Yesterday we argued that quantum computing is beginning to build the less glamorous infrastructure needed for commercial adoption. The same transition is now becoming visible in post-quantum security, where the conversation is moving beyond algorithms and standards towards validated products that governments and enterprises can actually procure.

Quantum computing has spent much of its life being measured through scientific achievement. Post-quantum cryptography has followed a similar pattern, with attention concentrated first on algorithm development and, more recently, on the standards needed to replace cryptography vulnerable to future quantum computers.

But standards alone do not secure an enterprise. On 20 August, Canadian cybersecurity company Crypto4A announced that its QASM cryptographic module had achieved FIPS 140-3 Level 3 validation. QASM sits at the core of the company’s QxHSM hardware security module platform and, according to Crypto4A, supports the complete set of post-quantum algorithms currently standardised by NIST. (PR Newswire)

The technology itself is important, but the more interesting development is what the certification represents.

Hardware security modules are one of the largely invisible foundations of digital infrastructure. They protect and manage the cryptographic keys used by banking systems, identities, government communications, applications and critical infrastructure. Moving those environments towards post-quantum cryptography therefore requires more than publishing new algorithms. Organisations need products capable of implementing them within security architectures that also satisfy existing assurance and procurement requirements.

FIPS 140-3 is part of that machinery. The standard establishes security requirements for cryptographic modules across areas including physical security, authentication, sensitive parameter management and lifecycle assurance. Level 3 introduces particularly stringent requirements around areas such as tamper resistance and protection of cryptographic material. (NIST Computer Security Resource Center)

That makes this another of quantum’s boring bits. And that is precisely why it matters.

From PQC standards to PQC procurement

NIST’s finalisation of its first post-quantum cryptography standards in 2024 was an essential milestone, but it was never the end of the migration process. Enterprises cannot simply replace an algorithm in a standards document and declare themselves quantum-safe.

Algorithms have to appear in libraries, hardware, PKI platforms, identity systems, network infrastructure and security products. Implementations have to be tested. Products need certification. Procurement frameworks have to recognise them. Organisations then have to work out where those products sit within existing architectures and how migration can take place without disrupting the systems they are intended to protect.

In other words, PQC has to move from cryptographic specification to operational infrastructure. The Crypto4A announcement is one indication that this process is beginning to mature.

There is also an important timing element. Existing FIPS 140-2 validated modules reach an important transition point on 21 September 2026, after which NIST’s Cryptographic Module Validation Program places them on its historical list for new US federal use, while FIPS 140-3 becomes the relevant validation regime for new systems. (NIST Computer Security Resource Center)

For organisations planning technology refreshes and long-term cryptographic migration, PQC support and current-generation validation can therefore increasingly become part of the same procurement conversation.

The boring bits are where adoption happens

This follows the broader pattern now appearing across quantum technology. Cloud providers are working on how enterprises will access quantum computers. Manufacturers are considering how the machines themselves can be industrialised. Computing companies are developing hybrid quantum, HPC and AI environments.

And on the security side, PQC is acquiring the certified hardware, validated implementations and migration infrastructure required to move from recommendation to deployment. None of this carries quite the excitement of announcing another quantum breakthrough but it is considerably closer to how technology becomes operational.

The transition to post-quantum security will not happen when somebody announces that quantum-safe algorithms exist. That happened two years ago. It happens when those algorithms become embedded in products that security architects can deploy, regulators can recognise and procurement departments can purchase

You could say that the quantum industry’s boring bits are getting rather interesting.


Discover more from The Quantum Space

Subscribe to get the latest posts sent to your email.

Leave a Reply

Trending

Discover more from The Quantum Space

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The Quantum Space

Subscribe now to keep reading and get access to the full archive.

Continue reading