Changelog
Current version: v4.152.0
What this means for you
- Executive / Business Leader
- Filter by your persona to see only the releases that changed something you use.
- GRC / Risk & Compliance
- Data Updates entries mark corrections to obligations and records; the Compliance and Timeline tags say which area moved.
- Developer / Engineer
- Entries tagged Software and Algorithms name the tool or view that gained or fixed something.
- Security Architect
- Architecture-relevant changes carry the Algorithms and Library tags; the Architect persona filter narrows to them.
- Researcher / Academic
- Data Updates entries say which dataset changed; the Revisions page has the row-level detail.
- Certification & Validation Engineer
- Data Updates entries say which dataset changed and when; the Revisions page has the row-level detail for any certificate record.
- IT Ops / DevOps
- The Ops persona filter covers deployment, certificate lifecycle and TLS configuration changes.
- Curious Explorer
- Each entry starts with what changed for you, in plain words; the version number is the least important part.
October 8, 2026
v4.152.0CurrentA mistyped or outdated address now shows a clear "Page not found" page instead of the home page; on phones every page has one main heading, shared Library links keep their status filter and the About page explains analytics; and the Simulation offers the new Homomorphic Encryption module.
- ›The Simulation offers the Homomorphic Encryption moduleDeveloperArchitectResearcherOps/simulation/learn/homomorphic-encryption
- ›An unknown address shows "Page not found"ExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious/
- ›Each page on a phone has exactly one main headingExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious/LearnPlayground
- ›On a phone, a shared Library link keeps its status filterExecutiveGRCResearcherCertificationLibrary
- ›The phone About page explains analyticsExecutiveGRCArchitectCurious/about
October 4, 2026
v4.150.0–v4.151.0The Privacy and Terms pages now say plainly that analytics run on every visit; Homomorphic Encryption becomes its own Learn module with fourteen new quiz questions; the assessment report keeps the frameworks you selected and names any it leaves out; every Crypto Lab tool, planning tool and Learn module has a page that search engines can read; and the About page, README, tour and manual quote the real counts. · Pages that quote when a quantum computer might arrive now stick to what their sources say: the Threats page drops the range this site had worked out itself and shows the Global Risk Institute survey in its own words, the Assess steps no longer claim a 2030–2040 expert range, and the FAQ, Simulation, report and Learn exercises say that these figures are published estimates, still open to debate. The Confidential Computing workshop also now prints the real ML-DSA key sizes.
- ›Homomorphic encryption now has its own moduleDeveloperArchitectResearcherOps/learn/homomorphic-encryption/learn/confidential-computing
- ›Quiz questions on homomorphic encryptionDeveloperArchitectResearcherOpsCurious/learn/quiz/learn/homomorphic-encryption
- ›The report names the frameworks you selected that were left outExecutiveGRCArchitectCertificationOps/reportAssess
- ›Every Crypto Lab and Business tool has its own page for search enginesExecutiveGRCDeveloperArchitectPlayground/business
- ›A short introduction on the Report pageExecutiveGRCArchitect/report
- ›Link to one Transition row, one landscape standard, a KAT variant or a coverage caseDeveloperArchitectResearcherCertificationAlgorithms
- ›Who maintains an open-source productArchitectDeveloperResearcherMigrate
- ›Certificates on phonesCertificationGRCOpsCompliance
- ›Share and "open on its page" from more placesGRCResearcher/leadersCompliance
- ›The FHE service installed in the shipped board imageArchitectResearcherOpsDeveloper/learn/homomorphic-encryption
- ›Notes that estimates are still open, on more pagesExecutiveGRCArchitectResearcherCurious/faq/report/simulationLearn
- ›The Privacy and Terms pages now say plainly that analytics run on every visitExecutiveGRCArchitectCurious/terms/about
- ›The privacy text on the About, Terms and README pages matches what the site doesExecutiveGRCArchitectCurious/terms/about
- ›The About page, README, tour and user manual quote the real countsExecutiveGRCResearcherCurious/aboutLearn
- ›The About page counts Timeline countries from the dataExecutiveResearcherGRCCurious/about
- ›The user manual describes the Compliance and Learn pages as they areGRCCertificationOpsCuriousComplianceLearn
- ›The role boards call the quantum-computer year our own planning yearExecutiveResearcherCuriousCertification/
- ›Automated reviews show as "maintainer (automated)"GRCResearcherCertification/revisionsCompliance
- ›The Quantum Threats lesson's search summary matches its sourcesExecutiveGRCArchitectResearcher/learn/quantum-threats
- ›The Quantum Threats lesson shows what each source says about a quantum-computer estimateExecutiveGRCArchitectResearcherCurious/learn/quantum-threats
- ›The Threats page shows the same behind each estimate's Sources buttonExecutiveGRCArchitectResearcherCuriousThreats
- ›Every Library document shows one of six labelsExecutiveGRCArchitectResearcherOpsCertificationCuriousLibrary
- ›Products whose PQC status is unknown no longer show a plain "Verified" badgeArchitectGRCCertificationResearcherOpsMigrate
- ›Extracted passages and obligations name "automated extraction" as their sourceGRCResearcherCertificationLibraryCompliance
- ›Confidential Computing & TEEs is back to its five TEE stepsDeveloperArchitectResearcherOps/learn/confidential-computing
- ›Learning paths list Homomorphic Encryption after Confidential Computing & TEEsDeveloperArchitectResearcherOpsLearn
- ›Very long pages are saved smaller for search engines, without dropping anythingResearcherGRCCuriousLibrary/changelog/leaders
- ›The Threats page no longer shows a CRQC range of its ownExecutiveGRCArchitectResearcherCuriousThreats
- ›The Assess steps no longer claim a 2030–2040 expert rangeExecutiveGRCArchitectResearcherAssess
- ›The Threats headline shows the Global Risk Institute survey in its own wordsExecutiveGRCArchitectResearcherThreats/learn/quantum-threats
- ›The report keeps the frameworks you selected that apply to your industry and countryExecutiveGRCArchitectCertificationOps/reportAssess
- ›Typed search text is cleaned before our analytics events count itExecutiveGRCArchitectCurious/leadersMigrateTimeline
- ›The page address we send to Google Analytics no longer includes anything after a "?"ExecutiveGRCArchitectCurious/terms
- ›Highlight links tint only the algorithm namedDeveloperCuriousAlgorithms
- ›The Entropy Evidence Lab shows the recorded commands without local file pathsResearcherDeveloperOps/learn/entropy-randomness
- ›The PQC Assistant can link to every Learn module and every business planning toolExecutiveGRCDeveloperArchitectResearcherOpsCuriousLearn/business
- ›The assistant's links use the exact filter values on the Algorithms, Threats, Timeline, Leaders and OpenSSL pagesDeveloperArchitectResearcherOpsCuriousAlgorithmsThreats
- ›More leaders appear when you filter the Community page by regionExecutiveGRCResearcherCertificationCurious/leaders
- ›Twelve more Learn modules can be found through searchDeveloperArchitectGRCOpsResearcherLearn
- ›Each Learn module page's study time matches the moduleDeveloperArchitectGRCCuriousLearn
- ›Learn, Explore and the home page quote the real number of modulesDeveloperArchitectGRCCuriousLearn/explore/
- ›The Business Tools page description quotes the real number of toolsExecutiveGRC/business
- ›The Migrate page's search description says 9 infrastructure layers, as the page groups themArchitectDeveloperOpsMigrate
- ›Clicking anywhere on a Crypto Lab card opens its preview againDeveloperArchitectResearcherPlayground
- ›Long workshop titles no longer overflow the page headerDeveloperArchitectResearcherOpsPlaygroundLearn
- ›The trusted-channel steps show the real ML-DSA key sizesArchitectResearcherCertification/learn/confidential-computing
- ›Library documents carry their lifecycle labelResearcherGRCArchitectCertificationOpsLibrary
- ›The Threats page's BSI, NSA and ANSSI entries now point at the current statementsGRCResearcherArchitectThreats
- ›Library dates and status correctedResearcherGRCArchitectCertificationLibrary
- ›Migrate catalog corrections for 13 productsArchitectGRCCertificationResearcherOpsMigrate
- ›Trust tiers of 20 sources correctedGRCResearcherCertificationLibraryComplianceThreatsAlgorithms
- ›One Timeline source date correctedGRCExecutiveResearcherTimeline
October 3, 2026
v4.146.0–v4.149.0FHE key custody now runs across two appliance boards with a backup and a failover, the data owner checks the custodian's attestation before trusting its keys, and the FHE compute service runs on a small Arm board over mutual TLS. Every "Validated" badge in the workshop now opens its results on the page, and the Threats and related pages now say plainly that some quantum estimates are still unresolved, with the BSI, NSA and ANSSI entries corrected to what those organisations actually state. · The FHE + HSM workshop's key-custody flow now runs with the key held on the MX95 appliance board, the Lattigo threshold scenario gets its first board measurements, Library dates cite their NIST sources, and shared links are now checked every night. · The FHE + HSM workshop now shows which steps have been validated, with measured runs on a Mac and on a KV260 board, including a first end-to-end run of TFHE key custody in a software token. · Links from the Assistant, search and shared URLs now open the item they name, Learn workshops and wide charts fit a phone screen again, and the Confidential Computing FHE content gets small accuracy fixes.
- ›FHE key custody with a backup boardArchitectResearcherOps/learn/confidential-computing
- ›Destroy and restore of the keyArchitectOpsCertification/learn/confidential-computing
- ›Failover to the backup boardArchitectOps/learn/confidential-computing
- ›The data owner checks the custodian's attestationArchitectResearcherCertification/learn/confidential-computing
- ›An FHE compute service on a small Arm boardDeveloperArchitectOps/learn/confidential-computing
- ›See the results behind every "Validated" badgeArchitectResearcherDeveloperOps/learn/confidential-computing
- ›A plain note that some quantum estimates are still unresolvedExecutiveGRCArchitectResearcherCuriousThreats/learn/quantum-threatsAssess/report
- ›FHE key custody on the MX95 boardArchitectResearcherOps/learn/confidential-computing
- ›Lattigo threshold timings on a small ARM boardResearcherArchitect/learn/confidential-computing
- ›8- and 16-bit encrypted arithmetic timed on the KV260DeveloperArchitectResearcher/learn/confidential-computing
- ›FHE + HSM Flows show what has actually been validatedArchitectResearcherCertification/learn/confidential-computing
- ›OpenFHE threshold sizes are now measuredResearcherDeveloperArchitect/learn/confidential-computing
- ›TFHE figures corrected from measurementsResearcherDeveloper/learn/confidential-computing
- ›First hardware numbers: the FHE server on a KV260ArchitectResearcherOps/learn/confidential-computing
- ›First end-to-end run of TFHE key custodyArchitectResearcherOps/learn/confidential-computing
- ›OpenFHE threshold timings on a small ARM boardResearcherArchitect/learn/confidential-computing
- ›Server-key export timed on the custodian boardArchitectOps/learn/confidential-computing
- ›Lattigo threshold sizes corrected from measurementsResearcherArchitectDeveloper/learn/confidential-computing
- ›Shared links are checked every nightDeveloperOps/about
- ›Pull requests get an automatic privacy check (report-only)DeveloperOps/about
- ›Learn pages and the report link to the exact topicCuriousDeveloperArchitectOpsLearn/report
- ›Corrected the German BSI migration dates on the Threats pageExecutiveGRCArchitectResearcherThreats
- ›Newer NSA and ANSSI statements on the Threats sources listExecutiveGRCArchitectResearcherThreats/learn/quantum-threats
- ›Assistant and search links to patents open the patentResearcherArchitect/patents
- ›Shared links skip the "Who's asking?" picker on phones for every kind of itemExecutiveGRCArchitectOpsMigrateComplianceAlgorithms
- ›Highlighted algorithms show on phonesDeveloperCuriousAlgorithms
- ›Library links tolerate hyphensResearcherDeveloperLibrary
- ›Assessment report → Threats for Education and ManufacturingExecutiveGRC/reportThreats
- ›Migrate category links land on the catalogArchitectOpsMigrate
- ›Phones follow the same filter links as desktopGRCResearcherOpsTimelineCompliance/patents/leadersAlgorithms
- ›A second link on the same page worksDeveloperArchitectAlgorithms/patents
- ›More links open the exact itemGRCCertificationArchitectComplianceTimeline/report/leadersMigrate
- ›Your saved settings survive a shared linkGRCExecutiveThreats
- ›The Migrate catalog filter is shareableArchitectOpsMigrate
- ›FHE + HSM Flows: corrected TFHE client-key size and a named sourceResearcherDeveloper/learn/confidential-computing
- ›Learn workshops fit a phone screen againCuriousDeveloperArchitectOpsGRCLearn
- ›Wide charts scroll inside their panel on phonesGRCExecutive/learn/emv-payment-pqc/learn/pqc-risk-management
- ›Revision history and long names wrap on phonesCuriousResearcher/revisions/learn/vpn-ssh-pqc
- ›Keyboard and screen-reader fixes in three workshopsDeveloperArchitect/learn/pki-workshop/learn/api-security-jwt/learn/trust-services-pqc
- ›ISO/IEC 28033 in the LibraryResearcherArchitectLibrary
- ›FIPS and entropy-certificate dates now name their NIST sourceCertificationOpsArchitectGRC/learn/crypto-mgmt-modernization/business/tools/crypto-cbom-builder
- ›New Library referencesDeveloperResearcherArchitectLibrary
October 2, 2026
v4.141.0–v4.145.0The FHE + HSM workshop now shows plainly when data is encrypted, computed on and decrypted, who may decrypt, and where every key sits; every HSM Learn lesson now runs on a fresh page, and the Library adds fhe.rs, the fourth open-source homomorphic-encryption library. · Confidential Computing now teaches fully homomorphic encryption, with a workshop step showing how an HSM can hold FHE keys. · A new HSM playground lesson shows how applications discover certificates across slots, the Rust engine follows PKCS#11 v3.2 more closely, HMAC works again after a hash-based signature on the C++ engine, and catalog entries were corrected after a source-by-source accuracy check. · The IoT & OT module is now two advanced modules, one for IoT and embedded devices and one for operational technology across five sectors, both checked against their standards; search stays smooth after the first search; the JWT workshop's encrypted tokens can run entirely inside the emulated HSM; and the Library and vendor roadmaps gain new entries. · Talking About PQC Accurately has been reviewed and now has its own quiz questions, the API Security workshop names the draft revision it actually implements, a new Attack Lab shows why a JWT verifier must check more than the signature, and the Library adds 42 references for the IoT and OT modules.
- ›Homomorphic encryption explained in Confidential ComputingArchitectDeveloperResearcherCurious/learn/confidential-computing
- ›New workshop step: FHE + HSM FlowsArchitectOpsResearcherDeveloper/learn/confidential-computing
- ›New HSM playground lesson: Discovering certificates across slotsDeveloperArchitectOpsCertificationPKCS#11 Playground
- ›More questions on industrial protocols and rulesArchitectOpsGRC/learn/ot-pqc
- ›New module: IoT & Embedded Device PQCDeveloperArchitectResearcherOps/learn/iot-pqc
- ›New module: OT & Industrial Control Systems PQCArchitectOpsGRCResearcher/learn/ot-pqc
- ›LMS signatures are checked against the RFC 8554 test vectorsDeveloperCertification/learn/iot-pqc/learn/ot-pqc
- ›Boot verify latencyDeveloperArchitect/learn/secure-boot-pqc
- ›V2X channel loadArchitectResearcher/learn/automotive-pqc
- ›NIST IR 8259 Rev. 1 in the LibraryGRCResearcherLibrary
- ›Six new trusted sourcesResearcherGRCLibrary
- ›Attack Lab: see why a JWT verifier must check more than the signatureDeveloperArchitectOps/learn/api-security-jwtPlayground
- ›Quiz questions for Talking About PQC AccuratelyCurious/learn/quiz
- ›FHE + HSM Flows: encrypt, compute on encrypted data, decrypt, in plain sightArchitectResearcherDeveloperCurious/learn/confidential-computing
- ›Where keys and data are, inside the flowArchitectOpsResearcher/learn/confidential-computing
- ›What an HSM decryption policy can and cannot doArchitectResearcherCertification/learn/confidential-computing
- ›The Rust HSM engine follows PKCS#11 v3.2 more closely when you list objectsDeveloperCertificationPKCS#11 Playground
- ›Secret keys, private keys and data objects are private by defaultDeveloperOpsCertificationPKCS#11 Playground
- ›IoT & Embedded Device PQC cites the current NIST guidanceGRC/learn/iot-pqc
- ›The JWT workshop's encrypted tokens can now run entirely inside the emulated HSMDeveloperArchitectCertification/learn/api-security-jwtPlayground
- ›Post-quantum HPKE checked against two more published test-vector setsResearcherCertification/learn/api-security-jwt
- ›Search stays smooth after the first search, and frees 37 MB of browser storageCuriousDeveloperArchitectResearcherGRCExecutiveOpsCertification/
- ›API Security & JWT now lists RFC 9068 and RFC 9864 among its referencesDeveloperArchitect/learn/api-security-jwt
- ›Old links keep working and your progress carries overCuriousLearn
- ›18 IoT and OT quiz questions corrected and 20 addedCuriousResearcher/learn/quiz
- ›Talking About PQC Accurately is reviewedCurious/learn/talking-about-pqc
- ›Routine library updatesDeveloperOps/about
- ›Every HSM Learn lesson now runs on a fresh pageDeveloperResearcherCertificationPKCS#11 Playground
- ›HMAC works again after a hash-based signature on the C++ engineDeveloperCertificationPlaygroundAlgorithms
- ›Dual-engine checks in the KEM and Sign/Verify tabs use a real Rust sessionDeveloperPKCS#11 Playground
- ›IoT and OT figures now match their sourcesResearcherArchitect/learn/iot-pqc/learn/ot-pqc
- ›The JWT encryption step no longer says the HSM cannot run the X-Wing hybridDeveloper/learn/api-security-jwt
- ›ETSI TS 103 744 shows the edition it links toArchitectResearcherLibrary
- ›The API Security workshop names the draft revision it actually implementsDeveloperResearcher/learn/api-security-jwt
- ›fhe.rs joins the homomorphic-encryption librariesDeveloperResearcherLibrary
- ›Three homomorphic-encryption libraries in the LibraryDeveloperResearcherArchitectLibrary
- ›New trusted sources for homomorphic encryptionResearcherLibrary
- ›Corrections from a source-by-source accuracy checkArchitectGRCResearcherMigrateAlgorithms
- ›General Dynamics KIV-80 shows its post-quantum claimArchitectOpsMigrate
- ›NICT post-quantum roadmapResearcherArchitectMigrate
- ›Four more vendor post-quantum roadmapsArchitectOpsMigrate
- ›Two new trusted sourcesGRCResearcherLibrary
- ›42 new library references for the IoT and OT modulesArchitectGRCOpsResearcherLibraryLearn
October 1, 2026
v4.139.0–v4.140.0The Curious Explorer role now also serves people who need post-quantum cryptography for their job without a technical background, the JWT module follows the current IETF drafts and passes their published test vectors, and two engine bugs found by Google's Wycheproof tests are fixed. · The Hybrid Certificate playground now builds every certificate the way its standard says, checks each one with a second, independent implementation, and tells you plainly which formats are published, which are drafts, and which are history.
- ›New module: Talking About PQC AccuratelyCurious/learn/talking-about-pqc
- ›"I talk about it at work" on the Curious home boardCurious/
- ›Wycheproof tests for ML-KEM and ML-DSADeveloperResearcherGRCPlayground
- ›Suggest a correction in one clickCuriousResearcherGRC/about/editorial-independence
- ›Advanced examples: Certificate Discovery and unsigned certificatesDeveloperArchitectResearcherCertificationOps/learn/hybrid-crypto
- ›Curious Explorer is for your job tooCuriousLearn
- ›"How bad is it really?" replaced on the Curious home boardCurious/
- ›Composite JWT signatures follow the current IETF draft and pass its published test vectorsDeveloperArchitectResearcher/learn/api-security-jwt
- ›The nested JWT checks both signatures, and SLH-DSA-SHAKE-128s is availableDeveloperArchitect/learn/api-security-jwt
- ›New lesson: JWT validation basics that post-quantum signatures do not fixDeveloperArchitectOpsGRC/learn/api-security-jwt
- ›Published IETF test vectors back the JWT workshopDeveloperResearcherCertification/learn/api-security-jwt
- ›Encrypt a token the way the post-quantum JWE drafts now specifyDeveloperArchitectResearcher/learn/api-security-jwtPlayground
- ›The JOSE known-answer suite now checks encryption tooDeveloperResearcherCertification/learn/api-security-jwt
- ›The JOSE row of the Protocol Matrix shows the current standardsArchitectResearcherExecutiveAlgorithms
- ›Every hybrid certificate is now verified, and you can see the checksDeveloperArchitectResearcherCertificationOps/learn/hybrid-cryptoPlayground
- ›ML-KEM certificates are issued the RFC 9935 wayDeveloperArchitectResearcherCertificationOps/learn/hybrid-crypto
- ›Related Certificates now follow RFC 9763DeveloperArchitectResearcherCertificationOps/learn/hybrid-crypto
- ›Alt-Sig's second signature covers the right dataDeveloperArchitectResearcherCertificationOps/learn/hybrid-crypto
- ›Composite ML-KEM cites revision 21 everywhereDeveloperArchitectResearcherCertificationOpsGRCAlgorithms/learn/hybrid-crypto
- ›Chameleon certificates are shown as historyDeveloperArchitectResearcherCertificationOps/learn/hybrid-crypto
- ›Generate All shows real progress and can be cancelledDeveloperArchitectResearcherCertificationOps/learn/hybrid-cryptoPlayground
- ›The X.509 matrix row is more completeGRCDeveloperArchitectResearcherCertificationOpsAlgorithms
- ›Curious home board no longer shows the same chip twiceCurious/
- ›Two Rust-engine bugs found by Google's Wycheproof tests are fixedCertificationDeveloperAlgorithmsPlayground
- ›The first search no longer freezes the pageCuriousDeveloperResearcherLibrary
- ›Hybrid cryptography explanations correctedCuriousDeveloperArchitectResearcherCertificationOps/learn/hybrid-crypto
- ›JOSE standards in the Library are currentDeveloperArchitectResearcherLibrary
- ›A second source on an IoT firmware threat now opens the current documentResearcherGRCOpsThreats
- ›Eight more products with NIST-validated post-quantum algorithmsOpsCertificationArchitectDeveloperMigrate
- ›Library: three new post-quantum documentsResearcherDeveloperGRCLibrary
- ›Vendor roadmaps: Cloudflare Workers and MTGDeveloperArchitectMigrate
- ›5G SUCI now points to 3GPP's post-quantum studyArchitectResearcherGRCAlgorithms
- ›Three new trusted sourcesGRCResearcher/about
- ›TimelineGRCExecutiveResearcherTimeline
- ›LibraryGRCResearcherLibrary
September 30, 2026
v4.137.0–v4.138.0Search finds what you typed more often: ⌘K shows strong matches without scrolling and tells you when a filter is hiding results, and the Glossary, Library and Learn search boxes now match every word of a query instead of the exact phrase. · The PQC Assistant answers from the retrieved PQC Today corpus again, responds more quickly on broad lists, and uses the better-tested Qwen 3 8B model by default while keeping Qwen 3.5 available.
- ›⌘K tells you when "Authoritative only" is hiding resultsExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious
- ›⌘K shows strong matches without scrollingExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious
- ›Glossary, Library and Learn search match every wordExecutiveGRCDeveloperArchitectResearcherCertificationOpsCuriousLibraryLearn
- ›The Glossary suggests close matches when nothing matches every wordExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious
- ›Qwen 3 8B is the local default againExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious
- ›Assistant answers use the passages that actually match the questionDeveloperArchitectResearcherCertificationLearnMigrateLibrary
- ›Local answers finish instead of exposing reasoning or partial metadataExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious
September 29, 2026
v4.133.0–v4.136.0The About page's list of the software this site is built from is now accurate and complete: it shows what the site really ships, with real versions and licenses, says plainly where something is not recorded, and can be downloaded in full. · Every item's panel now has its own Share button, so you can share a document, threat, algorithm, product or record while it is open — on desktop and on phones. · A new role for the people who test and certify cryptographic modules — validation-lab testers, module vendor engineers and scheme reviewers — with its own learning path, home boards and the validation tools up front. · The PQC VPN Simulator now runs hybrid IKEv2 in the order the ML-KEM draft recommends, and shows why pure ML-KEM runs into size limits. · Shared links now reach much further into the hub: you can link to a single algorithm, vendor roadmap, Compliance requirement, Community profile and more, and links from Learn modules, search and the PQC Assistant open the exact item they mention.
- ›Download the complete software bill of materialsGRCArchitectOpsExecutive/about
- ›AI models are listed tooGRCArchitectExecutive/about
- ›Fonts, the Python runtime and other parts that were missingOpsArchitect/about
- ›Share an item from its own panelExecutiveGRCDeveloperArchitectResearcherOpsCuriousLibraryThreatsAlgorithmsTimelineMigrate/patents/leadersCompliance
- ›Share an industry use case or an open comparisonArchitectExecutiveDeveloperAlgorithms
- ›More links work on phonesOpsResearcherMigrate/patents
- ›New role: Certification & Validation EngineerCertification/Learn
- ›Validation tools open first for this roleCertificationAlgorithmsPlayground
- ›Six home boards built on test evidenceCertification/Compliance
- ›Guidance written for this role across the siteCertificationLearn/faq/leaders
- ›176 existing quiz questions now count for this roleCertification/learn/quiz
- ›A Compliance view and a report summary for this roleCertificationCompliance/report
- ›Propose a test vector from where you spot the gapCertificationDeveloperPlaygroundLearn
- ›GRC entries are easier to find on this pageGRC/changelog
- ›Share a link to one algorithmDeveloperArchitectResearcherAlgorithms
- ›Links into more of the Algorithms pageArchitectResearcherDeveloperAlgorithms
- ›Links to Migrate domains and vendor roadmapsOpsArchitectExecutiveMigrate
- ›Links to Compliance requirements, products and CSWP.39 viewsGRCArchitectCompliance
- ›Stable links to Community profilesResearcherExecutive/leaders
- ›More of Timeline, Threats and Patents fits in a linkGRCResearcherDeveloperTimelineThreats/patents
- ›Every version and license on the About page now comes from the shipped filesGRCOpsArchitect/about
- ›Hybrid VPN mode now follows the IETF draft's recommended orderArchitectOpsDeveloper/playground/vpn-sim/learn/vpn-ssh-pqc
- ›The handshake diagram follows the ML-KEM size you pickArchitectDeveloper/playground/vpn-sim
- ›Wrong entries on the About page correctedGRCDeveloperArchitect/about
- ›Compliance toolbar no longer disappearsGRCCompliance
- ›Migrate shares the product you are looking atOpsArchitectMigrate
- ›Timeline event pop-up has a Close buttonGRCResearcherTimeline
- ›On phones, document and "try it" panels are no longer hidden under the headerDeveloperCurious
- ›Escape closes only the panel on topExecutiveGRCDeveloperArchitectResearcherOpsCurious
- ›Community lists each person onceResearcherExecutive/leaders
- ›FIPS badges in the Migrate catalog now match the certificate recordGRCOpsArchitectExecutiveCertificationMigrate/business
- ›An entropy quiz question shows againResearcherDeveloperArchitect/learn/quiz
- ›Classical VPN mode is now labelled with the key exchange it really runsDeveloperResearcher/playground/vpn-sim/learn/vpn-ssh-pqc
- ›Links from around the site open the right itemExecutiveGRCDeveloperArchitectResearcherOpsCuriousLearn/businessAssess/report/faq
- ›Site search and the PQC Assistant link to the exact itemExecutiveGRCDeveloperArchitectResearcherOpsCurious
- ›Library table view opens the full document panelResearcherGRCLibrary
- ›Old Migrate links from search keep workingOpsMigrate
September 28, 2026
v4.131.1–v4.132.0The Simulation no longer strands you — a wrong answer still costs you, but you can always carry on; play-mode pop-ups close; browser Back behaves; phones get the controls they were missing — and it now includes the hub's newest Learn modules and references. Across the hub, shared links now open exactly the item they point to, on phones too. · The VPN/IPsec & SSH module now explains where pure post-quantum IKEv2 runs into trouble, and why the standard's hybrid route avoids it.
- ›The newest Learn modules are now part of the SimulationGRCArchitectExecutive/simulation
- ›More references in the Simulation's Resources tabArchitectResearcher/simulationAlgorithms
- ›18 new comprehension-check questionsGRCArchitectDeveloper/simulationLearn
- ›Why pure post-quantum IKEv2 is hard over UDPArchitectOpsDeveloper/learn/vpn-ssh-pqc
- ›The Simulation on a phoneExecutiveCurious/simulation
- ›Pilots explains its migration limitExecutiveArchitect/simulation
- ›Industry Landscape inside modules opened in the SimulationArchitect/simulationLearn
- ›Smaller fixesCurious/simulation
- ›A wrong answer is never a dead endExecutiveGRCCurious/simulation
- ›Play-mode pop-ups can be closedExecutiveCurious/simulation
- ›Tip cards no longer cover the boardCurious/simulation
- ›Browser Back closes what you openedExecutiveCurious/simulation
- ›Difficulty can't be switched mid-runExecutiveCurious/simulation
- ›Leaving a played-through run cleans upExecutive/simulation/business
- ›Shared links now open the item they point to — on phones tooExecutiveGRCDeveloperArchitectResearcherOpsCuriousLibrary/patents/leadersComplianceTimelineMigrateAlgorithms
- ›Links no longer disappear behind your filtersExecutiveGRCDeveloperResearcherLibrary/patentsAlgorithmsTimelineThreats/leadersCompliance
- ›Old and mistyped links explain themselvesGRCResearcherLibraryComplianceThreatsMigrate/patents
- ›Compliance landscape no longer empty for readers with a saved regionGRCExecutiveCompliance
- ›Timeline shows every country again on first visitExecutiveGRCResearcherTimeline
- ›Every timeline event can be linkedGRCResearcherTimeline
- ›Product and certificate links open the right entryOpsDeveloperGRCMigrateCompliance
- ›Standards view stays putGRCArchitectCompliance
- ›Search and Assistant links to patents open the patentResearcherGRC/patents
- ›The protocol size section no longer overstates IKEv2 fragmentationArchitect/learn/vpn-ssh-pqc
- ›Two IPsec standards added to the library, and one marked as replacedResearcherArchitectLibrary
- ›The IKE / IPsec row in the Protocol Matrix notes the pure ML-KEM limitArchitectResearcherAlgorithms
September 27, 2026
v4.124.2–v4.131.0The FIPS 140-3 module now explains how NIST is automating validation — algorithms, then entropy, then the module — and what is and is not in production. · A new Learn chapter on the regional schemes built on Common Criteria, NIAP's CNSA 2.0 deadline in the data, a certification refresh, and a much lighter Timeline page. · FIPS 140-3 and PCI now each have their own certification module. · The validation workbench now says exactly what each test proves, runs trusted public test vectors, and publishes its full coverage and known gaps. · French (ANSSI) certificates now carry the product name their own certification report states, and a few certification verdicts are corrected. · Certificates that cover no post-quantum algorithm are now labelled "Classical only", and 40 products have a researched certification verdict. · Every country on the timeline shows its flag again. · Hundreds of product versions and dates are filled in from their own sources, and a batch of outdated or wrong values is fixed. · Fifteen more product claims now say only what their own documents support, and six catalogue entries that were really web-page titles are fixed. · France's post-quantum migration phases are now confirmed from ANSSI's own guidance, and the assistant can quote the source text for a few more references. · Product certifications now show where each product stands on the road to a FIPS 140-3 certificate — algorithms validated, in progress at NIST, or certified — and 27 product verdicts were re-checked against the official NIST records. · The certification Learn module is now three shorter modules: a fundamentals module every learner starts with, and two deep dives you take only for the schemes you need. · Timeline dates checked against their sources: phases whose source gives no end date are now shown as open-ended instead of being hidden, and several milestones move to the years their sources actually state.
