Ciptor Security Insights

Feitian's post-quantum upgrade: what Nordic CISOs need to know before their next hardware key procurement

On 22 June 2026, Feitian Technologies announced the completion of a major post-quantum cryptography upgrade across its core authentication product portfolio. The announcement covered Smart Cards, PKI Tokens, and FIDO Security Keys — and it deserves more attention than a press release typically receives. This is not a marketing milestone. It is a hardware architecture change with direct implications for how organisations in financial services, government, healthcare, and critical infrastructure should be thinking about their authentication hardware procurement right now.

This article translates the announcement into operational terms for security leaders in the Nordics and Baltics who are evaluating hardware authentication or reviewing their identity security roadmap for the next three to five years.

What Feitian actually did

The headline is that Feitian has integrated a dedicated post-quantum cryptography co-processor at the chip level across its product lines. That distinction — chip level, not firmware or software — matters significantly, and we will return to it.

The upgrade adds native support for two algorithms that NIST finalised as international standards in August 2024:

  • ML-KEM (FIPS 203, formerly CRYSTALS-Kyber) — a key encapsulation mechanism for securing the exchange of cryptographic keys. Used for secure email, encrypted file exchange, enterprise messaging, and data synchronisation.
  • ML-DSA (FIPS 204, formerly CRYSTALS-Dilithium) — a digital signature algorithm for authentication. Used for high-value transaction approvals, VPN access, government system authentication, and identity verification workflows.

These algorithms are specifically designed to remain secure against cryptanalytic attacks performed by quantum computers — the class of threats that renders current RSA and ECC-based systems vulnerable.

The Feitian FT-JCOS Smart Card Operating System, which underpins the upgraded product lines, now holds CC EAL6+ and EMVCo certifications at the chip level. EAL6+ is the highest Common Criteria Evaluation Assurance Level available for smart card hardware — a significant step up from the EAL5+ certification that characterised the previous generation.

The threat this addresses — and why it matters today, not in ten years

The "Harvest Now, Decrypt Later" threat
Nation-state adversaries — and increasingly well-resourced criminal organisations — are collecting encrypted data today with the explicit intent to decrypt it once quantum computing reaches sufficient capability. This is known as "Harvest Now, Decrypt Later" (HNDL). The decryption happens in the future; the data collection is happening right now. For any data with a security horizon longer than five to ten years — financial records, patient data, legal contracts, government communications, intellectual property — the quantum threat is not a hypothetical future problem. It is an active data collection campaign against your current encryption.

 

The implication is uncomfortable but important: the RSA or ECC-protected authentication events and data transmissions your organisation is generating today may be vulnerable to decryption within a decade. This is why NIST finalised the ML-KEM and ML-DSA standards in 2024 rather than waiting for quantum computers to materialise — the window for proactive migration is now, not later.

For Nordic organisations specifically, ENISA (the European Union Agency for Cybersecurity) published its post-quantum cryptography guidelines in 2022 and has since updated its recommendations to encourage early adoption planning. The Swedish NCSC and the Norwegian NSM have issued parallel guidance. The regulatory direction is unambiguous: begin PQC migration planning now, at the hardware layer first.

Why chip-level implementation is the only approach that matters

The Feitian announcement specifies that PQC algorithms are executed within an isolated hardware co-processor. This architectural choice is not a technical footnote — it is the core security property that differentiates meaningful PQC protection from marketing-grade PQC claims.

Software and firmware-based PQC implementations run on the main processor. That means key material is handled in a compute environment that can be compromised by side-channel attacks, by operating system vulnerabilities, or by an attacker who has already achieved code execution on the device. The PQC algorithm may be mathematically sound; the implementation environment may not be.

A hardware co-processor executing PQC algorithms in isolation provides full key isolation. The private key never leaves the dedicated hardware context. Side-channel attack surface is dramatically reduced. The security property is structural rather than dependent on the integrity of the surrounding software environment.

"By executing post-quantum algorithms within an isolated hardware co-processor, FEITIAN ensures full key isolation and significantly reduces exposure to side-channel attacks, offering stronger protection than software- and firmware-based PQC approaches." Feitian Technologies press release, 22 June 2026

This matters for procurement because it means you are evaluating not just whether a device claims PQC support, but where the PQC computation occurs and how the key material is protected during that computation.

