An ID card with a notary’s stamp.
A digital certificate is the ID card of a server or a device. What guarantees it is genuine is an authority that stamps it with its own signature, like a notary. And the notary’s stamp is, in turn, recognized by an authority above it: that is the chain of trust.
Today’s signatures (RSA, ECDSA) are stamps a quantum computer could forge. Whoever forges the notary’s stamp makes fake IDs that pass any check. That is why, during migration, the chain is only as strong as its weakest link.
Key exchange is moving. Signatures are at zero.
A 2026 study measured 32,011 web domains. 49.3% already do the key exchange with the new protection (ML-KEM together with X25519). The share of certificates with the new signature: 0%. Certificates remain 54% RSA and 42% ECDSA, two years after the standard.
In practice: what is being protected today is the secrecy of the conversation, not proof of who is on the other end. And the reason isn’t lack of interest. There are no authorities yet issuing new certificates recognized by browsers, expected for late 2026 or 2027.
Two caveats on the number: the 49% is inflated by sites behind delivery networks that turn the new mode on by default; and the study measures the public web, not the devices this page is about.
The device outlives the deadline.
A web server renews its certificate every few months. A substation remote unit stays 15 to 20 years in the field; a car’s control unit, more than 15; a satellite, years in orbit with nobody to swap parts. The cryptography must last the device’s whole life, and whoever records the traffic today may try to decrypt it tomorrow.
The deadlines already have dates: in the US, national security systems require resistant algorithms in new purchases from 2027 (CNSA 2.0); the US federal government targets 2030 for key exchange and 2031 for authentication; the European Union, critical infrastructure by 2030. A device installed in 2026 will still be running through all of them.
The good news: devices use their own certificates (private PKI), under your control. They don’t need to wait for browsers. New identity can be issued now.
Issue, verify, update.
Issue. Your own authority, under your control, issues identity with the new signature (ML-DSA, SLH-DSA or XMSS) for each device. That part is off-the-shelf software (EJBCA, step-ca); we deliver the integration, we don’t reinvent cryptography.
Verify. Issuing is useless if the device doesn’t check properly. The differentiator is the root of trust on the device: secure boot and identity checking done in a hardware component. It builds on our post-quantum coprocessor design for satellites (documented, not yet a flight product).
Update. A fixed lock becomes a liability at the first new standard. The device in the field must be able to switch algorithms by remote update, without replacing hardware: that is crypto-agility. During the transition, hybrid mode runs the old and new locks at the same time.
New signatures are big.
Today’s ECDSA signature is 64 bytes. ML-DSA-65 is 3,309; the most compact SLH-DSA, 7,856. On a server it doesn’t matter. On a satellite radio link with packets of about 200 bytes, one new signature takes 13 to 40 packets.
In practice: on a satellite you don’t sign every message. The new lock sits at the edge of the session (one key exchange per pass, signatures only for rare commands) and telemetry runs on symmetric encryption, which already resists. It is the same design as TUBESEC.
| Signature | Public key | Signature | Quantum-resistant |
|---|---|---|---|
| ECDSA P-256 | 64 B | 64 B | no |
| Ed25519 | 32 B | 64 B | no |
| ML-DSA-44 | 1,312 B | 2,420 B | yes |
| ML-DSA-65 | 1,952 B | 3,309 B | yes |
| SLH-DSA-SHA2-128s | 32 B | 7,856 B | yes |
Long-lived device, own PKI.
Makes sense
- Satellite and satellite IoT: command and telemetry of devices nobody can reach physically.
- Energy and industrial automation: meters, remote units and controllers with 15 to 20 years of life (NERC CIP, IEC 62443).
- Automotive: control units and vehicle-to-vehicle communication (UNECE R155/R156).
Not yet
- Public website: depends on browser-recognized authorities, expected for late 2026 or 2027.
- Short-lived device: if it will be replaced before the deadline, urgency is lower.
- No control of the root: if the manufacturer won’t let you issue or update, the first step is contractual.
The digital ID card of a server or device, stamped by an authority.
The sequence of stamps, from the root down to the device. It is worth what its weakest link is worth.
Changing the lock without changing the door: switching the algorithm by update, without replacing hardware.
Where this could be wrong.
The study measures the web, not your device
The 0% is for the public web. We don’t know adoption in private device PKIs, which is this page’s market.
Sizes are the standard’s
A real certificate carries names, dates and extensions, and is larger. The specimen’s packet count is a floor.
Deadlines are third parties’ and they move
The US and EU dates are those published through mid-2026 and have been revised, usually earlier.
The root of trust is still a design
Hardware verification builds on a satellite coprocessor design, not a certified product. Issuing and updating are off-the-shelf software.
How do your devices prove who they are, and how will they in 2035?
An assessment maps how your fleet issues and checks identity today, where "record now, decrypt later" exposes it, and what migration looks like: your own authority with the new signature, on-device checking and crypto-agility.
← Post-quantum · stickybit.com.br
- arXiv 2606.16473, "Measurement Study of Post-Quantum Readiness of Internet: 2026": 32,011 domains, 49.3% new key exchange, 0% certificates with the new signature (54% RSA, 42% ECDSA).
- NIST FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA), August 2024: key and signature sizes.
- Deadlines: NSA CNSA 2.0 (new acquisitions from 2027); US federal government (2030 key exchange, 2031 authentication); European Union (critical infrastructure by 2030, full transition by 2035).
- Post-quantum satellite coprocessor design and UHF link study (~200 B packets), Stickybit internal notes.