Podcast

Root Causes 633: ETSI PQC Conference Wrap Up

Hosted by
Tim Callan
Tim Callan
Chief Compliance Officer
Original broadcast date
June 24, 2026

We are freshly returned from the 2026 ETSI PQC Conference. We give a debrief on the conference, including the difference between post quantum cryptography (PQC) and quantum key distribution (QKD), the algorithmic zoo, PQC for blockchain, the Dunning Kruger Effect, and cryptographic Frogger.

Podcast Transcript

Tim CallanTim CallanSo, Jason, you and I are just right straight back from the 2026 ETSI Post-Quantum Cryptography Summit. Impressions?
Jason SorokoJason SorokoI was glad to be there. I've not even unpacked - that's how fresh it is. So, what an interesting conference, in terms of just the subject matter that was spoken about. We had everything from the most hardcore of hardcore PQC topics all the way to, like, the most airy government-policy stuff.
Tim CallanTim CallanGovernment policies. Absolutely.
Jason SorokoJason SorokoFor sure. And yet I found myself in a room with guys like Professor Mosca, with Bruno Couillard, with Jaime from Santander. I mean, what a conference.
Tim CallanTim CallanIt's the who's who of PQC in the room. So let's do a little bit of background for the listeners. This is the fourth annual ETSI PQC conference
Jason SorokoJason SorokoThat's a really good point - the disjointedness of the Quantum Key Distribution (QKD) stuff. I mean, I have an intellectual interest in the QKD stuff. I also completely understand that a lot of governments are looking at it more than they normally would, simply because we're kind of on a wartime footing right now, geopolitically. A lot of tension. And so here is a proposal to you, Tim, and to our listeners: we're going to have a few podcast episodes recording soon, and I want to bring up the NSA's position on QKD - which is no on QKD. And another point the NSA made, which is: you can't do QKD without PQC. Therefore, a lot of folks who are - there definitely were some people at that conference who were absolutely headfirst into QKD, and they're taking a different tack. Just wanted to propose that, Tim, as a podcast for us.
Tim CallanTim CallanI will readily admit my own perspective. Coming into this as somebody who thinks about quantum cryptography somewhere along the line every single day, and is dealing with it on a daily basis - quantum key distribution just seems like such a foreign thing to me. When I go to a conference and we hear a discussion of quantum key distribution, I kind of go, "eh," right? You and I just recently attended the Gartner Security Conference - didn't see a thing about QKD. On the other hand, I can imagine somebody who's very heads-down on QKD who's sort of having the same response to PQC. Although I think your point is absolutely valid: if you do feel that you're in the market for quantum key distribution, you have to be resolving the PQC issue as well. The opposite is not the case.
Jason SorokoJason SorokoThat is absolutely true. That is absolutely true. So that's one theme, Tim. I'm going to give you another, and it's this: the algorithm zoo. Because there was a Chinese contingent there who spoke very plainly about their opinions about NIST algorithms - what they were doing for their own stuff. There were subsequent talks where I was scrambling to take notes, Tim. You were watching me and I shot you over the note about the Korean -
Tim CallanTim Callan- whole different set of algorithms. No overlap with NIST at all.
Jason SorokoJason SorokoAt all. And not only crypto-algorithm sovereignty - whoever put that on your bingo card. But also, it came up: the very thing you and I talked about, which is ML-DSA - how many flavors do you want? In other words, there's a zoo even within our own NIST world that you and I kind of live in. So, Tim, it's getting a little crazy.
Tim CallanTim CallanIt's getting a little crazy. I actually did speak at the conference, and one of the points I tried to make - that I think landed very clearly - is that there is no single consistent cryptography moving forward. The days of "we've got this thing called RSA and we're going to work our whole career with the same cryptography" are behind us. From here on out, we have what I call cryptographic Frogger. If we all remember Frogger - there's a little frog, he's got to move across the road, cars and trucks are coming, and if the frog doesn't keep moving, the frog dies. So we're the frog, and that's just what we have to do from here on out. And I feel like that point resonated very well with the audience, and I very much believe it. I think it's correct. And I routinely talk to people who I think haven't wrapped their head around that idea yet - that the need for agility is not just a thing somebody says on a list of to-dos. It really is the difference between success and failure in the future.
Jason SorokoJason SorokoThat was very near the end of the conference, and you could see it - it was like a wave going through the room. Because for three days - a business track, then two days of technical track - nobody had heard those words said yet, and you're the one who made the point, and it really reverberated through the whole room. We had Dustin Moody on the track day one, and he went through his - very much standing by his standardized algorithms - and going through the fact that, at the same time, yes, we're going to stand by our current algorithms, and yet we have a major program to try to fill in the blanks of: are we even sure we're going to continue to use ML-DSA for long? Who knows? And Dustin was clear with you and me, at this point more than a year ago, on this very show -