The certification landscape — updated

Vol. 4 of our Zero Assumptions series covers the full hardware certification hierarchy in detail. The Feitian PQC upgrade changes the comparison meaningfully. Here is the updated picture:

Certification

What it validates

PQC coverage

FIDO2 / FIDO Alliance Protocol correctness only — the device implements FIDO2 as specified None — protocol test only
CC EAL4+ Systematic security function testing against a defined threat model None unless explicitly scoped
CC EAL5+ Semi-formal verification; side-channel and physical attack resistance None unless explicitly scoped
CC EAL6+ Updated Formal verification; highest assurance level for smart card hardware — now achieved by Feitian FT-JCOS Covers hardware co-processor isolation used for PQC execution
ANSSI Security Visa French national authority evaluation covering design, implementation, and supply chain Case-by-case — ANSSI is actively evaluating PQC standards for future visa requirements
FIPS 140-3 Level 3 Physical security and tamper evidence; required for US federal procurement NIST has announced FIPS 140-3 will be updated to cover PQC modules — timeline TBC

What the upgrade delivers operationally — by use case

FIDO Security Keys

For organisations deploying FIDO2 hardware keys for passwordless authentication — workstation login, VPN access, cloud SSO — the PQC upgrade adds a quantum-resistant layer to the existing origin-binding architecture that already defeats adversary-in-the-middle phishing attacks. The FIDO2 phishing resistance is unchanged; the upgrade adds protection against a future adversary using quantum capabilities to attack the underlying cryptographic primitives of the authentication exchange itself.

EAL6+

  • Common Criteria certification now achieved by Feitian FT-JCOS — the highest level available for smart card hardware.
  • Common Criteria Recognition Arrangement

2024

  • Year NIST finalised ML-KEM (FIPS 203) and ML-DSA (FIPS 204) as international PQC standards NIST, August 2024

5–10 yrs

  • Estimated window before quantum computers become capable of breaking current RSA / ECC encryption at scale
ENISA PQC guidelines, 2024

PKI Tokens and Smart Cards

For organisations using PKI-based authentication — digital signatures on contracts, e-government workflows, secure VPN authentication, certificate-based access to classified systems — ML-DSA-based signatures provide a drop-in replacement pathway for RSA/ECC certificate systems. Existing infrastructure is not replaced; the Crypto-Agile architecture allows legacy and PQC-enabled systems to run in parallel, with new authentication events gaining quantum-resistant protection while existing PKI infrastructure continues operating.

Secure email and classified data exchange

ML-KEM-based key encapsulation addresses the HNDL threat directly for data in transit. Organisations handling sensitive correspondence — legal, financial, medical, governmental — can begin protecting new transmissions against future quantum decryption immediately, without waiting for a full infrastructure migration.

What this means for the NeoWave vs Feitian hardware decision

Ciptor distributes both NeoWave and Feitian hardware, and we recommend them for different deployment contexts. That recommendation needs updating in light of this announcement.

NeoWave remains the recommendation for organisations where supply chain sovereignty is the primary requirement — specifically those in defence supply chains, handling classified EU data, or subject to regulatory requirements that mandate French or EU-origin hardware. NeoWave's ANSSI Security Visa provides the strongest available sovereign certification and full French-jurisdiction supply chain transparency. The PQC question for NeoWave is still being evaluated by ANSSI; no PQC co-processor announcement has been made at the time of writing.

Feitian has moved meaningfully in the certification landscape with this upgrade. The CC EAL6+ chip certification and hardware-native PQC co-processor make Feitian the most forward-compatible enterprise authentication hardware available at scale today, for organisations whose primary requirements are cryptographic assurance depth and long-term quantum readiness rather than EU-origin supply chain.

For most large-enterprise deployments, the practical approach remains a tiered model: NeoWave for privileged users and classified data environments, Feitian for the broader workforce — now with the added assurance that the Feitian fleet is quantum-ready at the hardware layer.

