Changelog

Current version: v4.152.0

What this means for you

Executive / Business Leader
Filter by your persona to see only the releases that changed something you use.
GRC / Risk & Compliance
Data Updates entries mark corrections to obligations and records; the Compliance and Timeline tags say which area moved.
Developer / Engineer
Entries tagged Software and Algorithms name the tool or view that gained or fixed something.
Security Architect
Architecture-relevant changes carry the Algorithms and Library tags; the Architect persona filter narrows to them.
Researcher / Academic
Data Updates entries say which dataset changed; the Revisions page has the row-level detail.
Certification & Validation Engineer
Data Updates entries say which dataset changed and when; the Revisions page has the row-level detail for any certificate record.
IT Ops / DevOps
The Ops persona filter covers deployment, certificate lifecycle and TLS configuration changes.
Curious Explorer
Each entry starts with what changed for you, in plain words; the version number is the least important part.
Data last updated:
Compliance·Sep 27, 2026Algorithms·Sep 29, 2026Software·Oct 3, 2026Timeline·Oct 3, 2026Library·Oct 3, 2026
Filter:

October 8, 2026

v4.152.0Current

A mistyped or outdated address now shows a clear "Page not found" page instead of the home page; on phones every page has one main heading, shared Library links keep their status filter and the About page explains analytics; and the Simulation offers the new Homomorphic Encryption module.

New Features1
  • ›
    The Simulation offers the Homomorphic Encryption module
    DeveloperArchitectResearcherOps/simulation/learn/homomorphic-encryption
Improvements1
  • ›
    An unknown address shows "Page not found"
    ExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious/
Bug Fixes3
  • ›
    Each page on a phone has exactly one main heading
    ExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious/LearnPlayground
  • ›
    On a phone, a shared Library link keeps its status filter
    ExecutiveGRCResearcherCertificationLibrary
  • ›
    The phone About page explains analytics
    ExecutiveGRCArchitectCurious/about

October 4, 2026

v4.150.0–v4.151.0

The Privacy and Terms pages now say plainly that analytics run on every visit; Homomorphic Encryption becomes its own Learn module with fourteen new quiz questions; the assessment report keeps the frameworks you selected and names any it leaves out; every Crypto Lab tool, planning tool and Learn module has a page that search engines can read; and the About page, README, tour and manual quote the real counts. · Pages that quote when a quantum computer might arrive now stick to what their sources say: the Threats page drops the range this site had worked out itself and shows the Global Risk Institute survey in its own words, the Assess steps no longer claim a 2030–2040 expert range, and the FAQ, Simulation, report and Learn exercises say that these figures are published estimates, still open to debate. The Confidential Computing workshop also now prints the real ML-DSA key sizes.

New Features11
  • ›
    Homomorphic encryption now has its own module
    DeveloperArchitectResearcherOps/learn/homomorphic-encryption/learn/confidential-computing
  • ›
    Quiz questions on homomorphic encryption
    DeveloperArchitectResearcherOpsCurious/learn/quiz/learn/homomorphic-encryption
  • ›
    The report names the frameworks you selected that were left out
    ExecutiveGRCArchitectCertificationOps/reportAssess
  • ›
    Every Crypto Lab and Business tool has its own page for search engines
    ExecutiveGRCDeveloperArchitectPlayground/business
  • ›
    A short introduction on the Report page
    ExecutiveGRCArchitect/report
  • ›
    Link to one Transition row, one landscape standard, a KAT variant or a coverage case
    DeveloperArchitectResearcherCertificationAlgorithms
  • ›
    Who maintains an open-source product
    ArchitectDeveloperResearcherMigrate
  • ›
    Certificates on phones
    CertificationGRCOpsCompliance
  • ›
    Share and "open on its page" from more places
    GRCResearcher/leadersCompliance
  • ›
    The FHE service installed in the shipped board image
    ArchitectResearcherOpsDeveloper/learn/homomorphic-encryption
  • ›
    Notes that estimates are still open, on more pages
    ExecutiveGRCArchitectResearcherCurious/faq/report/simulationLearn
Improvements19
  • ›
    The Privacy and Terms pages now say plainly that analytics run on every visit
    ExecutiveGRCArchitectCurious/terms/about
  • ›
    The privacy text on the About, Terms and README pages matches what the site does
    ExecutiveGRCArchitectCurious/terms/about
  • ›
    The About page, README, tour and user manual quote the real counts
    ExecutiveGRCResearcherCurious/aboutLearn
  • ›
    The About page counts Timeline countries from the data
    ExecutiveResearcherGRCCurious/about
  • ›
    The user manual describes the Compliance and Learn pages as they are
    GRCCertificationOpsCuriousComplianceLearn
  • ›
    The role boards call the quantum-computer year our own planning year
    ExecutiveResearcherCuriousCertification/
  • ›
    Automated reviews show as "maintainer (automated)"
    GRCResearcherCertification/revisionsCompliance
  • ›
    The Quantum Threats lesson's search summary matches its sources
    ExecutiveGRCArchitectResearcher/learn/quantum-threats
  • ›
    The Quantum Threats lesson shows what each source says about a quantum-computer estimate
    ExecutiveGRCArchitectResearcherCurious/learn/quantum-threats
  • ›
    The Threats page shows the same behind each estimate's Sources button
    ExecutiveGRCArchitectResearcherCuriousThreats
  • ›
    Every Library document shows one of six labels
    ExecutiveGRCArchitectResearcherOpsCertificationCuriousLibrary
  • ›
    Products whose PQC status is unknown no longer show a plain "Verified" badge
    ArchitectGRCCertificationResearcherOpsMigrate
  • ›
    Extracted passages and obligations name "automated extraction" as their source
    GRCResearcherCertificationLibraryCompliance
  • ›
    Confidential Computing & TEEs is back to its five TEE steps
    DeveloperArchitectResearcherOps/learn/confidential-computing
  • ›
    Learning paths list Homomorphic Encryption after Confidential Computing & TEEs
    DeveloperArchitectResearcherOpsLearn
  • ›
    Very long pages are saved smaller for search engines, without dropping anything
    ResearcherGRCCuriousLibrary/changelog/leaders
  • ›
    The Threats page no longer shows a CRQC range of its own
    ExecutiveGRCArchitectResearcherCuriousThreats
  • ›
    The Assess steps no longer claim a 2030–2040 expert range
    ExecutiveGRCArchitectResearcherAssess
  • ›
    The Threats headline shows the Global Risk Institute survey in its own words
    ExecutiveGRCArchitectResearcherThreats/learn/quantum-threats
Bug Fixes16
  • ›
    The report keeps the frameworks you selected that apply to your industry and country
    ExecutiveGRCArchitectCertificationOps/reportAssess
  • ›
    Typed search text is cleaned before our analytics events count it
    ExecutiveGRCArchitectCurious/leadersMigrateTimeline
  • ›
    The page address we send to Google Analytics no longer includes anything after a "?"
    ExecutiveGRCArchitectCurious/terms
  • ›
    Highlight links tint only the algorithm named
    DeveloperCuriousAlgorithms
  • ›
    The Entropy Evidence Lab shows the recorded commands without local file paths
    ResearcherDeveloperOps/learn/entropy-randomness
  • ›
    The PQC Assistant can link to every Learn module and every business planning tool
    ExecutiveGRCDeveloperArchitectResearcherOpsCuriousLearn/business
  • ›
    The assistant's links use the exact filter values on the Algorithms, Threats, Timeline, Leaders and OpenSSL pages
    DeveloperArchitectResearcherOpsCuriousAlgorithmsThreats
  • ›
    More leaders appear when you filter the Community page by region
    ExecutiveGRCResearcherCertificationCurious/leaders
  • ›
    Twelve more Learn modules can be found through search
    DeveloperArchitectGRCOpsResearcherLearn
  • ›
    Each Learn module page's study time matches the module
    DeveloperArchitectGRCCuriousLearn
  • ›
    Learn, Explore and the home page quote the real number of modules
    DeveloperArchitectGRCCuriousLearn/explore/
  • ›
    The Business Tools page description quotes the real number of tools
    ExecutiveGRC/business
  • ›
    The Migrate page's search description says 9 infrastructure layers, as the page groups them
    ArchitectDeveloperOpsMigrate
  • ›
    Clicking anywhere on a Crypto Lab card opens its preview again
    DeveloperArchitectResearcherPlayground
  • ›
    Long workshop titles no longer overflow the page header
    DeveloperArchitectResearcherOpsPlaygroundLearn
  • ›
    The trusted-channel steps show the real ML-DSA key sizes
    ArchitectResearcherCertification/learn/confidential-computing
Data Updates6
  • ›
    Library documents carry their lifecycle label
    ResearcherGRCArchitectCertificationOpsLibrary
  • ›
    The Threats page's BSI, NSA and ANSSI entries now point at the current statements
    GRCResearcherArchitectThreats
  • ›
    Library dates and status corrected
    ResearcherGRCArchitectCertificationLibrary
  • ›
    Migrate catalog corrections for 13 products
    ArchitectGRCCertificationResearcherOpsMigrate
  • ›
    Trust tiers of 20 sources corrected
    GRCResearcherCertificationLibraryComplianceThreatsAlgorithms
  • ›
    One Timeline source date corrected
    GRCExecutiveResearcherTimeline

October 3, 2026

v4.146.0–v4.149.0

FHE key custody now runs across two appliance boards with a backup and a failover, the data owner checks the custodian's attestation before trusting its keys, and the FHE compute service runs on a small Arm board over mutual TLS. Every "Validated" badge in the workshop now opens its results on the page, and the Threats and related pages now say plainly that some quantum estimates are still unresolved, with the BSI, NSA and ANSSI entries corrected to what those organisations actually state. · The FHE + HSM workshop's key-custody flow now runs with the key held on the MX95 appliance board, the Lattigo threshold scenario gets its first board measurements, Library dates cite their NIST sources, and shared links are now checked every night. · The FHE + HSM workshop now shows which steps have been validated, with measured runs on a Mac and on a KV260 board, including a first end-to-end run of TFHE key custody in a software token. · Links from the Assistant, search and shared URLs now open the item they name, Learn workshops and wide charts fit a phone screen again, and the Confidential Computing FHE content gets small accuracy fixes.

New Features16
  • ›
    FHE key custody with a backup board
    ArchitectResearcherOps/learn/confidential-computing
  • ›
    Destroy and restore of the key
    ArchitectOpsCertification/learn/confidential-computing
  • ›
    Failover to the backup board
    ArchitectOps/learn/confidential-computing
  • ›
    The data owner checks the custodian's attestation
    ArchitectResearcherCertification/learn/confidential-computing
  • ›
    An FHE compute service on a small Arm board
    DeveloperArchitectOps/learn/confidential-computing
  • ›
    See the results behind every "Validated" badge
    ArchitectResearcherDeveloperOps/learn/confidential-computing
  • ›
    A plain note that some quantum estimates are still unresolved
    ExecutiveGRCArchitectResearcherCuriousThreats/learn/quantum-threatsAssess/report
  • ›
    FHE key custody on the MX95 board
    ArchitectResearcherOps/learn/confidential-computing
  • ›
    Lattigo threshold timings on a small ARM board
    ResearcherArchitect/learn/confidential-computing
  • ›
    8- and 16-bit encrypted arithmetic timed on the KV260
    DeveloperArchitectResearcher/learn/confidential-computing
  • ›
    FHE + HSM Flows show what has actually been validated
    ArchitectResearcherCertification/learn/confidential-computing
  • ›
    OpenFHE threshold sizes are now measured
    ResearcherDeveloperArchitect/learn/confidential-computing
  • ›
    TFHE figures corrected from measurements
    ResearcherDeveloper/learn/confidential-computing
  • ›
    First hardware numbers: the FHE server on a KV260
    ArchitectResearcherOps/learn/confidential-computing
  • ›
    First end-to-end run of TFHE key custody
    ArchitectResearcherOps/learn/confidential-computing
  • ›
    OpenFHE threshold timings on a small ARM board
    ResearcherArchitect/learn/confidential-computing
Improvements4
  • ›
    Server-key export timed on the custodian board
    ArchitectOps/learn/confidential-computing
  • ›
    Lattigo threshold sizes corrected from measurements
    ResearcherArchitectDeveloper/learn/confidential-computing
  • ›
    Shared links are checked every night
    DeveloperOps/about
  • ›
    Pull requests get an automatic privacy check (report-only)
    DeveloperOps/about
Bug Fixes19
  • ›
    Learn pages and the report link to the exact topic
    CuriousDeveloperArchitectOpsLearn/report
  • ›
    Corrected the German BSI migration dates on the Threats page
    ExecutiveGRCArchitectResearcherThreats
  • ›
    Newer NSA and ANSSI statements on the Threats sources list
    ExecutiveGRCArchitectResearcherThreats/learn/quantum-threats
  • ›
    Assistant and search links to patents open the patent
    ResearcherArchitect/patents
  • ›
    Shared links skip the "Who's asking?" picker on phones for every kind of item
    ExecutiveGRCArchitectOpsMigrateComplianceAlgorithms
  • ›
    Highlighted algorithms show on phones
    DeveloperCuriousAlgorithms
  • ›
    Library links tolerate hyphens
    ResearcherDeveloperLibrary
  • ›
    Assessment report → Threats for Education and Manufacturing
    ExecutiveGRC/reportThreats
  • ›
    Migrate category links land on the catalog
    ArchitectOpsMigrate
  • ›
    Phones follow the same filter links as desktop
    GRCResearcherOpsTimelineCompliance/patents/leadersAlgorithms
  • ›
    A second link on the same page works
    DeveloperArchitectAlgorithms/patents
  • ›
    More links open the exact item
    GRCCertificationArchitectComplianceTimeline/report/leadersMigrate
  • ›
    Your saved settings survive a shared link
    GRCExecutiveThreats
  • ›
    The Migrate catalog filter is shareable
    ArchitectOpsMigrate
  • ›
    FHE + HSM Flows: corrected TFHE client-key size and a named source
    ResearcherDeveloper/learn/confidential-computing
  • ›
    Learn workshops fit a phone screen again
    CuriousDeveloperArchitectOpsGRCLearn
  • ›
    Wide charts scroll inside their panel on phones
    GRCExecutive/learn/emv-payment-pqc/learn/pqc-risk-management
  • ›
    Revision history and long names wrap on phones
    CuriousResearcher/revisions/learn/vpn-ssh-pqc
  • ›
    Keyboard and screen-reader fixes in three workshops
    DeveloperArchitect/learn/pki-workshop/learn/api-security-jwt/learn/trust-services-pqc
Data Updates3
  • ›
    ISO/IEC 28033 in the Library
    ResearcherArchitectLibrary
  • ›
    FIPS and entropy-certificate dates now name their NIST source
    CertificationOpsArchitectGRC/learn/crypto-mgmt-modernization/business/tools/crypto-cbom-builder
  • ›
    New Library references
    DeveloperResearcherArchitectLibrary

October 2, 2026

v4.141.0–v4.145.0

The FHE + HSM workshop now shows plainly when data is encrypted, computed on and decrypted, who may decrypt, and where every key sits; every HSM Learn lesson now runs on a fresh page, and the Library adds fhe.rs, the fourth open-source homomorphic-encryption library. · Confidential Computing now teaches fully homomorphic encryption, with a workshop step showing how an HSM can hold FHE keys. · A new HSM playground lesson shows how applications discover certificates across slots, the Rust engine follows PKCS#11 v3.2 more closely, HMAC works again after a hash-based signature on the C++ engine, and catalog entries were corrected after a source-by-source accuracy check. · The IoT & OT module is now two advanced modules, one for IoT and embedded devices and one for operational technology across five sectors, both checked against their standards; search stays smooth after the first search; the JWT workshop's encrypted tokens can run entirely inside the emulated HSM; and the Library and vendor roadmaps gain new entries. · Talking About PQC Accurately has been reviewed and now has its own quiz questions, the API Security workshop names the draft revision it actually implements, a new Attack Lab shows why a JWT verifier must check more than the signature, and the Library adds 42 references for the IoT and OT modules.

