Security Domains Digest

Secrets & Machine Identity / PQC

Secrets & Machine Identity / PQC

Key Questions

What are the key US mandates driving post-quantum cryptography (PQC) migration?

US executive orders require 2027 pilot migrations and cryptographic bills of materials. Microsoft has set a 2029 target for its full transition to PQC.

What does Cloudflare data reveal about current PQC adoption rates?

70% of key exchanges are already PQC-enabled, but only 10% of origin servers support it. This highlights a significant gap in end-to-end protection.

Why is Harvest Now, Decrypt Later (HNDL) considered a critical risk?

Adversaries can record encrypted data today for decryption once quantum computers mature. Multiple articles reframe HNDL as an immediate compliance and data-in-use risk.

How is cyber insurance responding to PQC readiness?

Insurers are increasingly scrutinizing organizations' PQC roadmaps as part of risk assessments. Lack of progress may affect coverage terms.

What new guidance addresses database encryption migration for PQC?

The article 'PQC at the Application Layer: Database Encryption Migration' focuses on key hierarchy re-wrapping to protect data at rest.

What growth metrics highlight the machine identity market?

Keeper Security reports $225M ARR and a 150:1 non-human identity (NHI) ratio, underscoring rapid expansion in secrets and machine identity management.

What real-world case study illustrates secrets hygiene failures?

CISA's GitHub leak after-action report exposed weaknesses in secrets management, playbook readiness, and reporting channels.

How are geopolitical deadlines affecting PQC strategies in North America?

Canada faces 2030/2031 deadlines aligned with US policy, creating urgency for coordinated cross-border quantum-safe transitions.

PQC urgency: US executive orders mandate 2027 pilot migration and cryptographic bill of materials; Microsoft targets 2029 transition. Cloudflare data shows 70% PQC key exchange but only 10% origin server support. HNDL critical. Cyber insurance scrutinizing PQC roadmaps. New: 'PQC at the Application Layer: Database Encryption Migration' addresses key hierarchy re-wrapping. New: Quantum legal issues article reframes HNDL as compliance risk. New: Post-quantum mandate analysis (EO 14409) highlights scope and data-in-use gap. New: Quantum HNDL piece (61% stat) reinforces urgency. New: SMB PQC readiness article. New: NetSfere post-quantum enterprise messaging technical deep-dive. Keeper Security $225M ARR and 150:1 NHI ratio underscores machine identity market growth. New: Bruno Couillard piece adds Canada-US geopolitical angle with 2030/2031 deadlines. New: CISA's own GitHub leak after-action report reveals failures in secrets hygiene, playbook readiness, and reporting channels—a real-world case study for secrets management and cloud security. New: SEALSQ and Quobly sign $5M deal to secure silicon quantum computing platforms with Cryo CMOS ASIC and Root-of-Trust. New: '5 Pillars of Post-Quantum Security Protocols for AI-Driven Systems' provides actionable framework (inventory, hybridization, crypto-agility, MCP transport security, continuous governance) directly addressing HNDL and AI system vulnerabilities. New: Article 'Quantum-safe encryption is becoming a licence to operate' reframes PQC as licensing/certification condition, citing France's policy shift—reinforcing compliance urgency for GRC and procurement teams. New: 'What Is HNDL? Harvest Now, Decrypt Later, Explained' provides a solid foundational explainer reinforcing the urgency of PQC migration.

Sources (13)
Updated Jul 12, 2026
What are the key US mandates driving post-quantum cryptography (PQC) migration? - Security Domains Digest | NBot | nbot.ai