✓ Available through Ciptor

Feitian's post-quantum upgraded FIDO Security Keys, PKI Tokens, and Smart Cards are available through Ciptor for enterprise deployments across Sweden, Norway, Denmark, Finland, Estonia, Latvia, and Lithuania. Volume pricing applies from 50 units. For deployments requiring a mix of NeoWave sovereign hardware and Feitian PQC-ready keys, contact us for a combined procurement briefing.

What to do now

1

Assess your data security horizon
Identify which data categories your organisation generates that carry a security requirement longer than five years. Financial records, patient data, long-term contracts, IP, and government communications are the primary candidates. These are the data sets at active HNDL risk today.

2

Review your hardware authentication roadmap
If you are planning a hardware security key deployment or refresh in the next 12 months, include PQC co-processor support as an explicit evaluation criterion. The cost premium for PQC-capable hardware is negligible at volume; the migration cost later is not.

3

Map your current PKI and certificate infrastructure
Identify which systems use RSA or ECC-based certificates for authentication, signing, or key exchange. These are the highest-priority migration targets for PQC-enabled replacements. The Crypto-Agile architecture of the Feitian upgrade means parallel operation is possible during transition.

4

Check your NIS2 and DORA obligations
Neither NIS2 nor DORA currently mandates PQC migration explicitly — but both require that essential and important entities implement state-of-the-art security measures and plan for emerging threats. ENISA's updated guidance makes PQC planning a reasonable component of demonstrating compliance with both directives.

5

Don't wait for a regulatory mandate
The HNDL threat is active today regardless of regulatory timelines. Organisations that begin hardware-layer PQC migration now will be in a significantly stronger position when mandates arrive — and will have avoided having their current authentication data collected and held for future decryption in the interim.
 

Further reading — Zero Assumptions series:

Vol. 4 — Sovereign hardware risk: The full certification comparison table — FIDO2 vs CC EAL5+ vs ANSSI Security Visa vs FIPS 140-3 — updated to reflect the Feitian EAL6+ upgrade.

Vol. 2 — The fallacy of network-delivered codes: Why hardware-bound FIDO2 origin binding defeats AiTM phishing at the structural level — the current-threat context that the PQC upgrade builds on.

Evaluating hardware key procurement for 2026?

Book a 30-minute briefing. We'll map your specific deployment context — including which users need sovereign NeoWave hardware and which benefit most from Feitian's PQC-capable fleet — and build the procurement case.

Book a briefing →

Announcing Our Strategic Partnership with IBM: Introducing Next-Level Passwordless Security

We are excited to announce a groundbreaking partnership between Ciptor and IBM aimed at eliminating account takeovers and revolutionizing identity verification. This collaboration leverages Ciptor's Cyber Security in One Framework (CSOF) integrated with IBM Security Verify, providing an extensive and robust solution for managing access and securing applications against evolving cyber threats.

Key Benefits of This Partnership:

  • Elimination of Passwords: Our joint solution is designed to remove the vulnerabilities associated with passwords, minimizing the risk of phishing attacks and human error, which are the leading causes of security breaches.
    Advanced Identity Verification: By integrating Ciptor’s cutting-edge passwordless identity verification technology with IBM Security Verify, administrators can now create customized passwordless journeys using pre-built templates. These templates support various authentication methods such as PKI, FIDO2, Passkeys, and SecurityKeys.
  • Comprehensive Orchestration Tools: Security architects can effectively manage different aspects of the passwordless identity verification process using advanced orchestration tools. This ensures a seamless and secure user experience.
  • Phishing Attack Prevention: Every second, a phishing attack occurs, and 90% of cybersecurity breaches result from users clicking fraudulent links. Our integrated solution ensures that even if users fall victim to phishing, our CSOF IAM powered by IBM is never fooled, preventing unauthorized access and protecting sensitive information.
  • Enhanced Security for Applications: The IBM Security Verify platform, enhanced through this partnership, offers unparalleled security for applications and systems, ensuring that access is meticulously managed and protected.

 

Why This Matters:

In today's digital landscape, the frequency and sophistication of cyber-attacks are on the rise. A forward-thinking approach to identity verification is crucial. With our integrated solution, we are confident that organizations will benefit from enhanced security measures, reduced risk of account takeovers, and a streamlined, passwordless user experience.