New Features13
  • ›
    Homomorphic encryption explained in Confidential Computing
    ArchitectDeveloperResearcherCurious/learn/confidential-computing
  • ›
    New workshop step: FHE + HSM Flows
    ArchitectOpsResearcherDeveloper/learn/confidential-computing
  • ›
    New HSM playground lesson: Discovering certificates across slots
    DeveloperArchitectOpsCertificationPKCS#11 Playground
  • ›
    More questions on industrial protocols and rules
    ArchitectOpsGRC/learn/ot-pqc
  • ›
    New module: IoT & Embedded Device PQC
    DeveloperArchitectResearcherOps/learn/iot-pqc
  • ›
    New module: OT & Industrial Control Systems PQC
    ArchitectOpsGRCResearcher/learn/ot-pqc
  • ›
    LMS signatures are checked against the RFC 8554 test vectors
    DeveloperCertification/learn/iot-pqc/learn/ot-pqc
  • ›
    Boot verify latency
    DeveloperArchitect/learn/secure-boot-pqc
  • ›
    V2X channel load
    ArchitectResearcher/learn/automotive-pqc
  • ›
    NIST IR 8259 Rev. 1 in the Library
    GRCResearcherLibrary
  • ›
    Six new trusted sources
    ResearcherGRCLibrary
  • ›
    Attack Lab: see why a JWT verifier must check more than the signature
    DeveloperArchitectOps/learn/api-security-jwtPlayground
  • ›
    Quiz questions for Talking About PQC Accurately
    Curious/learn/quiz
Improvements14
  • ›
    FHE + HSM Flows: encrypt, compute on encrypted data, decrypt, in plain sight
    ArchitectResearcherDeveloperCurious/learn/confidential-computing
  • ›
    Where keys and data are, inside the flow
    ArchitectOpsResearcher/learn/confidential-computing
  • ›
    What an HSM decryption policy can and cannot do
    ArchitectResearcherCertification/learn/confidential-computing
  • ›
    The Rust HSM engine follows PKCS#11 v3.2 more closely when you list objects
    DeveloperCertificationPKCS#11 Playground
  • ›
    Secret keys, private keys and data objects are private by default
    DeveloperOpsCertificationPKCS#11 Playground
  • ›
    IoT & Embedded Device PQC cites the current NIST guidance
    GRC/learn/iot-pqc
  • ›
    The JWT workshop's encrypted tokens can now run entirely inside the emulated HSM
    DeveloperArchitectCertification/learn/api-security-jwtPlayground
  • ›
    Post-quantum HPKE checked against two more published test-vector sets
    ResearcherCertification/learn/api-security-jwt
  • ›
    Search stays smooth after the first search, and frees 37 MB of browser storage
    CuriousDeveloperArchitectResearcherGRCExecutiveOpsCertification/
  • ›
    API Security & JWT now lists RFC 9068 and RFC 9864 among its references
    DeveloperArchitect/learn/api-security-jwt
  • ›
    Old links keep working and your progress carries over
    CuriousLearn
  • ›
    18 IoT and OT quiz questions corrected and 20 added
    CuriousResearcher/learn/quiz
  • ›
    Talking About PQC Accurately is reviewed
    Curious/learn/talking-about-pqc
  • ›
    Routine library updates
    DeveloperOps/about
Bug Fixes7
  • ›
    Every HSM Learn lesson now runs on a fresh page
    DeveloperResearcherCertificationPKCS#11 Playground
  • ›
    HMAC works again after a hash-based signature on the C++ engine
    DeveloperCertificationPlaygroundAlgorithms
  • ›
    Dual-engine checks in the KEM and Sign/Verify tabs use a real Rust session
    DeveloperPKCS#11 Playground
  • ›
    IoT and OT figures now match their sources
    ResearcherArchitect/learn/iot-pqc/learn/ot-pqc
  • ›
    The JWT encryption step no longer says the HSM cannot run the X-Wing hybrid
    Developer/learn/api-security-jwt
  • ›
    ETSI TS 103 744 shows the edition it links to
    ArchitectResearcherLibrary
  • ›
    The API Security workshop names the draft revision it actually implements
    DeveloperResearcher/learn/api-security-jwt
Data Updates9
  • ›
    fhe.rs joins the homomorphic-encryption libraries
    DeveloperResearcherLibrary
  • ›
    Three homomorphic-encryption libraries in the Library
    DeveloperResearcherArchitectLibrary
  • ›
    New trusted sources for homomorphic encryption
    ResearcherLibrary
  • ›
    Corrections from a source-by-source accuracy check
    ArchitectGRCResearcherMigrateAlgorithms
  • ›
    General Dynamics KIV-80 shows its post-quantum claim
    ArchitectOpsMigrate
  • ›
    NICT post-quantum roadmap
    ResearcherArchitectMigrate
  • ›
    Four more vendor post-quantum roadmaps
    ArchitectOpsMigrate
  • ›
    Two new trusted sources
    GRCResearcherLibrary
  • ›
    42 new library references for the IoT and OT modules
    ArchitectGRCOpsResearcherLibraryLearn

October 1, 2026

v4.139.0–v4.140.0

The Curious Explorer role now also serves people who need post-quantum cryptography for their job without a technical background, the JWT module follows the current IETF drafts and passes their published test vectors, and two engine bugs found by Google's Wycheproof tests are fixed. · The Hybrid Certificate playground now builds every certificate the way its standard says, checks each one with a second, independent implementation, and tells you plainly which formats are published, which are drafts, and which are history.

New Features5
  • ›
    New module: Talking About PQC Accurately
    Curious/learn/talking-about-pqc
  • ›
    "I talk about it at work" on the Curious home board
    Curious/
  • ›
    Wycheproof tests for ML-KEM and ML-DSA
    DeveloperResearcherGRCPlayground
  • ›
    Suggest a correction in one click
    CuriousResearcherGRC/about/editorial-independence
  • ›
    Advanced examples: Certificate Discovery and unsigned certificates
    DeveloperArchitectResearcherCertificationOps/learn/hybrid-crypto
Improvements17
  • ›
    Curious Explorer is for your job too
    CuriousLearn
  • ›
    "How bad is it really?" replaced on the Curious home board
    Curious/
  • ›
    Composite JWT signatures follow the current IETF draft and pass its published test vectors
    DeveloperArchitectResearcher/learn/api-security-jwt
  • ›
    The nested JWT checks both signatures, and SLH-DSA-SHAKE-128s is available
    DeveloperArchitect/learn/api-security-jwt
  • ›
    New lesson: JWT validation basics that post-quantum signatures do not fix
    DeveloperArchitectOpsGRC/learn/api-security-jwt
  • ›
    Published IETF test vectors back the JWT workshop
    DeveloperResearcherCertification/learn/api-security-jwt
  • ›
    Encrypt a token the way the post-quantum JWE drafts now specify
    DeveloperArchitectResearcher/learn/api-security-jwtPlayground
  • ›
    The JOSE known-answer suite now checks encryption too
    DeveloperResearcherCertification/learn/api-security-jwt
  • ›
    The JOSE row of the Protocol Matrix shows the current standards
    ArchitectResearcherExecutiveAlgorithms
  • ›
    Every hybrid certificate is now verified, and you can see the checks
    DeveloperArchitectResearcherCertificationOps/learn/hybrid-cryptoPlayground
  • ›
    ML-KEM certificates are issued the RFC 9935 way
    DeveloperArchitectResearcherCertificationOps/learn/hybrid-crypto
  • ›
    Related Certificates now follow RFC 9763
    DeveloperArchitectResearcherCertificationOps/learn/hybrid-crypto
  • ›
    Alt-Sig's second signature covers the right data
    DeveloperArchitectResearcherCertificationOps/learn/hybrid-crypto
  • ›
    Composite ML-KEM cites revision 21 everywhere
    DeveloperArchitectResearcherCertificationOpsGRCAlgorithms/learn/hybrid-crypto
  • ›
    Chameleon certificates are shown as history
    DeveloperArchitectResearcherCertificationOps/learn/hybrid-crypto
  • ›
    Generate All shows real progress and can be cancelled
    DeveloperArchitectResearcherCertificationOps/learn/hybrid-cryptoPlayground
  • ›
    The X.509 matrix row is more complete
    GRCDeveloperArchitectResearcherCertificationOpsAlgorithms
Bug Fixes4
  • ›
    Curious home board no longer shows the same chip twice
    Curious/
  • ›
    Two Rust-engine bugs found by Google's Wycheproof tests are fixed
    CertificationDeveloperAlgorithmsPlayground
  • ›
    The first search no longer freezes the page
    CuriousDeveloperResearcherLibrary
  • ›
    Hybrid cryptography explanations corrected
    CuriousDeveloperArchitectResearcherCertificationOps/learn/hybrid-crypto
Data Updates9
  • ›
    JOSE standards in the Library are current
    DeveloperArchitectResearcherLibrary
  • ›
    A second source on an IoT firmware threat now opens the current document
    ResearcherGRCOpsThreats
  • ›
    Eight more products with NIST-validated post-quantum algorithms
    OpsCertificationArchitectDeveloperMigrate
  • ›
    Library: three new post-quantum documents
    ResearcherDeveloperGRCLibrary
  • ›
    Vendor roadmaps: Cloudflare Workers and MTG
    DeveloperArchitectMigrate
  • ›
    5G SUCI now points to 3GPP's post-quantum study
    ArchitectResearcherGRCAlgorithms
  • ›
    Three new trusted sources
    GRCResearcher/about
  • ›
    Timeline
    GRCExecutiveResearcherTimeline
  • ›
    Library
    GRCResearcherLibrary

September 30, 2026

v4.137.0–v4.138.0

Search finds what you typed more often: ⌘K shows strong matches without scrolling and tells you when a filter is hiding results, and the Glossary, Library and Learn search boxes now match every word of a query instead of the exact phrase. · The PQC Assistant answers from the retrieved PQC Today corpus again, responds more quickly on broad lists, and uses the better-tested Qwen 3 8B model by default while keeping Qwen 3.5 available.

Improvements5
  • ›
    ⌘K tells you when "Authoritative only" is hiding results
    ExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious
  • ›
    ⌘K shows strong matches without scrolling
    ExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious
  • ›
    Glossary, Library and Learn search match every word
    ExecutiveGRCDeveloperArchitectResearcherCertificationOpsCuriousLibraryLearn
  • ›
    The Glossary suggests close matches when nothing matches every word
    ExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious
  • ›
    Qwen 3 8B is the local default again
    ExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious
Bug Fixes2
  • ›
    Assistant answers use the passages that actually match the question
    DeveloperArchitectResearcherCertificationLearnMigrateLibrary
  • ›
    Local answers finish instead of exposing reasoning or partial metadata
    ExecutiveGRCDeveloperArchitectResearcherCertificationOpsCurious

September 29, 2026

v4.133.0–v4.136.0

The About page's list of the software this site is built from is now accurate and complete: it shows what the site really ships, with real versions and licenses, says plainly where something is not recorded, and can be downloaded in full. · Every item's panel now has its own Share button, so you can share a document, threat, algorithm, product or record while it is open — on desktop and on phones. · A new role for the people who test and certify cryptographic modules — validation-lab testers, module vendor engineers and scheme reviewers — with its own learning path, home boards and the validation tools up front. · The PQC VPN Simulator now runs hybrid IKEv2 in the order the ML-KEM draft recommends, and shows why pure ML-KEM runs into size limits. · Shared links now reach much further into the hub: you can link to a single algorithm, vendor roadmap, Compliance requirement, Community profile and more, and links from Learn modules, search and the PQC Assistant open the exact item they mention.

New Features20
  • ›
    Download the complete software bill of materials
    GRCArchitectOpsExecutive/about
  • ›
    AI models are listed too
    GRCArchitectExecutive/about
  • ›
    Fonts, the Python runtime and other parts that were missing
    OpsArchitect/about
  • ›
    Share an item from its own panel
    ExecutiveGRCDeveloperArchitectResearcherOpsCuriousLibraryThreatsAlgorithmsTimelineMigrate/patents/leadersCompliance
  • ›
    Share an industry use case or an open comparison
    ArchitectExecutiveDeveloperAlgorithms
  • ›
    More links work on phones
    OpsResearcherMigrate/patents
  • ›
    New role: Certification & Validation Engineer
    Certification/Learn
  • ›
    Validation tools open first for this role
    CertificationAlgorithmsPlayground
  • ›
    Six home boards built on test evidence
    Certification/Compliance
  • ›
    Guidance written for this role across the site
    CertificationLearn/faq/leaders
  • ›
    176 existing quiz questions now count for this role
    Certification/learn/quiz
  • ›
    A Compliance view and a report summary for this role
    CertificationCompliance/report
  • ›
    Propose a test vector from where you spot the gap
    CertificationDeveloperPlaygroundLearn
  • ›
    GRC entries are easier to find on this page
    GRC/changelog
  • ›
    Share a link to one algorithm
    DeveloperArchitectResearcherAlgorithms
  • ›
    Links into more of the Algorithms page
    ArchitectResearcherDeveloperAlgorithms
  • ›
    Links to Migrate domains and vendor roadmaps
    OpsArchitectExecutiveMigrate
  • ›
    Links to Compliance requirements, products and CSWP.39 views
    GRCArchitectCompliance
  • ›
    Stable links to Community profiles
    ResearcherExecutive/leaders
  • ›
    More of Timeline, Threats and Patents fits in a link
    GRCResearcherDeveloperTimelineThreats/patents
Improvements3
  • ›
    Every version and license on the About page now comes from the shipped files
    GRCOpsArchitect/about
  • ›
    Hybrid VPN mode now follows the IETF draft's recommended order
    ArchitectOpsDeveloper/playground/vpn-sim/learn/vpn-ssh-pqc
  • ›
    The handshake diagram follows the ML-KEM size you pick
    ArchitectDeveloper/playground/vpn-sim
Bug Fixes14
  • ›
    Wrong entries on the About page corrected
    GRCDeveloperArchitect/about
  • ›
    Compliance toolbar no longer disappears
    GRCCompliance
  • ›
    Migrate shares the product you are looking at
    OpsArchitectMigrate
  • ›
    Timeline event pop-up has a Close button
    GRCResearcherTimeline
  • ›
    On phones, document and "try it" panels are no longer hidden under the header
    DeveloperCurious
  • ›
    Escape closes only the panel on top
    ExecutiveGRCDeveloperArchitectResearcherOpsCurious
  • ›
    Community lists each person once
    ResearcherExecutive/leaders
  • ›
    FIPS badges in the Migrate catalog now match the certificate record
    GRCOpsArchitectExecutiveCertificationMigrate/business
  • ›
    An entropy quiz question shows again
    ResearcherDeveloperArchitect/learn/quiz
  • ›
    Classical VPN mode is now labelled with the key exchange it really runs
    DeveloperResearcher/playground/vpn-sim/learn/vpn-ssh-pqc
  • ›
    Links from around the site open the right item
    ExecutiveGRCDeveloperArchitectResearcherOpsCuriousLearn/businessAssess/report/faq
  • ›
    Site search and the PQC Assistant link to the exact item
    ExecutiveGRCDeveloperArchitectResearcherOpsCurious
  • ›
    Library table view opens the full document panel
    ResearcherGRCLibrary
  • ›
    Old Migrate links from search keep working
    OpsMigrate

September 28, 2026

v4.131.1–v4.132.0

The Simulation no longer strands you — a wrong answer still costs you, but you can always carry on; play-mode pop-ups close; browser Back behaves; phones get the controls they were missing — and it now includes the hub's newest Learn modules and references. Across the hub, shared links now open exactly the item they point to, on phones too. · The VPN/IPsec & SSH module now explains where pure post-quantum IKEv2 runs into trouble, and why the standard's hybrid route avoids it.

