Quantum Deadlines Reach The Procurement Desk As Thales Launches Luna 8
Thales has released Luna 8, the first hardware security module built on a new platform designed for the migration to post-quantum cryptography, and the more important story sits in the timing rather than the specification sheet. The launch arrives only weeks after the United States and France converted years of post-quantum planning into fixed deadlines, moving the entire question from voluntary readiness to mandated migration.
That regulatory shift is what gives a single appliance wider commercial significance, because it changes what buyers are actually purchasing. The market is no longer paying for the fastest cipher on the rack. It is paying for hardware that can change ciphers on a schedule set by regulators, without tearing out the systems that depend on it.
The demand backdrop is already visible in Thales’s own research. According to the 2026 Thales Data Threat Report, the prospect of Harvest Now, Decrypt Later attacks was the most cited risk, with 59 percent of organisations reporting that they are prototyping and evaluating post-quantum algorithms. That figure describes an industry that has accepted the threat model but has not yet committed to deployment.
The commercial opportunity, and the competitive contest now under way among a small group of hardware vendors, lies precisely in that gap between evaluation and rollout. Luna 8 is Thales’s attempt to make the crossing from one to the other look routine rather than disruptive.
For the operators of roads, water networks, energy grids and the industrial systems that sit beneath them, the significance runs deeper than a procurement footnote. The data these organisations generate today, from control-system communications to design records, must stay confidential for decades, and the cryptography protecting it was never built to survive a quantum-capable adversary.
That combination of long asset life and long data sensitivity places infrastructure owners among the most exposed buyers in the entire transition, which is why a cybersecurity hardware launch belongs on the radar of anyone responsible for critical national assets.
Briefing
- Luna 8 is the first HSM on a new Thales platform, available now as a network appliance, and is being independently assessed against FIPS 140-3 Level 3 and EU Common Criteria.
- The launch follows a June 2026 US executive order setting federal post-quantum deadlines of end-2030 for key establishment and end-2031 for digital signatures, accelerating a timeline previously oriented towards 2035.
- France’s ANSSI will stop certifying security products that lack quantum-safe encryption from 2027, with government and critical-infrastructure buyers expected to procure only quantum-safe products by 2030.
- The hardware security module market is concentrated, with Thales, Entrust, Utimaco, IBM and Futurex holding roughly four-fifths of global revenue, and the competitive contest has shifted to crypto-agility and certification.
- Infrastructure operators face acute exposure because operational technology has long lifespans and control-system data retains its sensitivity for decades, making Harvest Now, Decrypt Later a present-day risk rather than a future one.
From Voluntary Guidance To Hard Deadlines
For most of the past decade, post-quantum cryptography lived in the language of recommendation. Standards bodies urged organisations to prepare, vendors published readiness guides, and boards filed the risk under long-term. That posture ended in mid-2026. On 22 June the White House issued an executive order titled Securing the Nation Against Advanced Cryptographic Attacks, directing federal civilian agencies to migrate high-value assets to post-quantum key establishment by the end of 2030 and to post-quantum digital signatures by the end of 2031.
The order also instructs contracting agencies to push the same requirements onto suppliers, and tasks federal bodies with helping critical-infrastructure operators make the move. The practical effect is to compress a timeline that agencies had generally expected to run to 2035.
France moved in the same direction and, in one respect, moved harder. At the France Quantum conference in Paris, ANSSI confirmed that from 2027 it will stop certifying security products that do not incorporate quantum-resistant encryption, and advised that organisations should be buying only quantum-safe products by 2030. Because ANSSI qualification is a prerequisite for deployment across French government and critical-infrastructure environments, the decision functions as a procurement gate rather than a guideline.
The agency’s chief of staff framed it as a matter of governance, industrial planning, regulation and sovereignty, which is a useful description of how quantum risk has migrated out of the security team and into the boardroom. The wider European roadmap points the same way, with member states expected to produce national transition plans by the end of 2026, migrate high-risk systems by 2030 and complete the shift by 2035.
Crypto-Agility Becomes The Product
Once deadlines are fixed and certification is tied to compliance, the buying criteria change. The decisive question is no longer which algorithm runs fastest today, but whether an organisation can adopt new algorithms as standards evolve without replacing the hardware that anchors its trust. Thales has built Luna 8 around that proposition, pairing support for current and post-quantum algorithms on a custom cryptographic processor with an upgradeable architecture intended to absorb new algorithms and standards over time.
Todd Moore, VP of Data Security Products at Thales, put the argument: “The risks that quantum computing poses to encryption standards are unprecedented,” he said, adding that “Enterprises need to build post-quantum readiness through cryptographic agility. Powered by our custom-designed cryptographic processor, Luna 8 delivers high-performance support for both current and post-quantum algorithms, while helping customers maintain control over security.”
