Microsoft is sounding a warning: the infrastructure that underpins digital trust—public key infrastructures (PKI), hardware security modules (HSMs), and security appliances—must begin preparing for post-quantum authentication. The company’s guidance, issued October 8, outlines how switching to quantum-resistant algorithms impacts not just encrypted traffic, but the full chain of certificate lifecycle and infrastructure.
The Challenge of Transitioning
Finding a quantum-safe cryptographic algorithm is only half the battle. Microsoft emphasizes that many organizations lack visibility into how certificates are used across their entire systems—embedded devices, custom applications, vendor services—and may discover failures only when pushing certificates into production. Larger, quantum-safe certificates and longer chains may affect performance, storage, and even network inspection.
Microsoft’s Path Forward
To accelerate readiness, Microsoft launched a Post-Quantum Cryptography TLS Pilot Program on August 27, 2026. The pilot lets trusted certificate authorities (CAs) test issuance and root certificates using ML-DSA-87, a signature algorithm resilient to quantum attacks. Seven CAs are already participating—including ComSign, DigiCert, Sectigo and others.
However, these pilot certificates are currently only intended for non-public, closed, or enterprise testing environments—not for production use or public websites. Microsoft is also calling on vendors of HSMs, certificate-managing software, and platform developers to confirm their involvement and support.
Organizations are urged to inventory certificate dependencies, map trust relationships (public and private), and take stock of equipment that may be difficult to update. This includes performing non-production tests covering issuance, renewal, validation, and management—not just a single successful connection.
The Broader Landscape
Other efforts are underway. Let’s Encrypt is charting a roadmap for Merkle Tree Certificates to adapt public-web authentication to quantum threats. Software improvements like OpenSSL’s post-quantum performance work are emerging, though hardware support lags in many cases. Supported Windows 11 systems have begun receiving updates that enable pilot certificate testing, showing Microsoft is already rolling out partial platform support.
To succeed, Microsoft’s guidance calls for a multi-year migration plan: clear ownership, prioritized modernization based on test outcomes, and conversations with all vendors in the certificate chain. Learning where assumptions about certificate size, algorithm behavior, or hardware limitations break down will help avoid painful surprises later.
Microsoft’s guidance marks a crucial inflection point in cybersecurity planning. As quantum computing steadily edges closer, attackers capturing or harvesting certificate data today could decrypt traffic after quantum breakthroughs. Rather than scrambling in response, organizations that proactively test, modernize, and coordinate across their certificate-and-HSM vendors will gain resilience. What to watch for next: vendor support for ML-DSA-87, concrete tests of specialized appliances, and how roadmap commitments translate into deployment in the field.