Tim CallanTim Callan- about that exact point: that no, this is not the end state. We are going to continue to work. And he always makes a joke - he says, "that way, I have job security." He's just joking
Jason SorokoJason SorokoTim, I'm going to bring up a third. It's kind of a sub-theme, but I'm going to bring it up anyway. Some of the things I saw were not just QKD versus PQC - it further split PQC out into, there were some talks, very specific and very technical talks, on PQC for blockchain.
Tim CallanTim CallanYes, that's true.
Jason SorokoJason SorokoAnd the reason I bring that up is because it's a whole other sub-genre. In other words, you could have a whole conference on that alone and completely split it out from the conference we were at, and it would make sense. But it just shows how - what Professor Mosca has brought everybody together at this conference is a good, good thing. I think it's the best of all echo-chamber-type conferences - where it's not an echo chamber, in the sense that there are very different kinds of players in the room. It's just not what you would normally see at, say, the Gartner conference that you and I recently reported on. But on the other hand, some of the topics were interesting to only some people. And I think it shows that the richness of what needs to be covered at a coming-together of human beings at a conference needs to start widening out and splintering a little more - because some of these things deserve their own extreme focus and attention, and I don't see it yet at a general PQC conference.
Tim CallanTim CallanI agree. Now, I will say there is one other PQC conference that - if you take out the quantum key distribution - feels in many ways like what you and I went to, and it's going to be happening in December: the PKI Consortium PQC Conference, which I have attended every year except last year (because, again, I had a conflict - I just couldn't). But it's a fabulous conference. There is a plurality of voices - a real, pragmatic conference focused on PQC, not QKD, focused on what practical users, subscribers, practitioners need to do, and when, and how. And we'll report on that one when it occurs. But I think that has a lot of what you were talking about at that conference as well.
Jason SorokoJason SorokoTim, I think that at the ETSI conference - the rubber-hits-the-road, we-know-how-to-really-solve-this standpoint - and this is something I'm trying to formulate in my head: the idea is, at what level do you get upset with the general practitioner who's not employing PQC, versus what's available to them to actually employ? I think right now, the people who have the voice - the beginnings of that - are the risk-averse, the banks, and there are some other industries in there as well. The other industry we heard from quite a bit at this conference was the telecoms. So the banks and the telecoms had a big voice, in terms of "here's what we're doing." I think it's going to take an awfully long time for everybody below that threshold to - you've got federal governments, banks -
Tim CallanTim Callan- and you've got the telecoms. Beyond that, nobody has a clue. And I'll share an anecdote with you. I spoke with somebody from a major bank, and I said, "well, you guys probably have all this completely" - I was making the point: don't compare yourself to just an average enterprise, because you guys are much more advanced than the average enterprise. And this guy I was talking to says, "well, I feel like we have miles to go." This was not somebody who was smug and felt like they had it all under control. This was somebody who felt like this was a vast and difficult ocean of work in front of them, and they had barely scratched the surface. So even the people who are most advanced — and that industry is the most advanced industry, and I think this bank was as advanced as anyone - even those people are struggling to figure out how they're going to get it done.
Jason SorokoJason SorokoTim, I think the threshold for what makes you advanced, if you want to use that word, is having had a holy-smokes moment of realizing "I don't know what I don't know." Oh my god - there may be a Dunning-Kruger thing going on here -
Tim CallanTim Callan- where, as you begin to dig into the topic and actually learn about it - not just get what you see in some article, but really understand what it means for your organization - you realize that you know less than you thought you did.
Jason SorokoJason SorokoI believe I witnessed Dunning-Kruger at the ETSI conference, and so it's alive and well right now, and I think we're going to see that for a long, long time to come.
Tim CallanTim CallanI agree. Thank you, Jay.
Jason SorokoJason SorokoThank you, Tim.

Stay informed with expert insights

Subscribe to Root Causes for engaging discussions on PKI, digital security, and best practices for protecting your organization's critical assets. Don’t miss an episode!

Listen on Apple PodcastsListen on SpotifyListen on SoundCloud