New Features4
  • ›
    The newest Learn modules are now part of the Simulation
    GRCArchitectExecutive/simulation
  • ›
    More references in the Simulation's Resources tab
    ArchitectResearcher/simulationAlgorithms
  • ›
    18 new comprehension-check questions
    GRCArchitectDeveloper/simulationLearn
  • ›
    Why pure post-quantum IKEv2 is hard over UDP
    ArchitectOpsDeveloper/learn/vpn-ssh-pqc
Improvements4
  • ›
    The Simulation on a phone
    ExecutiveCurious/simulation
  • ›
    Pilots explains its migration limit
    ExecutiveArchitect/simulation
  • ›
    Industry Landscape inside modules opened in the Simulation
    Architect/simulationLearn
  • ›
    Smaller fixes
    Curious/simulation
Bug Fixes16
  • ›
    A wrong answer is never a dead end
    ExecutiveGRCCurious/simulation
  • ›
    Play-mode pop-ups can be closed
    ExecutiveCurious/simulation
  • ›
    Tip cards no longer cover the board
    Curious/simulation
  • ›
    Browser Back closes what you opened
    ExecutiveCurious/simulation
  • ›
    Difficulty can't be switched mid-run
    ExecutiveCurious/simulation
  • ›
    Leaving a played-through run cleans up
    Executive/simulation/business
  • ›
    Shared links now open the item they point to — on phones too
    ExecutiveGRCDeveloperArchitectResearcherOpsCuriousLibrary/patents/leadersComplianceTimelineMigrateAlgorithms
  • ›
    Links no longer disappear behind your filters
    ExecutiveGRCDeveloperResearcherLibrary/patentsAlgorithmsTimelineThreats/leadersCompliance
  • ›
    Old and mistyped links explain themselves
    GRCResearcherLibraryComplianceThreatsMigrate/patents
  • ›
    Compliance landscape no longer empty for readers with a saved region
    GRCExecutiveCompliance
  • ›
    Timeline shows every country again on first visit
    ExecutiveGRCResearcherTimeline
  • ›
    Every timeline event can be linked
    GRCResearcherTimeline
  • ›
    Product and certificate links open the right entry
    OpsDeveloperGRCMigrateCompliance
  • ›
    Standards view stays put
    GRCArchitectCompliance
  • ›
    Search and Assistant links to patents open the patent
    ResearcherGRC/patents
  • ›
    The protocol size section no longer overstates IKEv2 fragmentation
    Architect/learn/vpn-ssh-pqc
Data Updates2
  • ›
    Two IPsec standards added to the library, and one marked as replaced
    ResearcherArchitectLibrary
  • ›
    The IKE / IPsec row in the Protocol Matrix notes the pure ML-KEM limit
    ArchitectResearcherAlgorithms

September 27, 2026

v4.124.2–v4.131.0

The FIPS 140-3 module now explains how NIST is automating validation — algorithms, then entropy, then the module — and what is and is not in production. · A new Learn chapter on the regional schemes built on Common Criteria, NIAP's CNSA 2.0 deadline in the data, a certification refresh, and a much lighter Timeline page. · FIPS 140-3 and PCI now each have their own certification module. · The validation workbench now says exactly what each test proves, runs trusted public test vectors, and publishes its full coverage and known gaps. · French (ANSSI) certificates now carry the product name their own certification report states, and a few certification verdicts are corrected. · Certificates that cover no post-quantum algorithm are now labelled "Classical only", and 40 products have a researched certification verdict. · Every country on the timeline shows its flag again. · Hundreds of product versions and dates are filled in from their own sources, and a batch of outdated or wrong values is fixed. · Fifteen more product claims now say only what their own documents support, and six catalogue entries that were really web-page titles are fixed. · France's post-quantum migration phases are now confirmed from ANSSI's own guidance, and the assistant can quote the source text for a few more references. · Product certifications now show where each product stands on the road to a FIPS 140-3 certificate — algorithms validated, in progress at NIST, or certified — and 27 product verdicts were re-checked against the official NIST records. · The certification Learn module is now three shorter modules: a fundamentals module every learner starts with, and two deep dives you take only for the schemes you need. · Timeline dates checked against their sources: phases whose source gives no end date are now shown as open-ended instead of being hidden, and several milestones move to the years their sources actually state.

New Features12
  • ›
    How FIPS validation is being automated
    GRCDeveloperOps/learn/fips-140-3-certification
  • ›
    The certification fundamentals module now links to all three deep dives
    GRCCurious/learn/crypto-product-certification
  • ›
    "One criteria, many schemes": the regional schemes built on Common Criteria
    GRCArchitectResearcherLearn
  • ›
    Every test result states its evidence
    DeveloperGRCResearcherPlaygroundAlgorithms
  • ›
    Coverage matrix and open gaps, published
    GRCArchitectAlgorithms
  • ›
    More NIST and Wycheproof vectors
    DeveloperResearcherPlayground
  • ›
    ECDSA signatures checked against NIST byte for byte
    DeveloperPlayground
  • ›
    Multi-part message signing tested
    DeveloperPlayground
  • ›
    New draft module: ACVP Lab Workflow
    DeveloperGRCLearn
  • ›
    ACVP-format practice tool
    DeveloperPlayground
  • ›
    See how far the catalogue has progressed toward post-quantum certification
    GRCExecutiveOpsCompliance
  • ›
    "In progress" now comes straight from NIST
    GRCOpsMigrateCompliance
Improvements7
  • ›
    FIPS 140-3 and PCI are now two separate modules
    GRCOps/learn/fips-140-3-certification/learn/pci-certification
  • ›
    Old links and saved progress still work
    CuriousLearn
  • ›
    The FIPS 140-3 and ACVP Lab Workflow modules now link to each other
    GRCDeveloper/learn/fips-140-3-certification/learn/acvp-lab-workflow
  • ›
    "Classical only" certificates are labelled, and never counted as post-quantum progress
    GRCArchitectOpsMigrateCompliance
  • ›
    New catalogue check
    Developer
  • ›
    Cryptographic Product Certification is now three modules instead of one long one.
    GRC/learn/crypto-product-certification/learn/fips-pci-certification/learn/cc-eucc-certification
  • ›
    The certification quiz questions now belong to the module that teaches them.
    GRC/learn/quiz
Bug Fixes20
  • ›
    The Timeline page downloads far less
    CuriousDeveloperTimeline
  • ›
    Verify-only algorithm validations are no longer at risk of being dropped
    ResearcherCompliance
  • ›
    The FIPS module now says plainly that P2PE v3.1 is superseded
    GRC/learn/fips-140-3-certification
  • ›
    "ACVP certificate" wording corrected
    GRCCuriousLearn
  • ›
    Test vectors corrected
    ResearcherAlgorithms
  • ›
    ANSSI certificates show the right product
    GRCResearcherCompliance
  • ›
    Three Chainguard builds shown as certified
    GRCOpsMigrate
  • ›
    Two retired duplicate entries no longer claim more than the product they point to
    GRCMigrate
  • ›
    Utimaco u.trust HSM and IBM z16 Crypto Express 8S show "in NIST's queue"
    GRCMigrate
  • ›
    Missing country flags restored
    CuriousExecutiveGRCTimeline/leaders
  • ›
    A check keeps it that way
    Developer
  • ›
    France's Phase 2 and Phase 3 are confirmed from ANSSI's own text
    GRCExecutiveTimeline
  • ›
    The PCI exercise uses distinct example certificate numbers
    GRCOps/learn/fips-pci-certification
  • ›
    Two learning modules no longer share an ID with another module
    CuriousLearn
  • ›
    27 product certification verdicts corrected against NIST's own records
    GRCOpsDeveloperMigrate
  • ›
    Certificates behind each verdict are now shown
    GRCDeveloperMigrate
  • ›
    Timeline phases with no stated end date are shown, not hidden.
    GRCExecutiveTimeline
  • ›
    Canada, France and Singapore timeline years corrected from their sources.
    GRCExecutiveTimeline
  • ›
    Three standards cross-references pointed at the wrong document.
    ResearcherGRCLibrary
  • ›
    36 products showed the placeholder "pqc_support" instead of their post-quantum support.
    OpsGRCDeveloperMigrate
Data Updates21
  • ›
    Five official sources added to the library
    ResearcherLibrary
  • ›
    NIAP now requires CNSA 2.0 for certified products
    GRCExecutiveArchitectComplianceTimelineLibrary
  • ›
    Regional certification records corrected
    GRCResearcherCompliance
  • ›
    China's QKD standards, Russia's certification schemes and Kazakhstan's trusted-software registry are added or corrected
    GRCResearcherComplianceLibrary
  • ›
    Certification records refreshed
    GRCOpsCompliance
  • ›
    French (ANSSI) certificates show ANSSI's own product categories
    GRCCompliance
  • ›
    Certification verdicts researched for 40 products
    GRCOpsResearcherMigrate
  • ›
    "Partial" is retired
    GRCMigrateCompliance
  • ›
    More certificates linked to the right product
    GRCArchitectMigrate
  • ›
    Duplicate entries merged
    CuriousMigrate
  • ›
    Versions and dates researched for 707 products
    OpsArchitectGRCMigrate
  • ›
    Outdated versions updated
    OpsMigrate
  • ›
    Wrong values fixed
    OpsArchitectMigrate
  • ›
    Renamed products
    CuriousOpsMigrate
  • ›
    Three entries retired
    GRCMigrate
  • ›
    Stronger evidence
    GRCResearcherMigrate
  • ›
    15 product claims corrected after a full read of their documents
    ArchitectOpsGRCMigrate
  • ›
    Six entries named after a web page, not a product, are fixed
    ArchitectOpsCuriousMigrate
  • ›
    Migration phases
    OpsArchitectMigrate
  • ›
    Evidence records for 10 products
    GRCResearcherMigrate
  • ›
    The assistant can quote the source for more references
    ResearcherGRC/

September 26, 2026

v4.123.1–v4.124.1

A full check of every migration-catalogue product against its own cited document: where a product listed specific post-quantum algorithms its source never mentions, the listing now says only what the source actually supports. · A new Learn module on how cryptographic products get certified, and a Migrate catalogue that now tells a certificate apart from the algorithm validation that comes before it.

New Features2
  • ›
    New Learn module: Cryptographic Product Certification.
    GRCArchitectOps/learn/crypto-product-certification
  • ›
    Learn modules can now be followed by path.
    CuriousLearn
Improvements4
  • ›
    The Migrate catalogue now follows the FIPS 140-3 track instead of treating every validation as a certification.
    GRCOpsArchitectMigrate
  • ›
    Certification badges say CAVP, and never call an algorithm validation a certificate.
    GRCDeveloperMigrate
  • ›
    A product page now says when a certificate belongs to something inside the product.
    OpsArchitectMigrate
  • ›
    Correction to the 4.123.2 note below.
    Ops
Bug Fixes12
  • ›
    98 products named post-quantum algorithms their own source document never mentions.
    OpsGRCDeveloperMigrate
  • ›
    17 products claimed an algorithm validation that isn't theirs.
    GRCOpsMigrateCompliance
  • ›
    3 more duplicate products retired, and one renamed.
    OpsMigrate
  • ›
    41 algorithm validations were missing from the Compliance and Migrate data, and are back.
    GRCResearcherComplianceMigrate
  • ›
    Several products were linked to the wrong company's certificate, or missed their own.
    GRCOpsMigrate
  • ›
    Ten Learn modules stated certification facts they could not support, and now match the scheme records.
    GRCArchitectLearn
  • ›
    Searching for a product's old name now finds the product again.
    OpsGRCMigrate
  • ›
    13 products were listed twice under different names, and the duplicates are now retired.
    OpsGRCMigrate
  • ›
    Two products that look like duplicates are deliberately kept as separate rows.
    OpsMigrate
  • ›
    A sweep of every catalogue column fixed 245 malformed values.
    OpsGRCMigrate
  • ›
    23 products showed a placeholder where a version number should be, and now show nothing.
    OpsDeveloperMigrate
  • ›
    The HSM learning module no longer calls an algorithm validation an "ACVP certificate".
    DeveloperOpsGRCLearn
Data Updates1
  • ›
    One product listed twice is retired.
    OpsMigrate

September 25, 2026

v4.117.0–v4.123.0

Every product in the migration catalogue was re-checked against its own evidence document, and anything a document does not actually say has been corrected or removed — including versions, dates and post-quantum claims. · The Timeline's review backlog is cleared: 19 rows that were already fully sourced but sitting unpublished are now live, taking the public Timeline from 163 events to 182, and the four still held back are held for a stated reason rather than by neglect. · Every certification record now comes straight from its official source — NIST for FIPS 140-3 and CAVP, the Common Criteria Portal, ANSSI and ENISA — and anything a source does not back is gone. · The 122 rows where the Timeline's two reviewers disagreed on 25 September were resolved by a closer read of what each one actually quoted from the source document. · Every entry on the Timeline was checked against its own source document by two independent reviewers, and the Timeline now shows only government, regulator and standards-body milestones — with honest labels for what was checked and when. · Every threat on the Threats page now says only what its cited document says — 71 threats are published, each with its main claims checked against the source, and 49 more are held back until a document that backs them is found.

