ProteQC flags browser trust deadlines as early PQC readiness test
ProteQC says browser root-certificate deadlines are already hitting organizations sooner than expected, with 13 dates passed and 17 more approaching through September 2027. The firm argues the shift is a practical dress rehearsal for post-quantum cryptography migration and has published free tools to help teams assess exposure.
Why it matters: - Browser trust changes are a live test of cryptographic agility, the same capability organizations will need for post-quantum cryptography migration. - The next wave of deadlines could force certificate renewal issues to surface during normal operations, not on a schedule organizations control. - Systems that do not update trusted roots automatically can face connection failures, hidden integration breakage or full-page browser warnings.
What happened: - ProteQC released research based on Google’s published root certificate data showing 47 Certificate Authority roots with trust deadlines between July 2025 and September 2027. - Of the 13 deadlines that have passed, only one has taken effect for most users. - The other 12 are set to take effect with Chrome 153 on September 8. - Another 17 deadlines are due within the next six weeks, including 13 on September 30, 2026. - ProteQC published a free register, research methodology and correction log at the full report and tools. - ProteQC also makes its broader PQC Lifecycle Framework information available at https://proteqc.com.
The details: - The deadline changes do not make existing websites suddenly stop working. - Certificates already issued remain valid until they expire. - Risk appears when an organization renews a certificate that depends only on a root that Chrome no longer trusts. - Visitors may then see a full-page security warning instead of the website. - Because many certificates renew on annual cycles, the problem may show up long after the published deadline. - ProteQC says organizations can check exposure by answering three questions: when the certificate expires, what root sits at the end of the chain, and whether that root appears on the expiring-root register. - Most organizations are expected to find they are unaffected. - The company says it is publishing the register and self-checks so organizations can confirm exposure directly. - ProteQC found that simple certificate counts overstate real risk because cross-signing can preserve a second valid path to trust after one root retires. - The firm withdrew an earlier estimate that relied on public data it later judged unreliable and published corrections with the research. - ProteQC released the affected-root register instead of a broad exposure estimate. - The register identifies every affected root and its relevant dates. - Many systems beyond browsers keep their own root lists, including Java runtimes, payment terminals, embedded devices and server-to-server integrations. - Older systems may keep working through cross-signed certificates, but alternative paths may not remain available. - ProteQC’s analysis found a 2022 Java installation containing only eight of the 53 roots that will remain valid, while a current patched build from another supplier contained all 53. - A comparison of trusted root lists across four Java builds is also available in the research materials.
Between the lines: - The browser deadline wave is smaller than the PQC transition ahead, but the operational questions are similar. - Organizations need to map where cryptography is used, identify dependencies, and understand who controls upgrade timing. - The current root-certificate shift may expose weak crypto inventory, poor dependency tracking and slow change management before quantum-resistant migration becomes urgent. - Tim D. Williams, ProteQC’s chief technology officer, said an organization budgeting this as a 2027 program has already missed 13 dates and 12 more arrive in Chrome on a single day next week. - Williams said Google’s 2027 deadline is real, but not the first deadline organizations will face. - BJ Miller, ProteQC’s chief executive officer, said teams that can answer these questions now will be better positioned for PQC migration later. - Miller said organizations that cannot may discover those gaps during a larger and more complex transition.
What’s next: - Twelve previously passed deadlines will take effect with Chrome 153 on September 8. - Thirteen more deadlines are scheduled for September 30, 2026. - Additional deadlines will continue through September 2027. - ProteQC says organizations can contact info@proteqc.com for guidance on where to start. - The company is offering free commands, data, methodology and a controlled demonstration transcript to help teams assess readiness.
The bottom line: - Browser trust deadlines are not just routine maintenance. - ProteQC says they are an early, low-stakes rehearsal for the crypto-agility organizations will need before post-quantum migration arrives.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Cryptocurrency Insider Today
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.