The economic logic behind agility is easier to grasp through the risk calculus that security teams now use to prioritise migration. A widely applied rule holds that if the length of time data must stay secret, added to the time needed to migrate an organisation’s cryptography, exceeds the time until a capable quantum computer exists, then the organisation is already exposed. Migration time is the variable buyers can control, and it is dominated by hardware refresh cycles, integration testing and vendor coordination rather than by the algorithms themselves.
An HSM that lets an operator swap in new standards without re-architecting applications shortens that variable directly. Thales has reinforced the point by designing Luna 8 to use the same ancillaries and interfaces as existing deployments, so migration for current customers is meant to avoid changes to the applications already relying on the platform. That portability is the commercial heart of the launch, because it lowers the cost of doing the right thing on time.
A Market Consolidating Around Quantum Readiness
The hardware security module market is small, concentrated and unusually strategic for its size. Analysts put its 2026 value at a little over two billion US dollars, growing at a double-digit annual rate, with the top five suppliers, Thales, Entrust, Utimaco, IBM and Futurex, accounting for roughly four-fifths of global revenue. Within that group the competitive axis has swung decisively towards quantum readiness.
Entrust has extended its nShield line to support the NIST-standardised ML-KEM and ML-DSA algorithms, Utimaco has leaned into European regulatory compliance and Common Criteria certification, and Thales has consolidated its position through the Luna and payShield portfolios. When a market this concentrated re-tools around a single capability at the same moment, the effect is less a scramble for new customers than a defence of installed bases against displacement.
Independent analysts read the launch as an answer to how organisations actually modernise, rather than a pure technology statement.
Michela Menting, Vice President, Research at ABI Research, observed that “Integration, automation and scalability are increasingly important considerations for organizations modernizing their cryptographic infrastructure,” and that “Luna 8 combines support for post-quantum cryptography with the flexibility organizations need to adapt as security requirements constantly evolve.” Her framing matters because it identifies where the purchasing power is concentrating.
Buyers with sprawling estates of certificates, keys and signing operations are not shopping for a single fast box. They are looking for platforms that reduce operational friction across many use cases while keeping the door open to the next standard, and that is the requirement Thales is aiming its new platform at.
What The Quantum Clock Means For Infrastructure Owners
The readership most likely to underestimate this transition is the one that runs physical infrastructure, and it is also the one with the least room for error. Operational technology environments in transport, water and energy were engineered for reliability across twenty or thirty years, not for cryptographic refreshes, and much of the encryption embedded in them predates any serious quantum planning.
The awkward arithmetic is that these systems will very likely still be running when a cryptographically relevant quantum computer arrives, which means decisions taken now determine whether the assets remain protected across their whole service life. The Harvest Now, Decrypt Later model sharpens the point, because an adversary does not need a quantum computer today to benefit from one tomorrow. Encrypted control-system traffic, network diagrams and operational configurations captured now can be stored and unlocked later, and for critical infrastructure that delay does not reduce the danger.
This is precisely why the US executive order does not stop at federal systems and explicitly tasks agencies with helping critical-infrastructure operators transition. Roads, ports, utilities and rail carry data whose confidentiality matters for the life of the asset, and whose compromise carries consequences well beyond commercial loss.
For infrastructure owners the implication is that quantum migration cannot be treated as an IT housekeeping item to be scheduled after everything else. It is a lifecycle question that belongs in asset-management planning, procurement specification and long-range capital budgeting, alongside the more familiar concerns of resilience and maintenance. An HSM designed for agility is one component of that answer, but the harder work is organisational, and it starts with knowing where vulnerable cryptography actually sits inside estates that were never mapped with this threat in mind.
Assurance, Performance And The Certification Gate
Performance still matters, and Thales has made throughput a headline attribute, describing Luna 8 as delivering cryptographic operations orders of magnitude faster than existing systems and scaling from enterprise to hyperscale workloads. Those are the company’s own figures rather than independently benchmarked results, and buyers will test them against their own demands, but the direction is sensible.
Post-quantum algorithms generally carry larger keys and heavier signatures than the schemes they replace, so headroom in the hardware is what prevents the migration from degrading the services that sit on top of it. In high-volume environments such as certificate issuance, authentication and signing, the practical value of a faster processor is that it lets an operator adopt heavier post-quantum operations without a visible penalty to the users depending on those services.
Assurance is where the commercial gate really sits. Luna 8 is being independently assessed against FIPS 140-3 Level 3 and EU Common Criteria, the two benchmarks that regulated and government buyers treat as non-negotiable. Certification is not a marketing badge in this market, because processes such as ANSSI qualification can take twelve to eighteen months, and a product that has not entered the pipeline is effectively behind before it reaches the shortlist.