New Features5
  • ›
    Each product now says what kind of thing it is.
    OpsArchitectMigrate
  • ›
    The catalogue says plainly that it is curated, not exhaustive.
    ExecutiveGRCMigrate
  • ›
    19 Timeline events are now public.
    GRCResearcherTimeline
  • ›
    The IETF hybrid key-exchange row now tracks a published standard.
    DeveloperResearcherTimeline
  • ›
    New milestones: the G7 Call to Action and the HAWK withdrawal.
    ResearcherExecutiveTimeline
Improvements28
  • ›
    7 products now use the name their vendor actually uses.
    OpsMigrate
  • ›
    Quantum key distribution and quantum random number generators are described for what they are.
    ResearcherGRCMigrate
  • ›
    Algorithm validations are labelled "CAVP" rather than "ACVP" on 91 products.
    DeveloperResearcherMigrate
  • ›
    Two published dates corrected.
    GRCResearcherTimeline
  • ›
    Two QKD rows restored.
    GRCTimeline
  • ›
    Japan's PQC-migration row re-sourced and re-dated.
    GRCResearcherTimeline
  • ›
    CISA's EO 14306 deadline now cites the actual order.
    GRCTimeline
  • ›
    The G7 financial-sector deadline now cites the document that states it.
    GRCTimeline
  • ›
    A UAE row is honest about what's confirmed and what's self-reported.
    ResearcherTimeline
  • ›
    Two mis-scoped rows corrected.
    GRCTimeline
  • ›
    Brazil's ICP-Brasil certificate-standards row is published.
    GRCTimeline
  • ›
    Algorithm validations are labelled "NIST CAVP", not "ACVP".
    DeveloperResearcherCompliance
  • ›
    French CSPN certifications have their own label.
    GRCCompliance
  • ›
    Historical and archived certificates are hidden unless you ask for them.
    GRCOpsCompliance
  • ›
    The Timeline drops 16 more entries that aren't post-quantum milestones.
    GRCResearcherTimeline
  • ›
    14 more entries are confirmed and now shown.
    GRCResearcherTimeline
  • ›
    Germany and the UK's country deadlines are held back pending stronger evidence.
    ExecutiveGRCTimelineAssess/report
  • ›
    26 field corrections across Description, Title, OrgFullName, binding force and dates.
    GRCResearcherTimeline
  • ›
    The Timeline now covers government, regulator and standards milestones only.
    ExecutiveGRCArchitectTimeline
  • ›
    Entries are shown only once they have been reviewed.
    GRCResearcherTimeline
  • ›
    Country deadlines in Assess, Report and the Simulation come only from reviewed entries, labelled binding or guidance.
    ExecutiveGRCAssess/report
  • ›
    Dates on Timeline cards say what they are.
    CuriousGRCTimeline
  • ›
    Authority links read correctly.
    GRCTimeline
  • ›
    The Threats page shows fewer threats, and every one it shows is backed by its source.
    GRCExecutiveResearcherThreats
  • ›
    The Evidence panel explains where each claim comes from.
    GRCResearcherThreats
  • ›
    One quantum-computer arrival window everywhere.
    ExecutiveGRCThreats
  • ›
    Threat classes and industry labels are reviewed, not inferred.
    GRCThreats
  • ›
    Criticality left blank reads "Unrated".
    GRCThreats
Bug Fixes23
  • ›
    47 products were described using the wrong company's document, and now cite their own.
    OpsGRCArchitectMigrate
  • ›
    81 products had a post-quantum status their evidence didn't support.
    OpsGRCMigrateAssess
  • ›
    27 products no longer carry a "Verified" badge they hadn't earned.
    GRCOpsMigrate
  • ›
    Version numbers that no document states are gone, and 64 were wrong.
    OpsDeveloperMigrate
  • ›
    Dates on 640 entries were unsupported or wrong.
    OpsGRCMigrate
  • ›
    16 entries that were not products have been retired.
    GRCMigrate
  • ›
    Taiwan's row was invisible even when published.
    GRCTimeline
  • ›
    Three US rows were resource pages, not events.
    GRCTimeline
  • ›
    A duplicate Malaysia row is retired.
    GRCTimeline
  • ›
    Two overstated fields corrected.
    GRCTimeline
  • ›
    A DoD row was colliding with its own retired predecessor.
    Researcher
  • ›
    The UK's 2035 row had no source date.
    ResearcherTimeline
  • ›
    562 records labelled "FIPS 140-3 Active" were really FIPS 140-2 certificates, and they are gone.
    GRCOpsExecutiveComplianceMigrate
  • ›
    Post-quantum algorithms on FIPS records now come only from NIST's Approved Algorithms list.
    GRCResearcherOpsCompliance
  • ›
    Product pages no longer show validations that do not apply to the product.
    OpsGRCMigrate
  • ›
    "Live certification records" and "refreshed daily" were not true, and are gone.
    ExecutiveGRCCompliance/business
  • ›
    A regulatory deadline in the Learn modules no longer borrows another policy's year.
    DeveloperGRCLearn
  • ›
    Threat links work.
    CuriousGRCThreats
  • ›
    The Shor risk tier is graded from the cryptography actually at risk.
    ResearcherThreats
  • ›
    Detection & Response tabs show the real SOC use cases and playbooks.
    OpsThreats
  • ›
    The Threats page fits a laptop screen, and short searches match at the start of words.
    CuriousThreats
  • ›
    Phones: the first-run notice sits below the role picker, with larger tap targets.
    Curious
  • ›
    Pages that don't need the in-browser crypto engines no longer reload on first visit.
    Curious
Data Updates6
  • ›
    Timeline 09252026_r7 → r9:
    GRCResearcherTimeline
  • ›
    Common Criteria, ANSSI and EUCC records were re-checked against their issuers.
    GRCCompliance
  • ›
    Timeline 09252026_r6:
    GRCResearcherTimeline
  • ›
    Timeline 09252026_r5:
    ResearcherGRCTimeline
  • ›
    Threat sources point at the documents themselves.
    ResearcherGRCThreats
  • ›
    The site search and assistant only know published threats.
    CuriousThreats

September 23, 2026

v4.116.0

The in-browser crypto engines carry the latest upstream security fixes, the About page's software list is accurate again, and a compliance chart stops risking a misleading tooltip.

Improvements2
  • ›
    The in-browser HSM and OpenSSL engines were rebuilt from current source, picking up upstream crypto-library fixes.
    DeveloperResearcherPlaygroundOpenSSL Studio
  • ›
    The About page's software list matches what the site actually ships.
    DeveloperGRC/about
Bug Fixes1
  • ›
    A compliance chart could have printed "Invalid Date" into its tooltip where a month should be.
    GRCExecutiveCompliance
Data Updates3
  • ›
    Anne Dames (IBM) joins the PQC Community roster.
    ExecutiveCurious/leaders
  • ›
    Ten timeline documents, six compliance-landscape documents and twenty-one named threat rows gained enriched detail.
    GRCResearcherTimelineComplianceThreats
  • ›
    CSWP.39 pillar tagging was re-derived through the fixed reader.
    GRCCompliance

September 22, 2026

v4.115.0

The in-browser HSM and OpenSSL simulators run today's crypto engine again, including Classic McEliece.

Bug Fixes2
  • ›
    The C++ HSM engine's in-browser build was silently broken for Classic McEliece.
    DeveloperResearcherPlayground
  • ›
    The Rust and OpenSSL engines that power the PKCS#11 and OpenSSL Studio playgrounds are rebuilt from current source
    DeveloperResearcherPlayground

September 21, 2026

v4.114.0

Workshop steps can be jumped to again, the About page's software list is always accurate, and the site's own checks now catch problems before they reach you.

Improvements1
  • ›
    The site's automated checks are trustworthy again
    DeveloperOps/about
Bug Fixes3
  • ›
    Workshop step chips work again
    DeveloperArchitectLearn
  • ›
    The About page lists the exact versions this site is built from
    ResearcherDeveloper/about
  • ›
    The chat side panel opens reliably
    Curious/

September 20, 2026

v4.110.0–v4.113.1

The last six figures the accuracy pass left open on the pages now have their sources or are gone. · The text of every routed page is now checked the way the Learn modules' text has been: the accuracy instrument read the components behind the pages for the first time, and the figures it found there are either backed by a Library document, worked out in the sentence, or gone. · Nineteen figures that no document we can capture actually states are gone from the pages; the sentences now say what the source reports without quoting numbers we cannot check. · The figures on the Learn modules and business tools now say where they come from: sizes are written the way the standards state them, worked examples say they are worked examples, the site's own estimates say so, and eleven more documents joined the Library so that the facts they back can be checked against them. · The figures on the Learn modules now point at the documents that state them: 79 documents joined the Library, 40 modules cite them from their References tab, and the site's own estimates say so beside the numbers.

New Features3
  • ›
    Seventy-nine Library documents behind figures the modules state
    ResearcherArchitectDeveloperGRCLibraryLearn
  • ›
    Citations from 40 modules to those documents
    ResearcherCuriousLearn
  • ›
    "Our estimate" beside modelled figures
    ExecutiveOpsCurious/learn/merkle-tree-certs/learn/aerospace-pqc/learn/automotive-pqc/learn/confidential-computing/playground/hsm-capacity
Improvements11
  • ›
    Sources named for the algorithm-status dates
    ResearcherAlgorithms/about
  • ›
    IBM Condor's 1,121 qubits
    ExecutiveThreats
  • ›
    TPM playground errata pointer removed
    DeveloperPlayground
  • ›
    Page figures name their sources
    ResearcherExecutiveThreats/faq/aboutCompliance
  • ›
    Three figures corrected
    DeveloperLearnPlayground
  • ›
    Unverifiable numbers removed or labelled
    CuriousThreats/faq
  • ›
    Unverifiable numbers removed
    ResearcherGRCLearn/business
  • ›
    Sizes and dates written the way their documents state them
    DeveloperArchitectResearcherLearn
  • ›
    Worked examples, scenarios and the site's own estimates are labelled
    CuriousExecutiveLearn/business
  • ›
    Three figures corrected
    DeveloperLearn
  • ›
    Unverifiable numbers softened
    GRCLearn
Data Updates3
  • ›
    Two Library rows added, two corrected
    ResearcherLibrary
  • ›
    Twelve Library documents added, three recaptured
    ResearcherLibrary
  • ›
    Eleven Library documents added
    ResearcherLibrary

September 19, 2026

v4.93.0–v4.109.0

Every figure on the Learn modules, tools and pages was checked word for word against the standards they cite; three signature-size figures that disagreed with the standard are corrected. · A "Try it" question under a reference page now tests something worth knowing, or the page has none. · Sixty-two Learn workshops now run on a phone; a step-by-step walk of every workshop at phone width found the four that needed a fix, and three stay on the laptop banner until walked by hand. · Every page, module and tool now opens the same way — what it is for, one worked run, a line for your role — and ends with a question you can answer from what you just used. · Fourteen role-board options now also list the Learn module that argues their case, so fifteen modules that only the Learn catalogue reached have a second front door. · Every Learn workshop step that takes input now ends with a question you can answer from that step, and the Crypto Dev APIs decision wizard no longer runs out of answers. · Every top-level page was walked end to end on a laptop and a phone; the handful of things the walk found are put right. · Every Learn module's workshop was walked end to end on a laptop; a step that crashed for everyone is fixed, and the small things the walk found are put right. · Every Command Center tool was walked end to end on a laptop and a phone, and each now ends with a question you can answer by using it. · Every Playground tool was walked end to end on a laptop and a phone; what clipped or ran off the screen now wraps, and each tool ends with a question you can answer by using it. · Every module and tool now says, for your role, what to do with it — written from the item's real steps and controls. · Every module now offers its quiz before you finish it, disabled buttons say why, and the small labels inside workshop steps are readable again. · Sliders, inputs and icon buttons inside workshop steps now say what they are to assistive technology. · Reference pages now show what is related to them, Industry Landscape use cases reach the module that teaches their protocol, and Command Center tools list two Learn modules for their phase. · Every page, module and tool now ends with a next step, tools show what is related to them, and the Playground and Command Center put a role's own tools first. · Module workshops are tidier — one step navigator, the right step count, the intro folded away while you work — and a handful of controls that clipped or overlapped now fit. · Returning visitors see what changed since they were last here, the Curious tour asks before it opens, and the home page no longer opens on a "WIP" badge. · Eleven reference pages now open with one line that says what the page means for your role.