This partnership represents a significant step forward in our mission to provide secure, efficient, and innovative identity verification solutions. We look forward to the opportunities this collaboration with IBM will bring to our customers and the cybersecurity community as a whole.

For more information or to RSVP for our exclusive seminar and webinar, please contact Ciptor directly via email.

Sincerely,

The Ciptor Team

contact@ciptor.com

The impending implementation of the revised Directive on Security of Network and Information Systems (NIS2) heralds a critical juncture for organizations operating within essential and important sectors across the European Union. With the integration of NIS2 into national law required by October 17, 2024, and the designation of relevant entities demanded by April 17, 2025, it is imperative that organizations respond promptly to these regulatory shifts.

Points of Contention

Key issues currently under debate include:

  • The scope and speed of implementing the extensive cybersecurity risk management measures.
  • The balance between meeting regulatory requirements and the day-to-day operational needs of businesses.
  • Financial and manpower investment needed to comply with NIS2, especially for entities only now beginning preparations.
  • Adherence to stringent incident notification requirements and the pressures of incident response times.
  • Ensuring appropriate encryption and data protection measures that satisfy NIS2 without hindering operational efficiency.

Seeking Middle Ground

In navigating these discussions, finding a middle ground is essential. The harmonization of an organization's strategic priorities with NIS2 compliance standards must involve a series of calibrated steps:

  1. Early Engagement & Planning: Immediate action is better than hurried compliance later. Begin with a thorough analysis of the directive's demands on your organization and create a strategic plan. Addressing issues early may reduce the need for more drastic changes closer to the regulatory deadlines.
  2. Consideration of Operational Impact: While NIS2 compliance is non-negotiable, the process should consider existing workflows, adopting solutions that complement rather than disrupt current operations whenever possible.
  3. Proportionate Investment: Rather than perceiving compliance as a financial drain, invest in measures that serve dual purposes, enhancing cybersecurity while increasing overall business value.
  4. Incremental Progress: Implement cybersecurity improvements in stages, ensuring each step is robust before proceeding to the next. This can help manage resources and staff workload, avoiding burnout and potential oversight.
  5. Expert Collaboration: Consulting with cybersecurity experts can provide valuable insights that streamline the compliance process, allowing organizations to benefit from field-tested solutions and foresight into potential pitfalls.
  6. Staff Involvement & Training: A company-wide culture of cybersecurity awareness can significantly aid compliance efforts, turning potential disruption into a unified corporate evolution.
  7. Transparent Communication: Keep stakeholders informed about the necessity of compliance, the progress made, and how it fortifies the organization against cyber threats.
  8. Feedback & Flexibility: Maintain a feedback loop involving all parts of the organization affected by NIS2. Adapt plans as necessary in response to practical insights from the operational frontline.

Conclusion

The path to NIS2 readiness should not be viewed solely through the lens of adhering to a regulatory requirement but as an opportunity to strengthen organizational infrastructure against an evolving cybersecurity landscape. By starting preparations today, entities can ensure a smooth transition into compliance, bolstering resilience while mitigating the risk of substantial penalties or operational interruptions.

For organizations seeking assistance or tailored advice, industry experts, including certified cybersecurity professionals with years of field experience, stand ready to support this pivotal transition. Remember, in cybersecurity, the cost of inaction can far exceed the investment in compliance and future-proofing your service offerings.

 

As the world continues to rely more on digital technology, businesses are no exception. The shift towards online transactions and communications brings with it new threats and risks. More and more businesses are falling victim to data breaches and cyber attacks. In the past, simply having a website was enough, but now it is essential for companies to protect their digital assets and adhere to compliance standards. In this post, we will explore the challenges of operating a business online, and provide tips and strategies for keeping your business safe.

 

The first step in protecting your company from cyber attacks is to take a proactive approach. Many businesses only act after a data breach has occurred, which results in increased costs and downtime. Companies should invest in preventative measures such as Passwordless Authentication, Digital Fingerprinting, Threat Management, and encryption. Regular risk assessments should be performed to identify potential vulnerabilities and address them accordingly.

