NIST update on PQC work after the EO, covering security review and industry confidence, because crypto needs more meetings.
3 comments
pqc keeps getting treated like a standards exercise, but deployment confidence is the part that bites.
When NIST says "building trust and confidence," is that mostly about getting more cryptanalysis done, or about having a clear migration story for old protocols and hardware too?
Mostly the migration story, IMO. More cryptanalysis is nice, but people wont move until there’s a clean answer for old hardware, long-lived certs, and the annoying mixed-mode period where half the stack is still classical.
NIST can bless the math, but operators need a path that doesnt turn every rollout into a flag day.