Historical analysis: this article examines information published by the source on June 12, 2026. Check the latest vendor guidance before acting.
What was published
On June 12, 2026, NIST released initial working drafts intended to update Personal Identity Verification (PIV) standards for post-quantum cryptography (PQC). These materials include a PQC Overview providing a gap analysis of necessary specification changes across the data model, command interface, and algorithm profile.
Status and scope
These documents are preliminary working materials and have not yet reached the status of formal public drafts. The scope of these updates covers three primary standards:
* SP 800-73 Part 1: PIV Card Application Namespace, Data Model, and Representation.
* SP 800-73 Part 2: PIV Card Application Card Command Interface.
* SP 800-78: Cryptographic Algorithms and Key Sizes for PIV.
What the guidance covers
The drafts focus on integrating two specific quantum-resistant algorithms: the ML-DSA digital signature algorithm and the ML-KEM key-encapsulation mechanism. To facilitate this, NIST proposes a “dual-stack model.” This architectural approach is designed to preserve existing classical PIV keys and data objects while simultaneously introducing new PQC-specific certificate containers, key references, and data objects.
How organizations can use it
Infrastructure owners and vulnerability management teams can use these working drafts to begin long-term cryptographic agility planning. The dual-stack model provides a framework for incremental deployment, suggesting that organizations will not need to perform a “rip-and-replace” of classical credentials but can instead layer PQC capabilities. This allows defenders to evaluate how their current PIV ecosystem—including card readers and middleware—will need to evolve to support the updated namespace and command interfaces defined in SP 800-73.
Decisions and next steps
Security leaders should treat these drafts as a roadmap for future exposure reduction rather than an immediate implementation guide. Our analysis suggests the following decision checkpoints:
1. Inventory Assessment: Identify all systems relying on PIV standards (SP 800-73/78) to determine the scale of the eventual transition.
2. Vendor Engagement: Query hardware and software providers on their roadmap for supporting ML-DSA and ML-KEM within a dual-stack framework.
3. Agility Review: Evaluate whether current credential management systems can support multiple concurrent certificate containers per user, as this is central to the proposed dual-stack model.
Limits and open questions
Because these are preliminary working materials, they are subject to change based on community feedback via GitHub and mailing lists. Implementing these drafts currently does not eliminate quantum risk, as the standards are not yet finalized. Furthermore, there is no established mandatory migration deadline provided in the source. The primary residual risk remains the gap between current classical deployments and the eventual availability of finalized, vendor-supported PQC hardware.
Source and editorial note
Working Drafts: Post-Quantum Cryptography Updates to the PIV Standards June 12, 2026 · Source date: June 12, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Archive date: June 15, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 08, 2026 at 02:06 UTC.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