New Features23
  • ›
    Workshops on your phone for 53 more modules
    DeveloperArchitectOpsExecutiveGRCResearcherCuriousLearn
  • ›
    "Start here" on 27 more Learn modules
    CuriousDeveloperArchitectOpsExecutiveLearn
  • ›
    "What you will do" and a worked example on 25 more Playground tools
    DeveloperArchitectResearcherOpsPlayground
  • ›
    A worked example on 16 more Command Center tools
    ExecutiveGRCArchitect/business
  • ›
    "What this means for you" on 15 more pages
    ExecutiveGRCDeveloperArchitectResearcherOpsCurious/reportAssessLearnAlgorithmsMigrateCompliance/businessTimelineLibraryPlaygroundOpenSSL StudioThreats
  • ›
    A "Try it" question under 19 pages
    CuriousGRC/reportAssess/AlgorithmsComplianceMigrate/businessTimelineLibraryPlaygroundOpenSSL StudioThreats/patents/leaders/explore/revisions/faq
  • ›
    66 more workshop-step questions
    DeveloperArchitectOpsResearcherGRCLearn
  • ›
    More modules reachable from the role boards
    ExecutiveDeveloperArchitectOpsResearcher/Learn
  • ›
    A question under every workshop step that takes input
    DeveloperArchitectOpsExecutiveGRCLearn
  • ›
    "Try it" under every Command Center tool
    ExecutiveGRCArchitectDeveloper/business
  • ›
    "Try it" under every Playground tool
    DeveloperArchitectResearcherCuriousPlayground
  • ›
    "For your role" on every Learn module, Playground tool and Command Center tool
    ExecutiveGRCDeveloperArchitectResearcherOpsCuriousLearnPlayground/business
  • ›
    "Check your understanding" on every module with a quiz
    CuriousDeveloperGRCLearn
  • ›
    "Try it" under thirteen workshop steps
    CuriousDeveloperGRC/learn/pqc-101/learn/quantum-threats/learn/cbom
  • ›
    A visible reason beside seven disabled buttons
    DeveloperOps/playground/interactive/learn/hsm-pqc/learn/kms-pqc/learn/entropy-randomness/learn/pki-workshop/playground/vpn-sim/playground/pqc-ssh-sim
  • ›
    Related content on every reference page
    CuriousResearcherGRC/AlgorithmsComplianceMigrateTimelineLibrary/patents/leaders
  • ›
    Industry Landscape rows reach the module that teaches their protocol
    ArchitectDeveloperOpsLearnAlgorithms
  • ›
    A "Next step" at the end of every page, module and tool
    CuriousExecutiveDeveloperArchitectOpsGRCResearcherLearnPlayground/business
  • ›
    Related content on every Playground and Command Center tool
    DeveloperArchitectOpsPlayground/business
  • ›
    "Tools for this role" on every role board
    ExecutiveGRCDeveloperArchitectOpsResearcherCurious/
  • ›
    Playground picks per role
    DeveloperArchitectResearcherOpsCuriousPlayground
  • ›
    "Reviewed data updates since your last visit" on the home page
    ExecutiveGRCResearcher//revisions
  • ›
    "What this means for you" on eleven reference pages
    ExecutiveGRCDeveloperArchitectResearcherOpsCurious//patents/leaders/explore/revisions/changelog/faq/about/editorial-independence/sponsor/terms
Improvements6
  • ›
    Command Center tools list up to two Learn modules for their phase
    ExecutiveGRC/business
  • ›
    Command Center tools are ordered for your role
    ExecutiveGRCArchitectDeveloper/business/tools
  • ›
    One step navigator per workshop
    DeveloperCuriousLearn
  • ›
    The module intro folds away on the Workshop tab
    DeveloperOpsLearn
  • ›
    The Curious tour offers itself instead of opening
    Curious/
  • ›
    No more "WIP" badge on the home page banner
    CuriousExecutive/
Bug Fixes33
  • ›
    LMS signature size now matches RFC 8554 in every module
    DeveloperArchitectOps/learn/aerospace-pqc/learn/automotive-pqc
  • ›
    SLH-DSA signature range in the TLS certificate inspector
    DeveloperCurious/learn/tls-basics
  • ›
    Page "Try it" questions ask about post-quantum cryptography, not about the page's own controls
    CuriousGRCExecutiveDeveloperArchitectThreatsOpenSSL Studio/faq/businessCompliance
  • ›
    Four workshops that ran past a phone screen
    CuriousDeveloper/learn/pqc-101/learn/automotive-pqc/learn/sbom/learn/secure-boot-pqc
  • ›
    The KMS key-policy lab starts with valid JSON
    DeveloperOps/learn/kms-pqc
  • ›
    Four tool descriptions now match the tool
    DeveloperGRC/playground/cacp-kmip/playground/hybrid-certs/playground/pqc-ssh-sim/business/tools/risk-register
  • ›
    The Crypto Dev APIs decision wizard answers every branch
    Developer/learn/crypto-dev-apis
  • ›
    The Timeline's filter bar no longer runs off the right edge
    GRCExecutiveTimeline
  • ›
    FAQ questions wrap on phones
    Curious/faq
  • ›
    Changelog entries with long technical names wrap on phones
    Developer/changelog
  • ›
    The Compliance table's PQC filter has a name for assistive technology
    GRCCompliance
  • ›
    The Network Security module's Vendor Matrix step no longer crashes
    OpsArchitect/learn/network-security-pqc
  • ›
    PQC 101 no longer logs an error on every load
    Curious/learn/pqc-101
  • ›
    Option cards that cut their text off
    DeveloperArchitect/learn/5g-security/learn/automotive-pqc/learn/code-signing
  • ›
    Inputs and buttons that had no name for assistive technology
    ResearcherDeveloper/learn/aerospace-pqc/learn/api-security-jwt/learn/kms-pqc/learn/pqc-testing-validation/learn/emv-payment-pqc/learn/vpn-ssh-pqc
  • ›
    Readable and explained
    CuriousOps/learn/quantum-threats/learn/pki-enrollment-protocols
  • ›
    The KPI persona lens fits a phone
    ExecutiveGRC/business/tools/kpi-dashboard/business/tools/kpi-tracker
  • ›
    Supply Chain Risk Matrix bars stay inside their track
    GRC/business/tools/supply-chain-matrix
  • ›
    Long headers and step titles wrap on a phone
    Developer/playground/email-signing/playground/api-security-jwt/playground/vpn-sim/playground/pqc-ssh-sim/playground/mls-group-messaging/playground/hybrid-certs
  • ›
    A long selected value no longer widens a drop-down past its cell
    Ops/playground/pki-enrollment
  • ›
    Tab bars used as switches no longer point at a panel that does not exist
    DeveloperKMIP 3.0 Playground/playground/cacp-kmip
  • ›
    The OpenSSL Studio file manager's buttons keep their names on a phone
    DeveloperOpenSSL Studio/playground/openssl-studio
  • ›
    The phone changelog's back arrow has a name
    Curious/changelog
  • ›
    Small labels inside workshop steps are readable again
    ArchitectOpsKMIP 3.0 PlaygroundMigrateTimeline/learn/confidential-computing/learn/automotive-pqc/learn/digital-id/learn/web-gateway-pqc
  • ›
    Fifteen workshop sliders and inputs now carry a name
    OpsDeveloper/learn/automotive-pqc/learn/energy-utilities-pqc/learn/iot-ot-pqc/learn/ai-security-pqc/learn/verification-closure/playground/vpn-sim
  • ›
    Nine icon-only buttons now have a name
    Developer/learn/crypto-dev-apis/learn/iam-pqc/learn/platform-eng-pqc/learn/healthcare-pqc
  • ›
    The web gateway vendor picker is one control, not two
    Ops/learn/web-gateway-pqc
  • ›
    Ten modules now declare every workshop step they render
    DeveloperArchitectOpsLearn
  • ›
    Selected values in drop-downs are no longer cut short
    CuriousDeveloperLearnPlayground/business
  • ›
    "First Steps" is awarded for a real step, not for opening the Workshop tab
    CuriousLearn
  • ›
    Overlapping option buttons in two workshops
    GRCDeveloper/learn/standards-bodies/learn/iot-ot-pqc
  • ›
    Architecture Diagram inputs fit their content and say what they are
    Architect/business/tools/crypto-architecture-diagram
  • ›
    "~380 min for a first look" on Explore
    ArchitectCurious/explore
Data Updates1
  • ›
    Quiz: the EU PQC roadmap is dated June 2025
    GRCExecutive/learn/quiz

September 18, 2026

v4.87.0–v4.92.0

Thirty-eight modules now tell you where to start: one real workshop step, what a first run of it gives you, and a button that opens it. · Every tool now opens with a worked example, so you can picture a run of it before the form. · Every page now passes the automated accessibility check with no serious or moderate findings. · Screen-reader outlines are in order on the tool, module and reference pages, and four more guided workshops run on a phone. · The 710 patents in scope were re-read from their cached documents and their summaries and claim descriptions rewritten from that text. · Every page reads better for screen-reader and keyboard users, the learning paths and role boards reach more of the site, and the Crypto Lab opens on a different set of tools for each role. · The Industry Landscape shows which post-quantum mechanism replaces which classical one, search results stop mixing crosswalk rows into the compliance frameworks, the site stays up for visitors in the minutes after a release, search engines can index every page, and a night of evidence work re-addresses 51 organisation sources and prunes copies that were never the cited document.

New Features11
  • ›
    A "Start here" line on 38 modules
    CuriousDeveloperArchitectExecutiveLearn
  • ›
    A worked example on all 21 business tools
    ExecutiveGRCOps/business
  • ›
    An intro strip on eight Playground tools
    DeveloperResearcherArchitectPlayground
  • ›
    Four more guided workshops run on a phone
    ExecutiveGRCResearcherDeveloperLearn
  • ›
    Every role board now opens a Learn module
    ExecutiveGRCArchitectResearcherCurious/Learn
  • ›
    The Crypto Lab "Start here" picks differ by role
    DeveloperArchitectResearcherOpsCuriousPlayground
  • ›
    A module lists every Playground tool built for it
    DeveloperOpsResearcherLearn
  • ›
    Researchers can browse 43 more modules by algorithm and standard
    ResearcherArchitectLearn
  • ›
    Five guided workshops now run on a phone
    ExecutiveGRCArchitectCuriousLearn
  • ›
    SOC detection and automotive modules reach the roles that need them
    ArchitectGRCOpsLearn
  • ›
    The Industry Landscape now says which post-quantum mechanism replaces which classical one
    ArchitectOpsExecutiveAlgorithms
Bug Fixes15
  • ›
    Architecture Quantum Impact declares all five of its workshop steps
    Architect/learn/arch-quantum-impact
  • ›
    Headings read in order on the remaining 45 module, tool and business-tool pages
    CuriousDeveloperExecutiveLearnPlayground/business
  • ›
    The Playground tool grid no longer sits inside a second main region
    CuriousPlayground
  • ›
    Headings read in order on 40 tool, module and reference pages
    CuriousDeveloperPlayground/businessLearnLibrary/leadersAlgorithms
  • ›
    The side navigation rail and the simulation start screen are labelled landmarks
    Curious/simulationTimeline
  • ›
    Small labels are readable again on 40 pages
    CuriousDeveloperLearnPlaygroundAlgorithms/about
  • ›
    Every page has a level-one heading, on desktop and on the phone
    Curious/businessPlayground/navigate/report
  • ›
    Wide tables can be scrolled with the keyboard
    DeveloperLearnPlayground
  • ›
    Links inside paragraphs are underlined
    CuriousLearn/about/terms
  • ›
    Opening /embed directly shows a plain explanation instead of an error
    Developer/embed
  • ›
    Six country flags on the community directory were missing
    Curious/leaders
  • ›
    The VPN and SSH comparison panels use valid list markup and the HSM learn tabs are a proper tab list
    Developer/playground/vpn-sim/playground/pqc-ssh-simPKCS#11 Playground
  • ›
    Search results no longer show crosswalk rows as compliance frameworks
    GRCCurious/Compliance
  • ›
    The site keeps working for visitors during the minutes after a release
    OpsCurious/
  • ›
    Search engines can index every page
    CuriousExecutive/navigate/
Data Updates6
  • ›
    Patent summaries and claim descriptions now come from the cached patent text
    ResearcherArchitect/patents
  • ›
    51 organisation sources re-addressed after a web-search pass
    ResearcherGRC/aboutLibrary
  • ›
    250 registry concepts whose source row had been deprecated are resolved
    GRCResearcherComplianceLearn
  • ›
    Every glossary term now links to a Learn module that actually uses it
    CuriousLearn
  • ›
    20 leader references added and 9 ANSSI certification reports re-addressed
    ResearcherGRC/leadersCompliance
  • ›
    Copies that were never the cited document no longer back a row
    GRCArchitectLibraryComplianceMigrate

September 17, 2026

v4.86.0–v4.86.1

The Navigate graph becomes readable when you zoom in, vendors can list more than one roadmap announcement, the Patents page stops carrying 1,133 patents it never showed, and a day of evidence work corrects certification, catalog, and reference data against the documents they cite.

New Features3
  • ›
    The Navigate graph stays readable when you zoom in
    CuriousExecutiveDeveloperArchitectResearcher/navigate
  • ›
    Every Navigate category now appears in the overview, and each can be narrowed to its sub-categories
    CuriousResearcher/navigate
  • ›
    A vendor can now have more than one active roadmap announcement
    ArchitectOpsExecutiveMigrate
Improvements1
  • ›
    The Patents page's population is now honest: 1,133 patents outside the post-quantum scope are retired
    ResearcherExecutive/patents
Bug Fixes3
  • ›
    8 quiz questions and 2 glossary entries corrected for accuracy against live NIST/IETF/OASIS sources
    CuriousResearcherLearn
  • ›
    3 timeline entries corrected
    GRCResearcherTimeline
  • ›
    Learn, quiz, glossary, and Playground references now resolve to the documents they name
    DeveloperCuriousLearnPlayground
Data Updates7
  • ›
    Nearly every patent on the Patents page now has its source document cached
    ResearcherExecutive/patents
  • ›
    Cloudflare's post-quantum DNSSEC announcement now has an archived copy
    ArchitectOpsMigrate
  • ›
    33 FIPS 140-3 certifications' post-quantum coverage corrected to what their own Security Policy says
    GRCOpsArchitectCompliance
  • ›
    11 Migrate catalog proofs now point at the publisher's actual document instead of a landing or empty page
    ArchitectOpsMigrate
  • ›
    545 concept-crosswalk links whose quoted evidence is not in the cited document are marked low-confidence
    GRCResearcherCompliance
  • ›
    Vendor identifiers cleaned up
    GRCExecutiveMigrate
  • ›
    Library and Community references brought up to date
    ResearcherLibrary/about

September 13, 2026

v4.84.0–v4.85.0
New Features5
  • ›
    A new Learn module: DNSSEC & Post-Quantum Signatures
    DeveloperArchitectResearcher/learn/dnssec-pqc
  • ›
    3 new hardware certifications and 2 new products in the Migration Catalog
    ArchitectResearcherMigrate
  • ›
    6 new industry threat entries
    GRCExecutiveThreats
  • ›
    A new compliance requirement: Executive Order 14306's TLS 1.3 deadline for U.S. federal agencies
    GRCOpsCompliance
  • ›
    The Simulation's closing debrief and usage analytics now show what kind of run you actually completed
    ExecutiveGRC/simulation
Bug Fixes4
  • ›
    All 64 Learn-module posters replaced with corrected, verified artwork
    CuriousDeveloperLearn
  • ›
    The Migration Catalog's search box now actually finds products, not just categories
    ArchitectResearcherDeveloperMigrate
  • ›
    A routing-security entry named the wrong classical algorithm
    Researcher/industry
  • ›
    The KMIP Control Plane playground now uses the correct wire format for object identifiers
    DeveloperOpsPlayground
Data Updates3
  • ›
    The Protocol Support matrix's DNSSEC row now reflects Cloudflare's real pilot
    ArchitectResearcherAlgorithms
  • ›
    Qinsight Atlas's catalog entry is now verified
    ArchitectResearcherMigrate
  • ›
    Daniel Speciale (Founder, Qinsight) added to Leaders
    Researcher/leaders

September 9, 2026

v4.83.0
New Features3
  • ›
    Every migration phase now has a complete maturity ladder, with no "open a page" shortcuts
    ExecutiveGRC/simulation
  • ›
    The phone version of the Simulation now has Progress and Resources views
    ExecutiveCurious/simulation
  • ›
    Each closing debrief is now personalized to your seat
    ExecutiveGRC/simulation
Bug Fixes1
  • ›
    Phases that hadn't started were mislabeled "locked"
    Curious/simulation

September 8, 2026

v4.82.1
Bug Fixes3
  • ›
    Several KMIP Control Plane operations now work correctly
    DeveloperArchitectPlayground
  • ›
    The KMIP Control Plane's conformance/corpus-replay check now passes
    DeveloperPlayground
  • ›
    The PKCS#11 HSM Playground reflects the latest engine fixes, on both engines
    DeveloperOpsPlayground
Data Updates1
  • ›
    Cloudflare's post-quantum algorithm data is restored
    ArchitectResearcherMigrate

September 7, 2026

v4.81.0–v4.82.0

The combined "Executive/GRC" role is now two roles: **Executive / Business Leader** for funding, sponsorship and oversight, and **GRC / Risk & Compliance** for tracing obligations to their source, assessing gaps, and recording evidence. If you were an Executive before this release, nothing changes automatically — a one-time notice lets you keep Executive or switch to GRC, and your saved progress, reports and business-tool work carry over either way. · Almost every fact on the site can now be traced to a document you can open — evidence coverage went from 85.5% to 99.2%, and around 310 missing source documents were recovered and checked.