- ›How FIPS validation is being automatedGRCDeveloperOps/learn/fips-140-3-certification
- ›The certification fundamentals module now links to all three deep divesGRCCurious/learn/crypto-product-certification
- ›"One criteria, many schemes": the regional schemes built on Common CriteriaGRCArchitectResearcherLearn
- ›Every test result states its evidenceDeveloperGRCResearcherPlaygroundAlgorithms
- ›Coverage matrix and open gaps, publishedGRCArchitectAlgorithms
- ›More NIST and Wycheproof vectorsDeveloperResearcherPlayground
- ›ECDSA signatures checked against NIST byte for byteDeveloperPlayground
- ›Multi-part message signing testedDeveloperPlayground
- ›New draft module: ACVP Lab WorkflowDeveloperGRCLearn
- ›ACVP-format practice toolDeveloperPlayground
- ›See how far the catalogue has progressed toward post-quantum certificationGRCExecutiveOpsCompliance
- ›"In progress" now comes straight from NISTGRCOpsMigrateCompliance
- ›FIPS 140-3 and PCI are now two separate modulesGRCOps/learn/fips-140-3-certification/learn/pci-certification
- ›Old links and saved progress still workCuriousLearn
- ›The FIPS 140-3 and ACVP Lab Workflow modules now link to each otherGRCDeveloper/learn/fips-140-3-certification/learn/acvp-lab-workflow
- ›"Classical only" certificates are labelled, and never counted as post-quantum progressGRCArchitectOpsMigrateCompliance
- ›New catalogue checkDeveloper
- ›Cryptographic Product Certification is now three modules instead of one long one.GRC/learn/crypto-product-certification/learn/fips-pci-certification/learn/cc-eucc-certification
- ›The certification quiz questions now belong to the module that teaches them.GRC/learn/quiz
- ›The Timeline page downloads far lessCuriousDeveloperTimeline
- ›Verify-only algorithm validations are no longer at risk of being droppedResearcherCompliance
- ›The FIPS module now says plainly that P2PE v3.1 is supersededGRC/learn/fips-140-3-certification
- ›"ACVP certificate" wording correctedGRCCuriousLearn
- ›Test vectors correctedResearcherAlgorithms
- ›ANSSI certificates show the right productGRCResearcherCompliance
- ›Three Chainguard builds shown as certifiedGRCOpsMigrate
- ›Two retired duplicate entries no longer claim more than the product they point toGRCMigrate
- ›Utimaco u.trust HSM and IBM z16 Crypto Express 8S show "in NIST's queue"GRCMigrate
- ›Missing country flags restoredCuriousExecutiveGRCTimeline/leaders
- ›A check keeps it that wayDeveloper
- ›France's Phase 2 and Phase 3 are confirmed from ANSSI's own textGRCExecutiveTimeline
- ›The PCI exercise uses distinct example certificate numbersGRCOps/learn/fips-pci-certification
- ›Two learning modules no longer share an ID with another moduleCuriousLearn
- ›27 product certification verdicts corrected against NIST's own recordsGRCOpsDeveloperMigrate
- ›Certificates behind each verdict are now shownGRCDeveloperMigrate
- ›Timeline phases with no stated end date are shown, not hidden.GRCExecutiveTimeline
- ›Canada, France and Singapore timeline years corrected from their sources.GRCExecutiveTimeline
- ›Three standards cross-references pointed at the wrong document.ResearcherGRCLibrary
- ›36 products showed the placeholder "pqc_support" instead of their post-quantum support.OpsGRCDeveloperMigrate
- ›Five official sources added to the libraryResearcherLibrary
- ›NIAP now requires CNSA 2.0 for certified productsGRCExecutiveArchitectComplianceTimelineLibrary
- ›Regional certification records correctedGRCResearcherCompliance
- ›China's QKD standards, Russia's certification schemes and Kazakhstan's trusted-software registry are added or correctedGRCResearcherComplianceLibrary
- ›Certification records refreshedGRCOpsCompliance
- ›French (ANSSI) certificates show ANSSI's own product categoriesGRCCompliance
- ›Certification verdicts researched for 40 productsGRCOpsResearcherMigrate
- ›"Partial" is retiredGRCMigrateCompliance
- ›More certificates linked to the right productGRCArchitectMigrate
- ›Duplicate entries mergedCuriousMigrate
- ›Versions and dates researched for 707 productsOpsArchitectGRCMigrate
- ›Outdated versions updatedOpsMigrate
- ›Wrong values fixedOpsArchitectMigrate
- ›Renamed productsCuriousOpsMigrate
- ›Three entries retiredGRCMigrate
- ›Stronger evidenceGRCResearcherMigrate
- ›15 product claims corrected after a full read of their documentsArchitectOpsGRCMigrate
- ›Six entries named after a web page, not a product, are fixedArchitectOpsCuriousMigrate
- ›Migration phasesOpsArchitectMigrate
- ›Evidence records for 10 productsGRCResearcherMigrate
- ›The assistant can quote the source for more referencesResearcherGRC/
September 26, 2026
v4.123.1–v4.124.1A full check of every migration-catalogue product against its own cited document: where a product listed specific post-quantum algorithms its source never mentions, the listing now says only what the source actually supports. · A new Learn module on how cryptographic products get certified, and a Migrate catalogue that now tells a certificate apart from the algorithm validation that comes before it.
- ›New Learn module: Cryptographic Product Certification.GRCArchitectOps/learn/crypto-product-certification
- ›Learn modules can now be followed by path.CuriousLearn
- ›The Migrate catalogue now follows the FIPS 140-3 track instead of treating every validation as a certification.GRCOpsArchitectMigrate
- ›Certification badges say CAVP, and never call an algorithm validation a certificate.GRCDeveloperMigrate
- ›A product page now says when a certificate belongs to something inside the product.OpsArchitectMigrate
- ›Correction to the 4.123.2 note below.Ops
- ›98 products named post-quantum algorithms their own source document never mentions.OpsGRCDeveloperMigrate
- ›17 products claimed an algorithm validation that isn't theirs.GRCOpsMigrateCompliance
- ›3 more duplicate products retired, and one renamed.OpsMigrate
- ›41 algorithm validations were missing from the Compliance and Migrate data, and are back.GRCResearcherComplianceMigrate
- ›Several products were linked to the wrong company's certificate, or missed their own.GRCOpsMigrate
- ›Ten Learn modules stated certification facts they could not support, and now match the scheme records.GRCArchitectLearn
- ›Searching for a product's old name now finds the product again.OpsGRCMigrate
- ›13 products were listed twice under different names, and the duplicates are now retired.OpsGRCMigrate
- ›Two products that look like duplicates are deliberately kept as separate rows.OpsMigrate
- ›A sweep of every catalogue column fixed 245 malformed values.OpsGRCMigrate
- ›23 products showed a placeholder where a version number should be, and now show nothing.OpsDeveloperMigrate
- ›The HSM learning module no longer calls an algorithm validation an "ACVP certificate".DeveloperOpsGRCLearn
- ›One product listed twice is retired.OpsMigrate
September 25, 2026
v4.117.0–v4.123.0Every product in the migration catalogue was re-checked against its own evidence document, and anything a document does not actually say has been corrected or removed — including versions, dates and post-quantum claims. · The Timeline's review backlog is cleared: 19 rows that were already fully sourced but sitting unpublished are now live, taking the public Timeline from 163 events to 182, and the four still held back are held for a stated reason rather than by neglect. · Every certification record now comes straight from its official source — NIST for FIPS 140-3 and CAVP, the Common Criteria Portal, ANSSI and ENISA — and anything a source does not back is gone. · The 122 rows where the Timeline's two reviewers disagreed on 25 September were resolved by a closer read of what each one actually quoted from the source document. · Every entry on the Timeline was checked against its own source document by two independent reviewers, and the Timeline now shows only government, regulator and standards-body milestones — with honest labels for what was checked and when. · Every threat on the Threats page now says only what its cited document says — 71 threats are published, each with its main claims checked against the source, and 49 more are held back until a document that backs them is found.
- ›Each product now says what kind of thing it is.OpsArchitectMigrate
- ›The catalogue says plainly that it is curated, not exhaustive.ExecutiveGRCMigrate
- ›19 Timeline events are now public.GRCResearcherTimeline
- ›The IETF hybrid key-exchange row now tracks a published standard.DeveloperResearcherTimeline
- ›New milestones: the G7 Call to Action and the HAWK withdrawal.ResearcherExecutiveTimeline
- ›7 products now use the name their vendor actually uses.OpsMigrate
- ›Quantum key distribution and quantum random number generators are described for what they are.ResearcherGRCMigrate
- ›Algorithm validations are labelled "CAVP" rather than "ACVP" on 91 products.DeveloperResearcherMigrate
- ›Two published dates corrected.GRCResearcherTimeline
- ›Two QKD rows restored.GRCTimeline
- ›Japan's PQC-migration row re-sourced and re-dated.GRCResearcherTimeline
- ›CISA's EO 14306 deadline now cites the actual order.GRCTimeline
- ›The G7 financial-sector deadline now cites the document that states it.GRCTimeline
- ›A UAE row is honest about what's confirmed and what's self-reported.ResearcherTimeline
- ›Two mis-scoped rows corrected.GRCTimeline
- ›Brazil's ICP-Brasil certificate-standards row is published.GRCTimeline
- ›Algorithm validations are labelled "NIST CAVP", not "ACVP".DeveloperResearcherCompliance
- ›French CSPN certifications have their own label.GRCCompliance
- ›Historical and archived certificates are hidden unless you ask for them.GRCOpsCompliance
- ›The Timeline drops 16 more entries that aren't post-quantum milestones.GRCResearcherTimeline
- ›14 more entries are confirmed and now shown.GRCResearcherTimeline
- ›Germany and the UK's country deadlines are held back pending stronger evidence.ExecutiveGRCTimelineAssess/report
- ›26 field corrections across Description, Title, OrgFullName, binding force and dates.GRCResearcherTimeline
- ›The Timeline now covers government, regulator and standards milestones only.ExecutiveGRCArchitectTimeline
- ›Entries are shown only once they have been reviewed.GRCResearcherTimeline
- ›Country deadlines in Assess, Report and the Simulation come only from reviewed entries, labelled binding or guidance.ExecutiveGRCAssess/report
- ›Dates on Timeline cards say what they are.CuriousGRCTimeline
- ›Authority links read correctly.GRCTimeline
- ›The Threats page shows fewer threats, and every one it shows is backed by its source.GRCExecutiveResearcherThreats
- ›The Evidence panel explains where each claim comes from.GRCResearcherThreats
- ›One quantum-computer arrival window everywhere.ExecutiveGRCThreats
- ›Threat classes and industry labels are reviewed, not inferred.GRCThreats
- ›Criticality left blank reads "Unrated".GRCThreats
- ›47 products were described using the wrong company's document, and now cite their own.OpsGRCArchitectMigrate
- ›81 products had a post-quantum status their evidence didn't support.OpsGRCMigrateAssess
- ›27 products no longer carry a "Verified" badge they hadn't earned.GRCOpsMigrate
- ›Version numbers that no document states are gone, and 64 were wrong.OpsDeveloperMigrate
- ›Dates on 640 entries were unsupported or wrong.OpsGRCMigrate
- ›16 entries that were not products have been retired.GRCMigrate
- ›Taiwan's row was invisible even when published.GRCTimeline
- ›Three US rows were resource pages, not events.GRCTimeline
- ›A duplicate Malaysia row is retired.GRCTimeline
- ›Two overstated fields corrected.GRCTimeline
- ›A DoD row was colliding with its own retired predecessor.Researcher
- ›The UK's 2035 row had no source date.ResearcherTimeline
- ›562 records labelled "FIPS 140-3 Active" were really FIPS 140-2 certificates, and they are gone.GRCOpsExecutiveComplianceMigrate
- ›Post-quantum algorithms on FIPS records now come only from NIST's Approved Algorithms list.GRCResearcherOpsCompliance
- ›Product pages no longer show validations that do not apply to the product.OpsGRCMigrate
- ›"Live certification records" and "refreshed daily" were not true, and are gone.ExecutiveGRCCompliance/business
- ›A regulatory deadline in the Learn modules no longer borrows another policy's year.DeveloperGRCLearn
- ›Threat links work.CuriousGRCThreats
- ›The Shor risk tier is graded from the cryptography actually at risk.ResearcherThreats
- ›Detection & Response tabs show the real SOC use cases and playbooks.OpsThreats
- ›The Threats page fits a laptop screen, and short searches match at the start of words.CuriousThreats
- ›Phones: the first-run notice sits below the role picker, with larger tap targets.Curious
- ›Pages that don't need the in-browser crypto engines no longer reload on first visit.Curious
- ›Timeline 09252026_r7 → r9:GRCResearcherTimeline
- ›Common Criteria, ANSSI and EUCC records were re-checked against their issuers.GRCCompliance
- ›Timeline 09252026_r6:GRCResearcherTimeline
- ›Timeline 09252026_r5:ResearcherGRCTimeline
- ›Threat sources point at the documents themselves.ResearcherGRCThreats
- ›The site search and assistant only know published threats.CuriousThreats
September 23, 2026
v4.116.0The in-browser crypto engines carry the latest upstream security fixes, the About page's software list is accurate again, and a compliance chart stops risking a misleading tooltip.
- ›The in-browser HSM and OpenSSL engines were rebuilt from current source, picking up upstream crypto-library fixes.DeveloperResearcherPlaygroundOpenSSL Studio
- ›The About page's software list matches what the site actually ships.DeveloperGRC/about
- ›A compliance chart could have printed "Invalid Date" into its tooltip where a month should be.GRCExecutiveCompliance
- ›Anne Dames (IBM) joins the PQC Community roster.ExecutiveCurious/leaders
- ›Ten timeline documents, six compliance-landscape documents and twenty-one named threat rows gained enriched detail.GRCResearcherTimelineComplianceThreats
- ›CSWP.39 pillar tagging was re-derived through the fixed reader.GRCCompliance
September 22, 2026
v4.115.0The in-browser HSM and OpenSSL simulators run today's crypto engine again, including Classic McEliece.
- ›The C++ HSM engine's in-browser build was silently broken for Classic McEliece.DeveloperResearcherPlayground
- ›The Rust and OpenSSL engines that power the PKCS#11 and OpenSSL Studio playgrounds are rebuilt from current sourceDeveloperResearcherPlayground
September 21, 2026
v4.114.0Workshop steps can be jumped to again, the About page's software list is always accurate, and the site's own checks now catch problems before they reach you.
- ›The site's automated checks are trustworthy againDeveloperOps/about
- ›Workshop step chips work againDeveloperArchitectLearn
- ›The About page lists the exact versions this site is built fromResearcherDeveloper/about
- ›The chat side panel opens reliablyCurious/
September 20, 2026
v4.110.0–v4.113.1The last six figures the accuracy pass left open on the pages now have their sources or are gone. · The text of every routed page is now checked the way the Learn modules' text has been: the accuracy instrument read the components behind the pages for the first time, and the figures it found there are either backed by a Library document, worked out in the sentence, or gone. · Nineteen figures that no document we can capture actually states are gone from the pages; the sentences now say what the source reports without quoting numbers we cannot check. · The figures on the Learn modules and business tools now say where they come from: sizes are written the way the standards state them, worked examples say they are worked examples, the site's own estimates say so, and eleven more documents joined the Library so that the facts they back can be checked against them. · The figures on the Learn modules now point at the documents that state them: 79 documents joined the Library, 40 modules cite them from their References tab, and the site's own estimates say so beside the numbers.
- ›Seventy-nine Library documents behind figures the modules stateResearcherArchitectDeveloperGRCLibraryLearn
- ›Citations from 40 modules to those documentsResearcherCuriousLearn
- ›"Our estimate" beside modelled figuresExecutiveOpsCurious/learn/merkle-tree-certs/learn/aerospace-pqc/learn/automotive-pqc/learn/confidential-computing/playground/hsm-capacity
- ›Sources named for the algorithm-status datesResearcherAlgorithms/about
- ›IBM Condor's 1,121 qubitsExecutiveThreats
- ›TPM playground errata pointer removedDeveloperPlayground
- ›Page figures name their sourcesResearcherExecutiveThreats/faq/aboutCompliance
- ›Three figures correctedDeveloperLearnPlayground
- ›Unverifiable numbers removed or labelledCuriousThreats/faq
- ›Unverifiable numbers removedResearcherGRCLearn/business
- ›Sizes and dates written the way their documents state themDeveloperArchitectResearcherLearn
- ›Worked examples, scenarios and the site's own estimates are labelledCuriousExecutiveLearn/business
- ›Three figures correctedDeveloperLearn
- ›Unverifiable numbers softenedGRCLearn
- ›Two Library rows added, two correctedResearcherLibrary
- ›Twelve Library documents added, three recapturedResearcherLibrary
- ›Eleven Library documents addedResearcherLibrary
September 19, 2026
v4.93.0–v4.109.0Every figure on the Learn modules, tools and pages was checked word for word against the standards they cite; three signature-size figures that disagreed with the standard are corrected. · A "Try it" question under a reference page now tests something worth knowing, or the page has none. · Sixty-two Learn workshops now run on a phone; a step-by-step walk of every workshop at phone width found the four that needed a fix, and three stay on the laptop banner until walked by hand. · Every page, module and tool now opens the same way — what it is for, one worked run, a line for your role — and ends with a question you can answer from what you just used. · Fourteen role-board options now also list the Learn module that argues their case, so fifteen modules that only the Learn catalogue reached have a second front door. · Every Learn workshop step that takes input now ends with a question you can answer from that step, and the Crypto Dev APIs decision wizard no longer runs out of answers. · Every top-level page was walked end to end on a laptop and a phone; the handful of things the walk found are put right. · Every Learn module's workshop was walked end to end on a laptop; a step that crashed for everyone is fixed, and the small things the walk found are put right. · Every Command Center tool was walked end to end on a laptop and a phone, and each now ends with a question you can answer by using it. · Every Playground tool was walked end to end on a laptop and a phone; what clipped or ran off the screen now wraps, and each tool ends with a question you can answer by using it. · Every module and tool now says, for your role, what to do with it — written from the item's real steps and controls. · Every module now offers its quiz before you finish it, disabled buttons say why, and the small labels inside workshop steps are readable again. · Sliders, inputs and icon buttons inside workshop steps now say what they are to assistive technology. · Reference pages now show what is related to them, Industry Landscape use cases reach the module that teaches their protocol, and Command Center tools list two Learn modules for their phase. · Every page, module and tool now ends with a next step, tools show what is related to them, and the Playground and Command Center put a role's own tools first. · Module workshops are tidier — one step navigator, the right step count, the intro folded away while you work — and a handful of controls that clipped or overlapped now fit. · Returning visitors see what changed since they were last here, the Curious tour asks before it opens, and the home page no longer opens on a "WIP" badge. · Eleven reference pages now open with one line that says what the page means for your role.
- ›Workshops on your phone for 53 more modulesDeveloperArchitectOpsExecutiveGRCResearcherCuriousLearn
- ›"Start here" on 27 more Learn modulesCuriousDeveloperArchitectOpsExecutiveLearn
- ›"What you will do" and a worked example on 25 more Playground toolsDeveloperArchitectResearcherOpsPlayground
- ›A worked example on 16 more Command Center toolsExecutiveGRCArchitect/business
- ›"What this means for you" on 15 more pagesExecutiveGRCDeveloperArchitectResearcherOpsCurious/reportAssessLearnAlgorithmsMigrateCompliance/businessTimelineLibraryPlaygroundOpenSSL StudioThreats
- ›A "Try it" question under 19 pagesCuriousGRC/reportAssess/AlgorithmsComplianceMigrate/businessTimelineLibraryPlaygroundOpenSSL StudioThreats/patents/leaders/explore/revisions/faq
- ›66 more workshop-step questionsDeveloperArchitectOpsResearcherGRCLearn
- ›More modules reachable from the role boardsExecutiveDeveloperArchitectOpsResearcher/Learn
- ›A question under every workshop step that takes inputDeveloperArchitectOpsExecutiveGRCLearn
- ›"Try it" under every Command Center toolExecutiveGRCArchitectDeveloper/business
- ›"Try it" under every Playground toolDeveloperArchitectResearcherCuriousPlayground
- ›"For your role" on every Learn module, Playground tool and Command Center toolExecutiveGRCDeveloperArchitectResearcherOpsCuriousLearnPlayground/business
- ›"Check your understanding" on every module with a quizCuriousDeveloperGRCLearn
- ›"Try it" under thirteen workshop stepsCuriousDeveloperGRC/learn/pqc-101/learn/quantum-threats/learn/cbom
- ›A visible reason beside seven disabled buttonsDeveloperOps/playground/interactive/learn/hsm-pqc/learn/kms-pqc/learn/entropy-randomness/learn/pki-workshop/playground/vpn-sim/playground/pqc-ssh-sim
- ›Related content on every reference pageCuriousResearcherGRC/AlgorithmsComplianceMigrateTimelineLibrary/patents/leaders
- ›Industry Landscape rows reach the module that teaches their protocolArchitectDeveloperOpsLearnAlgorithms
- ›A "Next step" at the end of every page, module and toolCuriousExecutiveDeveloperArchitectOpsGRCResearcherLearnPlayground/business
- ›Related content on every Playground and Command Center toolDeveloperArchitectOpsPlayground/business
- ›"Tools for this role" on every role boardExecutiveGRCDeveloperArchitectOpsResearcherCurious/
- ›Playground picks per roleDeveloperArchitectResearcherOpsCuriousPlayground
- ›"Reviewed data updates since your last visit" on the home pageExecutiveGRCResearcher//revisions
- ›"What this means for you" on eleven reference pagesExecutiveGRCDeveloperArchitectResearcherOpsCurious//patents/leaders/explore/revisions/changelog/faq/about/editorial-independence/sponsor/terms
- ›Command Center tools list up to two Learn modules for their phaseExecutiveGRC/business
- ›Command Center tools are ordered for your roleExecutiveGRCArchitectDeveloper/business/tools
- ›One step navigator per workshopDeveloperCuriousLearn
- ›The module intro folds away on the Workshop tabDeveloperOpsLearn
- ›The Curious tour offers itself instead of openingCurious/
- ›No more "WIP" badge on the home page bannerCuriousExecutive/
- ›LMS signature size now matches RFC 8554 in every moduleDeveloperArchitectOps/learn/aerospace-pqc/learn/automotive-pqc
- ›SLH-DSA signature range in the TLS certificate inspectorDeveloperCurious/learn/tls-basics
- ›Page "Try it" questions ask about post-quantum cryptography, not about the page's own controlsCuriousGRCExecutiveDeveloperArchitectThreatsOpenSSL Studio/faq/businessCompliance
- ›Four workshops that ran past a phone screenCuriousDeveloper/learn/pqc-101/learn/automotive-pqc/learn/sbom/learn/secure-boot-pqc
- ›The KMS key-policy lab starts with valid JSONDeveloperOps/learn/kms-pqc
- ›Four tool descriptions now match the toolDeveloperGRC/playground/cacp-kmip/playground/hybrid-certs/playground/pqc-ssh-sim/business/tools/risk-register
- ›The Crypto Dev APIs decision wizard answers every branchDeveloper/learn/crypto-dev-apis
- ›The Timeline's filter bar no longer runs off the right edgeGRCExecutiveTimeline
- ›FAQ questions wrap on phonesCurious/faq
- ›Changelog entries with long technical names wrap on phonesDeveloper/changelog
- ›The Compliance table's PQC filter has a name for assistive technologyGRCCompliance
- ›The Network Security module's Vendor Matrix step no longer crashesOpsArchitect/learn/network-security-pqc
- ›PQC 101 no longer logs an error on every loadCurious/learn/pqc-101
- ›Option cards that cut their text offDeveloperArchitect/learn/5g-security/learn/automotive-pqc/learn/code-signing
- ›Inputs and buttons that had no name for assistive technologyResearcherDeveloper/learn/aerospace-pqc/learn/api-security-jwt/learn/kms-pqc/learn/pqc-testing-validation/learn/emv-payment-pqc/learn/vpn-ssh-pqc
- ›Readable and explainedCuriousOps/learn/quantum-threats/learn/pki-enrollment-protocols
- ›The KPI persona lens fits a phoneExecutiveGRC/business/tools/kpi-dashboard/business/tools/kpi-tracker
- ›Supply Chain Risk Matrix bars stay inside their trackGRC/business/tools/supply-chain-matrix
- ›Long headers and step titles wrap on a phoneDeveloper/playground/email-signing/playground/api-security-jwt/playground/vpn-sim/playground/pqc-ssh-sim/playground/mls-group-messaging/playground/hybrid-certs
- ›A long selected value no longer widens a drop-down past its cellOps/playground/pki-enrollment
- ›Tab bars used as switches no longer point at a panel that does not existDeveloperKMIP 3.0 Playground/playground/cacp-kmip
- ›The OpenSSL Studio file manager's buttons keep their names on a phoneDeveloperOpenSSL Studio/playground/openssl-studio
- ›The phone changelog's back arrow has a nameCurious/changelog
- ›Small labels inside workshop steps are readable againArchitectOpsKMIP 3.0 PlaygroundMigrateTimeline/learn/confidential-computing/learn/automotive-pqc/learn/digital-id/learn/web-gateway-pqc
- ›Fifteen workshop sliders and inputs now carry a nameOpsDeveloper/learn/automotive-pqc/learn/energy-utilities-pqc/learn/iot-ot-pqc/learn/ai-security-pqc/learn/verification-closure/playground/vpn-sim
- ›Nine icon-only buttons now have a nameDeveloper/learn/crypto-dev-apis/learn/iam-pqc/learn/platform-eng-pqc/learn/healthcare-pqc
- ›The web gateway vendor picker is one control, not twoOps/learn/web-gateway-pqc
- ›Ten modules now declare every workshop step they renderDeveloperArchitectOpsLearn
- ›Selected values in drop-downs are no longer cut shortCuriousDeveloperLearnPlayground/business
- ›"First Steps" is awarded for a real step, not for opening the Workshop tabCuriousLearn
- ›Overlapping option buttons in two workshopsGRCDeveloper/learn/standards-bodies/learn/iot-ot-pqc
- ›Architecture Diagram inputs fit their content and say what they areArchitect/business/tools/crypto-architecture-diagram
- ›"~380 min for a first look" on ExploreArchitectCurious/explore
- ›Quiz: the EU PQC roadmap is dated June 2025GRCExecutive/learn/quiz
September 18, 2026
v4.87.0–v4.92.0Thirty-eight modules now tell you where to start: one real workshop step, what a first run of it gives you, and a button that opens it. · Every tool now opens with a worked example, so you can picture a run of it before the form. · Every page now passes the automated accessibility check with no serious or moderate findings. · Screen-reader outlines are in order on the tool, module and reference pages, and four more guided workshops run on a phone. · The 710 patents in scope were re-read from their cached documents and their summaries and claim descriptions rewritten from that text. · Every page reads better for screen-reader and keyboard users, the learning paths and role boards reach more of the site, and the Crypto Lab opens on a different set of tools for each role. · The Industry Landscape shows which post-quantum mechanism replaces which classical one, search results stop mixing crosswalk rows into the compliance frameworks, the site stays up for visitors in the minutes after a release, search engines can index every page, and a night of evidence work re-addresses 51 organisation sources and prunes copies that were never the cited document.
- ›A "Start here" line on 38 modulesCuriousDeveloperArchitectExecutiveLearn
- ›A worked example on all 21 business toolsExecutiveGRCOps/business
- ›An intro strip on eight Playground toolsDeveloperResearcherArchitectPlayground
- ›Four more guided workshops run on a phoneExecutiveGRCResearcherDeveloperLearn
- ›Every role board now opens a Learn moduleExecutiveGRCArchitectResearcherCurious/Learn
- ›The Crypto Lab "Start here" picks differ by roleDeveloperArchitectResearcherOpsCuriousPlayground
- ›A module lists every Playground tool built for itDeveloperOpsResearcherLearn
- ›Researchers can browse 43 more modules by algorithm and standardResearcherArchitectLearn
- ›Five guided workshops now run on a phoneExecutiveGRCArchitectCuriousLearn
- ›SOC detection and automotive modules reach the roles that need themArchitectGRCOpsLearn
- ›The Industry Landscape now says which post-quantum mechanism replaces which classical oneArchitectOpsExecutiveAlgorithms
- ›Architecture Quantum Impact declares all five of its workshop stepsArchitect/learn/arch-quantum-impact
- ›Headings read in order on the remaining 45 module, tool and business-tool pagesCuriousDeveloperExecutiveLearnPlayground/business
- ›The Playground tool grid no longer sits inside a second main regionCuriousPlayground
- ›Headings read in order on 40 tool, module and reference pagesCuriousDeveloperPlayground/businessLearnLibrary/leadersAlgorithms
- ›The side navigation rail and the simulation start screen are labelled landmarksCurious/simulationTimeline
- ›Small labels are readable again on 40 pagesCuriousDeveloperLearnPlaygroundAlgorithms/about
- ›Every page has a level-one heading, on desktop and on the phoneCurious/businessPlayground/navigate/report
- ›Wide tables can be scrolled with the keyboardDeveloperLearnPlayground
- ›Links inside paragraphs are underlinedCuriousLearn/about/terms
- ›Opening /embed directly shows a plain explanation instead of an errorDeveloper/embed
- ›Six country flags on the community directory were missingCurious/leaders
- ›The VPN and SSH comparison panels use valid list markup and the HSM learn tabs are a proper tab listDeveloper/playground/vpn-sim/playground/pqc-ssh-simPKCS#11 Playground
- ›Search results no longer show crosswalk rows as compliance frameworksGRCCurious/Compliance
- ›The site keeps working for visitors during the minutes after a releaseOpsCurious/
- ›Search engines can index every pageCuriousExecutive/navigate/
- ›Patent summaries and claim descriptions now come from the cached patent textResearcherArchitect/patents
- ›51 organisation sources re-addressed after a web-search passResearcherGRC/aboutLibrary
- ›250 registry concepts whose source row had been deprecated are resolvedGRCResearcherComplianceLearn
- ›Every glossary term now links to a Learn module that actually uses itCuriousLearn
- ›20 leader references added and 9 ANSSI certification reports re-addressedResearcherGRC/leadersCompliance
- ›Copies that were never the cited document no longer back a rowGRCArchitectLibraryComplianceMigrate
September 17, 2026
v4.86.0–v4.86.1The Navigate graph becomes readable when you zoom in, vendors can list more than one roadmap announcement, the Patents page stops carrying 1,133 patents it never showed, and a day of evidence work corrects certification, catalog, and reference data against the documents they cite.
- ›The Navigate graph stays readable when you zoom inCuriousExecutiveDeveloperArchitectResearcher/navigate
- ›Every Navigate category now appears in the overview, and each can be narrowed to its sub-categoriesCuriousResearcher/navigate
- ›A vendor can now have more than one active roadmap announcementArchitectOpsExecutiveMigrate
- ›The Patents page's population is now honest: 1,133 patents outside the post-quantum scope are retiredResearcherExecutive/patents
- ›8 quiz questions and 2 glossary entries corrected for accuracy against live NIST/IETF/OASIS sourcesCuriousResearcherLearn
- ›3 timeline entries correctedGRCResearcherTimeline
- ›Learn, quiz, glossary, and Playground references now resolve to the documents they nameDeveloperCuriousLearnPlayground
- ›Nearly every patent on the Patents page now has its source document cachedResearcherExecutive/patents
- ›Cloudflare's post-quantum DNSSEC announcement now has an archived copyArchitectOpsMigrate
- ›33 FIPS 140-3 certifications' post-quantum coverage corrected to what their own Security Policy saysGRCOpsArchitectCompliance
- ›11 Migrate catalog proofs now point at the publisher's actual document instead of a landing or empty pageArchitectOpsMigrate
- ›545 concept-crosswalk links whose quoted evidence is not in the cited document are marked low-confidenceGRCResearcherCompliance
- ›Vendor identifiers cleaned upGRCExecutiveMigrate
- ›Library and Community references brought up to dateResearcherLibrary/about
September 13, 2026
v4.84.0–v4.85.0- ›A new Learn module: DNSSEC & Post-Quantum SignaturesDeveloperArchitectResearcher/learn/dnssec-pqc
- ›3 new hardware certifications and 2 new products in the Migration CatalogArchitectResearcherMigrate
- ›6 new industry threat entriesGRCExecutiveThreats
- ›A new compliance requirement: Executive Order 14306's TLS 1.3 deadline for U.S. federal agenciesGRCOpsCompliance
- ›The Simulation's closing debrief and usage analytics now show what kind of run you actually completedExecutiveGRC/simulation
- ›All 64 Learn-module posters replaced with corrected, verified artworkCuriousDeveloperLearn
- ›The Migration Catalog's search box now actually finds products, not just categoriesArchitectResearcherDeveloperMigrate
- ›A routing-security entry named the wrong classical algorithmResearcher/industry
- ›The KMIP Control Plane playground now uses the correct wire format for object identifiersDeveloperOpsPlayground
- ›The Protocol Support matrix's DNSSEC row now reflects Cloudflare's real pilotArchitectResearcherAlgorithms
- ›Qinsight Atlas's catalog entry is now verifiedArchitectResearcherMigrate
- ›Daniel Speciale (Founder, Qinsight) added to LeadersResearcher/leaders
September 9, 2026
v4.83.0- ›Every migration phase now has a complete maturity ladder, with no "open a page" shortcutsExecutiveGRC/simulation
- ›The phone version of the Simulation now has Progress and Resources viewsExecutiveCurious/simulation
- ›Each closing debrief is now personalized to your seatExecutiveGRC/simulation
- ›Phases that hadn't started were mislabeled "locked"Curious/simulation
September 8, 2026
v4.82.1- ›Several KMIP Control Plane operations now work correctlyDeveloperArchitectPlayground
- ›The KMIP Control Plane's conformance/corpus-replay check now passesDeveloperPlayground
- ›The PKCS#11 HSM Playground reflects the latest engine fixes, on both enginesDeveloperOpsPlayground
- ›Cloudflare's post-quantum algorithm data is restoredArchitectResearcherMigrate
September 7, 2026
v4.81.0–v4.82.0The combined "Executive/GRC" role is now two roles: **Executive / Business Leader** for funding, sponsorship and oversight, and **GRC / Risk & Compliance** for tracing obligations to their source, assessing gaps, and recording evidence. If you were an Executive before this release, nothing changes automatically — a one-time notice lets you keep Executive or switch to GRC, and your saved progress, reports and business-tool work carry over either way. · Almost every fact on the site can now be traced to a document you can open — evidence coverage went from 85.5% to 99.2%, and around 310 missing source documents were recovered and checked.