 

Secondly, it is important to stop relying on outdated technology and processes. Passwords are easily compromised, and multifactor authentication methods that were effective a few years ago may no longer be enough. Companies should invest in new and more secure methods like passwordless authentication and zero trust. Ad-hoc security measures should be avoided as well. Formalized security processes should be established that should be audited by concerned authorities, establishing trust towards customers.

 

Thirdly, Modern companies need to depend on automation and artificial intelligence to scale expertise and reduce time-to-detection in case of a cybersecurity incident. By synthesizing security data, automated security processes can quickly respond before any damage occurs. Furthermore, AI can detect patterns and anomalies that would otherwise go unnoticed by human analysts, providing valuable insights about possible cyber threats.

 

Fourthly, a company's employees are often the weakest links in cybersecurity. Hackers often use phishing and social engineering to trick employees into divulging sensitive information or gaining access to company networks. Proper training and awareness programs should be in place to teach employees about the dangers of phishing emails and how to recognize and avoid them.

 

Finally, it's essential for companies to stay updated with compliance standards. Adherence to regulations such as GDPR, PSD2, NIS2, Dora, Bill C-26, CCPA, or HIPAA are not only legally required but also help establish trust and confidence among customers. Companies should monitor the latest compliance guidelines and make sure they have the right security controls and procedures in place.

 

Conclusion:

In conclusion, operating a business online comes with numerous challenges, and protecting it from cyber attacks and data breaches is not an easy task. A proactive approach, investment in modern security measures, and proper training are key to defending against cyber threats. Moreover, automation and AI can be leveraged to respond to incidents quickly and efficiently. Lastly, adhering to compliance standards is essential in building trust with stakeholders. By implementing these strategies, businesses can safeguard their digital assets and ensure their survival in the digital economy.

Unlocking the Power of Passwordless Authentication

Discover the simplicity and security of passwordless authentication. Say goodbye to the hassle of remembering and managing passwords. With the right platform, like IBM Verify Access, you can eliminate password-related support issues.

Enhanced Security to Protect Your Kingdom

Did you know that 61% of data breaches are caused by stolen or leaked credentials? Don't let your business fall victim to a bad actor. Passwordless authentication provides an extra layer of security, keeping your resources safe from potential ransom attacks.

Simple and Swift Access 

No more typing in usernames and passwords every time you log in. With passwordless authentication, all you need is to enter your username and touch a security key. It's that easy. Alternatively, you can even use your smartphone to authenticate through facial recognition.

Widespread Adoption for Maximum Convenience

Passwordless authentication is supported by big names like Google, Apple, Microsoft, and many others. Thanks to the FIDO2 standard, you can enjoy the benefits of passwordless authentication across various services and software.

Eliminating Phishing Threats

Say goodbye to the worry of phishing attacks. By removing the reliance on passwords, passwordless authentication eliminates the risk of falling victim to phishing attempts. Protect your organization and maintain smooth operations without disruptions.

A Wide Range of Benefits for Users

Passwordless authentication offers more than just enhanced security. You can remotely lock your computer using your smartphone, access computers offline, and securely gain entry to shared computers with a simple QR code scan. Maximize convenience while keeping your data secure.

Relieve IT Burdens and Cut Costs

By enabling users to self-manage their access privileges through a user-friendly portal, passwordless authentication reduces support tickets and frees up IT personnel to focus on other critical tasks. Say goodbye to long waiting times for password resets.

The Future of Authentication is Passwordless

With the introduction of new legislation mandating passwordless authentication for critical infrastructure industries, such as banking and financial services, it's clear that the passwordless revolution is here to stay. Stay ahead of the game and protect your business from state-sponsored hackers with passwordless authentication solutions.

Take the first step towards a more secure and streamlined authentication process. Embrace the power of passwordless authentication with IBM Verify Access today.

Minimize Risk Today

Discover the benefits of passwordless authentication for users, IT, and organizations. By removing obstacles between users and their resources, employees can boost productivity. Meanwhile, IT personnel can focus on important tasks without being overwhelmed by service tickets and management duties. Plus, with no vulnerability to phishing and ransomware attacks, organizations can drastically reduce their risk exposure.

And if you're switching to a hybrid cloud environment, taking advantage of passwordless authentication with IBM and ITSAFE now will streamline identity and access management and minimize risk before it becomes a pressing issue. Don't wait until it's too late.