New Features2
  • ›
    GRC / Risk & Compliance is a new, seventh role
    GRC/
  • ›
    A one-time notice for existing Executive users explains the split
    Executive/
Improvements3
  • ›
    Executive is now narrower and faster to start
    ExecutiveLearn
  • ›
    Shared reports and business tools now recognize GRC
    ExecutiveGRC/report/business
  • ›
    Every piece of evidence is now checked before it is accepted
    ArchitectResearcherComplianceLibraryMigrate
Bug Fixes2
  • ›
    The mobile Compliance view now honors a direct ?tab= link
    GRCExecutiveCompliance
  • ›
    A page that says "no roadmap published" is no longer treated as missing information
    OpsResearcherMigrate
Data Updates4
  • ›
    Nearly every catalogue entry now has a source document behind it
    ExecutiveArchitectResearcherOpsComplianceTimelineLibraryMigrateThreats
  • ›
    Four compliance entries now link to the actual document instead of a company's front page
    ExecutiveArchitectCompliance
  • ›
    Standards that cost money to read now show a free source that covers the same ground
    ResearcherArchitectLibraryCompliance
  • ›
    An industry entry was reading the wrong file for a 3GPP specification
    DeveloperOpsThreats

September 4, 2026

v4.77.0–v4.80.0

A global accuracy and consistency pass across all six role-based home boards, closing out the 2026-09-03 review with over 50 individual fixes plus two new pieces of user-visible behavior — plus a smaller Algorithms page default-filter change. · Two correctness fixes in the in-browser HSM engine, found and fixed on the Rust engine used across the PKCS#11 workshop, HPKE demos, and CACP policy sandbox.

New Features4
  • ›
    Role-home boards that reference a specific workshop now show a real link to it
    ExecutiveDeveloperArchitectResearcherOpsCurious/
  • ›
    Chip and CTA clicks on role-home boards are now tracked
    ExecutiveDeveloperArchitectResearcherOpsCurious/
  • ›
    The Algorithms page now opens on "NIST picks" by default
    DeveloperArchitectResearcherOpsExecutiveCuriousAlgorithms
  • ›
    Navigate's force graph now includes vendor nodes, with an auto-adapt density mode
    ExecutiveDeveloperArchitectResearcherCurious/navigate
Improvements1
  • ›
    The Navigate graph's filter panel now stays out of the way until you need it
    ExecutiveDeveloperArchitectResearcherOpsCurious/navigate
Bug Fixes9
  • ›
    Dozens of factual and overstated claims corrected across all six role-home boards
    ExecutiveDeveloperArchitectResearcherOpsCurious/
  • ›
    Dead-end and mismatched links on role-home boards now go where their own text says they go
    ExecutiveDeveloperArchitectResearcherCurious/
  • ›
    A role-home board's hero badge now shows your actual selected region and industry
    ExecutiveDeveloperArchitectResearcherOpsCurious/
  • ›
    The curious persona's "preview locked" notice no longer appears on pages it already has access to
    Curious/PlaygroundLearn
  • ›
    The example report now renders under your own role
    ExecutiveOps/
  • ›
    A node's detail panel no longer overflows with very long connection lists
    ExecutiveDeveloperArchitectResearcherCurious/navigate
  • ›
    Protocol Matrix library chips now link to the right place in the Migrate Catalog
    DeveloperArchitectAlgorithms
  • ›
    A rare but real failure in HPKE/ECDH key-derivation demos is fixed
    DeveloperResearcherPlayground
  • ›
    Nine XMSS stateful-signature parameter sets in the PKCS#11 workshop now actually work
    DeveloperResearcherPlayground
Data Updates1
  • ›
    PQC Community leaders page refreshed
    ExecutiveDeveloperResearcherCurious/leaders

September 2, 2026

v4.75.0–v4.76.0

A same-day follow-up to the PKCS#11/KMIP workshop redesign: a live production bug fixed, all five vendored HSM engines refreshed, four new real known-answer-test templates, and a handful of small workshop fixes. · The PKCS#11 and KMIP workshops were reorganized around how people actually use them — Learn, Operate/Build, and Inspect are now top-level, not buried two tabs deep — plus a compliance chart and a broad library/timeline/compliance data refresh.

New Features13
  • ›
    Four new real, standards-verified test templates in the PKCS#11 Developer tab
    DeveloperResearcherPlayground
  • ›
    The PKCS#11 shim gained new standards-accurate building blocks
    DeveloperPlayground
  • ›
    KMIP's Batch view can now pin a step to a specific stored key
    DeveloperPlayground
  • ›
    All five vendored HSM engine bundles (SoftHSM C++, Rust, KMIP, OpenSSL-PKCS#11, StrongSwan) refreshed to their latest source
    DeveloperPlayground
  • ›
    The PKCS#11 HSM workshop is now four tabs — Learn, Operate, Build, Inspect — instead of twelve
    DeveloperResearcherPlayground
  • ›
    One shared call log and key inventory for the whole PKCS#11 workshop
    DeveloperPlayground
  • ›
    PKCS#11 lessons can now jump you straight to the real control that just ran
    DeveloperResearcherPlayground
  • ›
    Stateful signature keys (XMSS/LMS) now show their real remaining-signature count
    DeveloperResearcherPlayground
  • ›
    Sign & Verify is now a clean 4-way switch — ML-DSA, SLH-DSA, Classical, Stateful
    DeveloperPlayground
  • ›
    ACVP known-answer tests and PKCS#11 v3.2 conformance checks now live inside the Build tab's workbench
    DeveloperResearcherPlayground
  • ›
    The KMIP control plane is now six tabs — Learn, Policy, Operate, Inspect, Dev, Migration Estate — instead of four, with the busiest ones no longer nested two levels deep
    DeveloperResearcherPlayground
  • ›
    KMIP's policy engine gained a Scenarios view
    DeveloperPlayground
  • ›
    Compliance now shows a monthly PQC certification adoption trend chart
    ExecutiveOpsCompliance
Improvements3
  • ›
    KmipPlaygroundView split into smaller, focused components
    Developer
  • ›
    KMIP's raw YAML view and the "not yet implemented" operations list are now Expert-mode only
    DeveloperPlayground
  • ›
    The KMIP workshop's crypto-agility explainer now appears on the Learn tab for every visitor in Guided mode
    CuriousDeveloperExecutivePlayground
Bug Fixes7
  • ›
    A real bug in production: some HSM workshop lessons could fail with a cryptic PKCS#11 error
    DeveloperResearcherLearnPlayground
  • ›
    The PKCS#11 workshop's KEM panel now honors a lesson's requested algorithm
    DeveloperPlayground
  • ›
    A wrong HIPAA citation in the Learn library was misattributed to the wrong CFR subsection
    ResearcherOpsLibrary
  • ›
    9 Learn-module citations pointed at library rows that had been incorrectly deprecated
    ResearcherLearn
  • ›
    Two vendor PQC roadmap rows carried a mixed-up URL and an undetected duplicate
    ResearcherMigrate
  • ›
    A stale timeline manifest label was silently blocking Germany/BSI milestone evidence from resolving
    ResearcherTimeline
  • ›
    Two Learn modules had a Tools & Products tab that looked broken (empty findings) and one had an unwired Exercises tab
    DeveloperResearcherLearn
Data Updates4
  • ›
    Broad evidence refresh across Library, Timeline, and Compliance Landscape
    ResearcherLibraryTimelineCompliance
  • ›
    Vendor roadmaps, migrate catalog, and trusted sources enrichment
    ResearcherMigrateLibrary
  • ›
    CVE data refreshed
    ResearcherDeveloper
  • ›
    3 IETF protocol-matrix corrections
    ResearcherAlgorithms

September 1, 2026

v4.73.0–v4.74.0
New Features7
  • ›
    The PKCS#11 pipeline builder now runs 3 more real NIST ACVP known-answer tests as editable, runnable pipeline steps
    DeveloperResearcherPlayground
  • ›
    The KMIP 3.0 Corpus Replay tab folded into the pipeline builder's own palette
    DeveloperPlayground
  • ›
    A hands-on HPKE (Hybrid Public Key Encryption) workshop joins the Hybrid Cryptography learning module
    DeveloperResearcherLearn
  • ›
    Keystore items now show their real PKCS#11 engine attributes when inspected
    DeveloperPlayground
  • ›
    PKCS#11 v3.2 Mechanism Coverage grew to include hybrid-KEM building blocks, classical asymmetric variants, symmetric/AEAD mechanisms, and PQC deterministic-seed keygen (CKA_SEED)
    DeveloperResearcherPlayground
  • ›
    The Navigate graph's category, sub-category, and node labels are now clickable
    CuriousExecutive/navigate
  • ›
    The KMIP Developer plane now lives inside KMIP 3.0's own Dev sub-tab, and Corpus Replay gained a Builder/Code split
    DeveloperPlayground
Improvements1
  • ›
    The PKCS#11 Developer tab's "Pipeline" sub-tab is now called "Standard"
    DeveloperPlayground
Bug Fixes1
  • ›
    A PKCS#11 pipeline builder param could show a false "nothing compatible earlier" error for a fixed-vector (hex-literal) input on any non-bytes parameter kind
    DeveloperPlayground
Data Updates2
  • ›
    Closed 573 missing-citation gaps across dozens of Learn modules
    ResearcherCuriousLearn
  • ›
    195 more Library documents enriched, including 2 new IETF CFRG hybrid-KEM Internet-Drafts
    ResearcherLibrary

August 31, 2026

v4.72.0
New Features3
  • ›
    VPN playground: choose your ML-KEM size (512/768/1024)
    DeveloperResearcherPlayground
  • ›
    SSH playground: SLH-DSA host keys now run for real
    DeveloperResearcherPlayground
  • ›
    KMIP and PKCS#11 Developer-tab pipeline builders gained a real per-step Inspect view
    DeveloperPlayground
Bug Fixes2
  • ›
    PKCS#11 pipeline builder no longer crashes importing SLH-DSA, HSS/LMS, RSA, ECDSA, or Ed25519 keys
    DeveloperPlayground
  • ›
    SSH playground: a real SLH-DSA handshake could silently report itself as not quantum-safe
    DeveloperPlayground

August 30, 2026

v4.70.1–v4.71.0
New Features3
  • ›
    Both Developer tabs gained a real ACVP known-answer test for ML-KEM-768 (FIPS 203)
    DeveloperResearcherPlayground
  • ›
    The KMIP Developer tab's generated script now speaks real KMIP 3.0 request grammar
    DeveloperPlayground
  • ›
    Keystore items now show their real PKCS#11 engine attributes when inspected
    DeveloperPlayground
Bug Fixes2
  • ›
    A stale claim in the PKCS#11 Developer tab's generated script explained key lifetime incorrectly
    DeveloperPlayground
  • ›
    Both Developer tabs' Session activity panel no longer pushes the key/keystore view below the fold
    DeveloperPlayground
Data Updates2
  • ›
    21 Library documents with confirmed-unfixable evidence deprecated
    ResearcherCuriousLibrary
  • ›
    70 more Library documents enriched
    ResearcherLibrary

August 29, 2026

v4.65.0–v4.70.0

The PKCS#11 and KMIP Developer tabs now show what your script actually did, and 150+ Learn module citations were closed out. · A big /navigate upgrade, real fixes across mobile, accessibility, Business Tools, and Learn, and a stuck local-AI loop on mobile fixed for good. · Two new Developer tabs teach PKCS#11 v3.2 and KMIP 3.0 by letting you build, run, and export a real sequence of calls, not just read about one — and now you can switch freely between the drag-and-drop builder and the real Python it generates. · The in-browser KMIP crypto-agility engine now runs the same modular, 40-policy set the server does, with a real module-status view and a scope-conflict warning when two policies disagree. · The Simulation is now genuinely playable on a phone, start to finish: every phase works, not just the first two, and every step type — including the ones that build a document — has a real way to complete it.

New Features23
  • ›
    The KMIP Developer tab now shows a real keystore viewer after each run
    DeveloperPlayground
  • ›
    Both Developer tabs now show a real session-activity log for the script you just ran
    DeveloperPlayground
  • ›
    The KMIP Developer tab's Governed-lifecycle template now prints real output for every step, not just the first two
    DeveloperPlayground
  • ›
    /navigate now has motion controls: spin it, take a guided tour, or turn it off
    ResearcherArchitectCurious/navigate
  • ›
    Accessibility coverage extended to 36 more Playground tools, with 9 real issues fixed
    CuriousPlayground
  • ›
    Two persona learning paths gained entries they'd been missing
    ExecutiveDeveloperOps
  • ›
    Related modules now show on mobile Learn pages, not just desktop
    CuriousLearn
  • ›
    Three industry-landscape use cases — web TLS, code signing, and VPN — now link to a real Learn module
    Curious/industry-landscape
  • ›
    Mobile Playground now suggests a "Start here" set of tools for new visitors
    CuriousPlayground
  • ›
    A Builder/Code switch on both Developer tabs
    DeveloperPlayground
  • ›
    A PKCS#11 v3.2 Developer tab, with a drag-and-drop sequence builder
    DeveloperPlayground
  • ›
    A KMIP 3.0 + crypto-agility Developer tab
    DeveloperArchitectPlayground
  • ›
    Guided lessons for both new tabs
    DeveloperPlayground
  • ›
    Every generated script exports as real Python you can take to the sandbox
    DeveloperPlayground
  • ›
    A KMIP Developer tab you can now build by dragging, not just fill in from a template
    DeveloperArchitectPlayground
  • ›
    A real LMS/HSS parameter-set picker on the PKCS#11 Developer tab
    DeveloperPlayground
  • ›
    The KMIP Developer tab's Sign step can now carry a genuinely binary payload
    DeveloperPlayground
  • ›
    The Playground's crypto-agility policy engine now shows which modules are active and warns about conflicts
    ArchitectDeveloperPlayground
  • ›
    The Playground's policy graph and simulator now reflect the real, modular policy set
    ArchitectDeveloperPlayground
  • ›
    All 9 migration phases (plus Foundations) are now playable on a phone, not just the first two
    ExecutiveDeveloperCurious/simulation
  • ›
    Steps that build a document now have a real phone-native way to complete them
    ExecutiveDeveloper/simulation
  • ›
    A move-by-move receipt after every decision
    ExecutiveCurious/simulation
  • ›
    End Quarter and the quarterly report now work on a phone
    Executive/simulation
Bug Fixes21
  • ›
    The PKCS#11 Developer tab's key viewer was unreliable — keys could vanish, show "read error," or get double-counted
    DeveloperPlayground
  • ›
    The PQC Assistant's local AI could get stuck in an endless download-crash-reload loop on mobile
    Curious/
  • ›
    The PKCS#11 and KMIP Developer tabs' Run button was silently failing every time
    DeveloperPlayground
  • ›
    /navigate's auto-rotation ignored your device's reduced-motion setting
    Curious/navigate
  • ›
    The landing page's headline stats flashed "..." before showing real numbers
    Curious/
  • ›
    Mobile's "Start Workshop" button went nowhere real
    CuriousPlayground
  • ›
    /explore was missing from the mobile navigation menu
    Curious/explore
  • ›
    The Library's persona-based narrowing could leave you with no way to see everything
    CuriousLibrary
  • ›
    Several Business Tools reset your work on every reload
    ExecutiveOps/business-tools
  • ›
    Two accessibility issues fixed
    Curious/business-tools
  • ›
    The new /navigate 3D knowledge-graph page failed to open, flashing "Loading..." on a repeating cycle
    ResearcherArchitectCurious/navigate
  • ›
    The precache manifest was 108 KB heavier than it needed to be
    DeveloperPlayground
  • ›
    The mobile "unread updates" indicator could get permanently stuck on, for every visitor
    CuriousDeveloper
  • ›
    The PKCS#11 Developer tab's C++ engine could never provision its own practice token
    DeveloperPlayground
  • ›
    A runaway script in either Developer tab could hang the browser tab indefinitely
    DeveloperPlayground
  • ›
    The new /navigate 3D knowledge-graph page failed to open, flashing "Loading..." on a repeating cycle
    ResearcherArchitectCurious/navigate
  • ›
    The in-browser KMIP engine was 2 commits behind the server engine
    Developer
  • ›
    The "Play This Phase" button in the Watch menu didn't play anything — it started the same narrated video as "Watch"
    ExecutiveCurious/simulation
  • ›
    A quiz question could grow tall enough on a phone to push its own answer button off-screen, with no way to scroll to it
    DeveloperCurious/simulation
  • ›
    Completing the assessment from the Simulation's locked screen, on a phone, never actually unlocked the simulation
    ExecutiveCurious/simulation
  • ›
    On tablets (768–1023px), the onboarding tour and the quiz-completion gate silently didn't appear even though the full desktop board was showing
    Developer/simulation
Data Updates9
  • ›
    150+ citation gaps closed across dozens of Learn modules
    CuriousResearcherLearn
  • ›
    74 additional Q&A/quiz and module content corrections
    CuriousLearn
  • ›
    Corrected a CRQC-timeline confidence figure
    ResearcherCuriousThreats
  • ›
    Recovered an Israel government PQC-readiness guide and a threats document
    ResearcherCuriousTimelineThreats
  • ›
    Fixed 15+ incomplete Library document-status entries and removed a duplicated GRI row
    ResearcherCuriousLibrary
  • ›
    Corrected 12 source dates and a broken Learn-module link
    ResearcherDeveloperTimelineMigrate
  • ›
    Added 25 new patent candidates and corrected an incorrect status on an existing one
    Researcher/patents
  • ›
    Removed a duplicate vendor-roadmap entry
    DeveloperArchitectMigrate
  • ›
    Corrected 5 editorial issues — hardcoded dates, missing citations — across Learn modules
    CuriousLearn