- ›GRC / Risk & Compliance is a new, seventh roleGRC/
- ›A one-time notice for existing Executive users explains the splitExecutive/
- ›Executive is now narrower and faster to startExecutiveLearn
- ›Shared reports and business tools now recognize GRCExecutiveGRC/report/business
- ›Every piece of evidence is now checked before it is acceptedArchitectResearcherComplianceLibraryMigrate
- ›The mobile Compliance view now honors a direct ?tab= linkGRCExecutiveCompliance
- ›A page that says "no roadmap published" is no longer treated as missing informationOpsResearcherMigrate
- ›Nearly every catalogue entry now has a source document behind itExecutiveArchitectResearcherOpsComplianceTimelineLibraryMigrateThreats
- ›Four compliance entries now link to the actual document instead of a company's front pageExecutiveArchitectCompliance
- ›Standards that cost money to read now show a free source that covers the same groundResearcherArchitectLibraryCompliance
- ›An industry entry was reading the wrong file for a 3GPP specificationDeveloperOpsThreats
September 4, 2026
v4.77.0–v4.80.0A global accuracy and consistency pass across all six role-based home boards, closing out the 2026-09-03 review with over 50 individual fixes plus two new pieces of user-visible behavior — plus a smaller Algorithms page default-filter change. · Two correctness fixes in the in-browser HSM engine, found and fixed on the Rust engine used across the PKCS#11 workshop, HPKE demos, and CACP policy sandbox.
- ›Role-home boards that reference a specific workshop now show a real link to itExecutiveDeveloperArchitectResearcherOpsCurious/
- ›Chip and CTA clicks on role-home boards are now trackedExecutiveDeveloperArchitectResearcherOpsCurious/
- ›The Algorithms page now opens on "NIST picks" by defaultDeveloperArchitectResearcherOpsExecutiveCuriousAlgorithms
- ›Navigate's force graph now includes vendor nodes, with an auto-adapt density modeExecutiveDeveloperArchitectResearcherCurious/navigate
- ›The Navigate graph's filter panel now stays out of the way until you need itExecutiveDeveloperArchitectResearcherOpsCurious/navigate
- ›Dozens of factual and overstated claims corrected across all six role-home boardsExecutiveDeveloperArchitectResearcherOpsCurious/
- ›Dead-end and mismatched links on role-home boards now go where their own text says they goExecutiveDeveloperArchitectResearcherCurious/
- ›A role-home board's hero badge now shows your actual selected region and industryExecutiveDeveloperArchitectResearcherOpsCurious/
- ›The curious persona's "preview locked" notice no longer appears on pages it already has access toCurious/PlaygroundLearn
- ›The example report now renders under your own roleExecutiveOps/
- ›A node's detail panel no longer overflows with very long connection listsExecutiveDeveloperArchitectResearcherCurious/navigate
- ›Protocol Matrix library chips now link to the right place in the Migrate CatalogDeveloperArchitectAlgorithms
- ›A rare but real failure in HPKE/ECDH key-derivation demos is fixedDeveloperResearcherPlayground
- ›Nine XMSS stateful-signature parameter sets in the PKCS#11 workshop now actually workDeveloperResearcherPlayground
- ›PQC Community leaders page refreshedExecutiveDeveloperResearcherCurious/leaders
September 2, 2026
v4.75.0–v4.76.0A same-day follow-up to the PKCS#11/KMIP workshop redesign: a live production bug fixed, all five vendored HSM engines refreshed, four new real known-answer-test templates, and a handful of small workshop fixes. · The PKCS#11 and KMIP workshops were reorganized around how people actually use them — Learn, Operate/Build, and Inspect are now top-level, not buried two tabs deep — plus a compliance chart and a broad library/timeline/compliance data refresh.
- ›Four new real, standards-verified test templates in the PKCS#11 Developer tabDeveloperResearcherPlayground
- ›The PKCS#11 shim gained new standards-accurate building blocksDeveloperPlayground
- ›KMIP's Batch view can now pin a step to a specific stored keyDeveloperPlayground
- ›All five vendored HSM engine bundles (SoftHSM C++, Rust, KMIP, OpenSSL-PKCS#11, StrongSwan) refreshed to their latest sourceDeveloperPlayground
- ›The PKCS#11 HSM workshop is now four tabs — Learn, Operate, Build, Inspect — instead of twelveDeveloperResearcherPlayground
- ›One shared call log and key inventory for the whole PKCS#11 workshopDeveloperPlayground
- ›PKCS#11 lessons can now jump you straight to the real control that just ranDeveloperResearcherPlayground
- ›Stateful signature keys (XMSS/LMS) now show their real remaining-signature countDeveloperResearcherPlayground
- ›Sign & Verify is now a clean 4-way switch — ML-DSA, SLH-DSA, Classical, StatefulDeveloperPlayground
- ›ACVP known-answer tests and PKCS#11 v3.2 conformance checks now live inside the Build tab's workbenchDeveloperResearcherPlayground
- ›The KMIP control plane is now six tabs — Learn, Policy, Operate, Inspect, Dev, Migration Estate — instead of four, with the busiest ones no longer nested two levels deepDeveloperResearcherPlayground
- ›KMIP's policy engine gained a Scenarios viewDeveloperPlayground
- ›Compliance now shows a monthly PQC certification adoption trend chartExecutiveOpsCompliance
- ›KmipPlaygroundView split into smaller, focused componentsDeveloper
- ›KMIP's raw YAML view and the "not yet implemented" operations list are now Expert-mode onlyDeveloperPlayground
- ›The KMIP workshop's crypto-agility explainer now appears on the Learn tab for every visitor in Guided modeCuriousDeveloperExecutivePlayground
- ›A real bug in production: some HSM workshop lessons could fail with a cryptic PKCS#11 errorDeveloperResearcherLearnPlayground
- ›The PKCS#11 workshop's KEM panel now honors a lesson's requested algorithmDeveloperPlayground
- ›A wrong HIPAA citation in the Learn library was misattributed to the wrong CFR subsectionResearcherOpsLibrary
- ›9 Learn-module citations pointed at library rows that had been incorrectly deprecatedResearcherLearn
- ›Two vendor PQC roadmap rows carried a mixed-up URL and an undetected duplicateResearcherMigrate
- ›A stale timeline manifest label was silently blocking Germany/BSI milestone evidence from resolvingResearcherTimeline
- ›Two Learn modules had a Tools & Products tab that looked broken (empty findings) and one had an unwired Exercises tabDeveloperResearcherLearn
- ›Broad evidence refresh across Library, Timeline, and Compliance LandscapeResearcherLibraryTimelineCompliance
- ›Vendor roadmaps, migrate catalog, and trusted sources enrichmentResearcherMigrateLibrary
- ›CVE data refreshedResearcherDeveloper
- ›3 IETF protocol-matrix correctionsResearcherAlgorithms
September 1, 2026
v4.73.0–v4.74.0- ›The PKCS#11 pipeline builder now runs 3 more real NIST ACVP known-answer tests as editable, runnable pipeline stepsDeveloperResearcherPlayground
- ›The KMIP 3.0 Corpus Replay tab folded into the pipeline builder's own paletteDeveloperPlayground
- ›A hands-on HPKE (Hybrid Public Key Encryption) workshop joins the Hybrid Cryptography learning moduleDeveloperResearcherLearn
- ›Keystore items now show their real PKCS#11 engine attributes when inspectedDeveloperPlayground
- ›PKCS#11 v3.2 Mechanism Coverage grew to include hybrid-KEM building blocks, classical asymmetric variants, symmetric/AEAD mechanisms, and PQC deterministic-seed keygen (CKA_SEED)DeveloperResearcherPlayground
- ›The Navigate graph's category, sub-category, and node labels are now clickableCuriousExecutive/navigate
- ›The KMIP Developer plane now lives inside KMIP 3.0's own Dev sub-tab, and Corpus Replay gained a Builder/Code splitDeveloperPlayground
- ›The PKCS#11 Developer tab's "Pipeline" sub-tab is now called "Standard"DeveloperPlayground
- ›A PKCS#11 pipeline builder param could show a false "nothing compatible earlier" error for a fixed-vector (hex-literal) input on any non-bytes parameter kindDeveloperPlayground
- ›Closed 573 missing-citation gaps across dozens of Learn modulesResearcherCuriousLearn
- ›195 more Library documents enriched, including 2 new IETF CFRG hybrid-KEM Internet-DraftsResearcherLibrary
August 31, 2026
v4.72.0- ›VPN playground: choose your ML-KEM size (512/768/1024)DeveloperResearcherPlayground
- ›SSH playground: SLH-DSA host keys now run for realDeveloperResearcherPlayground
- ›KMIP and PKCS#11 Developer-tab pipeline builders gained a real per-step Inspect viewDeveloperPlayground
- ›PKCS#11 pipeline builder no longer crashes importing SLH-DSA, HSS/LMS, RSA, ECDSA, or Ed25519 keysDeveloperPlayground
- ›SSH playground: a real SLH-DSA handshake could silently report itself as not quantum-safeDeveloperPlayground
August 30, 2026
v4.70.1–v4.71.0- ›Both Developer tabs gained a real ACVP known-answer test for ML-KEM-768 (FIPS 203)DeveloperResearcherPlayground
- ›The KMIP Developer tab's generated script now speaks real KMIP 3.0 request grammarDeveloperPlayground
- ›Keystore items now show their real PKCS#11 engine attributes when inspectedDeveloperPlayground
- ›A stale claim in the PKCS#11 Developer tab's generated script explained key lifetime incorrectlyDeveloperPlayground
- ›Both Developer tabs' Session activity panel no longer pushes the key/keystore view below the foldDeveloperPlayground
- ›21 Library documents with confirmed-unfixable evidence deprecatedResearcherCuriousLibrary
- ›70 more Library documents enrichedResearcherLibrary
August 29, 2026
v4.65.0–v4.70.0The PKCS#11 and KMIP Developer tabs now show what your script actually did, and 150+ Learn module citations were closed out. · A big /navigate upgrade, real fixes across mobile, accessibility, Business Tools, and Learn, and a stuck local-AI loop on mobile fixed for good. · Two new Developer tabs teach PKCS#11 v3.2 and KMIP 3.0 by letting you build, run, and export a real sequence of calls, not just read about one — and now you can switch freely between the drag-and-drop builder and the real Python it generates. · The in-browser KMIP crypto-agility engine now runs the same modular, 40-policy set the server does, with a real module-status view and a scope-conflict warning when two policies disagree. · The Simulation is now genuinely playable on a phone, start to finish: every phase works, not just the first two, and every step type — including the ones that build a document — has a real way to complete it.
- ›The KMIP Developer tab now shows a real keystore viewer after each runDeveloperPlayground
- ›Both Developer tabs now show a real session-activity log for the script you just ranDeveloperPlayground
- ›The KMIP Developer tab's Governed-lifecycle template now prints real output for every step, not just the first twoDeveloperPlayground
- ›/navigate now has motion controls: spin it, take a guided tour, or turn it offResearcherArchitectCurious/navigate
- ›Accessibility coverage extended to 36 more Playground tools, with 9 real issues fixedCuriousPlayground
- ›Two persona learning paths gained entries they'd been missingExecutiveDeveloperOps
- ›Related modules now show on mobile Learn pages, not just desktopCuriousLearn
- ›Three industry-landscape use cases — web TLS, code signing, and VPN — now link to a real Learn moduleCurious/industry-landscape
- ›Mobile Playground now suggests a "Start here" set of tools for new visitorsCuriousPlayground
- ›A Builder/Code switch on both Developer tabsDeveloperPlayground
- ›A PKCS#11 v3.2 Developer tab, with a drag-and-drop sequence builderDeveloperPlayground
- ›A KMIP 3.0 + crypto-agility Developer tabDeveloperArchitectPlayground
- ›Guided lessons for both new tabsDeveloperPlayground
- ›Every generated script exports as real Python you can take to the sandboxDeveloperPlayground
- ›A KMIP Developer tab you can now build by dragging, not just fill in from a templateDeveloperArchitectPlayground
- ›A real LMS/HSS parameter-set picker on the PKCS#11 Developer tabDeveloperPlayground
- ›The KMIP Developer tab's Sign step can now carry a genuinely binary payloadDeveloperPlayground
- ›The Playground's crypto-agility policy engine now shows which modules are active and warns about conflictsArchitectDeveloperPlayground
- ›The Playground's policy graph and simulator now reflect the real, modular policy setArchitectDeveloperPlayground
- ›All 9 migration phases (plus Foundations) are now playable on a phone, not just the first twoExecutiveDeveloperCurious/simulation
- ›Steps that build a document now have a real phone-native way to complete themExecutiveDeveloper/simulation
- ›A move-by-move receipt after every decisionExecutiveCurious/simulation
- ›End Quarter and the quarterly report now work on a phoneExecutive/simulation
- ›The PKCS#11 Developer tab's key viewer was unreliable — keys could vanish, show "read error," or get double-countedDeveloperPlayground
- ›The PQC Assistant's local AI could get stuck in an endless download-crash-reload loop on mobileCurious/
- ›The PKCS#11 and KMIP Developer tabs' Run button was silently failing every timeDeveloperPlayground
- ›/navigate's auto-rotation ignored your device's reduced-motion settingCurious/navigate
- ›The landing page's headline stats flashed "..." before showing real numbersCurious/
- ›Mobile's "Start Workshop" button went nowhere realCuriousPlayground
- ›/explore was missing from the mobile navigation menuCurious/explore
- ›The Library's persona-based narrowing could leave you with no way to see everythingCuriousLibrary
- ›Several Business Tools reset your work on every reloadExecutiveOps/business-tools
- ›Two accessibility issues fixedCurious/business-tools
- ›The new /navigate 3D knowledge-graph page failed to open, flashing "Loading..." on a repeating cycleResearcherArchitectCurious/navigate
- ›The precache manifest was 108 KB heavier than it needed to beDeveloperPlayground
- ›The mobile "unread updates" indicator could get permanently stuck on, for every visitorCuriousDeveloper
- ›The PKCS#11 Developer tab's C++ engine could never provision its own practice tokenDeveloperPlayground
- ›A runaway script in either Developer tab could hang the browser tab indefinitelyDeveloperPlayground
- ›The new /navigate 3D knowledge-graph page failed to open, flashing "Loading..." on a repeating cycleResearcherArchitectCurious/navigate
- ›The in-browser KMIP engine was 2 commits behind the server engineDeveloper
- ›The "Play This Phase" button in the Watch menu didn't play anything — it started the same narrated video as "Watch"ExecutiveCurious/simulation
- ›A quiz question could grow tall enough on a phone to push its own answer button off-screen, with no way to scroll to itDeveloperCurious/simulation
- ›Completing the assessment from the Simulation's locked screen, on a phone, never actually unlocked the simulationExecutiveCurious/simulation
- ›On tablets (768–1023px), the onboarding tour and the quiz-completion gate silently didn't appear even though the full desktop board was showingDeveloper/simulation
- ›150+ citation gaps closed across dozens of Learn modulesCuriousResearcherLearn
- ›74 additional Q&A/quiz and module content correctionsCuriousLearn
- ›Corrected a CRQC-timeline confidence figureResearcherCuriousThreats
- ›Recovered an Israel government PQC-readiness guide and a threats documentResearcherCuriousTimelineThreats
- ›Fixed 15+ incomplete Library document-status entries and removed a duplicated GRI rowResearcherCuriousLibrary
- ›Corrected 12 source dates and a broken Learn-module linkResearcherDeveloperTimelineMigrate
- ›Added 25 new patent candidates and corrected an incorrect status on an existing oneResearcher/patents
- ›Removed a duplicate vendor-roadmap entryDeveloperArchitectMigrate
- ›Corrected 5 editorial issues — hardcoded dates, missing citations — across Learn modulesCuriousLearn
August 28, 2026
v4.60.0–v4.63.0The Simulation now works honestly on a phone: learn and catalog steps can actually be marked complete there, and the artifact-reveal card no longer hides behind the run controls. · A new /navigate page renders the whole PQC knowledge hub as an explorable 3D graph, the Migrate vendor-risk tab's numbers are now trustworthy, and Share moves out of every page and into one place. · The HSM Playground gets a real PKCS#11 v3.2 conformance checker, the key attribute inspector stops mislabeling post-quantum stateful-signature keys, and ACVP testing gains 8 more real NIST vector categories with visible evidence tiers.
- ›A new 3D graph of the whole PQC knowledge hub, at /navigateResearcherArchitectCurious/navigate
- ›A new Conformance tab in the HSM Playground runs OASIS's own published PKCS#11 v3.2 test casesDeveloperArchitectOpsPKCS#11 Playground
- ›ACVP testing gains 8 more categories backed by real NIST test vectorsDeveloperOpsPKCS#11 Playground
- ›Share moved out of every individual page and into the top bar, everywhereExecutiveArchitectDeveloperResearcherOpsCurious
- ›On mobile, Simulation steps had no way to finish — a correct pick only ever linked awayExecutiveCurious/simulation
- ›The mobile run-progress card could land underneath the run-control bar at the bottom of the screen, with no way to scroll to the hidden partExecutiveCurious/simulation
- ›Leaving the Simulation phase overview and returning, or reloading the page on a phone, could silently reset an in-progress mobile run back to the overviewExecutiveCurious/simulation
- ›The Migrate vendor-risk tab significantly undercounted products and mislabeled infrastructure layersExecutiveArchitectOpsMigrate
- ›Industry names disagreed with each other across Threats, Compliance, and AlgorithmsExecutiveArchitectThreatsComplianceAlgorithms
- ›/migrate on mobile: product PQC capabilities were hard to read and 604 of about 1,011 catalog products had no path to browse to themExecutiveArchitectMigrate
- ›Post-quantum stateful-signature keys (HSS, XMSS, XMSS^MT) showed up as unlabeled hex instead of their key typeDeveloperPKCS#11 Playground
August 26, 2026
v4.59.0The compliance requirements catalogue grows by a third and every requirement in it is now traceable to a quote that really appears in the document it cites, 126 Library documents say which Learn modules teach them, and mobile Library and Timeline gain the Document Analysis panel desktop already had.
- ›Document Analysis now opens from Library and Timeline detail views on your phoneResearcherArchitectDeveloperCuriousLibraryTimeline
- ›687 more compliance requirements, drawn from 65 more sourcesArchitectExecutiveOpsCompliance
- ›126 Library documents now tell you which Learn modules teach themCuriousResearcherArchitectLibraryLearn
- ›83 compliance requirements quoted text that is not in the document they citeArchitectResearcherOpsCompliance
- ›Learn module pages ran flush against both edges of the screen on phonesCuriousLearn
- ›The SBOM module cited CISA's 2026 revision twice and the 2021 original not at allDeveloperArchitectLearn
August 25, 2026
v4.58.0A round of fixes to the mobile layer shipped in 4.57.0, found by testing it live on a phone: Assess, Compliance, Migrate, and Algorithms each had a screen that still fell through to the desktop layout, plus assorted overflow and state bugs.
- ›Assess now covers the same 13 steps on mobile as on desktop, with a quick/comprehensive track pickerExecutiveArchitectOpsDeveloperAssess
- ›Compliance and Migrate: tapping a framework or a vendor's roadmap entry now opens a real detail viewArchitectExecutiveOpsComplianceMigrate
- ›Algorithms: a real Protocol Support screen and a real KAT validation screen on mobileDeveloperArchitectResearcherAlgorithms
- ›Assess's compliance step showed an incomplete, unranked list of frameworks instead of what actually applies to youArchitectExecutiveAssess
- ›"Replace a classical algorithm" dumped up to 38 options onto one flat, unsorted screenDeveloperArchitectAlgorithms
- ›The Algorithms Transition and Detailed Comparison screens showed the full desktop search bar, filter deck, and 5-tab switcher squeezed onto a phoneDeveloperArchitectResearcherAlgorithms
- ›Text ran off the right edge of the screen instead of wrapping on 7 mobile screensCuriousResearcherOpsThreats/patents/leadersLibraryPlayground/businessCompliance
- ›Interactive simulation play on mobile lost your progress if you navigated away and came backDeveloperArchitect/simulation
- ›A card on the Algorithms landing screen ran its description text off the edge of the phoneCuriousAlgorithms
August 24, 2026
v4.57.0A real mobile experience across the whole app, an ACVP validator that now runs and checks against genuine NIST test vectors, and an accuracy pass across Learn's home boards, MLS/EO 14412 citations, and the compliance maturity catalogue.
- ›A real, phone-native version of every screenCuriousDeveloperArchitectExecutiveResearcherOps/
- ›The ACVP validator claimed a "real execution / FIPS 140-3 proof" it wasn't actually runningDeveloperArchitectOpsPlayground
- ›Four retired EU eIDAS requirements were loading as activeArchitectResearcherCompliance
- ›40 accuracy defects corrected across all 36 role-based home boardsExecutiveDeveloperArchitectResearcherOpsCurious/
- ›A module cited an old MLS draft while its own text described the current one, and four modules stated EO 14412 deadlines without citing where those dates come fromDeveloperArchitectOpsLearn
- ›FIPS 140-3 and SP 800-230 were each listed twice in the LibraryResearcherArchitectLibrary
August 23, 2026
v4.56.0A large accuracy pass across the Learn modules — dozens of citations now point at the standard that is actually current — plus a References tab showing what each module cites, working autosave in the business tools, and a keyboard-navigable, higher-contrast interface.
- ›Every Learn module now has a References tab showing exactly what it citesCuriousResearcherArchitectLearn
- ›Related modules, and 25 more pages reachable from searchCuriousLearn
- ›Slide export no longer depends on a third-party generatorExecutiveArchitectLearn
- ›Nine modules cited a TLS specification that was replaced in July 2026DeveloperArchitectOpsLearn
- ›The 5G module told readers to implement a profile 3GPP never definedDeveloperArchitectOpsLearn
- ›A payment module described card authorisation cryptography wronglyDeveloperArchitectLearn
- ›Wrong key and signature sizes in three placesDeveloperArchitectLearn
- ›Business-tool drafts are no longer silently lostExecutiveArchitect/business
- ›Modules that had dropped out of the guided paths are backCuriousResearcherLearn
- ›Keyboard and screen-reader navigation through module tabsCuriousLearn
- ›Phone and tablet layout fixesCuriousOpsLearn
- ›The Assistant's local model had weaker anti-hallucination instructions than the cloud oneDeveloperResearcher
- ›The Assistant stopped padding answers with weak sourcesResearcherCurious
- ›The sandbox no longer overstates what it supportsDeveloperOpsPlayground
- ›A secure-boot page linked to a superseded PKCS#11 draftDeveloperOpsLearn
- ›The Algorithms page said what its memory column cannot tell youDeveloperArchitectAlgorithms
- ›Every claim about a source document is now backed by a verified copyResearcherArchitectLibrary
- ›Duplicate and misattributed Library entries cleaned upResearcherLibrary
- ›Six documents were serving a catalogue or project page instead of the standard itselfResearcherArchitectLibrary
- ›eIDAS is described correctlyExecutiveArchitectCompliance
- ›The protocol matrix is current against the IETF datatrackerDeveloperArchitectAlgorithms
- ›Six algorithms the site already had data for are now in the catalogueDeveloperResearcherAlgorithms
August 19, 2026
v4.54.0–v4.55.0More product briefs and user manuals are linked, a batch of vendor data mistakes are corrected, the Industry Landscape page no longer sends you to the wrong Learn module, and changing your role on mobile actually works now. · More than double the product catalog now links straight to a vendor's own brief and user manual, 22 newly-discovered PQC patents are indexed, and every citation on the protocol-interoperability matrix now resolves to real evidence.
- ›The Industry Landscape page no longer points "Supply Chain / Logistics" at the wrong Learn moduleResearcherArchitectAlgorithms
- ›Changing your role on mobile actually works nowCuriousResearcherExecutiveDeveloperArchitectOps
- ›Product brief and user manual links, now on 695 of 1,011 catalog productsOpsArchitectMigrate
- ›Vendor data cleanup: 2 new vendors registered, 5 mismapped products repointed, 4 stale product rows retiredOpsArchitectMigrate
- ›Product brief and user manual links more than doubled, to 670 of 1,011 catalog productsOpsArchitectMigrate
- ›22 new patents added — 7 of them post-quantum — and a taxonomy error caught before it shippedResearcherArchitect/patents
- ›Every citation on the protocol interoperability matrix now resolves to real evidenceDeveloperArchitectAlgorithms
August 18, 2026
v4.53.0Hybrid certificates in the workshop now cover all six algorithm pairings the current standard recommends — and can be verified, not just generated — while the landing page loads noticeably less up front.
- ›Hybrid certificate workshop now offers all six recommended algorithm pairingsDeveloperArchitectOpsLearn
- ›Certificates you generate can now be checked, not just downloadedDeveloperArchitectLearn
- ›RSA key sizes are enforced against the standardArchitectOpsLearn
- ›HQC and FN-DSA now appear in the default algorithm viewArchitectDeveloperExecutiveAlgorithms
- ›Industry Landscape tiles sort by cybersecurity opportunityExecutiveArchitect/industry
- ›Hybrid certificates generated by the workshop were malformed and would be rejected elsewhereDeveloperArchitectLearn
- ›Key-splitting (M-of-N custody) had stopped working entirelyOpsArchitectPlayground
- ›The site downloads noticeably less before it can show you anythingCuriousOps
- ›Market-size figures refreshed, with Healthcare, Education and Water restoredExecutiveResearcher/industry
- ›Superseded spreadsheet generations archivedOps
August 17, 2026
v4.52.0Industry Landscape now covers Cryptocurrency/Blockchain consensus mechanisms, migrate-catalog product tiles link straight to vendor documentation, and the AI assistant recovers hundreds of sentences it was previously cutting off mid-thought.
- ›Cryptocurrency/Blockchain coverage added to Industry LandscapeResearcherDeveloperArchitectAlgorithms
- ›Three new signature mechanism families trackedDeveloperArchitectAlgorithms
- ›Product Brief and User Manual links on migrate-catalog product tilesOpsArchitectMigrate
- ›AI assistant answers recover sentences that used to get cut off mid-thoughtCuriousResearcher
- ›Two Learn modules (Government & Defense, Trust Services) now fully searchable by the AI assistantCuriousLearn
- ›Re-verified ~130 migrate-catalog products against current vendor evidence (spotcheck batches 39–64).OpsArchitect
- ›Refreshed the AI assistant's search index (16,322 chunks, up from 15,620) to reflect all of the above.CuriousResearcher
August 16, 2026
v4.51.0Industry Landscape rows now show whether their cited evidence names the crypto directly or is a governance driver proven elsewhere, and the Journey panel stops missing milestones in Command Center and OpenSSL Studio.
- ›Industry Landscape rows now show what kind of evidence backs themResearcherDeveloperArchitectAlgorithms
- ›75 of 80 Industry Landscape use cases now link to their Library evidence entryResearcherDeveloperAlgorithms
- ›Protocol Matrix flags FIDO as historical, with the standard that superseded itDeveloperArchitectAlgorithms
- ›The Journey panel no longer misses milestones from Command Center or OpenSSL StudioCuriousDeveloperOps/business/playground/openssl
August 15, 2026
v4.50.1–v4.50.3The two new PKCS#11 v3.2 library entries (Profiles and Usage Guide) now show full details instead of blank fields. · Library search now finds documents by their standard number no matter how it's written — "PKCS11", "PKCS-11", and "PKCS #11" all now find the same results. · Search results now cite roughly 800 more library documents whose citation links had quietly stopped resolving, and 13 compliance records that weren't being scored for trust are now scored.
- ›Search matches standard numbers regardless of spacing or punctuationResearcherDeveloperLibrary
- ›Search results cite the source passage again for ~800 library documentsResearcherDeveloperLibrary
- ›13 compliance records are now scored for trustResearcherOpsCompliance
- ›PKCS#11 v3.2 Profiles and Usage Guide have full detail pagesResearcherDeveloperLibrary
August 14, 2026
v4.50.0The PKCS#11 playground now runs the audited v3.2 engines rather than older builds, names every mechanism it advertises instead of showing raw hex, and cites the current standard — plus five correctness fixes found by auditing the two engines against each other.
- ›One implementation of stateful hash-based signatures instead of threeDeveloper
- ›The playground runs the engines the conformance work actually fixedDeveloperArchitectOpsPlayground
- ›The mechanism list reads as mechanism names, not hex codesDeveloperPlayground
- ›Panes no longer wipe each other's operation logDeveloperPlayground
- ›The key-encapsulation workbench waits for the engine to be readyDeveloperPlayground
- ›Hierarchical-deterministic wallet derivation keeps workingDeveloperArchitectLearn
- ›Standards citations point at sections that existResearcherDeveloperPlayground
- ›Two cryptographic reading errors, found by running the engines against each otherDeveloperPlayground
August 12, 2026
v4.48.1–v4.49.0The library sorts by when a document was actually published rather than when we last touched its record, and the business tools' dollar figures, quotations and vendor guidance have been checked against the documents they cite — three of five financial constants turned out to be wrong. · Seven playground tools now show a review that matches the version you are actually using, and the library stops implying a draft still says something it no longer says.
- ›The library shows each document's own publication date, and sorts by itResearcherArchitectOpsDeveloperLibrary
- ›Records say when they were last checked against the sourceResearcherOpsLibrary
- ›Standards citations in the business tools reach the documentExecutiveArchitectDeveloper
- ›The financial baselines were read from the reports, not their landing pagesExecutive
- ›A blank reached an exported board deck with no warningExecutive
- ›The Monte-Carlo histogram disagreed with the summary above itExecutive
- ›The Cost of Inaction export named no industry, then used oneExecutive
- ›Vendor guidance contradicted this site's own catalogueArchitectOpsMigrate
- ›A tool said the French authority accepts a NIST signature algorithm on its ownArchitectOps
- ›Two quotations attributed to the NIST crypto-agility white paper were not verbatimArchitectResearcher
- ›The Supply Chain Risk Matrix took ~19 seconds to appearArchitectOpsLearn
- ›Seven playground tools showed a review of an older version than the one runningResearcherDeveloperArchitectPlayground
- ›The library implied an internet draft still covers JSON web token encryptionDeveloperArchitectLibrary
- ›Publication dates derived from the cached evidenceResearcherOpsArchitectLibraryTimelineMigrate
August 11, 2026
v4.48.0Compliance answers "which rules bind me, and why" instead of listing every rule that exists; the business tools stop telling executives that doing nothing is free; every page now says whether it adapts to your role, and the ones that quietly didn't have been fixed or made honest about it.
- ›Compliance opens on the rules that bind youExecutiveArchitectOpsCompliance
- ›A reading room for the requirement itselfArchitectOpsCompliance
- ›Bring your own crypto inventory into the assessmentOpsArchitectAssess
- ›Which vendors have actually committed, and what they saidExecutiveResearcherMigrate
- ›Two more ways into the same dataCuriousDeveloperTimelineThreats
- ›Deadlines you can put in a calendar, evidence you can sort by strengthOpsResearcherTimelineLibrary
- ›Business tools show where their numbers come fromExecutiveArchitect
- ›One quantum model across the whole tool suiteExecutive
- ›The financial baselines say which are provenExecutive
- ›Every surface declares how it treats your roleCurious
- ›One place to set who you are, instead of threeCuriousOpsComplianceLibraryTimelineThreats
- ›Choosing your role in the top bar did nothing to the compliance pageExecutiveArchitectCompliance
- ›"Country: Any" returned nothing at allOpsArchitectCompliance
- ›The register is called Rules & StandardsCuriousExecutiveCompliance
- ›The Cost of Inaction Analyzer said inaction was freeExecutive
- ›A tool attributed section titles to a NIST document that does not contain themArchitect
- ›Five surfaces shipped unreachableCuriousOps
- ›The left rail is navigation againCurious
- ›A standards citation could not reach the standardArchitectResearcher
- ›Unfilled template placeholders could leave the appOps
- ›The About page had no top-level headingDeveloper
- ›The Learn modules are current againArchitectDeveloperLearn
- ›Seventy-nine library records gained a plain-language summaryResearcherLibrary
- ›Duplicate Common Criteria certificates collapsed onto stable idsOpsMigrate
- ›Seven Marvell certificates stopped being attributed to a Thales productOpsMigrate
- ›The authoritative-sources region field is nearly completeResearcher
- ›Proof age is now tracked, not just displayedOpsMigrate
- ›CI stops running files that are not in the repositoryOps
- ›A data-regression waiver with an expiry dateOps
August 10, 2026
v4.47.0The About page stops stating eleven wrong version numbers about the app you are looking at; three library records stop citing organisations that were never registered; thirty-six compliance write-ups a tooling bug had quietly deleted are back; and quiz answers finally have somewhere to record which document their fact comes from.
- ›Quiz answers can now say which document the fact came fromCuriousResearcherLearn
- ›The About page listed eleven wrong version numbersDeveloperCurious/about
- ›Three library records cited trusted sources that did not existResearcherLibrary
- ›Three claims in the Learn modules were false, found by reading them against their own cited evidenceArchitectDeveloperLearn
- ›A Learn module cited an initial public draft as though it were bindingArchitectLearn
- ›The architect's Explore card was the ops card with two synonyms swappedArchitect/
- ›Twenty CI gates were being skipped on every pull requestOps
- ›Thirty-six compliance maturity write-ups a tooling bug had deleted are restoredArchitectOpsCompliance
- ›One vocabulary for document types across the libraryResearcherLibrary
- ›A product catalogue entry conflates two different Azure HSM servicesOpsMigrate
- ›The search index the site answers from is now signedOps
- ›The three browser crypto engines were rebuilt from current sourceDeveloperOpsPlayground
- ›Dependency updatesOps
August 12, 2026
v4.46.0The entropy tool now runs both of the health tests the NIST standard requires rather than one, and catches a bad sample it used to pass; the 5G tool finally admits it does post-quantum cryptography, so searching for it works; and every tool page gains a proper heading and a genuinely useful "try this next".
