- Joined
- Jan 22, 2026
- Messages
- 101
- Reaction score
- 923
It's time to admit that quantum threats are no longer a fantasy scenario.

In the United States, a systematic transition continues to the use of cryptographic standards that are resistant to attacks by quantum computers. As part of Presidential Decree No. 14306, signed in the summer of 2025, the Cybersecurity and Infrastructure Protection Agency (CISA) has published updated lists of software and hardware categories in which solutions with support for post-quantum cryptography are already available.
This step is aimed at reducing the risks associated with the possible emergence of quantum computing systems capable of hacking conventional data protection algorithms.
The lists were developed jointly with the National Security Agency and are aimed primarily at government agencies purchasing IT products. They reflect those categories where technologies that implement algorithms that are resistant to quantum threats are already available. These include cloud platforms, browsers, servers, encryption tools for information on devices, as well as instant messengers.
Most of these products have already implemented secure key establishment mechanisms that are resistant to potential quantum attacks, although digital signatures and authentication have not yet been implemented everywhere. However, CISA recommends using such solutions for all new purchases.
Another list includes product categories where the implementation of new cryptographic algorithms is still under development and testing. This includes network devices and software, telephony, operating systems, SaaS cloud services, access controls, cybersecurity solutions, and databases.
CISA emphasizes that manufacturers must ensure resilience to quantum threats not only in basic functions, but also in related capabilities, for example, when installing updates. As soon as the products from this list are ready, they will be transferred to the list of widely available solutions.
The basis for determining reliable algorithms is the initiative of the National Institute of Standards and Technology of the USA, launched back in 2016. To date, three cryptographic standards have been approved: ML-KEM for establishing keys, as well as ML-DSA and SLH-DSA for digital signatures.
The use of stateful hashed digital signature algorithms, including tree-structured variants, is also temporarily allowed. These algorithms are gradually replacing schemes that are vulnerable to quantum computing and will become the basis for future cryptographic infrastructure.
The transition to post-quantum cryptography covers a wide range of technologies, including not only familiar IT products, but also Internet of Things devices, as well as industrial equipment. Although such solutions have not yet been included in the published lists, they also have to adapt to the new standards.
Regular updating of the lists by CISA will allow us to quickly take into account the development of technologies and ensure the relevance of information security requirements in a changing threat landscape.

In the United States, a systematic transition continues to the use of cryptographic standards that are resistant to attacks by quantum computers. As part of Presidential Decree No. 14306, signed in the summer of 2025, the Cybersecurity and Infrastructure Protection Agency (CISA) has published updated lists of software and hardware categories in which solutions with support for post-quantum cryptography are already available.
This step is aimed at reducing the risks associated with the possible emergence of quantum computing systems capable of hacking conventional data protection algorithms.
The lists were developed jointly with the National Security Agency and are aimed primarily at government agencies purchasing IT products. They reflect those categories where technologies that implement algorithms that are resistant to quantum threats are already available. These include cloud platforms, browsers, servers, encryption tools for information on devices, as well as instant messengers.
Most of these products have already implemented secure key establishment mechanisms that are resistant to potential quantum attacks, although digital signatures and authentication have not yet been implemented everywhere. However, CISA recommends using such solutions for all new purchases.
Another list includes product categories where the implementation of new cryptographic algorithms is still under development and testing. This includes network devices and software, telephony, operating systems, SaaS cloud services, access controls, cybersecurity solutions, and databases.
CISA emphasizes that manufacturers must ensure resilience to quantum threats not only in basic functions, but also in related capabilities, for example, when installing updates. As soon as the products from this list are ready, they will be transferred to the list of widely available solutions.
The basis for determining reliable algorithms is the initiative of the National Institute of Standards and Technology of the USA, launched back in 2016. To date, three cryptographic standards have been approved: ML-KEM for establishing keys, as well as ML-DSA and SLH-DSA for digital signatures.
The use of stateful hashed digital signature algorithms, including tree-structured variants, is also temporarily allowed. These algorithms are gradually replacing schemes that are vulnerable to quantum computing and will become the basis for future cryptographic infrastructure.
The transition to post-quantum cryptography covers a wide range of technologies, including not only familiar IT products, but also Internet of Things devices, as well as industrial equipment. Although such solutions have not yet been included in the published lists, they also have to adapt to the new standards.
Regular updating of the lists by CISA will allow us to quickly take into account the development of technologies and ensure the relevance of information security requirements in a changing threat landscape.