August 28, 2026

v4.60.0–v4.63.0

The Simulation now works honestly on a phone: learn and catalog steps can actually be marked complete there, and the artifact-reveal card no longer hides behind the run controls. · A new /navigate page renders the whole PQC knowledge hub as an explorable 3D graph, the Migrate vendor-risk tab's numbers are now trustworthy, and Share moves out of every page and into one place. · The HSM Playground gets a real PKCS#11 v3.2 conformance checker, the key attribute inspector stops mislabeling post-quantum stateful-signature keys, and ACVP testing gains 8 more real NIST vector categories with visible evidence tiers.

New Features3
  • ›
    A new 3D graph of the whole PQC knowledge hub, at /navigate
    ResearcherArchitectCurious/navigate
  • ›
    A new Conformance tab in the HSM Playground runs OASIS's own published PKCS#11 v3.2 test cases
    DeveloperArchitectOpsPKCS#11 Playground
  • ›
    ACVP testing gains 8 more categories backed by real NIST test vectors
    DeveloperOpsPKCS#11 Playground
Improvements1
  • ›
    Share moved out of every individual page and into the top bar, everywhere
    ExecutiveArchitectDeveloperResearcherOpsCurious
Bug Fixes7
  • ›
    On mobile, Simulation steps had no way to finish — a correct pick only ever linked away
    ExecutiveCurious/simulation
  • ›
    The mobile run-progress card could land underneath the run-control bar at the bottom of the screen, with no way to scroll to the hidden part
    ExecutiveCurious/simulation
  • ›
    Leaving the Simulation phase overview and returning, or reloading the page on a phone, could silently reset an in-progress mobile run back to the overview
    ExecutiveCurious/simulation
  • ›
    The Migrate vendor-risk tab significantly undercounted products and mislabeled infrastructure layers
    ExecutiveArchitectOpsMigrate
  • ›
    Industry names disagreed with each other across Threats, Compliance, and Algorithms
    ExecutiveArchitectThreatsComplianceAlgorithms
  • ›
    /migrate on mobile: product PQC capabilities were hard to read and 604 of about 1,011 catalog products had no path to browse to them
    ExecutiveArchitectMigrate
  • ›
    Post-quantum stateful-signature keys (HSS, XMSS, XMSS^MT) showed up as unlabeled hex instead of their key type
    DeveloperPKCS#11 Playground

August 26, 2026

v4.59.0

The compliance requirements catalogue grows by a third and every requirement in it is now traceable to a quote that really appears in the document it cites, 126 Library documents say which Learn modules teach them, and mobile Library and Timeline gain the Document Analysis panel desktop already had.

New Features2
  • ›
    Document Analysis now opens from Library and Timeline detail views on your phone
    ResearcherArchitectDeveloperCuriousLibraryTimeline
  • ›
    687 more compliance requirements, drawn from 65 more sources
    ArchitectExecutiveOpsCompliance
Improvements1
  • ›
    126 Library documents now tell you which Learn modules teach them
    CuriousResearcherArchitectLibraryLearn
Bug Fixes3
  • ›
    83 compliance requirements quoted text that is not in the document they cite
    ArchitectResearcherOpsCompliance
  • ›
    Learn module pages ran flush against both edges of the screen on phones
    CuriousLearn
  • ›
    The SBOM module cited CISA's 2026 revision twice and the 2021 original not at all
    DeveloperArchitectLearn

August 25, 2026

v4.58.0

A round of fixes to the mobile layer shipped in 4.57.0, found by testing it live on a phone: Assess, Compliance, Migrate, and Algorithms each had a screen that still fell through to the desktop layout, plus assorted overflow and state bugs.

New Features3
  • ›
    Assess now covers the same 13 steps on mobile as on desktop, with a quick/comprehensive track picker
    ExecutiveArchitectOpsDeveloperAssess
  • ›
    Compliance and Migrate: tapping a framework or a vendor's roadmap entry now opens a real detail view
    ArchitectExecutiveOpsComplianceMigrate
  • ›
    Algorithms: a real Protocol Support screen and a real KAT validation screen on mobile
    DeveloperArchitectResearcherAlgorithms
Bug Fixes6
  • ›
    Assess's compliance step showed an incomplete, unranked list of frameworks instead of what actually applies to you
    ArchitectExecutiveAssess
  • ›
    "Replace a classical algorithm" dumped up to 38 options onto one flat, unsorted screen
    DeveloperArchitectAlgorithms
  • ›
    The Algorithms Transition and Detailed Comparison screens showed the full desktop search bar, filter deck, and 5-tab switcher squeezed onto a phone
    DeveloperArchitectResearcherAlgorithms
  • ›
    Text ran off the right edge of the screen instead of wrapping on 7 mobile screens
    CuriousResearcherOpsThreats/patents/leadersLibraryPlayground/businessCompliance
  • ›
    Interactive simulation play on mobile lost your progress if you navigated away and came back
    DeveloperArchitect/simulation
  • ›
    A card on the Algorithms landing screen ran its description text off the edge of the phone
    CuriousAlgorithms

August 24, 2026

v4.57.0

A real mobile experience across the whole app, an ACVP validator that now runs and checks against genuine NIST test vectors, and an accuracy pass across Learn's home boards, MLS/EO 14412 citations, and the compliance maturity catalogue.

New Features1
  • ›
    A real, phone-native version of every screen
    CuriousDeveloperArchitectExecutiveResearcherOps/
Bug Fixes5
  • ›
    The ACVP validator claimed a "real execution / FIPS 140-3 proof" it wasn't actually running
    DeveloperArchitectOpsPlayground
  • ›
    Four retired EU eIDAS requirements were loading as active
    ArchitectResearcherCompliance
  • ›
    40 accuracy defects corrected across all 36 role-based home boards
    ExecutiveDeveloperArchitectResearcherOpsCurious/
  • ›
    A module cited an old MLS draft while its own text described the current one, and four modules stated EO 14412 deadlines without citing where those dates come from
    DeveloperArchitectOpsLearn
  • ›
    FIPS 140-3 and SP 800-230 were each listed twice in the Library
    ResearcherArchitectLibrary

August 23, 2026

v4.56.0

A large accuracy pass across the Learn modules — dozens of citations now point at the standard that is actually current — plus a References tab showing what each module cites, working autosave in the business tools, and a keyboard-navigable, higher-contrast interface.

New Features3
  • ›
    Every Learn module now has a References tab showing exactly what it cites
    CuriousResearcherArchitectLearn
  • ›
    Related modules, and 25 more pages reachable from search
    CuriousLearn
  • ›
    Slide export no longer depends on a third-party generator
    ExecutiveArchitectLearn
Bug Fixes13
  • ›
    Nine modules cited a TLS specification that was replaced in July 2026
    DeveloperArchitectOpsLearn
  • ›
    The 5G module told readers to implement a profile 3GPP never defined
    DeveloperArchitectOpsLearn
  • ›
    A payment module described card authorisation cryptography wrongly
    DeveloperArchitectLearn
  • ›
    Wrong key and signature sizes in three places
    DeveloperArchitectLearn
  • ›
    Business-tool drafts are no longer silently lost
    ExecutiveArchitect/business
  • ›
    Modules that had dropped out of the guided paths are back
    CuriousResearcherLearn
  • ›
    Keyboard and screen-reader navigation through module tabs
    CuriousLearn
  • ›
    Phone and tablet layout fixes
    CuriousOpsLearn
  • ›
    The Assistant's local model had weaker anti-hallucination instructions than the cloud one
    DeveloperResearcher
  • ›
    The Assistant stopped padding answers with weak sources
    ResearcherCurious
  • ›
    The sandbox no longer overstates what it supports
    DeveloperOpsPlayground
  • ›
    A secure-boot page linked to a superseded PKCS#11 draft
    DeveloperOpsLearn
  • ›
    The Algorithms page said what its memory column cannot tell you
    DeveloperArchitectAlgorithms
Data Updates6
  • ›
    Every claim about a source document is now backed by a verified copy
    ResearcherArchitectLibrary
  • ›
    Duplicate and misattributed Library entries cleaned up
    ResearcherLibrary
  • ›
    Six documents were serving a catalogue or project page instead of the standard itself
    ResearcherArchitectLibrary
  • ›
    eIDAS is described correctly
    ExecutiveArchitectCompliance
  • ›
    The protocol matrix is current against the IETF datatracker
    DeveloperArchitectAlgorithms
  • ›
    Six algorithms the site already had data for are now in the catalogue
    DeveloperResearcherAlgorithms

August 19, 2026

v4.54.0–v4.55.0

More product briefs and user manuals are linked, a batch of vendor data mistakes are corrected, the Industry Landscape page no longer sends you to the wrong Learn module, and changing your role on mobile actually works now. · More than double the product catalog now links straight to a vendor's own brief and user manual, 22 newly-discovered PQC patents are indexed, and every citation on the protocol-interoperability matrix now resolves to real evidence.

Bug Fixes2
  • ›
    The Industry Landscape page no longer points "Supply Chain / Logistics" at the wrong Learn module
    ResearcherArchitectAlgorithms
  • ›
    Changing your role on mobile actually works now
    CuriousResearcherExecutiveDeveloperArchitectOps
Data Updates5
  • ›
    Product brief and user manual links, now on 695 of 1,011 catalog products
    OpsArchitectMigrate
  • ›
    Vendor data cleanup: 2 new vendors registered, 5 mismapped products repointed, 4 stale product rows retired
    OpsArchitectMigrate
  • ›
    Product brief and user manual links more than doubled, to 670 of 1,011 catalog products
    OpsArchitectMigrate
  • ›
    22 new patents added — 7 of them post-quantum — and a taxonomy error caught before it shipped
    ResearcherArchitect/patents
  • ›
    Every citation on the protocol interoperability matrix now resolves to real evidence
    DeveloperArchitectAlgorithms

August 18, 2026

v4.53.0

Hybrid certificates in the workshop now cover all six algorithm pairings the current standard recommends — and can be verified, not just generated — while the landing page loads noticeably less up front.

New Features3
  • ›
    Hybrid certificate workshop now offers all six recommended algorithm pairings
    DeveloperArchitectOpsLearn
  • ›
    Certificates you generate can now be checked, not just downloaded
    DeveloperArchitectLearn
  • ›
    RSA key sizes are enforced against the standard
    ArchitectOpsLearn
Improvements2
  • ›
    HQC and FN-DSA now appear in the default algorithm view
    ArchitectDeveloperExecutiveAlgorithms
  • ›
    Industry Landscape tiles sort by cybersecurity opportunity
    ExecutiveArchitect/industry
Bug Fixes3
  • ›
    Hybrid certificates generated by the workshop were malformed and would be rejected elsewhere
    DeveloperArchitectLearn
  • ›
    Key-splitting (M-of-N custody) had stopped working entirely
    OpsArchitectPlayground
  • ›
    The site downloads noticeably less before it can show you anything
    CuriousOps
Data Updates2
  • ›
    Market-size figures refreshed, with Healthcare, Education and Water restored
    ExecutiveResearcher/industry
  • ›
    Superseded spreadsheet generations archived
    Ops

August 17, 2026

v4.52.0

Industry Landscape now covers Cryptocurrency/Blockchain consensus mechanisms, migrate-catalog product tiles link straight to vendor documentation, and the AI assistant recovers hundreds of sentences it was previously cutting off mid-thought.

New Features3
  • ›
    Cryptocurrency/Blockchain coverage added to Industry Landscape
    ResearcherDeveloperArchitectAlgorithms
  • ›
    Three new signature mechanism families tracked
    DeveloperArchitectAlgorithms
  • ›
    Product Brief and User Manual links on migrate-catalog product tiles
    OpsArchitectMigrate
Bug Fixes2
  • ›
    AI assistant answers recover sentences that used to get cut off mid-thought
    CuriousResearcher
  • ›
    Two Learn modules (Government & Defense, Trust Services) now fully searchable by the AI assistant
    CuriousLearn
Data Updates2
  • ›
    Re-verified ~130 migrate-catalog products against current vendor evidence (spotcheck batches 39–64).
    OpsArchitect
  • ›
    Refreshed the AI assistant's search index (16,322 chunks, up from 15,620) to reflect all of the above.
    CuriousResearcher

August 16, 2026

v4.51.0

Industry Landscape rows now show whether their cited evidence names the crypto directly or is a governance driver proven elsewhere, and the Journey panel stops missing milestones in Command Center and OpenSSL Studio.

New Features3
  • ›
    Industry Landscape rows now show what kind of evidence backs them
    ResearcherDeveloperArchitectAlgorithms
  • ›
    75 of 80 Industry Landscape use cases now link to their Library evidence entry
    ResearcherDeveloperAlgorithms
  • ›
    Protocol Matrix flags FIDO as historical, with the standard that superseded it
    DeveloperArchitectAlgorithms
Improvements1
  • ›
    The Journey panel no longer misses milestones from Command Center or OpenSSL Studio
    CuriousDeveloperOps/business/playground/openssl

August 15, 2026

v4.50.1–v4.50.3

The two new PKCS#11 v3.2 library entries (Profiles and Usage Guide) now show full details instead of blank fields. · Library search now finds documents by their standard number no matter how it's written — "PKCS11", "PKCS-11", and "PKCS #11" all now find the same results. · Search results now cite roughly 800 more library documents whose citation links had quietly stopped resolving, and 13 compliance records that weren't being scored for trust are now scored.