- ›The entropy tester now runs both health checks the NIST standard asks forResearcherDeveloperArchitectPlayground
- ›The 5G tool no longer hides the post-quantum half of what it doesDeveloperArchitectResearcherPlayground
- ›Searching for "post-quantum" now finds post-quantum toolsCuriousExecutiveDeveloperPlayground
- ›The firmware signing tool lists all four algorithms it offersDeveloperOpsPlayground
- ›Two unfinished tools now say they are unfinishedDeveloperArchitectPlayground
- ›The developer sandbox page stopped showing visitors a terminal commandDeveloperOpsPlayground
- ›"Try this next" now suggests where you actually areCuriousDeveloperPlayground
- ›Every tool page now has a proper main headingCuriousPlayground
- ›The "reviewed" mark now says what it meansResearcherExecutivePlaygroundLearnLibraryComplianceMigrateTimeline
- ›The JWT tool's encryption reference now names the exact draft it followsDeveloperArchitectPlaygroundLearn
August 9, 2026
v4.44.1–v4.45.0Whichever role you pick, your home page now reaches every part of the site rather than a sixth of it; the protocol readiness matrix stops overstating how far six protocols have actually got; the quiz gains questions for the two audiences that had the fewest; and compliance maturity coverage grows from four source documents to forty-eight. · Product catalog corrections: a tool that has shipped for weeks stops being listed as unfinished, two rows that contradicted their own descriptions are resolved, and rows claiming post-quantum support now say which algorithms they actually mean.
- ›Your home page now reaches the whole site, whichever role you pickedExecutiveDeveloperArchitectResearcherOpsCurious/
- ›Twelve new quiz questions for the two audiences that had the fewestCuriousExecutiveLearn
- ›Forty-four more people in the PQC community rosterResearcherCurious/leaders
- ›Six protocols in the readiness matrix were shown one stage further along than they areArchitectDeveloperAlgorithms
- ›Hand-written notes in the readiness matrix are no longer overwritten by the updaterArchitectAlgorithms
- ›The "just curious" home page works on a phone againCurious/
- ›Two compliance records now link to the document they rely on, not a company homepageArchitectOpsCompliance
- ›Search now ranks documents that have been replaced by a newer version properlyResearcherArchitectLibrary
- ›Forty-five quiz questions no persona filter could ever reach are back in circulationArchitectDeveloperOpsExecutiveLearn
- ›A working KMIP server was listed as still in developmentArchitectDeveloperOpsMigrate
- ›25 catalog entries said "yes, with details" and then named no detailsArchitectOpsMigrate
- ›Two entries contradicted their own descriptionsDeveloperMigrate
- ›Known-vulnerability data rebuilt against the current product cross-referenceOpsDeveloperMigrate
- ›Industry Landscape: the crypto each of three industries actually relies on, filled in from their own cited documentsResearcherArchitectAlgorithms
- ›Compliance maturity coverage goes from four source documents to forty-eightExecutiveArchitectOpsCompliance
- ›Forty-six people in the community roster still have no peer-review status, down from a hundred and twenty-oneResearcher/leaders
- ›Dead and redirected links repaired across the community roster, vendors and patentsResearcherOps/leadersMigrate/patents
- ›Eleven more compliance records name the standards they depend onArchitectCompliance
- ›Nine more product certification linksOpsMigrate
- ›Four tools added to the migrate catalogDeveloperOpsMigrate
- ›Refreshing the site's search index no longer takes 40 minutes for no reasonOps
- ›A build check that could never have run is now able to runOps
August 8, 2026
v4.43.0–v4.44.0Compliance maturity coverage more than quadruples as documents that were being read only part-way through are now read in full, a batch of library entries that pointed at landing pages get their real source documents, invented requirements are removed, and installing the site for offline use gets dramatically lighter. · Algorithm status pages get corrected for two real misclassifications, threat and timeline records gain dozens of missing links and cross-references, the PKI CRL workshop stops mislabeling a duplicate certificate, and About is reachable from mobile navigation again.
- ›Compliance maturity coverage more than quadruples — from 48 tracked requirements to 200ExecutiveArchitectOpsCompliance
- ›15 new documents in the library, and 24 compliance records now link straight to the source document they are based onResearcherArchitectLibraryCompliance
- ›Installing the site for offline use is roughly three times lighterCuriousOps/
- ›Vendor proof documents open properly instead of showing the site's own home pageArchitectOpsMigrate
- ›Invented requirements removed, and repaired records for Canada's CSE and FIPS-198ExecutiveResearcherCompliance
- ›12 library documents pointed at a landing page instead of the document itselfResearcherLibrary
- ›Three broken tool links in the sandbox scenariosDeveloperPlayground
- ›About is reachable from the mobile navigation menu againCurious/about
- ›The CRL Generator workshop no longer lists a phantom duplicate certificate, and explains real failures instead of a bare status codeDeveloperArchitectLearn
- ›Two algorithm status mislabels correctedResearcherArchitectAlgorithms
- ›Timeline and Compliance cross-references filled inResearcherOpsTimelineCompliance
- ›Every threat-landscape record now links to the Learn module that explains itOpsDeveloperThreats
- ›Three role-board tiles showed a placeholder label instead of a real oneExecutiveDeveloperArchitectOps
- ›The SSH sandbox scenario now covers OpenSSH 10.4 and compares two post-quantum signature schemes side by sideDeveloperArchitectPlayground
- ›The migrate catalog gains the pqctoday-strongswan-pkcs11 forkDeveloperOpsMigrate
- ›Every in-browser crypto engine rebuilt against the current HSM release, and OpenSSL moved to 3.6.3DeveloperArchitectOpsPlayground
- ›Patched 3 known vulnerabilities in bundled third-party libraries: a sanitizer bypass, a diagram-rendering prototype-pollution/DoS issue, and an ID generator that could loop indefinitely on bad input. A 4th (an image-dimension parser, pulled in by the PPTX export feature) has no upstream fix available yet; we've confirmed the affected code path isn't reachable from anything this site actually does with it.
August 7, 2026
v4.42.0The app installs roughly 250 MB lighter and works offline sooner, algorithm pages let you read a spec or try a tool without losing your place, and Compliance's maturity data is reconnected after a data-archival sweep silently broke it.
- ›Algorithm pages let you read the spec or try a tool without losing your placeDeveloperResearcherArchitectAlgorithms
- ›Patents now has a Sources button, like every other data pageResearcher/patents
- ›The crypto lab warns you before you open a tool your device can't runDeveloperPlayground
- ›Command Center's filters are shareableOpsArchitect/business
- ›Developers get a report built for developersDeveloper/report
- ›A "Runs on this device" filter in the crypto labDeveloperPlayground
- ›Command Center's tool grid can be grouped by framework phase or CSWP.39 zoneOpsArchitect/business
- ›Crypto lab tools link back to the module that explains themDeveloperCuriousPlayground
- ›First-visit install size cut by roughly 250 MBDeveloperOps
- ›Search loads only when you open itDeveloper
- ›The crypto lab grid shows browser-runnable tools by defaultDeveloperPlayground
- ›Search finds workshop and business tools even on broad queriesDeveloperOps/
- ›The vendor roadmap tracker states its real denominatorExecutiveOpsMigrate
- ›Compliance's maturity and governance requirements are reconnected on every pillarExecutiveArchitectOpsCompliance
- ›Compliance detail tiles no longer overflow their own cardExecutiveCompliance
- ›The CT Log simulator's Certificate Authority can now sign, not just verifyDeveloperArchitectLearn
- ›Eight real accessibility violations fixed across the business and crypto-lab toolsOpsResearcher/businessPlayground
- ›The Algorithms "FIPS-validated" and "NIST picks" quick views now show the right rowsResearcherArchitectAlgorithms
- ›The homepage's "continue where you left off" banner is backCuriousDeveloper/
- ›The executive algorithm card gives EU visitors EU-correct guidanceExecutiveArchitectAlgorithms
- ›The side panel's tab row hints when there's more to scroll toDeveloperOps
- ›Every row in the main navigation is reachable in one keyboard stop, not twoOpsResearcher
August 2, 2026
v4.38.0–v4.41.0Every role's home page now offers three different ways in rather than one, each pointing at its own tool, and the numbers those pages quote are computed rather than typed. The PKCS#11 playgrounds gained a live call log and a real view of what is on the token, and every crypto engine on the site was rebuilt current. · Text and controls across the light theme now meet the WCAG AA contrast standard, and the navigation loses three controls that duplicated the top bar. · A round of genuine bug fixes found by re-checking last week's UX audit against the actual code — a migration deadline that displayed a date in the past, filters that returned nothing, links that went nowhere, and a Share button that sent people to an empty page. Also roughly 26 MB less to download on your first visit. · A page-by-page pass across Algorithms, Compliance, Library, Migrate, Playground, Threats, Timeline, and the Command Center — unlocking content that was gated for no good reason, replacing hand-typed lists with the real catalogue behind them, and giving pages honest error states instead of silent blank ones.
- ›Your role's home page now offers three ways in, not oneExecutiveDeveloperArchitectResearcherOpsCurious/
- ›OpenSSL Studio shows what the security token actually didDeveloperOpsPlayground
- ›You can now read what is really stored on the tokenDeveloperOpsPlayground
- ›The SSH simulator shows the keys it createdDeveloperOpsPlayground
- ›The TPM inspector shows how many temporary slots are in useDeveloperArchitectPlayground
- ›Replaced keys show what they supersededOpsArchitectPlayground
- ›Phone-sized browser testingDeveloper
- ›Algorithms shows the ACVP verification claim up frontDeveloperResearcherAlgorithms
- ›Timeline shows how fresh each country's data isResearcherOpsTimeline
- ›Library shows corpus health at a glanceResearcherLibrary
- ›Migrate covers vendors who have announced a roadmap, not just those with nothingArchitectOpsMigrate
- ›Command Center gains a first-visit board-pack walkthroughExecutive/business
- ›Every crypto engine on the site was rebuilt currentDeveloperOpsArchitectPlayground
- ›The MLS workshop says which implementation you are drivingDeveloperPlayground
- ›The assistant and your journey map are both in the top barExecutiveDeveloperArchitectResearcherOpsCurious/
- ›The Reference group in the left bar starts openCuriousResearcher/
- ›The Learn page is less crowdedCuriousExecutiveLearn
- ›Role pages promise what they actually deliverOpsExecutive/
- ›About 26 MB less to download on your first visitDeveloper
- ›The footer year is computed rather than hardcoded
- ›The AI Assistant's anti-fabrication rules are stricter
- ›Fourteen tool links on the role home pages opened the wrong pageExecutiveDeveloperArchitectResearcherOpsCurious//business
- ›The researcher's field watch reported zero updates to everyone, permanentlyResearcher/
- ›The exposure card drew the wrong conclusion from its own numbersExecutiveResearcher/
- ›Opening a Learn module could complete it before you had read anythingCuriousDeveloperLearn
- ›A failed Root CA step left an unusable key behindOpsArchitectLearn
- ›Boards pointed at tools they did not describeExecutiveDeveloperArchitectResearcherOpsCurious/
- ›Modern elliptic-curve keys were filed as symmetric keysOpsDeveloperPlayground
- ›Resetting the VPN simulator left sessions open on the tokenOpsPlayground
- ›Writing a key "to the token" could silently produce an exportable file insteadDeveloperOpsPlayground
- ›Small text is readable again throughout the light themeExecutiveOpsCurious/TimelineLibraryComplianceMigrate
- ›Cards, table rows and framework tiles work with a keyboard and a screen readerResearcherOpsLibraryThreatsComplianceMigrate
- ›The achievement celebration appears when you earn it, not laterCuriousDeveloperLearn
- ›Horizontally scrolling strips can be scrolled without a mouseCompliance
- ›PQC 101's key generation works in both panes againDeveloperCuriousLearn
- ›Learn is visible on the left bar without expanding anythingCuriousDeveloper/
- ›The Threats page no longer shows a migration deadline that has already passed as if it were upcomingExecutiveArchitectThreats
- ›The Algorithms region filter actually returns resultsArchitectResearcherAlgorithms
- ›Sharing your readiness report now sends a working linkExecutive/report
- ›The Migration Workbench feeds the Roadmap Builder againOpsArchitectMigrate
- ›Migrate's references to learning modules are clickableDeveloperOpsMigrate
- ›Patent links to algorithms work for older patentsResearcher/patents
- ›First-time visitors can reach the whole site from the desktop menuResearcher/
- ›The Compliance table view can open framework detailsExecutiveCompliance
- ›The Library's top pick for executives opensExecutiveLibrary
- ›OpenSSL Studio shows the right documentation for post-quantum algorithmsDeveloperOpenSSL Studio
- ›The curious mobile home screen's buttons workCurious/
- ›The About page no longer describes a cloud-sync control that doesn't exist/about
- ›Migrate's page header stays putMigrate
- ›The Algorithms Protocol Support table is no longer locked for new visitorsCuriousAlgorithms
- ›Threats opens with the headline estimate, detail one click awayResearcherThreats
- ›Compliance tells you when a load fails instead of looking emptyResearcherCompliance
- ›Timeline says what actually went wrongResearcherTimeline
- ›Timeline's enrichment analysis is one click, not twoResearcherTimeline
- ›The Playground's mobile tool list matches the real catalogueDeveloperPlayground
- ›Sandbox-gated Playground tools are dimmed, not hiddenDeveloperOpsPlayground
- ›The Playground's engineering surfaces are hidden from non-engineering rolesExecutiveCuriousPlayground
- ›Library detail restores its evidence linksResearcherLibrary
- ›The "Start here" row on the Playground overview is 3 tools, not 6CuriousPlayground
- ›Token isolation and login fixesOpsDeveloperPlayground
August 1, 2026
v4.35.0–v4.37.0A full front-door and navigation redesign built around six personas — Executive, Developer, Security Architect, IT Ops, Researcher, and Curious Explorer — replacing the flat top nav with a two-section rail and giving every persona a real first win instead of a generic hero banner. · A three-phase mobile UX remediation: five app-wide root causes fixed once each, 28 high-severity page-specific bugs resolved, and a 51-finding touch-target sweep across 40 files — plus two real functional bugs caught along the way that weren't mobile-specific at all. · The Financial Services & Payments module gains a real Open Banking & PSD2 section, a revived BSI standard and 4 real evidence documents replace low-quality captures in the Library, and 22 broken glossary links across 9 modules are fixed.
- ›A new "Who's asking?" front doorExecutiveDeveloperArchitectOpsResearcherCurious
- ›A real navigation rail, not a flat rowExecutiveDeveloperArchitectOpsResearcherCurious
- ›One place to change who you are and where you workExecutiveDeveloperArchitectOpsResearcherCurious
- ›A single page-actions strip in the top barResearcherOps
- ›The Sources panel now names the data file behind the pageResearcher
- ›Six persona boards, each with a real first win
- ›A dedicated mobile experience for new/non-technical visitorsCurious
- ›Researchers can now watch specific topics for changesResearcher
- ›New section: Open Banking & PSD2 Strong Customer AuthenticationDeveloperArchitectLearn
- ›The buttons on every persona board now actually go somewhereExecutiveDeveloperArchitectOpsResearcherCurious
- ›Switching roles no longer leaves you scrolled past the new page's buttonsExecutiveDeveloperArchitectOpsResearcherCurious
- ›Persona board numbers are read from the real data, not typed by handExecutiveDeveloperArchitectOpsResearcherCurious
- ›Board copy no longer prints internal code names at readersExecutiveDeveloperArchitectOpsCurious
- ›The Glossary and User Manual panels close when you click outside themCurious
- ›Business Center opens straight into the Command CenterExecutive/business
- ›Breadcrumb trails removed from every page
- ›The "show me everything" escape hatch actually works nowCuriousLearn
- ›OpenSSL Studio no longer has two separate front doorsDeveloperArchitectOpsPlayground
- ›The AI Assistant no longer sends you to a dead personalization linkCurious
- ›Compliance no longer shows a generic Sources buttonResearcherCompliance
- ›The AI Assistant button no longer covers page content while you scroll on mobileCurious
- ›The glossary panel no longer crowds out tool content on mobileDeveloperOpsPlayground
- ›Mobile navigation hints when there's more to scroll to, and fits betterCurious
- ›A hidden Compliance tab is visible again on mobileResearcherCompliance
- ›Search is now reachable on mobileCurious
- ›iPhone/iPad users get honest guidance on the VPN/SSH live-crypto gateCuriousLearn
- ›Simulation's mobile locked-screen header and full-migration flow no longer clip or drop optionsCurious/simulation
- ›The Algorithms "Transition Guide" tab is reachable again on mobileResearcherAlgorithms
- ›TPM Playground's EK Certs tab no longer hangs foreverOpsDeveloperPlayground
- ›Threats dashboard cards no longer take up to a minute to appearResearcherThreats
- ›Playground Workshop's tool list and detail modal now work on mobileDeveloperPlayground
- ›The embedded (vendor-hosted) view's navigation and sidebar work correctly on mobileDeveloper
- ›51 more controls across 40 files now meet the app's 44px mobile touch-target minimumCurious
- ›Smaller mobile fixes
- ›BSI-AIS-20-31 standard revived a second timeResearcherLibrary
- ›4 more Library documents replaced with the real thingResearcherLibrary
- ›22 broken glossary links fixed across 9 Learn modulesCuriousLearn
- ›The financial sector's "no dated mandate" claim, qualifiedResearcherLearn
- ›"PQC Candidates & Lifecycle" title correctedCuriousLearn
- ›library_07312026_r2.csv and trusted_sources_07312026_r7.csv refreshedResearcherLibrary
- ›Search index refreshed
July 31, 2026
v4.33.0–v4.34.0The Digital ID module gets real mdoc/SD-JWT credential flows and links back from the compliance frameworks it covers, 10 new real regulations and 17 certification schemes join Standardization & Compliance, and this week's Financial Services quiz and module content is corrected. · Learn modules and Playground tools now show a real, working revision history instead of a button that always claimed everything was up to date.
- ›Digital ID module: real mdoc selective disclosure and the share chooserDeveloperArchitectLearn
- ›Compliance frameworks link back to the module that teaches themCuriousDeveloperCompliance
- ›Deadlines can now derive from the timelineResearcherComplianceTimeline
- ›Compliance deadlines: separate start and finish dates, sortable by finishExecutiveOpsCompliance
- ›The Simulation routes Digital ID from the government sector trackCurious/simulation
- ›Learn modules and Playground tools now show their real review statusDeveloperArchitectResearcherLearnPlayground
- ›Digital ID module: corrected wrong facts, refreshed stale spec references, fixed a shared-session bugDeveloperLearn
- ›The EUDI Wallet rollout date no longer overwrites the EU's PQC deadlineResearcherTimeline
- ›3 fabricated PQC standards removed from the Library, a 4th correctedResearcherLibrary
- ›Financial Services & Payments module (LM-044): factual and consistency correctionsResearcherLearn
- ›Financial Services & Payments quiz: 2 answers corrected, 2 learner paths now assessedCuriousAssess
- ›5 modules' listed duration/difficulty corrected to match their actual contentCuriousLearn
- ›10 new real compliance regulations added, across the US, EU, Canada, and 6 emerging marketsResearcherCompliance
- ›17 new certification schemes added and cross-linked into trusted sourcesResearcherCompliance
- ›20 organization rows corrected after wrongly claiming a PQC mandateResearcherCompliance
- ›13 missing EU member states added to the jurisdictions registryResearcherCompliance
- ›Compliance industry filter fixed to return what you actually selectResearcherCompliance
- ›Mastercard's 2025 PQC industry-awareness whitepaper added to Industry LandscapeResearcherAlgorithms
- ›Search index refreshed
- ›Corrected 4 mislabeled entries in the site's revision-history logResearcher/revisions
July 30, 2026
v4.30.1–v4.32.0Two new Learn modules cover government/defense and trust-service PQC migration, community leaders are now cross-linked to their patents and open-source projects, and this week's vendor, certification, and threat-watch data is refreshed. · A new Industry Landscape tab on the Algorithms page shows what crypto mechanisms each industry actually relies on today — cross-referenced against real standards, official market-size figures, and live threat data. · Four Migrate catalog entries had the wrong company listed as their maker, and five Library/Compliance citations that pointed at inaccessible pages now resolve to the real source documents.
- ›Two new Learn modules: Government & Defense, and Trust ServicesArchitectOpsLearn
- ›Leaders now link to their patents and open-source projectsResearcher/leaders
- ›Product-id and inventor deep links into Patents and MigrateResearcher/patentsMigrate
- ›Industry Landscape tabArchitectExecutiveResearcherAlgorithms
- ›"Learn: <industry>" links on industry pagesCuriousAlgorithms
- ›Library, compliance, algorithms, migrate, assessment, and threats catalogs refreshedResearcherLibraryComplianceAlgorithmsMigrate
- ›Product certifications and CRQC-watch data re-syncedResearcherMigrateThreats
- ›OpenSSH 10.4's composite signature support noted in the Protocol Support matrixDeveloperAlgorithms
- ›34 industry standards, verified to actually name a crypto mechanismResearcherAlgorithms
- ›8 new Library documents added, each independently downloaded and verifiedResearcherLibrary
- ›Insurance industry re-groundedResearcherAlgorithms
- ›4 products' vendor attribution correctedResearcherMigrate
- ›5 Library and Compliance citations now resolve to real source documentsResearcherLibraryCompliance
- ›A community leader's citation now points at a real, current documentResearcher/leaders
July 29, 2026
v4.29.1–v4.30.0The Simulation got a full accuracy, usability, and teaching pass: every factual claim was re-verified against its source, hands-on play is now a clearly named option (and phones can watch the narrated overview), and the game finally explains its own scoring. · Four organizations behind recently-added Library documents — an aviation standards consortium, an ISO committee, and Italy's and Japan's national cybersecurity bodies — are now tracked as verified sources instead of showing no source at all. · 52 Library documents that were sitting as bare, unreviewed stubs now show real information — document type, industries, authors, migration urgency, and more — instead of blank fields.
- ›"Play it yourself" is now a named way to playCuriousExecutive/simulation
- ›Watch the Executive Overview on your phoneExecutive/simulation
- ›Terms & glossary inside the simCurious/simulation
- ›The grade card explains its own mathCurious/simulation
- ›Save your roadmap at the finish lineExecutive/simulation
- ›What happens after the migration closesArchitectOps/simulation
- ›Wrong picks now state their priceCurious/simulation
- ›Playback progress no longer disappears/simulation
- ›Dialogs keep keyboard focus where it belongs/simulation
- ›Payment-industry claim brought up to dateExecutive/simulation
- ›Deadline attribution correctedResearcher/simulation
- ›The quantum-threat window now adds upResearcher/simulation
- ›Fictional planning dates no longer read as overdue/simulation
- ›India moved out of the jurisdiction pickerResearcher/simulation
- ›Framework cross-references verified against source documentsResearcher/simulation
- ›4 new trusted sources registeredResearcherLibrary
- ›6 cached evidence documents recoveredResearcher
- ›52 Library entries completed with real, cited detailResearcherArchitectDeveloperLibrary
- ›4 duplicate/superseded entries cleaned upResearcherLibrary
July 28, 2026
v4.28.0–v4.29.0The Algorithms catalog now describes hybrid key exchange properly — the pairing of a classical algorithm with a post-quantum one, which is how most real PQC deployments are rolling out. · A big data-accuracy and coverage pass across Migrate, Vendor Roadmaps, Timeline, Trusted Sources, Threats, and Algorithms — plus real fixes to broken certificate links, a mis-detected PQC algorithm, and several data-pipeline bugs found along the way.
- ›Hybrid key exchange is now catalogued beyond TLSArchitectDeveloperOpsAlgorithms
- ›X-Wing, the general-purpose hybridDeveloperAlgorithms
- ›Post-quantum SSH key exchangeOpsDeveloperAlgorithms
- ›Composite certificates for PKIArchitectOpsAlgorithms
- ›The SLSA v1.1 specification joins the LibraryDeveloperOpsLibrary
- ›13 previously-broken product certificate links now resolve to the real NIST validation recordDeveloperArchitectMigrate
- ›New Migrate catalog entries
- ›27 new authoritative sourcesResearcherArchitect
- ›18 new industry threat & compliance documentsOpsArchitectThreats
- ›New vendor roadmaps
- ›14 new government PQC milestones on the TimelineExecutiveOpsTimeline
- ›The three existing TLS hybrids are relabelled to say they're TLS-specificAlgorithms
- ›The WireGuard sandbox walkthrough is retiredOpsPlayground
- ›Classic McEliece is now shown as a fully standardised algorithmAlgorithms
- ›9 NIST digital-signature candidates (UOV, SQIsign, FAEST, SNOVA, MAYO, HAWK) now show Round 3 statusAlgorithms
- ›83 more Migrate catalog products now show up under the right migration stepArchitectOpsMigrate
- ›76 catalog entries were missing their internal product identifierDeveloper
- ›A product with LMS/HSS hash-based signatures was incorrectly marked as having no post-quantum supportDeveloper
- ›Three catalog entries had inaccurate claims corrected
- ›A threat-database document's evidence file was corrupted at the source
- ›Several internal consistency checks (duplicate source entries, stale playground scenario references, and a couple of new-algorithm classification gaps) were caught and fixed before release.
- ›Two SSH entries deliberately leave key sizes blank. Their specification doesn't state them and the sizes depend on an encoding defined in a different document, so the field says nothing rather than showing a number that looks more authoritative than it is.
July 26, 2026
v4.27.0The Library page now shows who reviewed each document and when, four documents that had been silently showing site-navigation text instead of their real content are fixed, and seven Timeline milestones get their review badge back.
- ›Library documents now show their review statusDeveloperArchitectResearcherLibrary
- ›The About page's Trust Engine section now explains the actual review pipelineCuriousExecutive/about
- ›Four recently-added Library documents had broken extracted contentResearcherLibrary
- ›Brand-new Library documents no longer sort to the bottom of "Newest first"DeveloperLibrary
- ›Seven Timeline milestones show their review badge againOpsResearcherTimeline
July 25, 2026
v4.25.5–v4.26.0OpenSSL Studio gets a working hardware-token workbench backed by a genuinely independent PQC engine, the TPM 2.0 Playground stops corrupting itself when two panels are used at once, and seven Learn modules get the infographic they were missing. · OASIS published the next revision of the KMIP 3.0 spec since our last update; this release moves the Protocol Matrix and the KMIP 3.0 Playground onto it.
- ›OpenSSL Studio has a new PKCS#11 (HSM) workbench you can actually generate keys inDeveloperArchitectOpsOpenSSL Studio
- ›The token behind OpenSSL Studio is now a genuinely independent implementationDeveloperResearcherOpenSSL Studio
- ›Seven Learn modules now show their infographicCuriousExecutiveArchitectLearn
- ›The TPM 2.0 Playground now proves the spec revision it claims, instead of asserting itDeveloperResearcherTPM 2.0 Playground
- ›Changelog entries now name the page they affect instead of showing a raw pathCurious/changelog
- ›The Algorithms page's Protocol Matrix now cites the published KMIP 3.0 spec, not the earlier draftDeveloperArchitectResearcherAlgorithms
- ›The KMIP 3.0 Playground's tour, glossary, quiz, and command reference now cite the published spec throughoutDeveloperArchitectKMIP 3.0 Playground
- ›The Revoke reason picker in the KMIP 3.0 Playground now offers all 10 real revocation reasons, up from 5DeveloperKMIP 3.0 Playground
- ›The KMIP 3.0 Playground's in-browser engine was rebuilt against the latest published specDeveloperArchitectKMIP 3.0 Playground
- ›The TPM 2.0 Playground no longer corrupts its own results when two panels run at onceDeveloperArchitectTPM 2.0 Playground
- ›Certificate steps that use an EC key in OpenSSL Studio's HSM demos now workDeveloperOpsOpenSSL Studio
- ›OpenSSL Studio's Workbench buttons no longer get pushed off the screenDeveloperOpenSSL Studio
- ›OpenSSL Studio's Explore and Learn tabs now tell you when the engine fails to loadDeveloperResearcherOpenSSL Studio
- ›A data-refresh bug that could have un-published two RFCs on the Algorithms page is fixedDeveloperArchitectResearcherAlgorithms
- ›Approving one Protocol Matrix correction no longer applies all of themOpsAlgorithms
- ›11 new standards documents added to the LibraryResearcherArchitectLibrary
- ›2 new industry threat framework entriesExecutiveArchitectThreats
- ›3 government timeline entries retired because their source links no longer resolveResearcherTimeline
- ›Australia keeps its 2030 deadlineExecutiveResearcherTimeline
- ›Three timeline entries now appear under their country againResearcherTimeline
July 24, 2026
v4.24.1–v4.25.4An OpenSSL Studio release: a new guided Learn tab and a live Algorithm Explorer, both running the real openssl.wasm engine bundled with the site (not simulated output). · A maintenance-pipeline accuracy pass: several standards, catalog, timeline, glossary, and leaders-profile corrections found and verified during a full end-to-end review of the data maintenance process.
- ›The TPM 2.0 Playground's Learn tab now shows each step's real wire exchange inlineDeveloperArchitectTPM 2.0 Playground
- ›The PKCS#11 Learn tab now shows each step's own call log inlineDeveloperPKCS#11 PlaygroundLearn
- ›OpenSSL Studio's Learn tab now shows the real command output under each stepDeveloperResearcher/playground/openssl
- ›New 11-lesson Learn tab for OpenSSL StudioDeveloperArchitectResearcher/playground/openssl
- ›New "Explore" tab shows every algorithm this exact OpenSSL build actually supportsDeveloperResearcher/playground/openssl
- ›Corrected 2 wrong spec-section citations in the KMIP 3.0 PlaygroundDeveloperArchitectKMIP 3.0 Playground
- ›Fixed a silently wrong algorithm codepoint in the KMIP 3.0 patch tablesDeveloperKMIP 3.0 Playground
- ›Added a completeness check for KMIP 3.0's WD19 draft deltaDeveloperArchitectKMIP 3.0 Playground
- ›The PKCS#11 Learn tab's call log no longer shows confusing internal housekeeping as failed callsDeveloperPKCS#11 PlaygroundLearn
- ›OpenSSL Studio's Learn tab no longer breaks partway through multi-step lessonsDeveloperResearcher/playground/openssl
- ›OpenSSL Studio's failure detection and error messages are now accurateDeveloperResearcher/playground/openssl
- ›The TPM Playground's compliance check no longer fails after visiting the Learn tab firstDeveloperResearcherPlayground
- ›5 protocols advanced in the Standards Support Matrix, reflecting real IETF progressDeveloperArchitectAlgorithms
- ›Corrected HAWK's post-quantum signature status in the Migrate catalogDeveloperResearcherMigrate
- ›4 more Migrate catalog products now show a verified certificationResearcherMigrate
- ›Fixed 2 Migrate catalog products linked to the wrong companyMigrate
- ›2 more Timeline milestones now show a verified source organizationResearcherTimeline
- ›Fixed 3 broken "learn more" links in the GlossaryLibrary
- ›Cleaned up 37 mislabeled entries in the authoritative sources directoryResearcherLibrary
- ›10 more Leaders profiles now show a verified peer-review credentialResearcher/leaders
July 23, 2026
v4.24.0A TPM 2.0 Playground release: a new guided Learn tab teaching classical-vs-post-quantum TPM operations side by side, and a fix to the underlying crypto bridge that had been silently substituting placeholder data for real ML-DSA signatures and ML-KEM key exchanges.
- ›New guided Learn tab for the TPM 2.0 PlaygroundDeveloperArchitectResearcherPlayground
- ›The TPM Playground's post-quantum cryptography is now genuinely realDeveloperResearcherPlayground
- ›The TPM Playground's Command Builder no longer sends made-up data for multi-step operationsDeveloperPlayground
- ›The TPM Playground's compliance checklist can no longer misreport a passing scoreDeveloperOpsPlayground
July 24, 2026
v4.22.1–v4.23.0A PKCS#11 Learn tab release: a new lesson on key-trust policy, and a more trustworthy call log across the whole HSM playground. · Small accuracy pass: Ops nav reachability, a persistence fix on mobile Timeline, softer Patents copy, several stale-citation and dead-link corrections across Learn, and a CACP KMIP 3.0 playground accuracy fix.
- ›New "Trust & wrapping policy" lesson in the PKCS#11 Learn tabDeveloperArchitectPKCS#11 Playground
- ›Added Algorithms to the IT Ops navigationOpsAlgorithms
- ›The mobile Timeline's "All phases" view now stays selectedOpsTimeline
- ›Softened the /patents preview banner for curious visitorsCurious/patents
- ›The PKCS#11 workshop and Learn tab's call log now shows what actually happened, by defaultDeveloperLearnPKCS#11 Playground
- ›A skipped lesson step could display as "refused, correctly" when it had actually crashedDeveloperPKCS#11 Playground
- ›Refreshed the HSM playground's underlying crypto enginesDeveloperOpsPKCS#11 Playground
- ›Corrected a stale 2024 data-breach citationExecutiveLearn
- ›Corrected the "10-50x larger certificates" claim in the last two places it survivedArchitectCuriousLearn
- ›Replaced personal email contact links on the About page/about
- ›Reviewed and corrected 8 Learn modules' internal citation listsDeveloperArchitectOpsLearn
- ›Corrected spec citations and a dormant algorithm-mapping bug in the CACP KMIP 3.0 playgroundDeveloperArchitectKMIP 3.0 Playground
- ›Resolved 7 library entries flagged for URL reviewResearcherLibrary
- ›Backfilled related-standards links on 3 compliance entriesResearcherCompliance
July 19, 2026
v4.22.0A major Simulation release: a six-wave accuracy and gameplay overhaul, real hub data flowing through the sim's documents and events, and a refreshed NIST library entry.
