Microsoft is urging enterprises to prepare for post-quantum authentication by testing certificate dependencies before attempting broad infrastructure migration.
Its Post-Quantum Cryptography Transport Layer Security Pilot Program, launched on August 27, 2026, gives approved certificate authorities a controlled environment to evaluate quantum-resistant certificate hierarchies and uncover interoperability, performance, and operational barriers.
The initiative addresses a gap in quantum-readiness planning: protecting encrypted traffic does not automatically modernize authentication.
Certificates underpin trust across applications, devices, network appliances, and public key infrastructure.
Migrating those relationships requires more than replacing a cryptographic algorithm; organizations must verify that certificate issuance, validation, storage, renewal, and distribution continue working across interconnected systems.
Much of the post-quantum discussion centers on “harvest now, decrypt later,” where attackers retain encrypted information for possible future decryption.
Authentication presents a separate challenge because digital signatures establish identity and detect unauthorized changes.
NIST’s FIPS 204 standard defines the Module-Lattice-Based Digital Signature Algorithm, or ML-DSA, which is designed to resist attacks involving large-scale quantum computers.
Microsoft said that, pilot uses ML-DSA-87 for its experimental TLS certificate hierarchies. However, algorithm standardization alone does not establish enterprise readiness.
Post-Quantum Certificates
Larger certificates and chains can expose assumptions in handshake processing, certificate parsing, storage capacity, traffic inspection, and application integration.
Testing must therefore examine complete trust paths and operational workflows, rather than merely confirming that a certificate can be generated.
Legacy infrastructure compounds the challenge. Embedded devices, operational technology, custom applications, hardware security modules, and security appliances may have long replacement cycles or fixed cryptographic capabilities.
Enterprises need visibility into systems that consume certificates, not just the certificate authorities that issue them.
Microsoft’s Trusted Root Program announcement lists seven participating root operators: ComSign, DigiCert, HARICA, IdenTrust Services, Sectigo, Shanghai Electronic Certification Authority, and SSL.com.
The pilot targets interoperability, compatibility, and ecosystem readiness for TLS server authentication.
The distinction between experimentation and deployment is critical. Pilot certificates are not publicly trusted and must not secure production environments or public-facing websites.
Microsoft also states that the roots will not enter the Common CA Database or Certificate Transparency logs. Their purpose is to identify adoption barriers, not establish production trust.
Platform compatibility already illustrates those barriers. Microsoft warns that unsupported Windows systems can encounter certutil -verifyCTL failures and NTE_BAD_ALGID errors when processing pilot roots.
Its announcement limits pilot TLS authentication support to specified Windows 11 releases with the July 28, 2026 updates; Windows Server support remains planned for a future release.
Security leaders should begin with a certificate dependency inventory covering trust anchors, issuing authorities, applications, devices, inspection systems, certificate-management platforms, and hardware-backed key storage.
Vendor assessments should distinguish algorithm availability from support for certificate lifecycle operations and end-to-end TLS authentication.
Non-production testbeds should then measure handshake behavior, chain validation, renewal workflows, inspection compatibility, and failure handling.
Teams should document unsupported components and prioritize long-lived infrastructure whose replacement cannot occur quickly.
The immediate objective is readiness, not an accelerated production rollout. By testing dependencies now, enterprises can separate cryptographic capability from operational compatibility and build migration plans grounded in observed constraints rather than vendor promises.
Findings should feed procurement requirements, vendor discussions, and staged modernization budgets, making later adoption less disruptive across complex enterprise environments.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

