Microsoft Transitions Windows Code Signing to Post-Quantum Cryptography

Microsoft Transitions Windows Code Signing to Post-Quantum Cryptography

First seen 24 Aug 2026, 16:21 UTC Feeds.4SysopsPetrisupport.microsoft.com 30.9

Article Content

Browse articles
ThreatCluster

Microsoft is updating its Windows code-signing infrastructure to replace the expiring Windows Production PCA 2011 certificate by October 19, 2026, and is preparing for post-quantum cryptography (PQC) adoption in 2027. This transition may cause compatibility issues for applications that hardcode certificate identities or rely on outdated cryptographic standards. Developers and IT teams are advised to review their software's certificate validation processes to ensure compatibility with the new signing algorithms, including RSA-3072 and SHA-384. Microsoft emphasizes that applications should not depend on specific certificate names or algorithms but should use approved APIs for validation. The changes aim to enhance security against potential threats posed by quantum computing. Organizations must engage with software vendors to confirm compliance with the new standards before the transition takes effect.

Key Points: • Microsoft is replacing the Windows Production PCA 2011 certificate by October 19, 2026. • Post-quantum cryptography will be introduced by default in 2027 for Windows code signing. • Applications hardcoding certificate details may face compatibility issues during the transition.

Timeline

2026-08-24
Microsoft announces code signing updates
Microsoft outlines plans to replace expiring certificates and adopt stronger cryptographic standards.
Petri
2026-08-24
Developers warned about compatibility issues
Microsoft advises developers to review certificate validation processes to prevent application failures.
support.microsoft.com
2026-08-24
Transition to post-quantum cryptography planned
Microsoft plans to implement post-quantum cryptography for Windows code signing by 2027.
Feeds.4Sysops