2026-06-14 · nist
NIST released initial working drafts on June 12, 2026 for proposed post-quantum cryptography updates to Personal Identity Verification standards. The work focuses on adapting PIV credentials for ML-DSA digital signatures and ML-KEM key encapsulation.
The draft set covers SP 800-73 Part 1, SP 800-73 Part 2, and SP 800-78, plus a PQC overview. NIST describes a dual-stack model that preserves existing classical PIV keys while adding new references, certificate containers, and data objects for PQC credentials.
Long-lived records face a different kind of data-loss risk: archives encrypted or signed with aging cryptography may become unverifiable or exposed over time. Identity and access systems that cannot transition cleanly can leave recovery operations dependent on credentials that no longer meet modern assurance standards.
Cold storage strategies should include crypto-agile metadata, offline key custody, and migration plans for long-term archives. Keeping preserved data offline protects it from immediate compromise, while post-quantum-ready identity standards help ensure future access and verification remain trustworthy.
Read Original Post →