- ›Simulation results now appear on the Executive ReportExecutive/report/simulation
- ›One unified scoreboard for the Simulation/simulation
- ›Hover/tap definitions for Simulation termsCuriousExecutive/simulation
- ›Simulation achievements and shareable challenge replaysExecutiveCurious/simulation
- ›Edge migration is now a first-class Simulation step, reachable by everyone/simulation
- ›Events with real stakes/simulation
- ›The Simulation's demo documents are now the real tools' own outputExecutiveArchitect/simulation
- ›The Simulation's event pool now partly reflects real, current data/simulation
- ›Several Simulation surfaces read your real data/simulationMigrate
- ›Corrected a wrong standards citation in the Audit Readiness ChecklistResearcher/business
- ›Fixed a text-overflow bug in the PKCS#11 HSM Learn tabDeveloperPlayground
- ›Removed a false product claim from the Simulation's event pool/simulation
- ›NIST CSWP 39 refreshed to Update 1ResearcherLibrary
July 18, 2026
v4.21.11A guided Learn tab for the PKCS#11 HSM Playground, and a new Developer Sandbox card on the Playground overview.
- ›PKCS#11 HSM Playground now has a guided Learn tabDeveloperArchitectPlayground
- ›Developer Sandbox card on the Crypto Lab overviewDeveloperPlayground
- ›Threats: top-level sections are now collapsibleResearcherExecutiveThreats
- ›KMIP Control Plane: mechanism panel now cites the spec section for every operationDeveloperPlayground
- ›Leaders / PQC Community: every profile independently re-verified against live sourcesResearcher/leaders
- ›KMIP 3.0 Playground: further compliance-audit gaps closedDeveloperPlayground
- ›Trusted-sources registry: a 420-row divergence between two conflicting files reconciled
- ›A duplicate vendor registration removed
- ›Library: large-scale re-verificationResearcherLibrary
- ›Timeline and Threats: re-verification of documents flagged as changedResearcherTimelineThreats
- ›Compliance-landscape: related standards backfilled
- ›5 more product certifications verifiedResearcherMigrate
July 17, 2026
v4.21.7–v4.21.9Spec-accuracy fixes across the KMIP 3.0 and HSM playgrounds, a batch of newly-discovered vendor roadmaps, and re-verified evidence across Timeline and Threats. · A routine maintainer-review pass adds new Compliance entries, fixes a Timeline citation error, and refreshes Library, Vendor Roadmaps, Product Certifications, and CVE data. · Compliance's trust panel and crosswalk registry now cover every active framework, Timeline's citations and trust links are fully verified across all 255 active milestones, and Migrate's vendor-risk cards now factor in real CVE exposure.
- ›KMIP 3.0 Playground documentation corrected against the actual OASIS draftDeveloperArchitectPlayground
- ›HSM Playground: 2 spec-label correctionsDeveloperPlayground
- ›Timeline: a citation's date precision correctedResearcherTimeline
- ›Timeline: corrected an ETSI document-number error and improved date precision on 2 entriesResearcherTimeline
- ›Compliance now shows a real Source & trust panel, with full traceability coverageResearcherArchitectCompliance
- ›Timeline citations and trust links fully verified across all 255 active milestonesResearcherTimeline
- ›Migrate vendor-risk cards now reflect real CVE exposureArchitectOpsMigrate
- ›40 vendor roadmaps reviewed, 1 new genuine find addedArchitectMigrate
- ›Threats: 72 documents with confirmed content drift re-verified and re-enrichedResearcherThreats
- ›1 Timeline entry deprecated
- ›5 new Compliance entries addedResearcherCompliance
- ›related_standards confirmed for 43 more Compliance rowsResearcherCompliance
- ›8 new Library documents enrichedResearcherLibrary
- ›5 vendor roadmap pages refreshedArchitectMigrate
- ›20 product certifications re-verifiedResearcherMigrate
- ›CVE database refreshed
- ›27 Timeline-to-Compliance citation links backfilledResearcherComplianceTimeline
- ›420 missing entries backfilled into the trusted-sources registryResearcher
- ›Migrate's certification and CPE cross-reference data fully regeneratedArchitectMigrate
July 16, 2026
v4.21.6The Compliance page's CSWP.39 governance tags (the badges showing which frameworks touch crypto governance, inventory, observability, assurance, or lifecycle) now come from real, full document text instead of a truncated, noisy extraction — plus new content across Timeline, Threats, Library, and Migrate from a maintainer review pass.
- ›Compliance framework governance tags are now genuinely reflective of each document, not just partially filledResearcherArchitectCompliance
- ›5 Compliance entries that were never really about post-quantum cryptography are now hiddenResearcherCompliance
- ›New Timeline entry
- ›New Threats entry
- ›22 new Library documentsResearcherLibrary
- ›Vendor roadmaps refreshed for Microsoft and CloudflareArchitectMigrate
- ›13 more Migrate catalog products verifiedResearcherMigrate
July 15, 2026
v4.21.5The Compliance page's traceability drawer now shows only real, data-backed relationships instead of fabricated boilerplate, and the Library, Timeline, Threats, and Migrate catalogs pick up a large batch of newly verified content following a full review of the maintainer agent's pending proposals.
- ›Compliance traceability chains no longer show fabricated claimsResearcherArchitectCompliance
- ›17 new PQC-certified products added to MigrateResearcherArchitectMigrate
- ›18 new vendors registered with verified GLEIF legal-entity recordsResearcherMigrate
- ›20+ new documents added to Library and TimelineResearcherLibraryTimeline
- ›Fixed a duplicate timeline entry
July 14, 2026
v4.21.3–v4.21.4Vendor Risk and certificate details get clearer in-place drill-downs on /migrate, the Protocol Support matrix picks up TLS 1.3's new RFC plus two new tracked protocols, and a data-quality pass recovers, verifies, and corrects more of the Migrate catalog's supporting evidence. · A large data-quality pass: hundreds of Migrate products got a real PQC-support assessment, Compliance framework tags now come from the actual regulation text instead of a one-line summary, and Library reference coverage is complete.
- ›Vendor Risk matrix rows and dependencies now expand in placeArchitectExecutiveMigrate
- ›Products with multiple certifications of the same type now show all of themArchitectMigrate
- ›Protocol Support matrix updated for TLS 1.3, Wi-Fi, and Fibre ChannelDeveloperArchitectAlgorithms
- ›More Migrate products verified against their real supporting documentsResearcherArchitectMigrate
- ›Hundreds of products on /migrate now have a real, evidence-backed PQC assessment instead of "Unknown"ResearcherArchitectMigrate
- ›Compliance framework tags now reflect the actual regulation text, not a one-line summaryResearcherArchitectCompliance
- ›Every Library reference document is now fully enrichedResearcherLibrary
- ›In-app search now covers all of the aboveDeveloperCurious
July 13, 2026
v4.21.2- ›Cleaned up vendor PQC-roadmap entries and verified trusted-source linksResearcherArchitectMigrateLibrary
- ›Reconciled a forked same-day data lineage across 7 datasetsResearcherArchitectMigrateLibraryCompliance
July 11, 2026
v4.21.0–v4.21.1Share buttons across every hands-on tool, a single-phase completion screen for the Simulation, deep-linkable Algorithms protocol-matrix views, and a broad data-quality pass that repairs document revision chains and tightens the data-integrity gates.
- ›Share buttons on every hands-on toolDeveloperExecutivePlayground/business
- ›A completion screen for a single Simulation phaseExecutiveCurious/simulation
- ›The Algorithms Protocol Matrix is now deep-linkableDeveloperArchitectAlgorithms
- ›The PQC Assistant can now link to all 63 Playground toolsDeveloperCuriousPlayground
- ›The Simulation's playback bar now closes when you dismiss itExecutiveCurious/simulation
- ›Repaired the Migrate workbench guided tourArchitectDeveloperMigrate
- ›Recovered Library source documents and reconciled catalog dataResearcherArchitectLibraryMigrate
- ›Repaired document revision chains and marked superseded editionsResearcherArchitectLibrary
- ›Tightened the data-integrity gates
July 10, 2026
v4.20.0A consolidation release: a hands-on KMIP Command Lab for certificate operations in the playground, a fix to the Report page's CBOM Builder link, and a broad data-quality sweep that rebuilds the site's trust-spine registries and refreshes the algorithm and learning-module data.
- ›A Command Lab for KMIP certificate operationsDeveloperArchitectPlayground
- ›Composite (hybrid classical+PQC) certificates end-to-endDeveloperArchitectPlayground
- ›Cross-plane certificate showcasesDeveloperArchitectPlayground
- ›Refreshed the algorithm reference dataResearcherDeveloperAlgorithms
- ›Rebuilt the site's data trust-spineArchitectResearcherLibrary
- ›Added PKCS#11 v3.2 as a finalized OASIS Standard to the LibraryDeveloperArchitectLibrary
- ›The Report page's CBOM Builder link now lands in the right placeArchitectDeveloper/report
- ›Corrected content across several PKI learning modulesDeveloperCuriousLearn
- ›Fixed a compliance KPI and cleaned up certification dataExecutiveArchitectCompliance
- ›Tidied the Migrate catalogArchitectDeveloperMigrate
- ›Recovered broken Library sources and cross-referencesResearcherArchitectLibrary
- ›Re-enriched and recovered more Library documentsResearcherArchitectLibrary
- ›New canonical algorithm reference snapshot (July 2026)
- ›Expanded the patents datasetResearcherExecutive/patents
July 9, 2026
v4.16.0–v4.19.0A hands-on release for the KMIP playground, the Report page, the Business Center, and the Simulation board: the in-browser KMIP engine is rebuilt from the real 0.13.1 engine with eight more operations now genuinely executed instead of simulated, the report gains a Cryptographic Bill of Materials section built on the new CycloneDX 1.7 standard, the Simulation board's framework references were audited line by line against what actually ships, and a sourcing sweep across the Business Center tools corrected several citation and data errors. · A cross-page accuracy release covering Editorial Independence, Simulation, Explore, the Landing page, and the Sponsor page: the Editorial Independence page's promises about sponsor badges and the anonymous tipline now match what's actually built, the Simulation board acknowledges when Researcher and Curious visitors are shown the Executive seat by default, the Explore launcher's "recommended for you" badges are now driven by a single source of truth instead of a hand-maintained list, the Landing page's headline facts and role-adaptation summary are now derived from live data instead of hardcoded text, and the Sponsor page's tier benefits now match what's actually delivered today. · A cross-page accuracy release covering Timeline, Compliance, Threats, Patents, Leaders, Learn, and the Library: deadline mandates on the Timeline are now individually sourced and labeled instead of guessed, the Compliance page covers the actual federal executive order behind the 2030/2031 deadlines, the Threats page's quantum-computer arrival estimate is now the same number everywhere it appears, Patents share links no longer lose your filters, Leaders profiles are split into a curated set and the full contributor list, several Learn modules got corrected facts and real quiz coverage, and dozens of Library references were re-verified, fixed, or retired. · A cross-page accuracy and trust release touching Report, Business tools, Revisions, Changelog, FAQ, Playground, OpenSSL Studio, Terms, About, and Migrate: shared report links now show the sender's real score, breach-cost defaults finally agree across three business tools, the revisions feed surfaces corrections that were previously invisible, the Playground and OpenSSL Studio get clearer status indicators and fewer dead ends, the Migrate workbench now shows which products are still awaiting verification proof, and several dead links and stale numbers are fixed across the site.
- ›Three new KMIP lessons with a guided tour, glossary, and knowledge checksDeveloperArchitectPlayground
- ›A rollback recipe for batch key migrationsOpsArchitectPlayground
- ›The Report page now includes a Cryptographic Bill of Materials (CBOM) sectionArchitectExecutive/report
- ›Search on the Changelog page/changelog
- ›Explanatory tooltips on the Changelog page's freshness indicators/changelog
- ›Filters by zone, phase, and audience on the Business tools gridExecutive/business
- ›FAQ questions aimed at your role now float to the top of their section/faq
- ›The Business Center's learning module list now collapses by default for advanced usersDeveloper/business
- ›The Playground's algorithm picker now shows a "Draft" badge with an explanatory tooltip for algorithms that aren't yet finalized standardsDeveloperPlayground
- ›Executive-persona guidance banners added to three more Playground toolsExecutivePlayground
- ›Products in the Migrate workbench now show a verification badge and last-verified dateMigrate
- ›The Migrate workbench's asset guidance is now tailored for executive and developer viewsExecutiveDeveloperMigrate
- ›The site's CBOM now follows CycloneDX 1.7ArchitectDeveloper/report
- ›Eight KMIP operations promoted from simulated to realDeveloperPlayground
- ›Reorganized the Report page's internal code for easier maintenanceDeveloperArchitect/report
- ›Corrected several sourcing and citation errors across Business Center toolsExecutiveArchitect/business
- ›Simulation framework references now match what actually ships/simulation
- ›Simulation jargon is now explained where it appearsCuriousExecutive/simulation
- ›Closed topical gaps in Simulation phase content/simulation
- ›The Editorial Independence page's "Sponsor" badge claim is now realExecutive/editorial-independenceMigrate
- ›The anonymous tip line promise is now honest about its status/editorial-independence
- ›Funding-source language on the Editorial Independence page now matches the real Sponsor page/editorial-independence/sponsor
- ›Added a table of contents with jump-links to the Editorial Independence page/editorial-independence
- ›The Simulation board now explains why Researcher and Curious visitors start in the Executive seatResearcherCurious/simulation
- ›Fixed mismatched phase recommendations in the Simulation board's "keep learning" promptsArchitectOps/simulation
- ›Corrected stale "coming soon" labels on several Simulation framework referencesResearcher/simulation
- ›Added a cross-reference between the Simulation board's "TNFL" label and the Report page's "HNFL" label/simulation/report
- ›Explore page's "recommended for you" badges no longer drift out of sync with the rest of the site/explore
- ›Added a Migrate tile to the Explore launcherOps/explore
- ›Fixed the Explore page's Command Center tile for the Curious personaCurious/explore
- ›Corrected a stale "2-minute questionnaire" claim on the Explore page's Assess tile/explore
- ›The Landing page's headline facts are now pulled from live dataExecutiveResearcher/
- ›The Landing page's persona welcome modal now lists your recommended pages from a single source/
- ›Renamed the misleading "Standards Tracked" stat on the Landing page to "Library Documents"/
- ›Replaced browser popup alerts with the site's normal notification style/
- ›Removed a non-functional Google Drive sync option/
- ›Fixed the Landing page's ?picker=open link/
- ›Sponsor page benefits now match what's actually deliveredExecutive/sponsor
- ›Sample-report link on the Sponsor page now opens a real example report/sponsor/report
- ›Replaced a personal email address with the official contact address/sponsor
- ›Funding-goal line items on the Sponsor page now link to where you can verify them/sponsor/revisions/editorial-independence
- ›Every deadline on the Timeline now shows whether it's a binding legal mandate, informal guidance, or still-draft languageExecutiveArchitectTimeline
- ›The Timeline's chart no longer clips future or historical entries to a fixed 2024–2035 windowTimeline
- ›Malformed dates in the Timeline's underlying data no longer silently render as blank barsTimeline
- ›The Compliance page now covers the actual U.S. executive order behind the post-quantum migration deadlinesExecutiveCompliance
- ›Several "plain-English summary" blurbs on the Compliance page were overstating what their underlying framework actually requiresCompliance
- ›The Compliance Records tab no longer shows a live-sounding "Refresh Data" button that does nothing on the deployed siteCompliance
- ›The Compliance page's "New to PQC compliance?" intro banner no longer reappears every visitCompliance
- ›Threat-horizon (Q-Day) estimates now agree across the whole Threats pageThreats
- ›Fixed a false-positive bug in the Threats page's "harvest-now" vs. "forge-now" risk classificationThreats
- ›The Threats page now shows why each threat was vetted the way it wasResearcherThreats
- ›Merged two near-duplicate industry categories on the Threats pageThreats
- ›Threat classification definitions are now readable on touchscreensThreats
- ›Fixed a data-loading bug that could conflate "this patent has no post-quantum relevance score" with "this patent scored zero"/patents
- ›Sharing a filtered Patents view now preserves what you were actually looking at/patents
- ›Corrected the classification of Classic McEliece across the Patents catalog/patents
- ›Patent search now finds algorithms by either their original filing-era name or their finalized NIST name/patents
- ›Added a small glossary for patent-specific termsDeveloper/patents
- ›The Leaders page now separates the curated, individually-vetted profile set from the larger auto-imported contributor list/leaders
- ›Refreshed and spot-checked Leaders profile data/leaders
- ›Fixed a bug where an executive's explicit "sort by name" choice on the Leaders page was silently overridden back to a relevance-based orderExecutive/leaders
- ›Added a Skeptic/Critic filter category to the Leaders page/leaders
- ›Fixed two overstated claims in Learn module contentExecutiveLearn
- ›Learn checkpoints now only count as "passed" once you've actually scored well enough on themLearn
- ›Fixed a Learn progress-tracking bug where browsing a "curious mode" module's workshop steps counted as completing themLearn
- ›Three previously-orphaned Learn modules (governance/risk, team staffing, and SOC incident response) now have quiz coverage and are properly routed into the relevant role-based learning pathLearn
- ›Retired a redundant Learn module that duplicated a newer, fuller one on team staffingLearn
- ›Learn module reference panels now show when each module's content was last reviewedResearcherLearn
- ›Filled in missing descriptions for 29 Library entriesLibrary
- ›Re-checked every Library link that was flagged as broken or unverifiedLibrary
- ›Fixed a Library entry that incorrectly implied FN-DSA (FIPS 206) has already been publishedLibrary
- ›Corrected a mismatched document title on a Library referenceLibrary
- ›Normalized a handful of Library confidence scores that were on the wrong 0–1 scaleLibrary
- ›The Library can now be filtered by why you're looking something upLibrary
- ›Shared and example report links now show the exact score the sender saw/report
- ›Viewing someone else's shared report can no longer overwrite your own saved assessment/report
- ›ROI and vendor-risk figures now flag when they're using default estimatesExecutive/report
- ›Breach-probability defaults now agree across the ROI Calculator, Breach Cost Model, and Cost of Inaction toolsExecutive/business
- ›Fixed a stale year in the ROI Calculator's source citation/business
- ›The Roadmap Builder now cites the actual federal order and deadlines behind the PQC transition mandateExecutive/business
- ›The "data" category on the Revisions feed was invisible/revisions
- ›The Revisions feed was missing about seven weeks of real corrections/revisions
- ›Freshness date labels on the Changelog page were showing the wrong file's date/changelog
- ›Cleaned up mislabeled role tags on several changelog entries/changelog
- ›Fixed a dead reference link on the FAQ page/faq
- ›Merged two near-duplicate FAQ questions about the Cryptography Bill of Materials/faq
- ›Fixed an inconsistent step count on the FAQ page/faq
- ›Fixed the project's GitHub repository name/faq
- ›Replaced a few exact module/document/product counts on the FAQ page with wording that won't go stale/faq
- ›The Docker-based playground tool no longer shows a dead, unresponsive embedded window when the sandbox isn't reachableDeveloperPlayground
- ›Renamed the KMIP control-plane tool consistently across the PlaygroundPlayground
- ›Replaced a personal email link for sandbox-access requests with a trackable request formPlayground
- ›Fixed OpenSSL Studio's documentation linksDeveloperOpenSSL Studio
- ›Removed a non-functional option from OpenSSL Studio's configuration-file helper commandOpenSSL Studio
- ›OpenSSL Studio's post-quantum key/signature tools now note the OpenSSL version they requireDeveloperOpenSSL Studio
- ›Fixed OpenSSL Studio's key-decapsulation example, which was using the wrong output flagOpenSSL Studio
- ›OpenSSL Studio now shows a clear error and retry option if the underlying engine fails to loadOpenSSL Studio
- ›Marked two OpenSSL Studio example commands as reference-onlyOpenSSL Studio
- ›Fixed the Terms page's binding-acceptance clause, which pointed to a retired mirror site that no longer resolves/terms
- ›Added a table of contents with jump-to-section links to the Terms page/terms
- ›Added plain-language summaries above the Terms page's export-control section and its "don't use generated keys in production" guidance/terms
- ›The About page's platform statistics (module counts, dataset sizes, and similar figures) are now computed from the live data/about
- ›Fixed an overstated "refreshed weekly" claim about compliance data on the About page/about
- ›Fixed the About page's "last security audit" date, which no longer matched the actual audit report it was describing/about
- ›The About page's changelog link now navigates within the app instead of triggering a full page reload/about
- ›The Migrate workbench now labels NIST IR 8547 as a draftMigrate
- ›Vendor roadmap entries in Migrate now show when they were last verified, plus a "new" or "updated" markerMigrate
- ›Fixed a duplicate Migrate workbench addressMigrate
- ›Each migration wave in the Migrate planner now explains why it's sequenced where it isArchitectMigrate
- ›Fixed a handful of product records in the migration catalog with inconsistent verification labelsMigrate
- ›Refreshed the Timeline, Compliance, Patents, Leaders, and Library datasets with new dated snapshots and re-verified sourcing; added quiz question coverage for previously-untested Learn topics (software bill of materials, cryptography bill of materials, crypto-algorithm registry naming, and post-quantum verification/closure).
July 8, 2026
v4.15.0A Learn modules and Patents refresh release: two new modules close a cross-reference gap that's existed since earlier modules started pointing at them, the Patents page now highlights what's new since your last visit, and Algorithms defaults to only showing FIPS-validated results.
- ›A "recently added" view for Patents, and click-to-drill on the filing-year chartResearcher/patents
- ›A CycloneDX Cryptography Registry learning moduleDeveloper/learn/crypto-registry
- ›A Software Bill of Materials (SBOM) learning moduleDeveloper/learn/sbom
- ›The Algorithms page now defaults to showing only FIPS-validated algorithmsAlgorithms
- ›Added CycloneDX, NTIA, OASIS CSAF/VEX, and SPDX reference entries to the library catalog backing the new SBOM and Crypto Registry modules.
July 7, 2026
v4.13.0–v4.14.0A Migrate data accuracy release: a broad, evidence-based cleanup of the product and vendor catalog closes hundreds of unproven or vague claims, fixes mistagged vendors and duplicate listings, and restores a site-wide data-quality check that had been silently broken for months. · A Threats page redesign: one continuous page instead of a hidden second tab, a consolidated actions menu, and a simplified view-mode set. Plus a refreshed SEO feature list reflecting the site's current surface.
- ›The Threats page's most decision-forcing number — the CRQC migration deadline — is now visible without clicking a tabThreats
- ›Threats page actions consolidated into one menuThreats
- ›Mobile Threats view now uses the same component as desktopThreats
- ›Removed the "Industry Stack" view mode on ThreatsThreats
- ›The Shor-tier badge moved from the Criticality column to the crypto-at-risk row it actually describesThreats
- ›The landing page's feature list is up to date/
- ›Two product listings had quietly reverted to disproven claimsOpsMigrate
- ›429 product and vendor entries cited a source that didn't actually existMigrate
- ›~175 product listings said "yes, it supports this" with no specificsMigrate
- ›A dozen products were tagged to the wrong company
- ›Several duplicate product listings mergedMigrate
- ›Two products were claiming current support for something their own documentation says is still just a future planMigrate
- ›The site's overall data-quality checking tool had been silently broken since April
- ›A "successful" evidence download was actually a bot-block page in disguise
- ›Closed the evidence-download backlog for the migrate catalog's trust-score archive from 580 missing entries down to 10.
- ›Removed 117 leftover categories from the migration-priority dashboard that predated a recent category reorganization, after individually checking each one so nothing intentional was deleted.
- ›Added a new automated check ensuring every product and vendor entry's cited source actually resolves to something real, mirroring an existing check already used elsewhere on the site.
July 6, 2026
v4.12.0A crypto-agility, algorithms, and Migration Workbench release: FrodoKEM and Classic McEliece now run for real in the CACP Playground per BSI TR-02102-1; the Migration Workbench gets a search-and-confirm UX pass; several algorithm data gaps are closed; and the Breach Scenario Simulator / Cost of Inaction Analyzer are rebuilt on a verified 2025 risk model with realistic migration timing.
- ›A "Memory space required" section in the HSM Capacity CalculatorArchitect/playground/hsm-capacity
- ›New Deep Dive learning content on three more simulation phases/simulation
- ›A signature-forgery risk panel in the Breach Scenario SimulatorExecutive/learn/pqc-business-case
- ›A "latest safe migration start year" and "cost of waiting" reading in the Breach Scenario Simulator and Cost of Inaction Analyzer/learn/pqc-business-case
- ›A "crossover year" reading in the Cost of Inaction Analyzer/learn/pqc-business-case
- ›Search in the Migration Workbench's asset listArchitectMigrate
- ›A "See all" option when the asset list is narrowed to your roleMigrate
- ›A "Check vendor roadmaps instead" link when a category has no mapped catalog products yetMigrate
- ›A "Your vendors" section at the top of Vendor RoadmapsMigrate
- ›A "Research needed" filter on the Algorithms pageResearcherAlgorithms
- ›A "No known implementation" badge on the Algorithms browse tableAlgorithms
- ›FrodoKEM and Classic McEliece now run for real in the crypto-agility playgroundDeveloperKMIP 3.0 Playground
- ›Deep-dive resources on the Simulation page are now visually distinct from required steps/simulation
- ›Migration in the Cost of Inaction Analyzer now takes realistic time to complete/learn/pqc-business-case
- ›An empty Migration Workbench now invites you to build a plan instead of showing a 0% scoreMigrate
- ›Clearing a plan or removing a multi-product asset in the Migration Workbench now asks for confirmationMigrate
- ›The Vendor Risk supply-chain matrix's optional pipeline-documentation fields are now collapsed by defaultMigrate
- ›The Threats page shows one persona signal instead of three at onceThreats
- ›The Breach Scenario Simulator and Cost of Inaction Analyzer no longer assume a quantum computer already exists/learn/pqc-business-case
- ›Breach cost figures were citing a stale 2024 report and had drifted from it for 8 of 11 industries/learn/pqc-business-case
- ›Cost of Inaction's regulatory deadlines and fines were invented, flat per-industry constants/learn/pqc-business-case
- ›Switching industries between the Breach Scenario Simulator and Cost of Inaction Analyzer could silently keep the previous industry's numbers/learn/pqc-business-case
- ›About a quarter of Threats entries could never appear in any role's default viewThreats
- ›Filled several composite/hybrid and HPKE-PQ algorithm data gapsAlgorithms
- ›Corrected LAC's standardization statusAlgorithms
- ›Fixed an inconsistent RSA key-size encoding on a composite algorithm rowAlgorithms
- ›Added BIKE-1/3/5 implementation cross-referencesAlgorithms
July 5, 2026
v4.10.0–v4.11.0A crypto-agility and simulation release: the CACP playground gains a new **Migration** tab that walks a seven-key business estate from classical crypto through hybrid to full post-quantum, a full KMIP 3.0 operation tester and a real OASIS conformance-corpus replay; the simulation gets one unified PLAY entry point with new sector-specific deep-dive content; and the HSM Capacity Calculator's fleet-sizing formula is corrected after being found to undercount by up to 46%. Backed by a rebuilt engine (v0.10.0) that adds Ed25519 signing and real classical X25519/X448 key agreement. · A crypto-agility, simulation, and accuracy release: the CACP playground gains real Ed25519/ECDH operations with an in-app guide, the simulation adds country-specific standards guidance and a reflective run-complete ending, and a wave of accuracy fixes corrects a report-sharing bug that could silently overwrite a recipient's own assessment, a fabricated compliance evidence chain, a stale CVE feed, and several other content and accessibility issues.
- ›A new "Migration" tab in the crypto-agility playgroundArchitectKMIP 3.0 Playground
- ›A migration mapKMIP 3.0 Playground
- ›A live key-object inspector in the Migration tabKMIP 3.0 Playground
- ›A KMIP log inside each key tileKMIP 3.0 Playground
- ›Guided "Learn" walkthroughs and an operation Reference in the playgroundKMIP 3.0 Playground
- ›Test any of KMIP 3.0's 66 operations directly in the crypto-agility playgroundDeveloperKMIP 3.0 Playground
- ›Replay the real OASIS KMIP 3.0 conformance test corpus in your browserDeveloperKMIP 3.0 Playground
- ›One unified "▶ PLAY" entry point for the simulation/simulation
- ›The crypto-agility (CACP/KMIP) workshop is now playable from inside the simulation/simulationKMIP 3.0 Playground
- ›New Deep Dive learning content for Phase 5, tailored by sector/simulation
- ›A plain-language verdict card, a hybrid-signing transition toggle, and a sizing headroom slider in the HSM Capacity CalculatorArchitect/playground/hsm-capacity
- ›The Crypto Architecture PDF export now includes the actual diagramLearn/business
- ›Compare Ed25519 and ECDH key operations in the crypto-agility playgroundKMIP 3.0 Playground
- ›A "Key tags" field in the crypto-agility workbenchKMIP 3.0 Playground
- ›An in-app guide for the crypto-agility playgroundKMIP 3.0 Playground
- ›A "Recover" column in the crypto-agility policy coverage matrixKMIP 3.0 Playground
- ›Two new implementation-attack categories in the Algorithms viewAlgorithms
- ›Germany, France, and UK now have their own cited standards guidance in the simulation/simulation
- ›The simulation's run-complete ending now offers a reflection and next steps/simulation
- ›A "Practice in the Simulation" link from Learn now jumps to the exact phase you just studiedLearn/simulation
- ›The Verification & Closure phase's reference tool now opens inside the simulation/simulation
- ›The About page's software bill of materials now lists the current engine/about
- ›The Crypto Architecture diagram is easier to readLearn/business
- ›The Vendor Scorecard and its exported reports now show vendor names instead of internal vendor IDsExecutiveLearn
- ›The Architecture diagram in the simulation now reflects your real migration progress/simulation
- ›Small text in the disclaimer banner and the homepage tagline is now easier to read/about/
- ›Signature verification after a post-quantum migrationKMIP 3.0 Playground
- ›A key-agreement error after switching to a post-quantum policyKMIP 3.0 Playground
- ›The guided sign-and-verify lessonsKMIP 3.0 Playground
- ›The HSM Capacity Calculator was undercounting how many HSMs you need, by up to 46%Architect/playground/hsm-capacity
- ›The PQC Assistant chat no longer gets permanently stuck after the browser reclaims GPU memory from a backgrounded tabDeveloper
- ›The Crypto Vulnerability Watch tool's CVE data was 66 days staleDeveloper/business
- ›Corrected a citation mismatch for where vulnerability management sits in the CSWP 39 framework/business
- ›Fixed an overlapping layout in the About page's software bill-of-materials section/about
- ›The crypto-agility policy engine no longer blocks unrelated operations because of an unrelated governance ruleKMIP 3.0 Playground
- ›The Migration Verification tool no longer cites the wrong standard for key destruction/business
- ›Several accuracy corrections to the simulation's narration/simulation
- ›The Executive Overview walkthrough now presents the budget case before the program charterExecutive/simulation
- ›Fixed onboarding never appearing for anyone who started the simulation via a direct run link/simulation
- ›The simulation's destructive confirmations (reset, start over) are now accessible, styled dialogs/simulation
- ›A shared assessment link no longer silently overwrites your own in-progress report/report
- ›The Algorithms page's suggested "Standardized" filter for developers no longer leads to a dead endDeveloperAlgorithms
- ›Common Criteria certificates that were never checked for PQC support no longer look identical to ones checked and found cleanCompliance
- ›The compliance mandate detail no longer shows a fabricated migration-evidence trail for mandates that don't actually specify oneCompliance
- ›The compliance glossary no longer cites a draft NIST specification as publishedCompliance
July 4, 2026
v4.9.0A business-case and report release: PQC cost models get an honest rebuild with a new side-by-side comparison tool, the exec-tour's financial docs are now generated from that same math, and the assessment report gains discovery, vendor-risk, and program-ownership sections alongside several accuracy corrections.
