Sectigo announced Private PQC, a feature added to its Sectigo Certificate Manager platform that lets organizations issue and manage private post-quantum cryptography TLS certificates using the same approval, auditing, renewal, and revocation workflows they already use for conventional certificates.
Why "private" rather than public
This isn't a public, browser-trusted post-quantum certificate — it's for internal testing, using private PKI rather than the public certificate ecosystem. That distinction matters: public post-quantum certificate infrastructure (the kind a browser would actually trust by default) is still being built out industry-wide, a process our own coverage of Let's Encrypt's Merkle Tree Certificate commitment touches on. Private PQC is squarely aimed at organizations that want to start building operational experience with post-quantum algorithms now, inside environments they fully control, rather than waiting for that public infrastructure to be ready.
The stated motivation: momentum, not immediate threat
Sectigo frames the launch around a familiar problem: many organizations have post-quantum migration on their roadmap and even have budget allocated, but struggle to move from planning documents to actual hands-on testing across genuinely fragmented, legacy-heavy environments. A low-risk way to start testing — without new tooling or infrastructure — is aimed directly at that planning-to-execution gap.
How this fits the broader timeline
Google and Cloudflare have both moved their own post-quantum migration timelines up to 2029, and NIST's already-published post-quantum standards (finalized back in August 2024) give the algorithms a stable, standardized foundation to build against. Tooling like this doesn't change when the quantum threat itself materializes, but it does lower the cost of an organization getting comfortable with post-quantum certificate operations well before that deadline arrives — the same logic behind treating certificate automation (see our guide to automating renewal) as worth doing before it's strictly necessary, not after.
This is our own summary and analysis of publicly reported news, written independently — not a reproduction of any single source's article. Where we reference a specific announcement, we link to it or name the organization directly.