That timing turns validation into a competitive weapon, since the suppliers whose quantum-safe hardware clears the recognised standards first will be the ones eligible for the procurement cycles the new deadlines are about to unleash. For buyers, the lesson is to write post-quantum and certification requirements into solicitations now, rather than discovering at contract stage that the compliant options are limited.
One Platform For Keys, Identity And Payments
Luna 8 is described as the first module on a new Thales HSM platform, and that platform framing is a deliberate strategic move rather than a naming convention. The appliance is built to run a range of cryptographic applications on unified hardware, and Thales has signalled that future releases will extend the same platform to payShield 11K, its payment HSM line that protects transactions, PINs and the cryptographic keys used by banks and payment providers.
Bringing general-purpose and payment security onto a common platform is an attempt to consolidate two historically separate product lines, which would let customers standardise their cryptographic estate and give Thales a broader footprint inside each account. In a market defined by installed bases, that kind of consolidation is how a leader defends share while the ground shifts beneath everyone.
Early adopters tend to come from sectors where cryptographic trust is the product itself. HKVAX, a digital-asset exchange, is among the first named customers, and its chief information officer, Jack Zhou, framed the appeal in operational rather than cryptographic terms: “The new quantum-safe HSM from Thales enables us to support multiple secure environments while simplifying operations and making more efficient use of our infrastructure,” he said, adding that “The flexibility to support multiple use cases, applications and business needs over time helps us maximize hardware investments. The combination of predictable performance and high availability gives our IT and security teams the assurance they need to operate efficiently to deliver consistent service to our stakeholders.”
The emphasis on consolidation and predictable performance is telling, because it confirms that buyers value an HSM as much for how many jobs it can absorb as for the specific algorithms it runs. That is the logic Thales is betting the new platform can satisfy for years.
Turning Readiness Into A Migration Plan
The clearest signal from this launch is that the industry has moved past the argument about whether quantum risk is real and into the harder work of scheduling a response against dates that are now fixed. The organisations that will manage the transition well are those treating it as a multi-year programme rather than a single purchase, beginning with a cryptographic inventory that reveals where vulnerable algorithms are embedded, then prioritising migration by the shelf-life of the data each system protects.
Hardware that offers genuine crypto-agility shortens the most controllable part of that programme, but it does not remove the need for governance, ownership and a sequenced plan tied to the regulatory calendar. For infrastructure owners in particular, the most valuable step available today is unglamorous, which is to specify post-quantum capability and recognised certification in every relevant procurement so that the assets bought now are not obsolete on the security dimension before they are commissioned.
Seen in that light, Luna 8 is best understood as a marker of where commercial value is concentrating rather than as a finished solution to the quantum problem. Value is migrating towards platforms that combine performance, certification and the ability to change cryptography on demand, and towards the suppliers able to prove all three to regulated buyers first.
The deadlines set in Washington and Paris have given that migration a schedule, and the vendors have responded by re-tooling their flagship hardware around agility and assurance. What remains is for asset owners and infrastructure operators to translate that market movement into their own plans, because the one variable none of them controls is how much time is left before the data they are protecting today becomes readable to whoever has been patient enough to keep it.

Key Industry Questions
- What is Harvest Now, Decrypt Later and why does it make quantum risk a present-day concern?Β Harvest Now, Decrypt Later describes a strategy in which an adversary captures and stores encrypted data today, intending to decrypt it once a capable quantum computer becomes available. The threat is immediate rather than hypothetical, because the collection is happening now even though the decryption lies in the future. It matters most for information with a long confidentiality life, such as infrastructure design records, control-system communications and personnel data, where the value of secrecy stretches across decades. For organisations holding such data, the practical conclusion is that waiting for quantum computers to arrive before acting guarantees a long window of exposure, since anything harvested in the interim is already beyond recall.
- What deadlines have governments actually set for post-quantum migration?Β The United States issued an executive order in June 2026 directing federal agencies to migrate high-value assets to post-quantum key establishment by the end of 2030 and to post-quantum digital signatures by the end of 2031, with contractors pulled into scope through procurement rules. France’s ANSSI will stop certifying security products that lack quantum-safe encryption from 2027 and expects buyers to procure only quantum-safe products by 2030. The broader European roadmap anticipates national transition plans by the end of 2026, migration of high-risk systems by 2030 and full migration by 2035. Together these measures convert post-quantum cryptography from a recommendation into a scheduled, enforceable requirement for regulated and government-facing buyers.
- Why is crypto-agility more important than any single post-quantum algorithm?Β Cryptographic standards will continue to evolve, and early post-quantum algorithms may be supplemented or revised as analysis matures. An organisation that hard-wires one algorithm into its infrastructure risks a costly hardware replacement each time the standard changes. Crypto-agility, the ability to adopt new algorithms without re-architecting the systems that depend on them, turns that recurring capital problem into a manageable update. It also shortens the migration time that dominates quantum risk calculations, because most of the effort in a transition lies in hardware refreshes, integration testing and vendor coordination rather than in the mathematics. For buyers, agility is effectively insurance against a standard changing after the money has been spent.
- How does the quantum transition affect operators of physical infrastructure?Β Operational technology in transport, water and energy is engineered for service lives measured in decades, and much of its embedded cryptography predates serious quantum planning. These systems will probably still be running when a capable quantum computer arrives, so the protection chosen now has to last the whole lifecycle. Control-system traffic, network diagrams and operational configurations are exactly the kind of long-sensitive data that Harvest Now, Decrypt Later targets. The consequence is that quantum migration belongs in asset-management and capital planning rather than in routine IT maintenance, and infrastructure owners should begin by identifying where vulnerable cryptography sits inside estates that were never mapped with this threat in mind.
- Why do FIPS 140-3 Level 3 and Common Criteria certifications matter for buyers?Β These certifications are the assurance benchmarks that regulated and government buyers treat as prerequisites, confirming that a device meets defined standards for tamper resistance and cryptographic integrity. In the current market they also act as a competitive gate, because national qualification processes can take twelve to eighteen months and a product that has not entered the pipeline cannot serve buyers whose deadlines are approaching. Suppliers whose quantum-safe hardware clears these standards first become eligible for procurement cycles that competitors cannot yet reach. For purchasers, the practical implication is to require both post-quantum capability and recognised certification in tender documents, rather than assuming compliant options will be plentiful at contract stage.
- Who competes with Thales in the hardware security module market?Β The market is concentrated, with Thales, Entrust, Utimaco, IBM and Futurex accounting for roughly four-fifths of global revenue and the sector valued at a little over two billion US dollars in 2026. Entrust has extended its nShield modules to support the NIST-standardised ML-KEM and ML-DSA algorithms, while Utimaco has focused on European regulatory compliance and Common Criteria certification. Cloud providers including AWS and Microsoft offer hosted HSM services that widen access for mid-market buyers. The common thread is that competition has shifted from raw performance towards crypto-agility, certification and platform breadth, as suppliers defend large installed bases against displacement during a once-in-a-generation cryptographic change.
- What are the NIST post-quantum standards that underpin these products?Β In August 2024 NIST finalised its first post-quantum standards after an eight-year process: FIPS 203, known as ML-KEM, for key encapsulation; FIPS 204, known as ML-DSA, for digital signatures; and FIPS 205, known as SLH-DSA, as a hash-based signature alternative. These algorithms are designed to resist attacks from quantum computers and to replace the public-key schemes, such as RSA and elliptic-curve cryptography, that quantum machines could eventually break. Their standardisation gave vendors a stable target to build towards, which is why current HSM launches emphasise native support for ML-KEM and ML-DSA. The existence of finalised standards is also what allowed governments to move from planning to enforceable deadlines.
- What should an organisation do first to prepare for the quantum transition?Β The recommended starting point is a cryptographic inventory that maps where encryption, keys and signing operations live across the estate, since most organisations cannot yet see their own exposure clearly. From there, migration should be prioritised by the shelf-life of the data each system protects, so that the longest-sensitive information is addressed first. Governance matters as much as technology, which is why regulators are requiring named migration leads and documented plans. Buyers should favour crypto-agile, upgradeable hardware and hybrid approaches during the transition, and should embed post-quantum and certification requirements into procurement now. Treating the effort as a sequenced multi-year programme, rather than a single purchase, is what separates organisations that meet the deadlines from those that miss them.
Strategic Takeaways
- Regulatory deadlines in the United States and France have converted post-quantum cryptography from a voluntary readiness exercise into an enforceable procurement requirement, and the buying criteria have shifted accordingly towards agility and certification.
- The commercial value in this transition is concentrating in hardware that can change cryptographic algorithms without a rip-and-replace, because migration time, not algorithm choice, is the variable buyers can actually control.
- Infrastructure owners face acute and under-appreciated exposure, since operational technology with decade-long lifespans will still be running when quantum capability arrives and the data it protects is already a Harvest Now, Decrypt Later target.
- Certification against FIPS 140-3 Level 3 and Common Criteria has become a competitive gate rather than a formality, and suppliers that validate quantum-safe hardware first will capture the procurement cycles the new deadlines are releasing.
- Organisations should treat quantum migration as a sequenced multi-year programme beginning with a cryptographic inventory and data prioritised by confidentiality shelf-life, and should write post-quantum capability into procurement now to avoid buying assets that are obsolete on security before commissioning.