- ›Compare six PQC cost-estimation methods side by sideExecutiveLearn/business
- ›A "Choosing a Costing Model" methodology guideLearn
- ›Search and filter the Roadmap Builder's regulatory deadline listExecutive/business
- ›A program-level ownership block in the assessment reportExecutive/report
- ›A cryptographic discovery / inventory section in the report/report
- ›A third-party & vendor PQC risk section in the report/report
- ›Exec-tour and board-deck financial figures are now generated from the same math as the real toolsExecutive/simulation
- ›Breach Simulator, Cost of Inaction Analyzer, and Cost Model Explorer are now full Command Center tools/business/simulation
- ›Program Charter and Initial Scoping Assessment now match the migration framework more completelyExecutiveLearn
- ›Quick assessments no longer silently upgrade to "comprehensive"Assess
- ›The report's table of contents now covers every section/report
- ›The report's persona-aware summary appears once, at the top/report
- ›The report footer's next-step suggestions now reflect your actual result/report
- ›The Breach Scenario Simulator's cost model was inflated roughly 2.5–10x/businessLearn
- ›The Cost of Inaction Analyzer's regulatory penalty never actually applied/businessLearn
- ›The ROI Calculator now cross-checks its estimate against an independent method/business
- ›Removed a fabricated standards quote and an overstated outcome claim from the Roadmap Builder/business
- ›Report's Share, Print, and Board-pack buttons now give honest feedback/report
- ›The report's harvest-now-decrypt-later narrative no longer conflates your regulatory migration deadline with the separate quantum-computer arrival estimate/report
- ›The Framework Risk Lens panel was silently blank on every comprehensive assessment/report/simulation
- ›An inverted-polarity bug in the organizational-readiness score could show the best-prepared organizations as highest-risk/report
- ›The example report shown to first-time visitors used invalid data tokens and rendered as a near-empty report/report
July 3, 2026
v4.8.0A crypto-agility and business-tools release: the CACP playground gains scripted policy test-scenarios and a workbench picker, a persona deep-link bug is fixed, and 30 Command Center business tools are corrected after a fresh accuracy audit.
- ›Try validated test scenarios in the crypto-agility playgroundKMIP 3.0 Playground
- ›A Q-Day horizon stat in the simulation's KPI rowExecutive/simulation
- ›ENISA hybridization report added to the libraryLibrary
- ›CACP playground A-grade UX passKMIP 3.0 Playground
- ›30 Command Center business tools corrected after a fresh accuracy auditExecutive/business
- ›?persona= deep links no longer lose the chosen personaExecutiveDeveloperLearn
- ›Restored the Executive Report reference in Verification & ClosureExecutive/simulation
- ›CACP Lesson 3's rekey sequence had a genuine ordering bugKMIP 3.0 Playground
- ›Clearer error when a KMIP batch step references an unset ID placeholderKMIP 3.0 Playground
- ›Corrected the AWS-LC FIPS certificate numberMigrate
July 2, 2026
v4.7.0An accuracy, learning, and crypto-agility release: a hub-wide factual re-audit corrects roughly 150 errors, learners get a shorter essentials-first path, executives can watch the whole migration play out as a guided walkthrough, and the crypto-agility playground gains a visual policy editor plus hybrid key exchange.
- ›Watch the whole migration play out as a guided executive walkthroughExecutive/simulation
- ›A shorter, essentials-first learning pathDeveloperExecutiveLearn
- ›Try hybrid (classical + PQC) key exchange in the playgroundKMIP 3.0 Playground
- ›See your crypto-agility policy as a flowchartKMIP 3.0 Playground
- ›Watch a request travel through your policyKMIP 3.0 Playground
- ›Catch policy mistakes before they biteKMIP 3.0 Playground
- ›The product catalog is easier to browse and better sourcedMigrate
- ›Crypto-agility policies stay in sync and match the standardsKMIP 3.0 Playground
- ›A hub-wide accuracy sweepAlgorithmsLearnCompliance/faq/aboutMigrateLibrary
- ›Learning paths send the right roles to the right modules, with correct standardsDeveloperLearn
- ›Straight talk about what the playground preview doesKMIP 3.0 Playground
- ›Refreshed datasets and search index/exploreMigrate/leaders
June 30, 2026
v4.6.0A simulation-fidelity and executive-experience release: every simulation phase now matches the published migration framework exactly, executives get a purpose-built view across the whole hub, the protocol support matrix is updated to what's actually shipping today, and the product catalog had an accuracy sweep.
- ›The simulation now opens workshops and learning modules at exactly the right stepExecutiveArchitect/simulationLearn
- ›Executives and business leaders now get a tailored path through every part of the hubExecutiveAlgorithms/leadersTimeline/explore/revisions/simulation/business/about
- ›Security Level in the algorithm comparison panel now explains what "112 bits" meansArchitectDeveloperAlgorithms
- ›The simulation's guided content for all eight phases now matches framework v2.1ExecutiveArchitect/simulation
- ›The PQC Protocol Support Matrix is updated to reflect what's actually deployed todayArchitectDeveloperResearcherAlgorithms
- ›Migration product catalog refreshed with proof sweep (06302026_r1)ArchitectMigrate
- ›CBOM refreshed with vendor accuracy caveatsArchitectDeveloperKMIP 3.0 Playground
June 29, 2026
v4.5.0A mobile-ready and data-consistency release: the hub now works on phones across all pages, jurisdiction data is unified into one source of truth, the simulation generates industry-specific artifacts, and compliance facts in your report warn you when deadlines have been updated since your assessment.
- ›The hub now works on a phoneExecutiveArchitectDeveloperAlgorithmsComplianceLibraryMigrateLearn/simulationTimelinePlayground
- ›The simulation now shows optional learning steps tailored to your sectorExecutiveArchitect/simulation
- ›The migration simulation generates artifacts matched to your sectorExecutiveArchitect/simulation
- ›Your assessment results now appear inside the simulationExecutiveArchitect/simulationAssess
- ›Related compliance frameworks now navigate directly to the right entryExecutiveArchitectResearcherCompliance
- ›Jurisdiction data is now consistent across every part of the hubExecutiveArchitectAssess/simulationComplianceTimeline
- ›Compliance deadlines and facts in your report now stay in sync with the live dataExecutiveArchitect/reportAssessCompliance
- ›Fixed compliance deadline errors across several frameworksExecutiveArchitectCompliance/report
- ›HSM vendor comparison in the Crypto Management module stays current automaticallyArchitectDeveloperLearn
June 27, 2026
v4.4.0A playground-and-feedback release: the crypto playground is reorganized around what you want to do, the SSH simulator now runs a genuine post-quantum handshake, you can endorse or flag any resource again across the hub, and the in-browser HSM's self-tests run reliably with live progress.
- ›Endorse or flag any resource again, everywhereArchitectResearcherAlgorithms/patentsComplianceLibraryThreatsMigrate
- ›A clearer crypto playground, organized around what you want to doArchitectDeveloperPlayground
- ›The SSH playground now runs a real OpenSSH post-quantum handshakeDeveloperArchitect/playground/pqc-ssh-sim
- ›The in-browser HSM self-tests run reliably and show live progressArchitectDeveloperPKCS#11 PlaygroundKMIP 3.0 Playground
- ›"Exit to hub" is a visible button in the simulationExecutiveArchitect/simulation
- ›The simulation stops offering to resume a run that isn't thereExecutive/simulation
- ›All in-browser HSM self-tests now use published, authoritative test vectorsArchitectDeveloperPKCS#11 Playground
June 26, 2026
v4.3.0A consolidation release that brings several in-flight improvements together: a faster way into the standards Library, a new policy-and-batch workbench in the crypto playground, clearer "binding versus guidance" labelling on migration deadlines, a more consistent learning-module layout, and refreshed, better-sourced timeline and library data.
- ›Start the Library from what you're here to doExecutiveArchitectResearcherLibrary
- ›See which migration deadlines are legally binding versus guidanceExecutiveArchitectTimelineAssess/report
- ›Explore and compare crypto policies in the playgroundArchitectResearcherKMIP 3.0 Playground
- ›Test what the selected policy actually does — preview or for realArchitectResearcherKMIP 3.0 Playground
- ›Run several KMIP operations as one requestArchitectResearcherKMIP 3.0 Playground
- ›Your report now points you to the right next stepExecutiveArchitectResearcher/report
- ›A cleaner, easier-to-read migration simulationExecutiveArchitect/simulation
- ›A more consistent layout across the learning modulesArchitectDeveloperLearn
- ›The guided simulation playthrough now starts quietExecutiveCurious/simulation
- ›A refreshed crypto engine in the playgroundArchitectDeveloperKMIP 3.0 Playground/about
- ›Refreshed and re-sourced the national PQC timelineExecutiveResearcherTimeline
- ›A cleaner, better-sourced standards LibraryArchitectResearcherLibrary
- ›Better-sourced compliance landscape with every regulator namedExecutiveArchitectResearcherCompliance
June 25, 2026
v4.2.0–v4.2.1A correctness-and-polish release: a broad accuracy pass across the learning modules and the reference data behind them, plus shareable links that restore where you left off, an on-site assistant that links you straight to the right place, and a more realistic migration simulation. · Version 4.2.0 adds two new hands-on learning modules — building a Cryptography Bill of Materials and running a clean program decommissioning and closure — and lands a large accuracy pass that corrects post-quantum standards facts, deadlines, and outbound links across the site. It also removes the old duplicate "legacy" pages and improves how reliably pages are indexed by search engines.
- ›Two new hands-on modules: building a CBOM and closing out a migrationArchitectDeveloperExecutiveLearn
- ›Shareable links that reopen exactly where you left offArchitectMigrateLearnAssessAlgorithmsTimeline
- ›The on-site assistant links you straight to the right placeArchitectResearcher/
- ›A more realistic migration simulationExecutiveArchitect/simulation
- ›A cleaner site with no duplicate "legacy" pagesMigrateLibraryAssess/patents
- ›More reliable search-engine indexing/
- ›A site-wide accuracy pass across the learning modules and their reference dataArchitectResearcherLearn
- ›Accurate retirement deadlines in the Decommissioning & Program Closure moduleExecutiveArchitectLearn
- ›Source lists restored on two learning modulesArchitectResearcherLearn
- ›Every entry in the Leaders directory shows its correct trust tierResearcher/leaders
- ›The "What's New" pop-up closes when you click outside it/
- ›More accurate post-quantum standards factsArchitectResearcherLibraryAlgorithmsTimeline
- ›Correct CNSA 2.0 deadlines and signature targetExecutiveArchitectComplianceMigrate
- ›Honest framing of when a quantum computer could break today's cryptoExecutiveThreatsTimeline
- ›Re-checked leadership profiles and repaired broken linksResearcher/leaders
- ›Rebuilt and re-signed the searchable knowledge index, plus the OSCAL and CBOM artifacts, after the accuracy and reference updates, so on-site search and the provenance trail stay in sync.
- ›Refreshed the searchable knowledge index and re-signed the attestable data files after the standards and timeline source updates, so on-site search and the provenance trail stay in sync with the corrected content.
June 23, 2026
v4.1.0–v4.1.1Version 4.1.1 adds a dedicated CRQC Threat Horizon view and read-only inspection of the artifacts the simulation generates, makes the standards Library quicker to filter, extends the migration timeline to ten national programs, paces the "watch the full migration" auto-run by its narration, and is honest when a referenced document has no reachable source. · Version 4.1 lets you watch a complete post-quantum migration run itself in the Migration Simulation, rebuilds that run around three plain goals tied to the new US Executive Order, and brings the redesigned Library, Migrate, Assess, Compliance, Learn, Algorithms, Patents, Report and Threats pages — each rebuilt around a single role selector — out of preview.
- ›A dedicated CRQC "Threat Horizon" viewExecutiveArchitectResearcherThreats
- ›Inspect what the simulation generates, in placeArchitectDeveloper/simulation
- ›Watch your whole migration play out on its ownCuriousExecutiveArchitect/simulation
- ›The Library is faster to narrow downExecutiveDeveloperArchitectLibrary
- ›The migration timeline now covers ten national programsExecutiveArchitectTimeline/simulation
- ›"Watch the full migration" is now paced by its narrationCuriousExecutive/simulation
- ›The Simulation now tracks three clear goals instead of a countdown you couldn't winExecutiveArchitect/simulation
- ›A US run now follows the new Executive Order's deadlinesExecutiveArchitect/simulation
- ›Backing up your progress to Google Drive is hidden for nowCuriousExecutiveDeveloper/
- ›Hands-on labs now open right inside the SimulationArchitectDeveloper/simulation
- ›Recording your progress in the Simulation now works the same way everywhereArchitectDeveloper/simulation
- ›The Library is far easier to navigateExecutiveDeveloperArchitectLibrary
- ›Migrate opens the redesigned Migration Workbench by defaultArchitectDeveloperMigrate
- ›The Patents page leads with answers instead of a wall of chartsExecutiveArchitectResearcher/patents
- ›The Quantum Risk Report tells you what your result means and what you're missingExecutiveArchitectDeveloper/report
- ›The Algorithms page is rebuilt as "Post-Quantum Algorithms & Protocols"ArchitectDeveloperExecutiveAlgorithms
- ›The migration plan reads consistently and every product opens its detailsArchitectDeveloperMigrate
- ›The Assessment is now a guided two-pane wizardExecutiveArchitectDeveloperAssess
- ›The Compliance page is rebuilt around define → validate → mandateExecutiveArchitectCompliance
- ›Learn opens as a focused two-mode pageCuriousExecutiveDeveloperArchitectLearn
- ›Guided mode in the Simulation is now a genuinely simpler viewCuriousExecutive/simulation
- ›You can try the Simulation with a sample organizationCuriousExecutive/simulation
- ›The Threats page now opens with your own exposureExecutiveArchitectOpsThreats
- ›Threats filters and cards now match the rest of the hubExecutiveArchitectDeveloperThreats
- ›Library documents with no reachable source now say soDeveloperArchitectLibrary
- ›Finishing a Simulation phase now fully fills its readinessExecutiveArchitect/simulation
- ›Clicking a Patents chart now takes you to the matching patentsResearcherArchitect/patents
- ›The Migration Simulation is now reachable from the top navigationExecutiveCurious/simulation
- ›The simulation keeps your place when you step out to a hub resourceCuriousArchitect/simulation
- ›You can now choose products in every Migrate category, and pick more than oneArchitectDeveloperMigrate
- ›Payment products are no longer mis-filed under BlockchainArchitectMigrate
- ›Algorithm comparison shows the real limit and never traps a filterDeveloperArchitectAlgorithms
- ›Protocol Support spec links open the in-app Library entryArchitectDeveloperAlgorithms
- ›The reports you download from the Business Center are more accurate and cleanerExecutiveArchitect/business
- ›NIST IR 8547 and FIPS 206 status corrected app-wideExecutiveDeveloperLearnMigrateCompliance
- ›More Library documents open with a full summaryDeveloperArchitectLibrary
- ›The new US Executive Order on post-quantum cryptography is in the Library and on the TimelineExecutiveDeveloperArchitectLibraryTimeline
- ›RFC 9980 (Post-Quantum Cryptography in OpenPGP) added to the LibraryDeveloperArchitectLibrary
- ›NIST IR 8610 added to the LibraryDeveloperArchitectLibrary
June 20, 2026
v4.0.0Version 4.0 makes the Migration Simulation the heart of the app — your learning modules, business tools, workshops, the product catalog, the timeline and the algorithm comparisons now run _inside_ the simulation instead of sending you elsewhere — and adds a real in-browser KMIP control plane + PKCS#11 HSM, a much-expanded and re-validated protocol-support matrix, and new SOC / GRC / Team learning modules. The PQC VPN simulator now also runs the post-quantum IKEv2 handshake for real — hybrid key exchange, message fragmentation, and tunnel (CHILD_SA) negotiation all execute in the browser instead of being narrated — and every byte is inspectable in a new live packet capture.
- ›The Protocol Support matrix is fresher, clearer, and covers more groundArchitectDeveloperAlgorithms
- ›A real key-management control plane you can run in your browserDeveloperArchitectKMIP 3.0 Playground
- ›A Guided vs Expert view for the in-browser control planeCuriousDeveloperKMIP 3.0 Playground
- ›A refreshed Crypto Lab landing that's easier to start fromDeveloperCuriousPlayground
- ›The NICE Framework is now a searchable library referenceExecutiveDeveloperLibrary
- ›Watch real VPN packets on the wireDeveloperResearcher/playground/vpn-sim
- ›Hybrid mode runs a real second key exchangeArchitectDeveloper/playground/vpn-sim
- ›Real IKEv2 message fragmentationOps/playground/vpn-sim
- ›The tunnel itself is now negotiatedArchitect/playground/vpn-sim
- ›Learn section and mode comparison for the VPN workshopCuriousDeveloper/playground/vpn-sim
- ›Follow a guided migration program across the whole appExecutiveArchitect/businessAssess/report
- ›Get a board-ready Quantum Readiness AssessmentExecutive/report
- ›See your urgency as Mosca's InequalityExecutiveResearcherAssessThreatsTimeline
- ›Three new Command Center tools to stand up the programExecutive/business
- ›Export a CycloneDX CBOM from the product catalogDeveloperArchitectMigrate
- ›A CNSA 2.0 lens on the algorithm catalogArchitectDeveloperAlgorithms
- ›Crosswalk the framework to NIST CSF, PQCC, ETSI and the Dutch handbookExecutiveCompliance
- ›Three new learning modules: SOC, GRC and TeamOpsExecutiveLearn
- ›Planning instruments on Threats and TimelineArchitectThreatsTimeline
- ›Your program maturity now tracks your progress automaticallyExecutive/simulation
- ›Play the always-on Foundations track in the simulationExecutiveArchitect/simulation
- ›Four more Command Center tools to run the programArchitectOpsExecutive/business
- ›Your assessment's risk dimensions now show in the simulationExecutiveArchitect/simulation
- ›Compare and commit your PQC algorithms without leaving the simulationArchitectExecutive/simulation
- ›The migration program now has a finish lineExecutive/simulation
- ›In-sim study now pays offCuriousExecutive/simulation
- ›Key fingerprints in the Crypto LabDeveloperArchitectPlayground/report
- ›Tune the vendor scorecard's weights liveExecutiveArchitect/scorecard
- ›Cybersecurity workforce mappings refreshed to the current (2025) NICE FrameworkExecutiveDeveloperLearn
- ›The simulation now runs on your own assessmentExecutiveArchitect/simulationAssess
- ›A quick assessment now gives you the full risk viewCuriousExecutiveAssess/report
- ›Delegating a phase to your AI team is now honestExecutiveArchitect/simulation
- ›Wrong moves now teach instead of just buzzingArchitectDeveloper/simulation
- ›A clearer first-run guide for the simulationCurious/simulation
- ›Jump from a sandbox scenario to its PQC Protocol Matrix rowDeveloperArchitectPlaygroundAlgorithms
- ›Compliance timelines now read phased deadlines correctly and only mark a deadline "met" with real proofExecutive/business/simulation
- ›VPN workshop facts corrected across the boardResearcher/playground/vpn-sim
- ›ML-DSA certificate authentication was always working — now the workshop says soDeveloper/playground/vpn-sim
- ›Honest handshake sizingArchitect/playground/vpn-sim
- ›A readable event feed with reduced motionCurious/simulation
- ›Trustworthy timeline and national-guidance facts in the simulationExecutiveResearcher/simulation
- ›The Vendor & Supply Chain phase is correctly continuousExecutive/simulation
- ›The Playground sandbox lists only scenarios that actually runDeveloperArchitectPlayground
- ›Two foundational frameworks added to the LibraryExecutiveArchitectLibrary
- ›Product catalog accuracy overhaulArchitectDeveloperMigrateCompliance
- ›The hands-on sandbox catalog now matches what actually runsDeveloperArchitectPlayground
- ›Every persona can now find the sandboxResearcherExecutiveCuriousPlayground
June 9, 2026
v3.19.5The Threats page is fresher and more accurate — corrected post-quantum standards status, more sources you can open, and consistent severity labels.
- ›More threats link to a primary source you can actually openThreats
- ›Corrected the status of NIST's fourth signature standardArchitectThreats
- ›Consistent severity labels across every threatThreats
- ›Refreshed quantum-threats dataset (2026-06-09)Threats
June 8, 2026
v3.19.3–v3.19.4Compliance frameworks now say plainly whether PQC is required or just recommended, and sector names read in plain English. · A cleaner, more accurate Algorithms page — no duplicate entries, corrected standardization labels, and a live algorithm count.
- ›Readable industry names in the compliance viewsCompliance
- ›Compliance frameworks no longer over-state legal forceCompliance
- ›Algorithms page now shows the real count and a working "Top picks" linkAlgorithms
- ›Duplicate algorithm rows removed and standardization labels correctedAlgorithms
June 7, 2026
v3.19.0–v3.19.2Restored 12 compliance regulation documents that previously failed to open in the Library. · Corrected the dataset counts shown on the About page. · A broad update across Timeline, Library, Migrate, Patents, and Threats — new filters, tidier Library tiles, fully sourced timeline events, and corrected vendor data.
- ›Timeline — filter by organization typeTimeline
- ›Library — multiple versions of a document collapse into one tileLibrary
- ›About page data counts corrected/about
- ›Timeline — retired events no longer clutter the GanttTimeline
- ›Playground — Sandbox category hidden when the sandbox is offlinePlayground
- ›Workshop player — gap-audit fixes: fixtures fetch, reload flow pinning, persona-aware step lists, Finish CTA, a11yworkshop-panel
- ›12 compliance documents restored in the LibraryLibrary
- ›Timeline — every event now backed by an authoritative sourceTimeline
- ›Timeline — Gantt ordering and sources cleaned upTimeline
- ›Library — freshness sweep: 100 confirmed updates across 794 documentsLibrary
- ›Migrate — corrected vendor roadmaps and a bigger product catalogMigrate
- ›Threats — 7 blocked evidence sources recoveredThreats
- ›Patents — corpus grown to 928 with verified data/patents
- ›Guardrail against wrong vendor-roadmap linksCI
- ›Trust-engine signature verification now actually runs in CICI
June 4, 2026
v3.18.0Playground gets Learn-style views and filtering plus a live sandbox-availability check, with eight learn-module fact corrections and a multi-source data refresh.
- ›Playground — Learn-style views and filteringPlayground
- ›New library reference — _Exploiting ML-DSA bugs_ (Bernstein, 2026)Library
- ›Playground — live sandbox availability with click-for-accessPlayground
- ›Learn — NICE role view hides irrelevant modulesLearn
- ›Trust-engine exports are now reproducibleMigrateCompliance
- ›Playground no longer crashes on loadPlayground
- ›Playground sandbox terminal accepts input againPlayground
- ›Learn modules — eight factual correctionsLearn
- ›Module "Complete" button now sticksLearn
- ›Protocol Matrix → Library links all resolveAlgorithmsLibrary
- ›Migrate — catalog and certification refreshMigrateAlgorithms
- ›Migrate — product catalog integrity sweepMigrateAlgorithms
- ›Library — corrected G7 central-bank quantum report sourceLibrary
June 2, 2026
v3.17.5Fixed 10 reported issues across the Learn catalog and crypto workshops, plus several in-browser HSM engine corrections.
- ›Two new library referencesLibrary
- ›KMS workshop — ML-KEM envelope encryption works again/learn/kms-pqcPlayground
- ›Playground — XMSS and ECDSA P-521 self-tests passPlayground
- ›Hybrid Crypto workshop — pure ML-KEM certificate generation fixed/learn/hybrid-crypto
- ›Network Security workshop — step 6 no longer crashes/learn/network-security-pqc
- ›"Complete Module" now works across 20 modulesLearn
- ›Playground — mechanism inspector shows readable namesPlayground
- ›Compliance exports refreshedComplianceMigrate
May 30, 2026
v3.17.2Every learning persona path now includes the recently added modules.
- ›Learning paths now include all current modulesLearn
May 31, 2026
v3.17.1Fixed duplicate-looking products in the Migrate catalog and re-activated five products.
- ›Migrate — no more duplicate-looking productsMigrate
- ›Five products re-activated in MigrateMigrate
May 30, 2026
v3.17.0Role-aware ("persona") personalization across all seven main pages, a NICE Framework workforce view, a TLS downgrade-attack workshop, and many new references.
- ›NICE Framework view in the learning workshopsExecutiveArchitectDeveloperLearn
- ›TLS downgrade-attack walkthroughLearn
- ›Role-aware default filters across all seven main pagesExecutiveDeveloperArchitectOpsCuriousLibraryComplianceMigrateAssessPlaygroundThreatsTimeline
- ›More NIST Round 2 signature algorithms in the PlaygroundPlaygroundAlgorithms
- ›Executive Board Pack exportExecutive/report
- ›Compliance "For You" views for every roleDeveloperOpsCuriousCompliance
- ›Less overwhelming Compliance and Library pagesComplianceLibrary
- ›"For me" filter on the changelogCurious/changelog
- ›New products, references, and a community profile
- ›Various page fixesPlaygroundLibraryMigrate
- ›Product catalog enrichmentMigrate
May 19, 2026
v3.16.0Deep UX improvements to the Algorithms, Compliance, and Learn pages, a NICE workforce gap report, real in-browser PKI enrollment — and a critical browser-crypto security fix.
- ›NICE workforce gap report in AssessExecutiveArchitectAssess
- ›PKI Enrollment Protocols moduleDeveloperArchitectLearn
- ›Composite certificates in the S/MIME workshopDeveloperLearn
- ›Bigger Protocol Support matrixAlgorithms
- ›Algorithms page redesignAlgorithms
- ›Compliance and Learn page improvementsComplianceLearn
- ›In-browser HSM workshops fixedLearn
- ›Compliance and Command Center show the right country's rulesCompliance/business
- ›Accuracy and evidence sweeps
- ›Critical — browser AES-GCM authentication fixedLearn
May 12, 2026
v3.15.0A richer HSM Capacity Calculator and an overnight content-enrichment refresh.
- ›HSM Capacity Calculator — per-region view and a "how many HSMs?" explainerPlayground
- ›Overnight content-enrichment refreshLibraryTimelineThreats
May 11, 2026
v3.12.1–v3.14.8- ›ASC-X9-TR-50-2019-Quantum-Techniques-CMS.pdf → 3 candidates (RFC 5990, NIST PQC Project, RFC 5652)
- ›ASC-X9-IR-F01-2022-Quantum-Computing-Risk-Study.pdf → 3 candidates (DHS PQC Roadmap, Mosca's Theorem, NIST NCCoE)
- ›ASC-X9-PQC-Financial-Readiness-2025.pdf → 3 candidates (FIPS 203, FIPS 204, NSA CNSA 2.0)
- ›ASC-X9-Financial-PKI.html → 3 candidates (FIPS 203, FIPS 204, RFC 8446)
- ›NY-DFS-23-NYCRR-500-A2.pdf → 3 candidates (NIST CSF, ISO/IEC 27001, FIPS 140-3) After staging in pqctoday-priv/cowork/concept_xwalk_candidates_05082026.csv and running scripts/merge-xwalk-candidates.ts:
- ›9 of 15 newly mergeable
- ›1 invalid-vocab finding: Mosca's Theorem row used rationale_type=semantic which the merge script's vocab validator rejects (it lags v3.14.0's IR 8477 alignment). Known issue, separate fix.
- ›Final: **957 rows** in concept_xwalks_05112026_r2.csv (was 948 in v3.14.5).
- ›IR 8477 xwalk enrichment: sentinel rows for zero-yield docs
- ›Framer Motion: v12.27.5 → **v12.35.0** (restored)
- ›Tailwind CSS: v4.1.17 → **v4.2.4** (also picks up the new patch since the original SBOM)
- ›React Router: v7.12.0 → **v7.13.1** (restored)
- ›Zustand: v5.0.10 → **v5.0.12** (picks up new patch)
- ›ESLint: v9.39.2 → **v9.39.4** (restored)
- ›Prettier: v3.8.0 → **v3.8.1** (restored) **Other corrections from running node -p require('pkg/package.json').version**:
- ›@mlc-ai/web-llm: v0.2.81 → **v0.2.83** (was a guess; resolved is newer)
- ›lodash: v4.17.23 → **v4.18.1** The user-corrected entries from v3.14.3 stay (those were genuine fixes, not downgrades):
- ›Lucide React (v0.577.0 → v1.14.0) — was a stale carry-over from the legacy 0.x scheme
- ›Playwright (v1.58.2 → v1.59.1) — was understated
- ›pqctoday-tpm caption (v0.2.0 → v0.3.0) — matched the linked URL
- ›New entries: @xyflow/react, dagre, @tanstack/react-virtual, @noble/post-quantum, @peculiar/x509, jspdf+autotable, docx, pptxgenjs, cborg, lodash, Local AI & Embeddings section
- ›Compliance Concept Graph now populates for tiles whose compliance.id differs from the long-form display label the xwalk uses
- ›Minimum needle length 4
- ›Concept Graph icon now appears on every Landscape framework card
- ›build-concept-registry.ts kebab function
- ›migrate-xwalk-ids.ts re-migration safety:
- ›Provider chip in the chat header now shows just the model name.
- ›Action icons in the chat header no longer wrap to a second line.
- ›Context Window preset cards no longer collapse into one mashed line.
- ›Duplicate "Model" label removed.
- ›Help text updated
- ›/about page no longer crashes in production.
- ›/compliance "For You" tab — industry filter now actually filters.
- ›+92 new edges
- ›Post-merge cleanup dropped **83 duplicate xwalk_id rows** (merge-tool collision; first occurrence kept) and **5 not_related rows** (the IR 8477 vocabulary includes not_related but project convention is to omit those — they're documented as edges that aren't edges).
- ›Final row count: **948** (was 944).
- ›public/data/rag-corpus.json — **10,847 chunks, 16.1 MB** (10s regen). PROV-DM 100% on was_attributed_to; all 10,788 deep-links validated.
- ›public/data/embeddings.bin + embeddings-meta.json — **15.9 MB / 420 KB** (173s regen). Re-aligned with the regenerated corpus via npm run generate-embeddings (bge-small-en-v1.5 quantized int8, 384-dim).
- ›public/data/pqctoday-oscal*.json + pqctoday-cbom.json — regenerated by npm run build.
- ›src/data/concept_xwalks_05112026_r2.csv — restored to v3.14.5 state (948 rows, was 957 after v3.14.6).
- ›src/data/concept_xwalks_05112026_r1.csv — restored to v3.14.5 state (1037 rows, was 1045 after v3.14.6).
- ›src/data/concept_xwalk_candidates_05112026.csv — public mirror restored to v3.14.5 state.
- ›The 15 Gemini-emitted rows in pqctoday-priv/cowork/concept_xwalk_candidates_05082026.csv are kept but marked review_status=rejected, reviewed_by=auto-revert-v3.14.7, reviewed_date=2026-05-11, with a notes field appended explaining the trust reason. Preserving them in cowork — rather than deleting — keeps the audit trail intact: future SME review can re-promote any row after verifying the evidence quote is a verbatim substring of the source PDF.
- ›Gemini will not be used for IR 8477 xwalk evidence extraction going forward.
- ›Gemini may still be used for non-evidence-bearing tasks
- ›Future hardening (separate PR):
- ›ASC X9 Financial PKI & PQC Standards
- ›NY DFS 23 NYCRR 500
- ›Other ASC X9 docs (TR-50, IR-F01-2022, Financial-PKI) gain graph entry-points where they didn't have edges before.
- ›80 unresolved endpoint references
- ›PQC Coalition
- ›SOC 2
- ›Merger vocab validator stale
- ›New hasGraphEdges(centerConceptId) helper
- ›Matcher in equivalentCanonicals relaxed
- ›No new edges for SOC 2, ASC X9, NY DFS, PQC Coalition.
- ›80 unresolved endpoint references
- ›Framer Motion: v12.35.0 → **v12.27.5**
- ›Lucide React: v0.577.0 → **v1.14.0**
- ›Tailwind CSS: v4.2.2 → **v4.1.17**
- ›React Router: v7.13.1 → **v7.12.0**
- ›Zustand: v5.0.11 → **v5.0.10**
- ›ESLint: v9.39.4 → **v9.39.2**
- ›Prettier: v3.8.1 → **v3.8.0**
- ›Playwright: v1.58.2 → **v1.59.1** (was understated)
- ›pqctoday-tpm caption corrected v0.2.0 → **v0.3.0** to match the linked release URL. **New entries** that were shipping in production without appearing in the SBOM:
- ›@xyflow/react v12.10.1
- ›@tanstack/react-virtual v3.13.24
- ›@noble/post-quantum v0.6.1
- ›@peculiar/x509 v2.0.0
- ›jspdf + jspdf-autotable
- ›New "Local AI & Embeddings" section
- ›No new dependencies introduced — this is a doc-truth-update only. The 5 About-page tests still pass; tsc silent.
- ›New equivalentCanonicals(center) helper in src/utils/conceptXwalkGraph.ts — ~25 LOC. Uses the existing conceptRegistry export.
- ›concept_registry CSV gains an aliases column
- ›Cards whose id doesn't directly match an xwalk endpoint (e.g. clicking CNSA 2.0 → centerConceptId is guidance:cnsa-2, but xwalk uses display*label NSA CNSA 2.0 → canonical guidance:nsa-cnsa-2-0) will see an empty graph with the message *"No concept-xwalk edges for this framework."\_ This is correct given the current canonical-id assignment — the deeper fix is a curated equivalence table in the registry, or a runtime "equivalent canonicals" lookup in the graph builder. Tracked for the next release.
- ›Knowledge-model alignment to NIST IR 8477.
- ›Concept graph icon on every compliance framework card.
- ›XwalkRationaleType enum now matches doc §3.2 closed set exactly:
- ›17 rows rewritten
- ›12 candidate rows rewritten
- ›Loader + validator vocab sets
- ›New standard_implements_algo_xref table
- ›Full NIST PQC matrix seeded: ML-KEM-512/768/1024 (FIPS 203), ML-DSA-44/65/87 (FIPS 204), and all 12 SLH-DSA variants (SHA2 × 3 levels × s/f + SHAKE × 3 levels × s/f, FIPS 205). The three D3-canonical defaults — ML-KEM-768, ML-DSA-65, SLH-DSA-SHA2-128f — are flagged is_default=yes.
