The State of Cryptography in Q2 2026

The cryptographic landscape in 2026 sits in a strange place. The algorithms everyone trusts are slowly becoming the algorithms nobody should trust, and the algorithms everyone should trust are still too new to deploy at scale. The migration has started,…

Dark cinematic editorial image for The State of Cryptography in Q2 2026 - abstract cyan digital composition, hacker aesthetic, no text no logos

3 MIN READ

The cryptographic landscape in 2026 sits in a strange place. The algorithms everyone trusts are slowly becoming the algorithms nobody should trust, and the algorithms everyone should trust are still too new to deploy at scale. The migration has started, but the gap has not closed. The honest framing matters here, because the working engineer who pretends the gap does not exist will end up filing the breach disclosure that the migration was supposed to prevent.

What follows is the working version of the Q2 state. The full report runs longer. The shorter version is what the security engineer actually has time to read. The big change since Q1 2026 sits in the post quantum migration, where the NIST final standards, the vendor implementations, and the federal deadline have all landed within a 90 day window, and the practitioner who treats the deadline as a procurement problem rather than a security one is about to be the one filing the disclosure. RSA 2048 still works against the classical computer, but the margin has narrowed enough that the new floor for any high value certificate is 3072, with 4096 catching up fast on the systems that have to last past 2030.

What is happening with post quantum

Three shifts landed in Q2 2026, and all three matter to anyone running TLS at scale. The NIST standards are finalised, with FIPS 203 (ML-KEM, the key encapsulation mechanism), FIPS 204 (ML-DSA, the primary post quantum signature), and FIPS 205 (SLH-DSA, the hash based signature for constrained use cases) all in the final form, ready to use in any new system being designed today. The vendor implementations are in, with OpenSSL 3.5, BoringSSL, and RustTLS all now shipping the post quantum key exchange as the default for new connections, and the hybrid key exchange running in the browser, the server stack, and the cloud provider. The federal deadline landed with CNSA 2.0, which requires the post quantum migration for the national security systems by 2030 and for the broader federal systems by 2035, with the deadline that looked theoretical in 2024 now running as a procurement constraint in 2026. The combined effect is that any procurement spec written today that does not require hybrid post quantum key exchange will be rewritten in two years, and the security org that lets the spec through now will own the rewrite.

What is happening with everything else

Three warnings worth flagging for the working engineer. The RSA key size problem, where the RSA 2048 key that everyone uses is still secure against the classical computer but the margin has narrowed, with the 2048 bit key that served as the default for twenty years now the floor and 3072 or 4096 the new default for any high value certificate. The SHA-1 collision risk, where the SHA-1 that everyone deprecated in 2017 still appears in the legacy certificate, the legacy code signing path, and the legacy firmware, with the SHA-1 collision attack remaining a real risk for the system that has not finished the migration. The random number generator weakness, where the implementations that rely on the predictable entropy source, the embedded device, the IoT firmware, the older virtual machine, produce the keys that the attacker can predict, with the random number generator that served as an implementation detail in 2010 now serving as the attack surface in 2026. None of the three are exotic. All three are the kind of finding that shows up in the post mortem after the breach.

What the practitioner should do

Three moves that close the migration gap without breaking the production system. Inventory the certificates, because the certificate inventory sits at the foundation for every other move, and the inventory finds the certificates that are still on SHA-1, the certificates that are still on RSA 1024, and the inventory gives the working engineer the migration list. Turn on the hybrid key exchange at the edge, because the hybrid (X25519 plus ML-KEM) gives the working engineer the post quantum protection without breaking the client, the cloud provider already supports it, the edge appliance already supports it, and the only thing missing is the configuration. Audit the entropy source, because weak entropy produces the weak key, the weak key produces the breach the migration was supposed to prevent, and the entropy audit costs a day and finds the device that needs the fix. The working engineer who inventories the certificates, turns on the hybrid key exchange, and audits the entropy source lands the migration without breaking the production system. The working engineer who waits for the deadline files the disclosure.

Abstract cryptography state as glowing cyan layered grid on a dark navy surface, dramatic chiaroscuro lighting from above.
Cryptography in Q2 2026: 3 post quantum shifts, 3 classic algorithm warnings, 3 moves the working engineer should make.

The bottom line

The cryptographic state in Q2 2026 sits in a transition. The post quantum standards are ready, the classic algorithms are weakening, the entropy problem still lurks in the embedded fleet. The working engineer who inventories, turns on the hybrid, and audits the entropy holds the line. The one who waits for the deadline does not.


Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading