www.microsoft.com 8 Oct 2026, 20:44 UTC

Microsoft launches PQC TLS pilot to test post-quantum certificates

Microsoft launches PQC TLS pilot to test post-quantum certificates
CyberSIXT Evidence Panel Source marked as original reporting

POST-QUANTUM authentication is moving from theory to concrete testing, with Microsoft launching a PQC TLS Pilot Program to help certificate authorities evaluate interoperability and operational readiness in controlled environments. Key focus is on how post-quantum algorithms affect the entire certificate ecosystem—from trust anchors and PKI services to devices and hardware security modules.

The pilot, announced for 27 August 2026, is limited to approved certificate authorities in good standing with the Microsoft Trusted Root Program and aims to surface interoperability, performance, and workflow gaps before broad adoption. Seven pilot roots were added in August 2026: ComSign, DigiCert, HARICA, IdenTrust Services, Sectigo, Shanghai Electronic Certification Authority, and SSL[.]com, with rolling admissions through to the end of 2026.

Participants are instructed that pilot certificates are not publicly trusted and must not be used for production trust or public websites, as ML-DSA support remains evolving.

Microsoft outlines a practical, multi-year approach for organisations preparing for post-quantum authentication. The article emphasises inventorying certificate dependencies, mapping trust relationships, and assessing vendor readiness, while identifying long-lived infrastructure and establishing safe, non-production testing environments.

It also describes end-to-end testing on supported Windows 11 configurations (e.g., OS Build 28000.2608 for 26H1 and 26200.8973/26100.8973 for 25H2) with ML-DSA certificates usable via Secure Channel in appropriate scenarios. The guidance invites PKI administrators, security leaders, and architects to build a phased roadmap, involve certificate providers, and pursue multi-year transition planning to mitigate migration risk as standards and platform support evolve.

The overarching message is to begin testing now to understand dependencies, performance implications, and operational impacts before post-quantum authentication is required at scale.

View full article

Article by CyberSIXT