Post-quantum authentication: Why organizations should start testing certificate ecosystems now
Microsoft urges organizations to inventory and test certificate systems now for post-quantum authentication using its PQC TLS pilot.
Microsoft says post-quantum planning must cover authentication as well as harvest-now-decrypt-later confidentiality risk, because certificates, PKI services, applications, devices, and hardware security modules will face new algorithms and larger chains. Its PQC TLS Pilot Program, launched August 27, 2026, lets approved certificate authorities in the Microsoft Trusted Root Program test non-public ML-DSA-87 roots and issuance in closed environments. Pilot certificates are not publicly trusted and must not be used for production or public websites. Microsoft recommends inventorying dependencies, reviewing vendor roadmaps, and creating non-production test environments before post-quantum authentication is required at scale.