A sufficiently powerful quantum computer does not exist yet. The risk it poses already exists today, because encrypted traffic can be recorded now and decrypted later. We meet exactly that risk with hybrid post-quantum cryptography, ML-KEM and ML-DSA per FIPS 203 and 204, in addition to classical cryptography, not instead of it.
A classical computer essentially checks possible solutions one after another. A quantum computer uses quantum-mechanical effects to approach certain mathematical problems in a structurally different way, no advantage for most everyday tasks, a fundamental advantage for a small number of specific mathematical problems.
We do not replace classical cryptography with post-quantum methods, we combine both. An attacker would then have to break both the classical and the new mathematical problem at the same time, not just one of the two.
This means for every receipt: an attacker with a quantum computer breaks the classical signature, but not the post-quantum signature. An attacker who finds a still-unknown weakness in the comparatively young lattice-based method breaks the new signature, but not the classical one. Breaking both simultaneously is the actual security threshold, not either one alone.
Neither NIS2 nor DORA nor the eIDAS 2.0 provisions currently mandate a post-quantum migration. The hybrid combination of ML-KEM, ML-DSA, and the already quantum-resistant HMAC-SHA256 is already active for us, not as a reaction to an obligation, but ahead of one. The same direction, post-quantum cryptography and zero-trust architecture as a modernisation priority, also appears in the US federal cyber strategy published in March 2026, alongside the NIST SP 800-207 Zero Trust framework. We are not following a single rule after the fact, we already sit on the line several major frameworks are converging toward at the same time.
The master signing key does not sit with any single entity. It is split via Shamir Secret Sharing into five shares, distributed across five non-US jurisdictions. Every signing operation requires at least three of the five shares to be temporarily reassembled, no single operator, no single location ever holds full access.
Infrastructure runs on Hetzner (DE), IONOS (DE) and OVH (FR), deliberately without a US hyperscaler, to structurally avoid the reach of the US Cloud Act rather than negotiate around it contractually. Two regions run active-active in parallel, a third provides asynchronous geographic replication for disaster recovery.
If a single key share is suspected to be compromised, operations follow a fixed, documented sequence, no ad-hoc handling, every step is itself recorded in the ledger.