Microsoft starts testing quantum-safe web certificates on Windows 11
A July 28 update quietly added support for ML-DSA certificates. A pilot with seven certificate authorities followed in August.

Key points
- Microsoft began shipping Windows 11 support for post-quantum ML-DSA certificates in the July 28, 2026 cumulative update KB5101684 for versions 25H2 and 24H2, and KB5101681 for 26H1.
- The company then opened a Post-Quantum Cryptography TLS Pilot Program on August 27, 2026 with seven certificate authorities: ComSign, DigiCert, HARICA, IdenTrust Services, Sectigo, Shanghai Electronic Certification Authority and SSL.com.
- Certificates issued through the pilot are not publicly trusted and must not be used on live websites, Microsoft says.
- Windows 11, version 24H2 Home and Pro editions reach end of updates on October 13, 2026, per the same KB5101684 advisory.
- Secure Boot certificates used by most Windows devices begin expiring in June 2026, with replacements rolling out through Windows Update.
Microsoft has started wiring quantum-resistant website certificates into Windows 11. The work is early, deliberately small, and tells you where the next few years of internet plumbing are headed.
Here is the plain version. Websites prove they are really themselves using digital certificates, small files signed by a trusted authority. Today's signatures rely on math that a future quantum computer could, in theory, break. So the industry is moving to new algorithms designed to resist that attack. The one Microsoft is testing is called ML-DSA-87, a lattice-based signature scheme standardised by the US National Institute of Standards and Technology.
What did Microsoft actually ship?
Two Windows 11 updates on July 28, 2026 added the plumbing. KB5101684 covers Windows 11 versions 25H2 and 24H2, at OS builds 26200.8973 and 26100.8973. KB5101681 covers the newer 26H1 branch at build 28000.2608. On supported machines, the Schannel component, which is the part of Windows that handles secure web connections, can now process ML-DSA certificates in test scenarios.
These are not production features. They let security teams load the new certificates into lab environments and see what breaks.
| Item | Detail |
|---|---|
| 26H1 update | KB5101681, build 28000.2608 |
| 25H2 / 24H2 update | KB5101684, builds 26200.8973 / 26100.8973 |
| Release date | July 28, 2026 |
| Pilot launch | August 27, 2026 |
| Pilot CAs | 7 |
| Algorithm | ML-DSA-87 |
Who is in the pilot?
The Microsoft Security Response Center said the August 2026 release of the Trusted Root Program added seven pilot roots, run by ComSign, DigiCert, HARICA, IdenTrust Services, Sectigo, Shanghai Electronic Certification Authority and SSL.com. More authorities can apply through the end of 2026. The roots are flagged as pilot-only. Any certificate signed by them is for closed testbeds, not public websites.
Why does this matter for ordinary users?
Not much, yet. You will not see a different padlock in your browser. The point of the pilot is to find out what quietly falls over when certificates get bigger and signatures look different: old load balancers, deep-packet inspection boxes, embedded devices, hardware security modules, custom apps that hard-coded assumptions about key sizes.
That is where the honest reporting lives. Post-quantum migration is being sold in some corners as a confidentiality story, the "harvest now, decrypt later" worry. Authentication is the harder half and the one almost nobody has inventoried. Microsoft's own guidance makes the point bluntly: most organisations know where TLS protects their traffic, but few have a full list of every system that issues, validates, stores or depends on a certificate. The pilot exists because nobody yet knows what will break.
What should IT teams do now?
Start the inventory. Which internal certificate authorities do you run, which appliances pin specific algorithms, which vendors have published a post-quantum roadmap, which devices in the field will still be running in 2030. Then build a non-production environment and ask for a pilot certificate once your CA joins.
Two housekeeping items from the same Microsoft advisories are worth noting while you are patching. Windows 11, version 24H2 Home and Pro reach end of updates on October 13, 2026. And the Secure Boot certificates baked into most Windows PCs start expiring from June 2026, with Microsoft pushing replacements through Windows Update over the following months. Machines that miss the new certificates will still boot and still get updates, but the clock is running.



