Post-quantum attestation: what procurement should ask in 2026
Long-lived proofs and audit artefacts issued with classical signatures may not verify after Q-Day. ML-DSA attestation at issuance is now a standard RFP question.
Post-quantum attestation signs allow or deny outcomes with NIST-approved algorithms such as ML-DSA-65 (FIPS 204) so proofs remain verifiable when quantum-capable adversaries threaten classical cryptography. AffixIO exposes PQC paths on live sandbox endpoints.
Post-quantum attestation uses NIST FIPS 204 ML-DSA signatures so verification proofs remain valid against harvest-now-decrypt-later adversaries. AffixIO attests live API responses with ML-DSA-65.
July 2026 procurement context
US federal contractor PQC compliance trajectory targets 31 December 2030 under current executive order guidance. NCSC and ENISA publish parallel migration timelines. Any proof that must verify five or more years after issuance should not rely on RSA or ECDSA alone.
Harvest now, decrypt later
Adversaries capture encrypted traffic and ciphertext today to decrypt after quantum advances. TLS protects in transit. Long-lived credentials, audit exports, and offline QR proofs need PQC signatures at issuance. Validate attestations with the PQC verifier.
Questions for vendor questionnaires
- Which NIST parameter set signs proofs at issuance? (AffixIO: ML-DSA-65)
- Is crypto-agility documented for algorithm rotation?
- Can auditors verify signatures without vendor admin access?
- Are classical and PQC dual-sign paths available during migration?
Reproduce on live endpoints
Walk through ML-DSA attestation in the sandbox. Read PQC migration buyer guide and US federal PQC executive order whitepaper. Calendar: regulatory deadlines.