Microsoft published guidance on October 8, 2026, outlining the operational and architectural challenges of post-quantum authentication and urging organizations to begin testing certificate ecosystems.
The Authentication Challenge
Microsoft stated that while much of the current post-quantum cryptography discussion focuses on data confidentiality and "harvest now, decrypt later" risks, post-quantum authentication introduces a different set of challenges. Authentication depends on a broad ecosystem of technologies, including certificates, private keys, trust anchors, PKI services, applications, devices, and hardware security modules.
Because certificates must be issued, distributed, stored, validated, renewed, and managed across diverse environments, changes to cryptographic algorithms impact operational processes, interoperability, and infrastructure readiness. Microsoft noted that many organizations lack a complete inventory of every system depending on certificates.
PQC TLS Pilot Program and Windows Support
To help the ecosystem gain practical experience, Microsoft launched the PQC TLS Pilot Program on August 27, 2026. The pilot enables approved certificate authorities in the Microsoft Trusted Root Program to evaluate PQC TLS roots and certificate issuance using the ML-DSA-87 algorithm in controlled environments.
An August 2026 release added seven pilot roots operated by ComSign, DigiCert, HARICA, IdenTrust Services, Sectigo, Shanghai Electronic Certification Authority, and SSL.com. Furthermore, on supported Windows 11 systems, ML-DSA certificates can be evaluated using updates released on July 28, 2026: KB5101681 for version 26H1 and KB5101684 for versions 25H2.
Recommended Preparation Steps
Microsoft recommends viewing post-quantum readiness as a multi-year planning effort rather than a future migration project. Security leaders and administrators are advised to test interoperability and surface compatibility gaps early to reduce future migration risk.
What to do
- Inventory certificate-dependent systems such as applications, services, devices, and appliances.
- Map public and private trust relationships, including internal hierarchies and device authentication systems.
- Assess vendor readiness by engaging certificate providers, PKI vendors, and hardware security module providers on their post-quantum roadmaps.
- Identify long-lived infrastructure with lengthy upgrade cycles, like embedded devices and operational technology.
- Establish non-production testing environments to safely evaluate post-quantum certificate hierarchies.
- Build a multi-year transition roadmap by assigning owners, sequencing dependencies, and prioritizing modernization work.
Key facts and where they come from
- Microsoft launched the PQC TLS Pilot Program on August 27, 2026.
Microsoft launched the PQC TLS Pilot Program on August 27, 2026.
- The pilot uses the ML-DSA-87 algorithm for evaluating PQC TLS roots and certificate issuance.
Module-Lattice-Based Digital Signal Algorithm, ML-DSA-87.
- The August 2026 release added seven pilot roots from specific certificate authorities.
the August 2026 release added seven pilot roots operated by ComSign, DigiCert, HARICA, IdenTrust Services, Sectigo, Shanghai Electronic Certification Authority, and SSL.com.
- Windows support for testing ML-DSA certificates begins with July 28, 2026 updates KB5101681 and KB5101684.
Support begins with the July 28, 2026 updates: KB5101681 (OS Build 28000.2608) for 26H1 and KB5101684 (OS Builds 26200.8973 and 26100.8973) for 25H2.