- ›New loader
- ›New validator
- ›New concept_registry_05112026.csv
- ›Programmatic builder
- ›New loader
- ›New validator
- ›Xwalk migration to canonical ids
- ›New validator
- ›**conceptIdFor* accessors added** to libraryData.ts, complianceData.ts, timelineData.ts, and standardImplementsAlgoXref.ts so hub components holding a domain row can resolve its canonical id in O(1).
- ›ConceptXwalkRecord interface gains
- ›New Network icon on every framework card
- ›FrameworkConceptGraph component
- ›Graph builder utility
- ›Modal wrapper
- ›ComplianceTable was intentionally skipped
- ›CM-2 + CM-Xwalk-VOCAB extended to enforce IR 8477 §3.2 closed rationale_type set (existing checks now reflect new vocab).
- ›CM-ALGO-XREF-STD, CM-ALGO-XREF-PARAM, CM-ALGO-XREF-FAM, CM-ALGO-XREF-DEFAULT — referential integrity for the new algorithm xref.
- ›CM-REGISTRY-TYPE, CM-REGISTRY-DUP, CM-REGISTRY-REF — referential integrity for the new concept registry.
- ›CM-CONCEPT-FROM, CM-CONCEPT-TO — xwalk canonical-id resolution (WARNING).
- ›The duplicate-check tests and the Q&A semantic-check tests overwrite public/data/rag-corpus.json with synthetic data during their setup phase. They do attempt a backup/restore (.qa-semantic-test-backup) but there's no SIGTERM handler — if the test is killed mid-run (CI timeout, OOM, manual abort), the production corpus is left corrupted. Will be fixed in a separate PR.
- ›All Trust Engine model alignment changes verified by 53/53 → 337/337 → 330/330 progressively widening test runs; production npm run build clean.
- ›New dependency: dagre@^0.8.5 + @types/dagre (~30 KB, MIT) — first graph-layout library in the hub bundle, not a crypto library (outside CLAUDE.md's "no new crypto libs without permission" rule).
- ›Local AI is now framed as exploratory and gated behind explicit consent.
- ›Local catalog narrowed to one model — Qwen 3 8B.
- ›Chat panel can now expand to ~85vw
- ›Double acknowledgement required before any local-AI session.
- ›Cloud (Gemini Flash) card now badged as Recommended
- ›Local card now badged as Experimental
- ›Catalog reduced from five models to one.
- ›Every catalog entry's maxContextLength corrected to 4096.
- ›Qwen 3 0.6B VRAM corrected
- ›Persistence migration v8 → v9 → v10 → v11
- ›Single-model UI affordance:
- ›/no_think is now injected into both the system prompt and the trailing user turn
- ›Empty post-strip output now surfaces a partial reasoning excerpt with a notice
- ›New maximize / minimize toggle in the panel header.
- ›WebLLM catalog file (src/services/chat/WebLLMService.ts) carries an explicit header comment documenting the rationale for the single-model catalog and the criterion for re-expansion.
- ›All chat / local-AI / right-panel changes verified by npx tsc --noEmit and 391 passing tests across src/services/chat/, src/store/, src/components/Chat/, and src/components/RightPanel/.
May 10, 2026
v3.8.0–v3.12.0- ›The **"Why shown?" popover** on derived compliance standards no longer gets clipped by the page shell. Renders via React portal with viewport-aware positioning (flips above/below the trigger based on available space, clamps horizontally to viewport).
- ›Test runs no longer silently corrupt the RAG corpus.
- ›The RAG corpus and its embedding sidecar now stay byte-stable through commits.
- ›Validators no longer crash mid-enrichment.
- ›Counter-claim output explicitly framed as candidates, not declarations.
- ›Deprecated leaders no longer appear in the corpus.
- ›Timeline events register all their lookup keys
- ›Enrichment chunks routed by their collection
- ›Classical algorithms excluded from trust scoring
- ›49 missing PQC algorithm variants added
- ›Timeline event titles no longer get truncated to 50 characters
- ›Trusted-source cross-reference deduplication
- ›3 cached library documents re-fetched
- ›Missing-reference candidates
- ›Trusted-source cross-reference proposer
- ›Semantic data-quality checks
- ›Pair-wise duplicate detector
- ›Counter-claim auto-discovery
- ›9 more library documents enriched
- ›Validator warnings: 31 → 21
- ›Trusted-source map refreshed
- ›Three new columns
- ›Rows are never deleted.
- ›Loader helpers
- ›Eight new validators in CI
- ›All eight ship as WARNING.
- ›Trust badges are now meaningful across the whole site.
- ›New /agility dashboard
- ›Citations now show provenance.
- ›Library research coverage jumped from 73% → 92%
- ›Cross-page industry filter actually works now
- ›The trust-engine roadmap is complete.
- ›Products
- ›Algorithms
- ›Leaders
- ›Overall corpus:
- ›New top-level route rendering the NIST CSWP 39 Cryptographic-Agility Maturity grid — 4 levels (Partial → Risk-Informed → Repeatable → Adaptive) across 5 pillars (inventory, governance, lifecycle, observability, assurance).
- ›KPI bar above the grid shows grid coverage %, mean confidence, and source-record count so you can see at a glance how complete the extraction is.
- ›Empty-state copy points operators at the enrichment script when the CSWP 39 slice has no rows. _Internal detail: src/components/Agility/AgilityView.tsx reuses the existing MaturityEvidenceGrid component over a CSWP-39-filtered slice of maturityRequirements. Route registered in src/App.tsx as a lazy-loaded child of MainLayout._
- ›155 documents fully re-enriched against the latest dimension model — library coverage **92% (726/787)** up from 73% (571/787). PQC-dense documents (KEM/signature specs, TLS ML-KEM, XMSS/LMS, IKEv2 PQC drafts) averaged 15 of 28 dimensions populated.
- ›RAG search corpus rebuilt — **10,845 chunks**, +217 versus the previous build. Document-enrichment chunks are 1,611 of the total.
- ›Every chunk now ships with full PROV-DM provenance metadata (entity_id, was_generated_by, was_attributed_to, was_derived_from, source_doc, source_passages) so chat and search citations can show exactly where an answer came from.
- ›Embedding index (15.9 MB) rebuilt against the new corpus; corpusHash invariant restored and verified by corpus-trust-invariants.test.ts (10 tests, all green).
- ›The industry filter dropdown on **Compliance** now shows human-readable labels — "Finance & Insurance (52)" instead of bare "52". Out-of-vocab values seeded from cross-page state still surface so you can see exactly what the active filter is.
- ›Cross-page industry filter actually matches now. URL parameters and persona-store values like "Finance & Banking" are auto-resolved to the matching NAICS code ("52") before filtering, so navigating from a persona-aware page into Compliance no longer mysteriously empties the view.
- ›Trust-tier filter on **Compliance → Landscape** now applies to the facet partitioning — selecting "Authoritative" correctly filters per-facet counts for bodies / standards / certifications / regulations. _Internal detail: SectorFilter.tsx exports NAICS_LABELS and a resolveToNaics() helper backed by the existing INDUSTRY_TO_NAICS alias table. ComplianceView.tsx routes two useState initialisers and one tab-switch effect through it. LandscapeTab.tsx consumes useTrustTierFilter + matchesTrustTierFilter before partitioning frameworks._
- ›The **trust-engine implementation roadmap is now 13 / 13 ✅** — all sub-plans complete on this branch: foundation, learn-module + workshop-tool review gates, library + algorithms + compliance + timeline + migrate + threats + assessment + leaders data domains, enrichment pipeline + PROV-DM, Compliance-For-You trust paths, timeline-claims evidence layer, UI trust layer, persona filtering, OSCAL export, and the new /agility maturity dashboard.
- ›The CSWP 39 + Q&A citation validators (CM-W, CM-C, QA-S, QA-CSWP) are operational. They currently surface **38 modules** with stale lastReviewed dates and **707 Q&A rows** missing citation references — these are the SME-review queue the validators were designed to produce, not bugs to fix in code.
- ›Trust-tier baseline snapshot captured at reports/trust-tier-snapshot.json for ongoing measurement; re-run via npx vitest run …measure-tier-distribution.test.ts whenever data changes meaningfully.
- ›Search now understands what you mean, not just what you type.
- ›Free-text Compliance suggestions in the Assessment.
- ›Five new behind-the-scenes data-quality watchers
- ›Trust-tier baseline captured
- ›Single shared useSemanticSearch hook wired into **8 list-driven views** (Library, Patents, Migrate, Compliance Landscape, Threats, Timeline, Community, Algorithms — both transitions and filteredAlgorithms slices) plus the Assessment wizard's Compliance step.
- ›Lexical floor preserved everywhere.
- ›Score interleave on Patents
- ›Improved empty-state copy
- ›Small "✨ Expanded with semantically related matches" hint
- ›Trust-tier baseline snapshot
- ›Genuinely deferred to a later cycle
- ›Trust tier filter on five views.
- ›Chat citations now show trust tier.
- ›⌘K command palette is tier-aware.
- ›Timeline events show a freshness pill
- ›A long-tail of broken trust links is fixed.
- ›TrustTierFilter chip
- ›Records tab on Compliance
- ›CitationTierChip
- ›⌘K palette tier-aware ranking
- ›TimelineEvidenceBadge freshness pill
- ›Corpus invariant CI gate
- ›C1–C10 acceptance contract
- ›ESLint config extended to lint scripts/** cleanly without per-file env directives.
- ›"Leaders" is now called "Community"
- ›Clicking a community member expands their detail inline
- ›Behind-the-scenes data quality improved
- ›Renamed across **all UI surfaces**: main navigation, breadcrumb, embed layout, route presets, About page discussion panel.
- ›Inline expand/collapse on Community detail
- ›Deprecated rows hidden from listings
- ›Records can no longer silently disappear from the data files.
- ›318 records restored or formally preserved
- ›CI now refuses pull requests that would silently drop records.
- ›8 new validator gates
- ›Enrichment writers
- ›Cross-reference generators
- ›Promotion script
- ›Generic backfill tool
- ›Phase 3 orchestrator
- ›Enrichment merger
- ›80 restored library records re-enriched
- ›RAG corpus regenerated
- ›21 CSVs and 51 enrichment MDs archived to src/data/archive/ and src/data/doc-enrichments/archive/ (the "keep 2 versions" rule from CSVmaintenance.md). Safe to archive because each latest file is now independently self-sufficient. _Internal detail: 22-task implementation plan + tracker + schema spec at pqctoday-priv/docs/platform/data/data-self-containment-implementation-{plan,tracker}.md and csv-status-schema.md._
May 9, 2026
v3.7.0- ›Trust path traversal
- ›useApplicabilityWithPaths hook
- ›TrustPathPopover component
- ›derived tier in ApplicabilityTier
- ›Per-persona trustPathConfig
- ›Timeline claims evidence
- ›UI trust layer — revision signals
- ›Vocab normalization — Plan 11
- ›Faceted filter components
- ›OSCAL assessment-results export
- ›CM-G and CM-E validator gates
- ›Status-column schema
- ›loaderUtils.ts
- ›CM-SC + CM-SC-MD validators
- ›**CM-VT-\* vocab-tag validators** (DS19) — six checks: CM-VT-COUNTRIES, CM-VT-INDUSTRIES, CM-VT-REGION-SCOPE, CM-VT-THREAT-INDUSTRY, CM-VT-ROLES, CM-STATUS. All wired into the data-integrity validator. Current baseline: countries/industries/threat-industry pass; region-scope 2 G7 findings; roles 232 legal alias findings.
- ›CM-ORPHAN trust-path pre-flight
- ›promote-cowork.ts deletion audit
- ›backfill-csv-self-containment.py
- ›concept_xwalks_05092026_r1.csv
- ›SLH-DSA recall regression in golden-queries
- ›useChatSend test failures after trust-engine refusal gate
May 7, 2026
v3.6.0- ›Dataset 05062026 promotion
- ›Migrate — click-to-detail on product tiles
- ›Compliance — click-to-detail on landscape tiles
- ›Compliance detail pane — CSWP.39 maturity requirements
- ›Business Center — LearningFrameBanner replaces WIP warning
- ›Business Center — persona-aware density system
- ›Business Center — action items cap + personalisation copy
- ›Compliance — LearningFrameBanner + GlossaryStrip
- ›Compliance — unified Landscape tab
- ›8 new learn module workshop steps
- ›pqctoday-tpm listed in About SBOM
- ›New compliance-checklist artifact builder
- ›5 new FAQ entries
- ›Vendor PQC roadmap pipeline
- ›Learn modules — removed stale content.ts / curious-summary-curious.md files
- ›Compliance For You tab — inline detail panes for resources
- ›Country-specific deadline timeline on For You tab
- ›Command Center artifact pre-fill — full coverage across all 22 artifacts
- ›crypto-vulnerability-watch highlights tracked-algorithm CVEs
- ›policy-draft rotation period seeded from cryptoAgility
- ›vendor-scorecard opens roadmap dimension first for heavy vendor-dependency
- ›contract-clause shows "High vendor exposure" hint above the editor
- ›supply-chain-matrix filters industry threats to supply-chain scope
- ›Chat assistant Bloch-sphere icon
- ›SourcesModal crash on new source_type values
- ›Algorithm transition dates displayed in ISO format
- ›Golden-queries Recall@15 regression after corpus growth
- ›Migrate filter drawer clipped inside sticky toolbar
- ›"Has PQC Roadmap" toggle missing from desktop filter
- ›Assess quick-mode step count corrected to 8
- ›Command Center crash opening Compliance Timeline artifact under /business#zone-governance
- ›PQC 101 phantom "Hands-on 5/5" caption
- ›Executive p-landing step referenced removed home-page sections
- ›Executive Finance & Banking workshop — comprehensive accuracy, completeness, and audio review
- ›TPM PQC Crypto Bridge (Issue #9)
- ›TTS caption interruptions eliminated — generation counter
- ›TTS audio still interrupted — speechSynthesis.speaking primary guard
- ›TPM Playground full TCG V1.85 PQC compliance
- ›References tab deduplicated across foundation modules
- ›Assess wizard navigation broken after workshop reset
- ›p-assess step: only 6 of 8 wizard steps driven; submit never fired
- ›p-report step: wrong section order, hidden sections cited, all TOC clicks missed
- ›Command Center artifact drawer "works only once"
- ›May 4 data accuracy refresh
- ›OpenSSL 3.5.0 enriched
- ›Vendor PQC roadmap data
- ›Learn module reference and product mappings curated
- ›Learn module search powered by topic-scope summaries
- ›RAG search index regenerated
- ›npx tsc -b clean; full vitest suite passes.
May 3, 2026
v3.5.64- ›4 new persona workshop flows
- ›Executive workshop flow gains 2 modules
- ›Quiz showcase close step
- ›20 PKI Learning module Introductions instrumented
- ›Three new workshop cue kinds
- ›6 governance sub-steps
- ›TPM playground scenario flow tab
- ›TPM V1.85 compliance suite extended to 16/16
- ›TPM bridge error surfacing
- ›useModuleStore.markLearnSectionRead(moduleId, sectionId)
- ›Workshop voice "Test Voice" button
- ›LearnStepper — sticky TOC + all-DOM render
- ›LEARN_SECTIONS registry aligned to rendered DOM
- ›Dynamic workshop caption timing
- ›WaveNet / neural voice auto-pick
- ›Workshop cue generator drops learnTabIsStepper flag
- ›"Workshop N/M:" → "Hands-on N/M:"
- ›Workshop speed picker → Preview vs Presentation modes
- ›Workshop persona-driven flow matching
- ›Stale ROLE_ADAPTATIONS strings
- ›Caption-driven section auto-scroll
- ›Workshop content cleanup
- ›CuriousSummaryBanner.tsx
- ›MainLayout.tsx
- ›WorkshopPrereqList rewritten
- ›Executive flow widened
- ›Workshop captions read 1/4 → 2/4 → 3/4 → 4/4 in cue order
- ›Stale "Section 3 of 5" caption
- ›52 caption rewrites
- ›One HARD caption mismatch
- ›Workshop region scoping
- ›Workshop click cue retry
- ›Workshop selectTab handles label/value mismatch
- ›Workshop URL deep-link fixes
- ›Workshop slow/fast math fix
- ›Workshop no-cue step duration cap
- ›Workshop persona region propagation
- ›Workshop preview mode skips cues entirely
- ›Workshop auto-scroll on navigate
- ›Command Center bypass when workshop is active
- ›Workshop voice on Chrome
- ›Workshop voice priming on user gesture
- ›Assess wizard auto-walks
- ›TPM Playground V1.85 compliance
- ›TPM V1.85 use-phase commands
- ›TPM WASM stubs for use-phase crypto
- ›TPM2_Encapsulate wire format
- ›TPM2_SignDigest wire format
- ›CommandBuilder
- ›TPM SHA-2 hash table wrappers
- ›TPM EMULATE_FUNCTION_POINTER_CASTS=1
- ›Patents data refresh
- ›Infographics regeneration
- ›Multi-Session Safety Rules
- ›Semantic caption-vs-content audit
- ›Workshop bug-fix wave + artifact-management cues
- ›npx tsc -b clean; npx vitest run 2086/2086 pass.
May 2, 2026
v3.5.63Playground UX audit Wave 2A/2B/2C: error UX hardening across workshop tools, WasmModeIndicator in HSM Key Derivation, isStepComplete gating in all three blockchain flows, and supporting UX additions (SSH hybrid KEX rationale, Source Combining FilterDropdown, HD Wallet mnemonic panel, Solana tamper toggle, Patents full-text search, 5G scenario intro strip, PKI Workshop artifact strip).
- ›Patents — full-text search panel
- ›5G SUCI — scenario intro strip
- ›PKI Workshop — artifact summary strip
- ›HD Wallet — BIP-39 mnemonic word grid
- ›HD Wallet — extractable-key security callout
- ›Solana — tamper-signature toggle
- ›SSH Sim — hybrid KEX rationale callout
- ›SSH Sim — wire-packets view switcher
- ›SSH Sim — beginner PKCS#11 mode
- ›Bitcoin — isStepComplete step gating
- ›Solana — isStepComplete step gating
- ›HD Wallet — isStepComplete step gating
- ›VPN Simulator — translateCryptoError + <ErrorAlert>
- ›Source Combining — translateCryptoError
- ›SSH Sim — translateCryptoError + <ErrorAlert>
- ›HSM Key Derivation — WasmModeIndicator
- ›Library — staleness badge excludes Expired/Superseded
- ›tsc --noEmit clean; 2021 unit tests pass.
May 1, 2026
v3.5.30–v3.5.62Wave 3 UI audit completion: all P1, P2, and P3 items shipped. Learn module workshop UX fixes for EntropyTestingDemo, SuciFlow, and MerkleTreeCerts. · Wave 1 UX/UI implementation: 8 P0/P1 plans executed covering persona access, analytics instrumentation, filter UX, table virtualization, compliance tab overflow, and shareable report URLs. · Routine dependency hygiene: 5 Dependabot updates landed in one batch after local CI verification, plus a transitive override that closes the last remaining moderate-severity vulnerability flagged by GitHub Security. No runtime or visible behaviour changes. · A second data-substrate sweep on the same day: vendor partnerships now have a proper schema, SaaS-only products land in their own cross-reference family, the assessment wizard knows which compliance frameworks and threats each question maps to, the maturity corpus consolidates into a single canonical file, and the trust-score tooltip honestly distinguishes verified attribution from heuristic guesses. · This release closes a long backlog of cross-reference gaps in the data layer. The Library now contains every standard, RFC, and policy that the rest of the site already cited; the Migrate page knows the vendors behind 31 products it previously labeled with bare names; and the trust-source attribution badges catch up to the current data after a 32-day lag.
- ›OpenSSL Studio — persona cheat sheet strip
- ›Library — citation staleness badge
- ›Assess — "Save link" CTA
- ›Algorithms — executive "Top 5" shortcut
- ›Timeline — search auto-scroll
- ›About — deploy timestamp
- ›Compliance — cert-records cross-link
- ›Patents — "Explore Related" cross-links
- ›SuciFlow — SUPI input validation
- ›SuciFlow — Perspective switcher in config panel
- ›SuciFlow — HSM/OpenSSL mode indicator
- ›MerkleTreeCerts — two-stage reset confirmation
- ›MerkleTreeCerts — step-dependency warning
- ›MerkleTreeCerts — workshop completion card
- ›MerkleTreeCerts — step nav accessibility
- ›Entropy Testing — paste-hex error state
- ›Entropy Testing — mode-switch state preservation
- ›QRNG Demo — live randomization
- ›Envelope Encryption — per-sub-operation progress labels
- ›Cert Capacity Calculator — relative-size toggle
- ›Product catalog module mapping — 100% coverage
- ›slh-dsa module fully stocked
- ›scripts/generate-module-gap-report.py
- ›crypto-mgmt-modernization module cleanup
- ›WasmModeIndicator
- ›Reset / Start Over buttons
- ›Developer persona unlocked for /business
- ›Analytics: persona-labeled events + 4 new event types
- ›FilterDrawer
- ›Table virtualization
- ›Compliance tab overflow menu
- ›Shareable report URL token
- ›Removed curious dead config
- ›Vendor partnerships table
- ›SaaS cross-reference family
- ›Assessment wizard FK columns
- ›32 missing Library entries
- ›30 new vendor profiles
- ›Playground — "Crypto Workshop" → "Crypto Lab"
- ›Compliance — Leaders cross-links
- ›Patents — executive default sort
- ›Learn Dashboard — "Path" terminology
- ›Timeline — persona hint strip
- ›Algorithms — persona hint strip
- ›lucide-react 0.577.0 → 1.14.0
- ›@tailwindcss/vite + tailwindcss 4.2.2 → 4.2.4
- ›@mlc-ai/web-llm 0.2.81 → 0.2.83
- ›zustand 5.0.11 → 5.0.12
- ›Maturity governance corpus consolidated
- ›Assessment wizard content refresh
- ›Trust-score cross-reference scoring distinguishes verified vs heuristic attribution
- ›Authoritative-source freshness sweep
- ›Trusted-source cross-reference refreshed
- ›migrate_purl_xref regenerated against the current product catalog
- ›migrate_certification_xref regenerated
- ›Catalog vendor IDs normalized to VND-XXX format
- ›TEEHSMTrustedChannel.tsx import syntax error
- ›Workshop WASM error messages
- ›cryptoErrorHints.ts deprecated
- ›CHANGELOG version-number duplicates
- ›Validator graph-consistency now recognizes vendor_partners
- ›Two corrupted Library archive files removed
- ›Trusted-source-xref test was rejecting legitimate cross-resource attributions
- ›postcss 8.5.6 → 8.5.13
- ›uuid pinned to ^14.0.0 via overrides
- ›tsc --noEmit clean; 2021 Vitest unit tests pass.
- ›tsc --noEmit clean; all 232 unit tests pass.
- ›Added @tanstack/react-virtual dependency.
- ›Global vitest setup mocks @tanstack/react-virtual so table tests pass in jsdom (no layout engine). Updated kpiCatalog.test.ts, ComplianceView.test.tsx, and ReportContent.test.tsx to reflect new developer KPI access and compact share token format.
- ›All 2015 unit tests pass; tsc --noEmit clean.
- ›Verified locally before push
- ›Eslint group bump (#175) not yet adopted
- ›Validator: 99 → 101 checks
- ›Test suite: 2010/2012 → 2014/2014
- ›Data integrity validator: 6 ERRORs → 0
- ›CSV archive hygiene
- ›RAG corpus regenerated
April 30, 2026
v3.5.27–v3.5.29The app gets a new logo, the top navigation no longer overflows on standard laptop screens, and pages stop drifting sideways when wide content is on screen. The Compliance page is also tidier on phones — filters wrap into neat rows and overflowing strips show a soft fade so it's clear there's more to scroll to. · The CSWP.39 governance dataset on the Compliance page now covers 1,332 requirements from 189 source documents (up from 970 / 107). The Library page gained a CSWP.39 filter, and clicking any library card now shows the obligations extracted from that source inline — with the original quote that justifies each one. · A major Command Center upgrade: every zone is now wired, your assess answers and "My X" selections flow through to artifact builders, the page copy adapts to your persona, and artifacts gain an approval workflow + audit trail. Library cards link to their CSWP.39 zone and the CBOM tool now overlays live CMVP matches next to its illustrative cert numbers.
- ›Brand refresh across favicons, PWA icons, and social previews
- ›Android adaptive home-screen icons
- ›See every CSWP.39 requirement extracted from a library document, inline
- ›"CSWP.39" filter on the Library page
- ›+362 new CSWP.39 governance obligations
- ›All six CSWP.39 zones now have data wires
- ›Persona-aware Command Center copy
- ›"Suggested by your assessment" badges on missing artifacts
- ›Artifact builders auto-fill from your assessment
- ›CBOM "From your assessment" mode
- ›Live CMVP / Common Criteria match badges on cert numbers
- ›"Sample" badges + disclaimer banner on illustrative data
- ›Approval workflow on artifacts
- ›Artifact audit trail
- ›§3 / §4 / §5 / §6 NIST CSWP.39 section nav
- ›§-reference hover popovers
- ›"Learn this zone →" link in every Command Center zone header
- ›Half-page / full-page toggle on every artifact builder
- ›Glossary hover tooltips on jargon
- ›Action Items "why" chips
- ›"My X" selections from other pages now flow into Command Center
- ›Bidirectional "Add to My X" chips inside builders
- ›Source provenance chips on tracked frameworks
- ›Library cards show CSWP.39 zone link + maturity tier
- ›Quick assessment mode now covers all 5 CSWP.39 process steps
- ›Top navigation no longer scrolls horizontally on typical laptops
- ›Compliance filter chips on mobile
- ›Compliance mobile tab strip and CSWP.39 framework matrix show a soft right-edge fade
- ›Compliance → CSWP.39 explorer headline
- ›CBOM and Vulnerability Watch artifacts re-classified to the Assets zone
- ›Mobile navigation order tweaked
- ›About page
- ›Changelog page
- ›Pages no longer drift sideways on phones
- ›Cyber Insurance Lens panel
- ›New persisted store version (v14) with safe migrations for the audit trail and approval workflow fields. Existing artifacts keep their createdAt and default to draft approval status.
- ›Two new test files (DocumentCard.test.tsx, cswp39ZoneData.test.ts) and a new E2E spec (library-cswp39.spec.ts) covering the Library ↔ Command Center cross-walk.
April 29, 2026
v3.5.21–v3.5.26Fixed a production-only crash on the Command Center page. · Added an FAQ tab to the right panel and turned on usage analytics for several pages. · The VPN Simulator is out of "work in progress" — ML-DSA-65 dual-auth IKEv2 with ML-KEM-768 key exchange now establishes successfully every time. · Added a "work in progress" banner to the Command Center. · CVE snapshots now record total counts so the UI can show "showing 20 of N" when results are capped. · Major Command Center expansion: the NIST CSWP.39 zones are now an interactive diagram with per-zone artifact tracking. Adds a daily CVE feed, shared PDF export, and a new architecture diagram.
- ›FAQ tab in the right panel
- ›Usage analytics for Explore, Report, and Business Tools
- ›Command Center work-in-progress notice
- ›CSWP.39 zone diagram in the Command Center
- ›Live data wires inside Command Center zones
- ›Daily CVE snapshot system
- ›Shared markdown viewer
- ›Shared PDF export utility
- ›PKI Learning — crypto architecture diagram
- ›Updated product–CPE cross-references
- ›Analytics test coverage
- ›CVE snapshots now carry total counts
- ›PKI Learning artifacts now sync to the Business Center
- ›CSWP.39 zone definitions consolidated
- ›HSM Capacity Calculator — multi-location math corrected
- ›Command Center page no longer crashes in production
- ›VPN Simulator — diagnostic noise removed
- ›VPN Simulator — dual-authentication tests rewritten
- ›VPN Simulator's "work in progress" banner
April 28, 2026
v3.5.20Major milestone: ML-DSA-65 dual-auth IKEv2 in the VPN Simulator now completes a full handshake end-to-end with real ML-KEM-768 key exchange, all running in the browser.
- ›VPN Simulator — ML-DSA-65 dual-auth handshake completes successfully
April 27, 2026
v3.5.19Major VPN Simulator milestone: full IKE_SA reaches ESTABLISHED with real ML-KEM-768 inside the browser. Also unifies the search service shared by ⌘K and the PQC Assistant, and adds a deep-link validator that ensures every link in the corpus actually works.
- ›Unified search service shared by ⌘K and the PQC Assistant
- ›Deep-link grammar validator
- ›Strict corpus invariants gate
- ›⌘K parity for 8 missing sources
- ›Persona and intent boosts for 16 more sources
- ›FAQ button on every content page header
- ›RAG corpus deep links — 0 missing (down from 722)
- ›PQC Assistant deep-link grammar refreshed
- ›Track and persona filters on the Learn page now work from URL
- ›Workspace persistence — visited routes and advanced-views unlock
- ›Persona voice refresh
- ›VPN Simulator — full IKE_SA reaches ESTABLISHED in the browser
- ›Service worker WASM cache staleness
- ›VPN Simulator — ML-DSA cert-auth wiring (partial)
April 25, 2026
v3.5.12–v3.5.18Updated GitHub organisation links throughout the app and swapped a brand icon that was removed in lucide-react v1. · Added 47 Common Evaluation Methodology requirements to the maturity governance corpus. · Resolved three soft-duplicate library entries with coordinated cite rewriting across library and compliance data. · Fixed a regression introduced in v3.5.14: the library dedup script was overwriting `reference_id` values, orphaning 20+ external citations. · Library catalog deduplicated: 543 → 531 rows. · Added a freshness check on the CSWP.39 source data, expanded the maturity governance corpus with CC 2022 and NERC CIP rows, and raised the offline cache size limit so the full bundle precaches. · Across-the-board mobile responsive fixes for PKI Learning, Patents, Playground, and embed views; iOS/Android safe-area insets; deep-link to specific changelog versions; and new data files for SLH-DSA Q&A and the governance corpus.
- ›Common Evaluation Methodology requirements
- ›CSWP.39 source freshness check
- ›Maturity governance corpus refresh
- ›"Best on desktop" badge on Landing journey steps
- ›Changelog deep links
- ›Search corpus enriched with cross-reference fields
- ›35 new golden queries
- ›New data files
- ›iOS/Android native platform detection
- ›Search corpus and embed SDK refreshed
- ›Library deduplication — Phase 2
- ›Library deduplicated — 543 → 531 rows
- ›Library archive
- ›GitHub organisation links updated
- ›Icon compatibility
- ›Library dedup — reference_id corruption fix
- ›Offline cache size raised from 15 MB to 20 MB
- ›Mobile responsive layouts across the app
- ›Patents page mobile layout
- ›iOS/Android safe-area insets
- ›Narrow-viewport embed grids
- ›Compliance frameworks enrichment refreshed
April 24, 2026
v3.5.8–v3.5.11Removed unused Knowledge Graph module files left over from the v3.5.10 cleanup. · Removed the Knowledge Graph tab from the right-side panel. Existing user state is migrated automatically. · New Patents landscape explorer with 202 PQC-relevant patents. New CSWP.39 Maturity Evidence Grid on the Compliance page. Refreshed library and compliance data, plus a new compliance and standards-bodies enrichment pipeline. · Command Center reorganised around the NIST CSWP.39 5-step process (Govern → Inventory → Identify Gaps → Prioritise → Implement) with maturity tier badges. Closes coverage of every CSWP.39 (December 2025) requirement bullet — 26 of 26 — through reuse of existing site resources and extensions to existing planning tools, with no new tools added.
- ›New Patents page — PQC patent landscape explorer
- ›CSWP.39 Maturity Evidence Grid on Compliance
- ›3D infrastructure SVG generator
- ›Compliance and standards-bodies enrichment pipeline
- ›Library and compliance data refresh (April 23–24)
- ›Search corpus and embed SDK refreshed
- ›CSWP.39 5-step Command Center
- ›CSWP.39 educational coverage — 26 of 26 requirement bullets
- ›Existing builders extended with CSWP.39 sections
- ›Cross-surface CSWP.39 continuity
- ›Knowledge Graph orphan files removed
- ›Knowledge Graph right-panel tab removed
- ›Tier 4 maturity gating
- ›Compliance and Command Center share the same step card
- ›Lint cleanup across new modules
April 23, 2026
v3.5.4–v3.5.7New CSWP.39 Framework tab on the Compliance page lets users explore the NIST CSWP.39 (December 2025) Crypto Agility Strategic Plan in-place — overview, interactive process diagram, 5-step process cards, 4-tier maturity model, and a framework cross-walk to compliance frameworks already catalogued elsewhere on the page. · Realigned the Crypto Management Modernization module's maturity scale to NIST CSWP.39's 4-tier model and added a cross-walk between four industry frameworks. · Three CI fixes — type union completeness, exhaustive record coverage, and test expectations updated for revised HSM ops/sec defaults. · Fixed a Hybrid Signature workshop crash, corrected HSM ops/sec defaults to better match published vendor data, and routed ML-DSA hybrid signatures through the in-browser HSM where the standard mode applies.
