechanism (policy calendar versus platform calendar, and where the certificate lives); the sharp case of one vendor walked through all six weeks; four workstreams with an inspectable artifact each — the calendar-to-estate map, the certificate re-basing before September 21, the ML-KEM-768/1024 parameter-set policy tested against the JDK default and the defense specification, and the reporting rehearsal on the CRA clock; seven board oversight questions, each with what a good answer looks like; strategic insights; refresh triggers; and sources linked on the source name, with type and date.
Grounded in Ivy League research and a golden-triangle vantage across policy, academia, and industry. Published intelligence, identical for every reader; for advice on your specific case, consult qualified counsel. Digital download (PDF); single-organization internal-use license. All-access members read the full edition in the Quentir Library.
Quentir Signature Brief 2026.9 — October 19 Comes Before 2030. The September 2026 edition, on the post-quantum procurement calendar: six dates between September 11 and October 22, 2026 that change what your estate does and what your procurement paper claims, laid against the federal and EU policy destinations they sit inside.
The six dates. September 11: the EU Cyber Resilience Act’s reporting duty applies (24 hours, 72 hours, 14 days). September 15: JDK 27 ships hybrid post-quantum key exchange first in its default TLS 1.3 preference list. September 21: every remaining FIPS 140-2 certificate moves to the CMVP Historical List. September 27: the Department of War closes a request for software-only encryption specified at ML-KEM-1024. October 19: the Windows Production PCA 2011 signing certificate expires, the first step to post-quantum signing by default in 2027. October 22: every federal agency’s migration plan is due under OMB M-26-15.
What you get. A 16-page board-ready brief: the calendar table with the artifact to ask for before each date; the mechanism (policy calendar versus platform calendar, and where the certificate lives); the sharp case of one vendor walked through all six weeks; four workstreams with an inspectable artifact each — the calendar-to-estate map, the certificate re-basing before September 21, the ML-KEM-768/1024 parameter-set policy tested against the JDK default and the defense specification, and the reporting rehearsal on the CRA clock; seven board oversight questions, each with what a good answer looks like; strategic insights; refresh triggers; and sources linked on the source name, with type and date.
Grounded in Ivy League research and a golden-triangle vantage across policy, academia, and industry. Published intelligence, identical for every reader; for advice on your specific case, consult qualified counsel. Digital download (PDF); single-organization internal-use license. All-access members read the full edition in the Quentir Library.