- ›CSWP.39 Framework tab on Compliance
- ›PQC maturity model cross-walk
- ›Meta Engineering further reading
- ›Library enrichment for the Meta PQC migration paper
- ›Maturity scale realigned to NIST CSWP.39's 4 tiers
- ›Hybrid Signatures — ML-DSA backend split by construction
- ›Quiz category type union completeness
- ›Quiz category metadata exhaustiveness
- ›HSM Capacity Calculator test expectations
- ›Hybrid Signature workshop crash
- ›HSM ops/sec defaults corrected
April 22, 2026
v3.4.0–v3.5.3Three new workshop steps in the Crypto Management Modernization module that close the gap on CSWP.39 Identify Gaps → Prioritise → Implement, and a CSWP.39 process badge on every workshop step. · Realigned the Crypto Management Modernization module to NIST CSWP.39 (December 2025), framing it explicitly as the operational execution layer of the Crypto Agility Strategic Plan. · New Threshold Signing step in the Stateful Signatures workshop — educational simulation of the Haystack/coalition threshold construction for hash-based signatures, with configurable t-of-n thresholds. · Major release: a new Hybrid Signature Spectrums workshop demonstrating three hybrid signature constructions (concatenation, nesting, and Silithium fused Fiat-Shamir); SP 800-90B Entropy Source Validation status now tracked on libraries and HSMs; six new posture KPIs; and a complete cross-check remediation of the Crypto Management Modernization module to v1.1.0 with five corrected CMVP cert numbers and two new content sections. · Major release: SP 800-227 hybrid KEM coverage expanded from name-drop to spec-faithful teaching across the Hybrid Crypto module; new Cryptographic Management Modernization learn module (LM-052) — a 55-minute, 5-step executive-track module covering posture management; first WASM charon validation exports proving the ML-DSA + ML-KEM source patches are live; VPN Simulator gap-closure phase 1 (algorithm benchmark matrix, config-bundle export, IndexedDB session history, sandbox launch contract); and a major library refresh adding 26 authoritative references plus 13 newly tagged rows.
- ›Three new workshop steps in Crypto Management Modernization
- ›CSWP.39 process badge on every workshop step
- ›CSWP.39 process diagram on the Visual tab
- ›Three new Learn tab sections
- ›Maturity Self-Assessment CSWP.39 callout
- ›Scenario 9 — "Crypto gateway or full migration"
- ›Threshold Signing — Step 5 in Stateful Signatures workshop
- ›Hybrid Signature Spectrums workshop
- ›Entropy Source Validation status on libraries and HSMs
- ›Six new posture KPIs
- ›Crypto Management Modernization Q&A coverage
- ›New learn module: Cryptographic Management Modernization
- ›WASM charon validation exports (Phase 3a)
- ›VPN Simulator gap-closure (phase 1 of 6)
- ›SP 800-227 coverage expanded — Hybrid Crypto module
- ›Google Quantum AI whitepaper added to library
- ›secp256k1 added to Quantum Threats workshop
- ›ECC qubit estimates revised
- ›Fast-clock vs slow-clock CRQC distinction
- ›Guided exercise — "ECC Blockchain Under Quantum Attack"
- ›Calculator math disclosures
- ›Library refresh — 26 new authoritative references plus 13 newly tagged rows
- ›Crypto Management Modernization → v1.1.0 — cross-check remediation
- ›HSM Capacity Calculator — multi-location support
- ›Cert Capacity Calculator — bandwidth model corrected
- ›Cert Capacity defaults — AVX2 cycle-accurate benchmarks
- ›Certificate Lifecycle tools moved to PKI Workshop
- ›VPN Simulator marked work-in-progress
- ›VPN Simulator — ML-DSA private keys discoverable by PKCS#11 plugin
- ›VPN Simulator — IPsec config hardened for tunnel mode
- ›VPN Simulator — cert auth uses leftcert= for all algorithm types
- ›Hybrid Crypto module — Composite Signatures section removed
- ›Role guide — self-assessment checklist removed
- ›Library CSV refresh
- ›Quiz answer buttons no longer truncate long options
- ›HSM key inspection was silently broken for VPN simulation keys
- ›Charon diagnostic lines no longer misclassified as errors
- ›Hybrid Cert Inspector panel no longer overflows on narrow screens
- ›ML-KEM-512 corrected to NIST Level 1
- ›VPN sim RSA certs now carry SubjectKeyIdentifier extension
- ›VPN sim ML-DSA cert auth fully wired end-to-end
- ›Mobile / iOS Safari polish
April 20, 2026
v3.3.9Major release. Highlights: a critical Learn page crash fixed for all visitors; an experimental WASM strongSwan v2 build with in-browser ML-DSA + ML-KEM selftest and cross-Worker handshake; a new HSM Capacity Calculator covering the top 10 enterprise HSM workflows; a Command Center overhaul including in-drawer artifact creation and a redesigned ROI Calculator; a complete compliance ↔ timeline consistency pipeline; a 5G SUCI playground UX overhaul with plain-English mode; the Right Panel migrated from a bottom drawer to a right sidebar; comprehensive PKI / TPM / TLS workshop additions; updated NIST CMVP scraper covering all security levels; and Implementation Attacks + KAT Validation tabs in the Detailed Comparison view.
- ›Experimental WASM strongSwan v2 — selftest + cross-Worker KEM handshake
- ›HSM Capacity Calculator
- ›PKI Workshop — Certificate Capacity Calculator overhaul
- ›Command Center — in-drawer artifact creation with builder adapters
- ›Deployment Playbook → Command Center save
- ›Compliance Table — mandate deadline labels
- ›FilterDropdown keyboard navigation
- ›Manufacturing industry support in assessment
- ›Compliance ↔ Timeline consistency pipeline
- ›Compliance data — accuracy and completeness overhaul
- ›Command Center — ROI Calculator overhaul
- ›Command Center — KPI plan completion (E4 / D9 / E2 / E1)
- ›VPN Simulator — ML-DSA authentication via draft standards
- ›5G SUCI Playground — UX overhaul
- ›Step Wizard — phase progress and plain-English rail
- ›PKCS#11 Log Panel — Beginner Mode
- ›PKCS#11 log panel — "Crypto Only" filter
- ›Browser compatibility notice on VPN and SSH simulators
- ›Secure Boot PQC — TPM 2.0 sandbox deep-link
- ›Docker Playground — pqctoday-sandbox iframe embed
- ›Glossary — TPM 2.0 / TCG V1.85 terms
- ›PKCS#11 glossary terms
- ›Library v04172026 entries
- ›Implementation Attacks tab in Detailed Comparison
- ›KAT Validation tab in Detailed Comparison
- ›FN-DSA / Falcon attack profile
- ›LMS / XMSS stateful signature attack profile
- ›BIKE-1/3/5 added to algorithm reference
- ›Cryptographic hardness assumptions in Security Levels view
- ›"Why KATs Matter" explainer
- ›"Quick Reference" panel in About modal
- ›Curious persona — single-click experience shortcut
- ›Right Panel layout — bottom drawer → right sidebar
- ›strongSwan WASM rebuilt
- ›strongSwan WASM — 44% size reduction
- ›VPN Simulator — true MTU and fragmentation config logic
- ›VPN Simulator — FlaskConical icon for ML-DSA draft warning
- ›Module store — persisted version 12 migration
- ›NIST CMVP scraper — all security levels
- ›Compliance data re-scraped
- ›Library v04152026
- ›Product catalog v04162026
- ›Vendors v04162026
- ›Catalog enrichments
- ›Library and timeline enrichments refreshed
- ›SSH simulator — "Build in progress" notice removed
- ›Playground Workshop — work-in-progress tools hidden by default
- ›Performance baseline description fixed
- ›Composite & Hybrid attack profile split into two tiles
- ›NTRU+ attack reference clarified
- ›Draft / Candidate badges added to Performance and Size views
- ›Attack severity ratings replace uniform "Vulnerable" badges
- ›Countermeasures section added to all attack profiles
- ›SLH-DSA side-channel status corrected
- ›Search corpus and embed manifest regenerated
- ›OpenSSH WASM connector path
- ›Learn page crash on first visit
- ›Compliance facets (Org / Industry / Region) derived from full dataset
- ›VPN Simulator — daemon-default cert algorithm switched to RSA
- ›VPN Simulator — visual SKF payload fragmentation slicing
- ›VPN Simulator — ML-DSA raw pubkey configuration respected
- ›VPN Simulator — WASM OOM and thread-pool exhaustion
- ›What's New modal — View Changelog deep link
- ›Bouncy Castle FIPS 140-3 cert #4943 security level corrected
April 14, 2026
v3.3.6–v3.3.8Six new reference library entries covering government guidance and emerging standards, plus six new algorithm entries for the draft SLH-DSA limited-signature parameter sets from NIST SP 800-230. FAQ copy updated to reflect current module count and corpus size. · Picking a row from the Transition Guide now adds both the classical algorithm and its PQC replacement to the comparison panel in one click — select three RSA rows to benchmark RSA-2048/3072/4096 alongside ML-KEM-512/768/1024 all at once. · The algorithm comparison table now labels each column so you can tell at a glance which algorithms are classical, which are PQC, and which is the reference baseline. HSM engine upgraded to softhsmv3 v0.4.23.
- ›NIST SP 800-230 (IPD) in the Reference Library
- ›ANSSI PG-083 v3.00 in the Reference Library
- ›Applied Quantum PQC Migration Framework v1.1 in the Reference Library
- ›Charter of Trust "Decrypting the Future" in the Reference Library
- ›Cambridge JBS / CCAF quantum blockchain article in the Reference Library
- ›Australian ACSC Quantum Technology Primer (Communications) in the Reference Library
- ›Six SLH-DSA limited-signature algorithm variants in the Algorithms reference
- ›Entropy & Randomness FAQ entry
- ›Compare classical and PQC together from the Transition Guide
- ›Classical / PQC / baseline labels in the comparison panel
- ›FAQ copy refreshed
- ›RAG corpus grown to 6,507 chunks
- ›Older library and algorithm CSVs archived
- ›HSM engine updated to softhsmv3 v0.4.23
- ›HSM engine v0.4.22 improvements (included)
- ›ECDH P-384 benchmark now produces results
- ›Comparison panel shows only what you selected
- ›Certificate and compliance detail pop-ups now open centered on screen
- ›Timeline pop-ups no longer get cut off on mobile
April 13, 2026
v3.3.3–v3.3.5The algorithm benchmark now covers the full PQC and classical portfolio — SLH-DSA, RSA, ECDSA, Ed25519, ECDH, X25519, X448, LMS, and XMSS all run through the in-browser HSM engine alongside ML-KEM and ML-DSA. X448 was not benchmarkable at all before this release. · AI-powered analysis now covers all 535 products in the Migration catalog. Each product entry surfaces 19 dimensions of PQC readiness — algorithms in use, hybrid approaches, migration timeline, compliance alignment, and more. · Mobile fixes and algorithm comparison improvements.
- ›Benchmark engine extended to the full algorithm portfolio
- ›"Enriched" badge now reflects current AI analysis
- ›Timeline event pop-ups now have a proper backdrop
- ›Migration Planner stack view
- ›Stack view dark-mode contrast
- ›Stack view active layer visibility in dark mode
- ›Stack minimap dots
- ›Stack minimap hidden in embedded widgets
- ›Persona avatar displayed correctly on mobile
- ›"What's New" panel centers correctly on iOS and Android
- ›Update notifications no longer clip on narrow screens
- ›Composite and Hybrid algorithm types now show the compare button
- ›19 additional migration catalog products enriched with AI analysis.
- ›New products added: IBM z16 Crypto Express 8S HSM, AWS Certificate Manager.
- ›7 new threats added: Grover attacks on AES-128, quantum halving of SHA-256 collision resistance, PRNG quantum entropy risks, PQC timing/power side-channel attacks, lattice cryptanalysis advances, fault injection on PQC key generation, and resource-constrained PQC deployment.
- ›2 new timeline entries: Brazil's ITI federal mandate for ML-DSA and ML-KEM, ITU-T X.1811.
- ›New library entry: Google/QuantumAI paper on securing elliptic curve cryptography against quantum attacks.
- ›535 migration catalog products enriched
- ›Library (315 entries), timeline (213 entries), and threat (80 entries) enrichments all refreshed to the current 19-dimension analysis schema.
April 12, 2026
v3.2.0–v3.3.2Every operation in the HSM Playground now shows the exact bytes sent to and received from the HSM — see precisely what the PKCS#11 standard is doing at every step. · 22 additional ACVP test vectors now pass. · Role-specific exercise guides, an entropy workshop, and new dedicated panels in the HSM Playground. · OpenSSL engine upgraded to v3.6.2. · Mobile app foundation — the codebase now supports a future native iOS/Android build with zero impact on the web app. Changelog entries rewritten in plain language across all recent releases.
- ›Full parameter inspection across all HSM panels
- ›Role-specific exercise guides
- ›Entropy workshop
- ›Dedicated ML-KEM panel in the HSM Playground
- ›Stateful signature panel in the HSM Playground
- ›Operation history
- ›Native mobile app platform support
- ›Unified platform detection
- ›All HSM panels upgraded to the full inspectable log
- ›In-browser HSM engine updated to softhsmv3 v0.4.21
- ›In-browser OpenSSL engine updated to v3.6.2
- ›Embedded widget SDK
- ›Changelog dates are now human-readable
- ›Changelog descriptions rewritten for plain language
- ›App startup sequence
- ›Sign and Verify operations now show the actual data
- ›Key Unwrap operations now decode correctly
- ›Inspect toggle clearly shows when it is active
- ›Embed error page
- ›Auto-reload disabled in native WebView
- ›Library and catalog data refreshed; knowledge base regenerated.
- ›Knowledge base refreshed: 5,881 indexed chunks.
April 11, 2026
v3.1.0–v3.1.4Polish pass for embedded widgets and the learning module navigator — modals, tables, and step indicators now display correctly at all screen widths. · Bug fix for embedded widget brand theming, plus vendor certificate infrastructure cleanup. · Embed SDK: partner portals can now display custom logos, brand names, and navigation colors. · Fixed Migration Planner interactivity and improved embedded widget behavior across 18 components. · Visual consistency pass — gradient buttons and the shared Button component are now applied uniformly across every page.
- ›Custom logos and brand names in embedded widgets
- ›Vendor certificate registry simplified
- ›Trust anchor certificates can be committed to version control
- ›Consistent gradient button style across the entire app
- ›Unified interactive button component throughout the codebase
- ›Pop-ups and overlays display correctly in embedded widgets
- ›Tables and charts fit properly at narrow widths
- ›More content visible on medium-size screens and in embedded views
- ›Content fills the full width inside embedded portals
- ›Learning module step indicators are more compact
- ›Improved text legibility when switching between light and dark themes
- ›Detail pop-ups no longer appear above unrelated content
- ›Feedback and tooltip overlays stay within embedded widget boundaries
- ›Custom brand colors in embedded widgets now load correctly
- ›Migration Planner layer categories are now fully interactive
- ›Migration Planner filter bar stays visible while scrolling through layers
- ›Drawers, alerts, and navigation panels stay within embedded widget boundaries
- ›Embedded widget height adjusts correctly for host pages
- ›Vendor token is preserved when navigating within embedded widgets
- ›No private key material is stored in the repository
April 10, 2026
v2.98.0–v3.0.0- ›Embed SDK — left sidebar nav layout (navLayout: 'sidebar')
- ›Embed SDK — VendorTheme v2 status/link color overrides
- ›Embed SDK — cert color mode default (colorMode)
- ›pqc-admin CertIssueWizard — Nav Layout control
- ›test-vendor-custom-design cert updated
- ›Embed SDK — VendorTheme full component theming
- ›Embed SDK — nav bar color (sidebar/sidebarForeground)
- ›Embed SDK — solid status badges (badgeFill: 'solid')
- ›Embed SDK — INDUSTRY_SLUG_TO_LABEL mapping
- ›test-vendor-custom-design cert preset
- ›Embed SDK — granular route presets
- ›Embed SDK — Algorithms and Threats nav items
- ›Embed SDK — assistant URL param
- ›Embed SDK — About page always accessible
- ›Embed SDK — Right Panel scoped to iframe
- ›Embed SDK — query-string passthrough on nav
- ›CuriousSummaryBanner layout
- ›Embed mode — Compliance tables empty
- ›Embed mode — Assessment industry not pre-populated
- ›Embed mode — region validation
- ›Embed mode — URL param bypass
- ›Semantic token consistency
- ›Embed modal positioning
- ›Bookmark links in embed mode
- ›Theme not applied in embed mode
- ›Embed vendor cert import path
- ›Assistant button styling
- ›Back-to-modules button hidden in embed
April 9, 2026
v2.96.0–v2.97.0- ›Embed SDK — policy enforcement
- ›Embed SDK — VendorPolicy X.509 format
- ›Embed SDK — module/tool path validation
- ›GA4 analytics — embed mode coverage
- ›GA4 analytics — assessment wizard
- ›GA4 analytics — persona/personalization
- ›GA4 analytics — module tab switches
- ›Embed SDK — vendor iframe integration
- ›Embed SDK — persistence and auth
- ›Embed SDK — PQCEmbed JS client
- ›Service worker — embed COOP header
- ›EmbedVerificationError TypeScript compile error
- ›crypto.subtle.verify() type error
- ›Pre-existing analytics test failures
- ›consoleLogSpy unused variable lint error
- ›Safari blank page
- ›Safari EmbedState binding error
- ›Nested <button> in MobileThreatsList
- ›Leader avatars — CORP violation
- ›CSP — flagcdn.com and frame-ancestors
- ›Analytics noise
- ›sdk.ts memory leak
April 8, 2026
v2.94.1–v2.95.0- ›EUDI Wallet — pluggable CryptoProvider architecture
- ›EUDI Wallet — X.509 certificate generation
- ›EUDI Wallet — native CBOR encoding
- ›Entropy — HMAC_DRBG Architecture Demo
- ›Entropy — danger-zone gauge arc
- ›Entropy — QRNG "Simulated" badge
- ›Deep linking — ?flow= URL parameter
- ›Digital ID E2E test
- ›Playground workshop registry
- ›PKCS#11 Log Panel
- ›Workshop HSM key tracking
- ›EdDSA PKCS#11 bindings
- ›PKCS#11 Walkthrough removed from Playground
- ›useModuleDeepLink test suite
- ›Rust WASM binary updated to v0.4.17
- ›About page SBOM — softhsmv3 link and version updated to v0.4.16
- ›RAG corpus regenerated
- ›SBOM: @pqctoday/softhsm-wasm updated to v0.4.17
- ›SBOM: @pqctoday/softhsm-wasm updated to v0.4.16
April 7, 2026
v2.83.0–v2.94.0- ›New SLH-DSA learning module
- ›SLH-DSA Playground — context string support (FIPS 205 §9.2)
- ›SLH-DSA Playground — deterministic mode toggle (FIPS 205 §10)
- ›SLH-DSA Playground — FIPS 205 §6 internal parameter table
- ›SLH-DSA — FIPS 205 §11 compliance labels on pre-hash options
- ›KMS Envelope Encryption — three new KAT specs
- ›KMS Envelope Encryption — envelope blob hex viewer
- ›PKCS#11 v3.2 hedge variant constants
- ›SLH-DSA Playground — SHA-2 vs SHA-3 hardware hint
- ›PKI Workshop now in the Playground
- ›Bitcoin Flow — quantum threat warning on public key export
- ›Bitcoin Flow — clearer address and transaction explanations
- ›HD Wallet Flow — expanded to 5 steps with live derivation tree
- ›HD Wallet Flow — hardened vs non-hardened live demo (Step 3)
- ›Solana Flow — explains how real wallet apps derive keys
- ›Solana Flow — Ed25519 public key format explained
- ›CRL Generator — revocation reasons and human-readable output
- ›PKI Workshop — NIST security level shown next to algorithm picker
- ›PKI Workshop — ML-DSA and SLH-DSA labels updated to final standard names
- ›Cert Parser — fingerprint, CSR verify, and CRL verify
- ›Hybrid Cert Formats — generated PEMs flow into Cert Parser and OpenSSL Studio
- ›New in-app glossary tooltips for Solana transaction concepts
- ›Blockchain Playground tools marked production-ready
- ›MTC Workshop — shared tree state across Steps 1→2→3
- ›MTC Workshop — Landmark MTC column in Step 4 size comparison
- ›MTC Workshop — Step 4→5 bridge text
- ›MTC Workshop — production-use context in ProofVerifier
- ›MTC Workshop — padding divergence disclosure
- ›MTC — Landmark MTC functions in mtcConstants.ts
- ›Playground — 5G SUCI deep-link profile/pqcMode support
- ›5G SUCI — deep-link URL encodes profile and pqcMode
- ›5G SUCI — Profile B (P-256) dedicated step content
- ›5G SUCI — Profile B compressed key encoding
- ›5G SUCI — educational content: compressed vs uncompressed EC point encoding
- ›5G SUCI — PKCS#11 mechanism accuracy
- ›5G SUCI — Profile C visualization corrected
- ›Library — 3 new records with proper titles and download links
- ›5G SUCI — removed WIP badge
- ›VPN Simulation — SKEYSEED key derivation step
- ›VPN Simulation — IKE exchange phase labels on logs
- ›VPN Simulation — payload size note
- ›VPN Simulation — QKD toggle clarified
- ›VPN Simulation — full IKEv2 + ML-KEM-768 handshake working end-to-end
- ›KMS Envelope Encryption — HKDF salt now follows SP 800-56C Rev 2 §4.1
- ›SLH-DSA Workshop — C_GetAttributeValue removed from live PKCS#11 log
- ›SLH-DSA Stateful Signatures Workshop — prehash options unified with Playground
- ›Playground — default engine in URL state changed from cpp to rust
- ›VPN Simulation and Token Setup panels migrated to Rust WASM module
- ›HsmSetupPanel label corrected
- ›PKCS#11 log panel — step header now appears above its commands
- ›Step results accumulate newest-first
- ›TLS comparison table — ML-DSA-65 signature size corrected
- ›TLS Introduction — SLH-DSA-SHA2-128s signature size now shows exact byte count
- ›TLS Handshake Diagram — removed misplaced encryption boundary marker
- ›Internal: PKCS#11 CKA_PUBLIC_KEY_INFO constant corrected
- ›MTC Workshop — KAT signing spec corrected
- ›MTC Workshop — ECDSA standalone savings corrected
- ›MTC Workshop — SCT count and traditional total corrected
- ›MTC Workshop — ML-DSA-44 savings corrected to 60%
- ›MTC Workshop — PROOF_VERIFIER_CERTS stabilised with useMemo
- ›MTC Workshop — "Step 1 — Generate CA Key" label conflict
- ›MTC Workshop — CA key label now includes size
- ›MTC Workshop — Step 1 stats bar clarified
- ›MTC Workshop — draft status disclosed
- ›Playground — 5G SUCI Profile C hybrid mode URL sync
- ›Playground — fixed race condition on Profile C switch
- ›Playground — SuciFlow pqcMode state sync
- ›Playground — SuciFlowRoute extracted to dedicated file
- ›Playground — 5G SUCI URL stays in sync when switching profiles/modes
- ›Playground — suci-flow deep-link actually works now
- ›5G SUCI — deep-link URL now actually updates in the browser
- ›5G SUCI — Profile C pure PQC no longer shows hybrid code snippets
- ›VPN Simulation — C_CloseSession and C_Verify now emit RPC log entries
- ›VPN Simulation — PKCS#11 log panel no longer shows bookkeeping operations
- ›5G SUCI — profile transitions always reset to step 1
- ›5G SUCI — profile state set before every step executes
- ›5G SUCI — B→C transition no longer double-cleans
- ›5G SUCI — HSM and OpenSSL cross-check now agree on key derivation
- ›HSM — AES-GCM per-message encrypt/decrypt enabled on Rust engine
- ›5G SUCI — dual-engine comparison uses real HSM output
- ›5G SUCI Profile C — KEM ciphertext carried forward correctly
- ›Stateful Signatures — default message aligned across panels
- ›VPN Simulation — engine stability
- ›HSM — encapsulation bug fixed in softhsmv3
- ›HSM — 8 additional Rust engine functions now active
- ›RAG corpus regenerated
- ›Compliance — ANSSI catalog re-scraped
- ›RAG corpus updated
- ›softhsmv3 Rust WASM
- ›index.d.ts trailing-comma cleanup
- ›SLH-DSA workshop link updated in Playground registry
April 6, 2026
v2.81.0–v2.82.0- ›5G SUCI — 3GPP TS 33.501 reference vectors modal
- ›Profile C hybrid mode — full TR 33.841 §5.2.5.2 implementation
- ›Stateful Signatures — cross-engine sign and verify
- ›VPN Simulation — RSA-3072 certificate generation and inspection
- ›Download hybrid certificates
- ›5G SUCI — spec-correct ANSI X9.63-KDF replaces HKDF
- ›5G SUCI — AES-128-CTR with zero IV (was AES-GCM)
- ›5G SUCI — authenticate-then-decrypt at SIDF
- ›HSM slot initialization — reuses existing slot on conflict
- ›softhsmv3 WASM updated
- ›5G SUCI flow matches the real spec
- ›Envelope Encryption — accurate sizes and wrap overhead
- ›Bitcoin Playground — pure HSM path
- ›Firmware Signing wizard
- ›Key Derivation panel labels
- ›VPN Simulation works on the live site
- ›RAG corpus regenerated
April 5, 2026
v2.77.0–v2.80.0- ›Algorithm region and status filters
- ›Algorithm implementations
- ›Work-in-progress badges on Playground tools
- ›Migrate WIP filter
- ›XMSS deterministic keygen test
- ›VPN simulation — all crypto through the in-browser HSM
- ›Complete LMS/LMOTS parameter support
- ›VPN Simulation with ML-KEM-768
- ›Configurable VPN pre-shared key
- ›Stateful Hash-Based Signatures Workshop
- ›VPN Simulation — isolated HSM slot management
- ›Hybrid Encryption Demo
- ›SLH-DSA sign panel
- ›Stateful Signatures workshop — key generation no longer crashes
- ›LMOTS W4 signature size lookups corrected
- ›VPN simulation no longer crashes on start
- ›New algorithm reference data with Region and Status fields.
- ›New algorithm implementations cross-reference.
- ›RAG corpus regenerated.
- ›RAG corpus regenerated.
- ›strongSwan product entry updated
- ›RAG corpus regenerated
- ›Standalone SLH-DSA demo
April 2, 2026
v2.75.0–v2.76.0- ›Collapsible Analysis section in the Gantt chart modal
- ›ACVP tests 23 & 24 — X25519/X448 ECDH round-trip
- ›ACVP test 25 — X9.63 KDF with SHA3-256 / SHA3-512 (PKCS#11 v3.2 §5.2.12)
- ›hsm_pqcEncap / hsm_pqcDecap wrappers (PKCS#11 v3.2 §6.3)
- ›hsm_generateX25519KeyPair
- ›hsm_importECPrivateKey
- ›DerivedKeyProfile interface + buildDerivedKeyTemplate
- ›ML-KEM keygen and import: optional CKA_LABEL support
- ›GSMA TS 33.501 Annex C.4 Profile B KAT
- ›5G SUCI dual-engine output viewer
- ›Threats dashboard multi-view mode
- ›Leaders sector stack view
- ›Unified bookmark icon across all pages
- ›Migrate catalog table cleanup
- ›My filter connected to bookmark store (Migrate)
- ›Stack view collapses empty layers when My filter is active
- ›BookmarksPanel uses unified product store
- ›Export CSV button icon-only
- ›softhsm-wasm C++ engine rebuilt (0.4.3)
- ›softhsm-wasm Rust engine rebuilt (0.4.3)
- ›HsmKeyInspector display names updated
- ›CKK_EC_MONTGOMERY value corrected to 0x41
- ›Product catalog updated
- ›Library updated
April 1, 2026
v2.69.0–v2.74.0- ›CISA Stack view for the Migrate catalog
- ›PQC readiness progress bars in Infrastructure Stack
- ›License type filter in Migrate catalog
- ›Quantum technology badges
- ›Share links for library documents
- ›Share links for migrate products
- ›Share country timeline links
- ›Share buttons in all HSM Playground panels
- ›SLH-DSA context string support (FIPS 205 §9.2)
- ›SLH-DSA deterministic signing (FIPS 205 §10)
- ›ACVP tests 21 & 22 — SLH-DSA context binding and deterministic mode
- ›Copy button on ACVP execution log
- ›Proof details popup
- ›Expanded validation status badges
- ›Visual infographics for all 49 learning modules
- ›"Next Stack" navigation in Curious mode
- ›Source verification data in product catalog
- ›Validation badges in product expanded view
- ›AI assistant aware of validation results
- ›Compliance Module Refactoring
- ›Global Filter Consolidation
- ›Resilient UI Testing
- ›CISA category field added to all products
- ›Enrichment merge improved
- ›SLH-DSA multi-message signing correctness
- ›Chatbot blank screen after API key error
- ›Timeline data updated to April 2026
- ›Product catalog updated
- ›Product catalog expanded to 622 entries
- ›All 521 catalog entries now have validation results
March 31, 2026
v2.67.0–v2.68.0- ›Certificate Transparency Log Simulator
- ›TLS 1.3 Simulator
- ›Algorithm comparison sub-tab deep links
- ›Compliance migrate-category filter
- ›Library taxonomy refresh
- ›Migration catalog "Work in Progress" notice
- ›HSM key inspection improvements
- ›Improved AI assistant navigation links
- ›Firmware Signing Migrator rewritten
- ›Envelope Encryption Demo expanded
- ›PKCS#11 call log — expandable entries
- ›HSM attribute read errors resolved
- ›Duplicate "Code Signing" tool removed from Playground
- ›New document enrichments
- ›Data quality improvements across multiple datasets
- ›Data integrity
March 30, 2026
v2.66.0- ›Evidence warnings on products
- ›Verification status filter
- ›Evidence flags affect trust score
- ›21 products corrected to Unknown
- ›4 products upgraded
- ›Node.js corrected
- ›Cisco IOS XE corrected
- ›Algorithm names standardized
- ›FIPS scope clarifications
- ›415 products in catalog
- ›72 products independently verified
March 29, 2026
v2.63.0–v2.65.3- ›Envelope encryption via HKDF
- ›SLH-DSA pre-hash mismatch warning
- ›PKCS#11 mechanism flag reference
- ›KDF tool scenarios expanded
- ›Trust score badges
- ›9 new achievements
- ›Curious learning path expanded
- ›Google Drive CSRF protection
- ›Business Center export improvements
- ›Audit Checklist expanded
- ›Deployment Playbook new sections
- ›RACI Builder multi-accountable warning
- ›Business Center keyboard navigation
- ›Persona-aware Business Center
- ›Real X.509 certificates in Hybrid Cryptography module
- ›Alt-Sig / Catalyst as a distinct certificate format
- ›SLH-DSA learn card
- ›SLH-DSA IETF reference certificate
- ›Hybrid KEM + ECDH key derivation error
- ›Google sign-in flow corrected
- ›FrodoKEM benchmark crash
- ›secp256k1 benchmark crash
- ›Ed448 and X448 benchmarks removed
- ›Diffie-Hellman benchmark crash
- ›SoftHSM WASM import errors
- ›ROI Calculator unrealistic defaults
- ›CNSA 2.0 deadline labels corrected
- ›Roadmap Builder export
- ›RFC 9763 Related Certificates OID corrected
- ›Alt-Sig factual error corrected
- ›Certificate format count inconsistency
March 28, 2026
v2.58.0–v2.59.0- ›Bookmarks
- ›Product comparison panel
- ›Breadcrumb navigation
- ›Mobile Playground
- ›Automated content integrity checks in CI
- ›Page descriptions visible on more screen sizes
- ›Compliance framework website links corrected
March 27, 2026
v2.56.0–v2.57.0- ›Migrate view URL sync
- ›Google Drive cloud backup
- ›Cloud sync privacy details on About page
- ›Comprehensive mobile layout improvements (70+ components)
- ›Navigation scrollbar restored
March 24, 2026
v2.50.0–v2.55.0- ›Algorithm comparison — security level and key size badges
- ›Mobile algorithm cards — function type and key size chips
- ›OpenSSL Studio collapsible workbench
- ›Curious Explorer persona content
- ›Curious context banners
- ›Key size display in Playground
- ›Mobile compliance improvements
- ›Mobile migration phase selector
- ›Page header actions menu on mobile
- ›Navigation header — text-only branding
- ›Curious Explorer auto-completes onboarding
- ›Playground simplified for Curious and Executive personas
- ›Faster app updates
- ›App stayed on old version after deployment
- ›HSM product PQC algorithm details corrected
- ›Entrust nShield PQC support details corrected
March 23, 2026
v2.47.0–v2.49.0- ›ACVP Testing expanded
- ›Standard reference links in ACVP results
- ›Crucible conformance harness added to PQC Testing module
- ›Trail of Bits ml-dsa added to catalog
- ›HSM vendor accuracy update
- ›HKDF mechanism constants corrected
March 22, 2026
v2.46.0- ›Key Check Values (KCV) for all key types
- ›ACVP multi-algorithm test suite
- ›Visual tab for all 48 learning modules
- ›WIP badge with community feedback
- ›Enrichment previews in Timeline
- ›PQC Testing & Validation learning module
- ›"What's New" modal
- ›Terms of Service page
- ›Curious Explorer glossary
- ›"In Simple Terms" summaries rewritten across all 48 modules
- ›Module infographics standardized to 640×640
- ›Tools & Products tab sources from live catalog
- ›Library "Relevant Features" links broken
- ›Snapshot backup/restore data loss
March 13, 2026
v2.45.2- ›Library document popover — mobile sheet layout
- ›Endorse and Flag buttons visible on mobile
- ›Airplane Mode in mobile nav
March 14, 2026
v2.45.1- ›Stateful Endorse/Flag with discussion links
- ›Flag button missing from several views
March 13, 2026
v2.45.0- ›Flag issue button
Related content
Next step
Data correctionsRow-level corrections to the data live on the revisions page.