Bug Fixes3
  • ›
    Search matches standard numbers regardless of spacing or punctuation
    ResearcherDeveloperLibrary
  • ›
    Search results cite the source passage again for ~800 library documents
    ResearcherDeveloperLibrary
  • ›
    13 compliance records are now scored for trust
    ResearcherOpsCompliance
Data Updates1
  • ›
    PKCS#11 v3.2 Profiles and Usage Guide have full detail pages
    ResearcherDeveloperLibrary

August 14, 2026

v4.50.0

The PKCS#11 playground now runs the audited v3.2 engines rather than older builds, names every mechanism it advertises instead of showing raw hex, and cites the current standard — plus five correctness fixes found by auditing the two engines against each other.

Improvements1
  • ›
    One implementation of stateful hash-based signatures instead of three
    Developer
Bug Fixes7
  • ›
    The playground runs the engines the conformance work actually fixed
    DeveloperArchitectOpsPlayground
  • ›
    The mechanism list reads as mechanism names, not hex codes
    DeveloperPlayground
  • ›
    Panes no longer wipe each other's operation log
    DeveloperPlayground
  • ›
    The key-encapsulation workbench waits for the engine to be ready
    DeveloperPlayground
  • ›
    Hierarchical-deterministic wallet derivation keeps working
    DeveloperArchitectLearn
  • ›
    Standards citations point at sections that exist
    ResearcherDeveloperPlayground
  • ›
    Two cryptographic reading errors, found by running the engines against each other
    DeveloperPlayground

August 12, 2026

v4.48.1–v4.49.0

The library sorts by when a document was actually published rather than when we last touched its record, and the business tools' dollar figures, quotations and vendor guidance have been checked against the documents they cite — three of five financial constants turned out to be wrong. · Seven playground tools now show a review that matches the version you are actually using, and the library stops implying a draft still says something it no longer says.

New Features3
  • ›
    The library shows each document's own publication date, and sorts by it
    ResearcherArchitectOpsDeveloperLibrary
  • ›
    Records say when they were last checked against the source
    ResearcherOpsLibrary
  • ›
    Standards citations in the business tools reach the document
    ExecutiveArchitectDeveloper
Improvements1
  • ›
    The financial baselines were read from the reports, not their landing pages
    Executive
Bug Fixes9
  • ›
    A blank reached an exported board deck with no warning
    Executive
  • ›
    The Monte-Carlo histogram disagreed with the summary above it
    Executive
  • ›
    The Cost of Inaction export named no industry, then used one
    Executive
  • ›
    Vendor guidance contradicted this site's own catalogue
    ArchitectOpsMigrate
  • ›
    A tool said the French authority accepts a NIST signature algorithm on its own
    ArchitectOps
  • ›
    Two quotations attributed to the NIST crypto-agility white paper were not verbatim
    ArchitectResearcher
  • ›
    The Supply Chain Risk Matrix took ~19 seconds to appear
    ArchitectOpsLearn
  • ›
    Seven playground tools showed a review of an older version than the one running
    ResearcherDeveloperArchitectPlayground
  • ›
    The library implied an internet draft still covers JSON web token encryption
    DeveloperArchitectLibrary
Data Updates1
  • ›
    Publication dates derived from the cached evidence
    ResearcherOpsArchitectLibraryTimelineMigrate

August 11, 2026

v4.48.0

Compliance answers "which rules bind me, and why" instead of listing every rule that exists; the business tools stop telling executives that doing nothing is free; every page now says whether it adapts to your role, and the ones that quietly didn't have been fixed or made honest about it.

New Features7
  • ›
    Compliance opens on the rules that bind you
    ExecutiveArchitectOpsCompliance
  • ›
    A reading room for the requirement itself
    ArchitectOpsCompliance
  • ›
    Bring your own crypto inventory into the assessment
    OpsArchitectAssess
  • ›
    Which vendors have actually committed, and what they said
    ExecutiveResearcherMigrate
  • ›
    Two more ways into the same data
    CuriousDeveloperTimelineThreats
  • ›
    Deadlines you can put in a calendar, evidence you can sort by strength
    OpsResearcherTimelineLibrary
  • ›
    Business tools show where their numbers come from
    ExecutiveArchitect
Improvements3
  • ›
    One quantum model across the whole tool suite
    Executive
  • ›
    The financial baselines say which are proven
    Executive
  • ›
    Every surface declares how it treats your role
    Curious
Bug Fixes12
  • ›
    One place to set who you are, instead of three
    CuriousOpsComplianceLibraryTimelineThreats
  • ›
    Choosing your role in the top bar did nothing to the compliance page
    ExecutiveArchitectCompliance
  • ›
    "Country: Any" returned nothing at all
    OpsArchitectCompliance
  • ›
    The register is called Rules & Standards
    CuriousExecutiveCompliance
  • ›
    The Cost of Inaction Analyzer said inaction was free
    Executive
  • ›
    A tool attributed section titles to a NIST document that does not contain them
    Architect
  • ›
    Five surfaces shipped unreachable
    CuriousOps
  • ›
    The left rail is navigation again
    Curious
  • ›
    A standards citation could not reach the standard
    ArchitectResearcher
  • ›
    Unfilled template placeholders could leave the app
    Ops
  • ›
    The About page had no top-level heading
    Developer
  • ›
    The Learn modules are current again
    ArchitectDeveloperLearn
Data Updates5
  • ›
    Seventy-nine library records gained a plain-language summary
    ResearcherLibrary
  • ›
    Duplicate Common Criteria certificates collapsed onto stable ids
    OpsMigrate
  • ›
    Seven Marvell certificates stopped being attributed to a Thales product
    OpsMigrate
  • ›
    The authoritative-sources region field is nearly complete
    Researcher
  • ›
    Proof age is now tracked, not just displayed
    OpsMigrate
Security2
  • ›
    CI stops running files that are not in the repository
    Ops
  • ›
    A data-regression waiver with an expiry date
    Ops

August 10, 2026

v4.47.0

The About page stops stating eleven wrong version numbers about the app you are looking at; three library records stop citing organisations that were never registered; thirty-six compliance write-ups a tooling bug had quietly deleted are back; and quiz answers finally have somewhere to record which document their fact comes from.

New Features1
  • ›
    Quiz answers can now say which document the fact came from
    CuriousResearcherLearn
Bug Fixes6
  • ›
    The About page listed eleven wrong version numbers
    DeveloperCurious/about
  • ›
    Three library records cited trusted sources that did not exist
    ResearcherLibrary
  • ›
    Three claims in the Learn modules were false, found by reading them against their own cited evidence
    ArchitectDeveloperLearn
  • ›
    A Learn module cited an initial public draft as though it were binding
    ArchitectLearn
  • ›
    The architect's Explore card was the ops card with two synonyms swapped
    Architect/
  • ›
    Twenty CI gates were being skipped on every pull request
    Ops
Data Updates3
  • ›
    Thirty-six compliance maturity write-ups a tooling bug had deleted are restored
    ArchitectOpsCompliance
  • ›
    One vocabulary for document types across the library
    ResearcherLibrary
  • ›
    A product catalogue entry conflates two different Azure HSM services
    OpsMigrate
Security3
  • ›
    The search index the site answers from is now signed
    Ops
  • ›
    The three browser crypto engines were rebuilt from current source
    DeveloperOpsPlayground
  • ›
    Dependency updates
    Ops

August 12, 2026

v4.46.0

The entropy tool now runs both of the health tests the NIST standard requires rather than one, and catches a bad sample it used to pass; the 5G tool finally admits it does post-quantum cryptography, so searching for it works; and every tool page gains a proper heading and a genuinely useful "try this next".

New Features1
  • ›
    The entropy tester now runs both health checks the NIST standard asks for
    ResearcherDeveloperArchitectPlayground
Bug Fixes8
  • ›
    The 5G tool no longer hides the post-quantum half of what it does
    DeveloperArchitectResearcherPlayground
  • ›
    Searching for "post-quantum" now finds post-quantum tools
    CuriousExecutiveDeveloperPlayground
  • ›
    The firmware signing tool lists all four algorithms it offers
    DeveloperOpsPlayground
  • ›
    Two unfinished tools now say they are unfinished
    DeveloperArchitectPlayground
  • ›
    The developer sandbox page stopped showing visitors a terminal command
    DeveloperOpsPlayground
  • ›
    "Try this next" now suggests where you actually are
    CuriousDeveloperPlayground
  • ›
    Every tool page now has a proper main heading
    CuriousPlayground
  • ›
    The "reviewed" mark now says what it means
    ResearcherExecutivePlaygroundLearnLibraryComplianceMigrateTimeline
Data Updates1
  • ›
    The JWT tool's encryption reference now names the exact draft it follows
    DeveloperArchitectPlaygroundLearn

August 9, 2026

v4.44.1–v4.45.0

Whichever role you pick, your home page now reaches every part of the site rather than a sixth of it; the protocol readiness matrix stops overstating how far six protocols have actually got; the quiz gains questions for the two audiences that had the fewest; and compliance maturity coverage grows from four source documents to forty-eight. · Product catalog corrections: a tool that has shipped for weeks stops being listed as unfinished, two rows that contradicted their own descriptions are resolved, and rows claiming post-quantum support now say which algorithms they actually mean.

New Features3
  • ›
    Your home page now reaches the whole site, whichever role you picked
    ExecutiveDeveloperArchitectResearcherOpsCurious/
  • ›
    Twelve new quiz questions for the two audiences that had the fewest
    CuriousExecutiveLearn
  • ›
    Forty-four more people in the PQC community roster
    ResearcherCurious/leaders
Bug Fixes9
  • ›
    Six protocols in the readiness matrix were shown one stage further along than they are
    ArchitectDeveloperAlgorithms
  • ›
    Hand-written notes in the readiness matrix are no longer overwritten by the updater
    ArchitectAlgorithms
  • ›
    The "just curious" home page works on a phone again
    Curious/
  • ›
    Two compliance records now link to the document they rely on, not a company homepage
    ArchitectOpsCompliance
  • ›
    Search now ranks documents that have been replaced by a newer version properly
    ResearcherArchitectLibrary
  • ›
    Forty-five quiz questions no persona filter could ever reach are back in circulation
    ArchitectDeveloperOpsExecutiveLearn
  • ›
    A working KMIP server was listed as still in development
    ArchitectDeveloperOpsMigrate
  • ›
    25 catalog entries said "yes, with details" and then named no details
    ArchitectOpsMigrate
  • ›
    Two entries contradicted their own descriptions
    DeveloperMigrate
Data Updates8
  • ›
    Known-vulnerability data rebuilt against the current product cross-reference
    OpsDeveloperMigrate
  • ›
    Industry Landscape: the crypto each of three industries actually relies on, filled in from their own cited documents
    ResearcherArchitectAlgorithms
  • ›
    Compliance maturity coverage goes from four source documents to forty-eight
    ExecutiveArchitectOpsCompliance
  • ›
    Forty-six people in the community roster still have no peer-review status, down from a hundred and twenty-one
    Researcher/leaders
  • ›
    Dead and redirected links repaired across the community roster, vendors and patents
    ResearcherOps/leadersMigrate/patents
  • ›
    Eleven more compliance records name the standards they depend on
    ArchitectCompliance
  • ›
    Nine more product certification links
    OpsMigrate
  • ›
    Four tools added to the migrate catalog
    DeveloperOpsMigrate
Security2
  • ›
    Refreshing the site's search index no longer takes 40 minutes for no reason
    Ops
  • ›
    A build check that could never have run is now able to run
    Ops

August 8, 2026

v4.43.0–v4.44.0

Compliance maturity coverage more than quadruples as documents that were being read only part-way through are now read in full, a batch of library entries that pointed at landing pages get their real source documents, invented requirements are removed, and installing the site for offline use gets dramatically lighter. · Algorithm status pages get corrected for two real misclassifications, threat and timeline records gain dozens of missing links and cross-references, the PKI CRL workshop stops mislabeling a duplicate certificate, and About is reachable from mobile navigation again.

New Features2
  • ›
    Compliance maturity coverage more than quadruples — from 48 tracked requirements to 200
    ExecutiveArchitectOpsCompliance
  • ›
    15 new documents in the library, and 24 compliance records now link straight to the source document they are based on
    ResearcherArchitectLibraryCompliance
Bug Fixes11
  • ›
    Installing the site for offline use is roughly three times lighter
    CuriousOps/
  • ›
    Vendor proof documents open properly instead of showing the site's own home page
    ArchitectOpsMigrate
  • ›
    Invented requirements removed, and repaired records for Canada's CSE and FIPS-198
    ExecutiveResearcherCompliance
  • ›
    12 library documents pointed at a landing page instead of the document itself
    ResearcherLibrary
  • ›
    Three broken tool links in the sandbox scenarios
    DeveloperPlayground
  • ›
    About is reachable from the mobile navigation menu again
    Curious/about
  • ›
    The CRL Generator workshop no longer lists a phantom duplicate certificate, and explains real failures instead of a bare status code
    DeveloperArchitectLearn
  • ›
    Two algorithm status mislabels corrected
    ResearcherArchitectAlgorithms
  • ›
    Timeline and Compliance cross-references filled in
    ResearcherOpsTimelineCompliance
  • ›
    Every threat-landscape record now links to the Learn module that explains it
    OpsDeveloperThreats
  • ›
    Three role-board tiles showed a placeholder label instead of a real one
    ExecutiveDeveloperArchitectOps
Data Updates3
  • ›
    The SSH sandbox scenario now covers OpenSSH 10.4 and compares two post-quantum signature schemes side by side
    DeveloperArchitectPlayground
  • ›
    The migrate catalog gains the pqctoday-strongswan-pkcs11 fork
    DeveloperOpsMigrate
  • ›
    Every in-browser crypto engine rebuilt against the current HSM release, and OpenSSL moved to 3.6.3
    DeveloperArchitectOpsPlayground
Security1
  • ›
    Patched 3 known vulnerabilities in bundled third-party libraries: a sanitizer bypass, a diagram-rendering prototype-pollution/DoS issue, and an ID generator that could loop indefinitely on bad input. A 4th (an image-dimension parser, pulled in by the PPTX export feature) has no upstream fix available yet; we've confirmed the affected code path isn't reachable from anything this site actually does with it.

August 7, 2026

v4.42.0

The app installs roughly 250 MB lighter and works offline sooner, algorithm pages let you read a spec or try a tool without losing your place, and Compliance's maturity data is reconnected after a data-archival sweep silently broke it.

New Features8
  • ›
    Algorithm pages let you read the spec or try a tool without losing your place
    DeveloperResearcherArchitectAlgorithms
  • ›
    Patents now has a Sources button, like every other data page
    Researcher/patents
  • ›
    The crypto lab warns you before you open a tool your device can't run
    DeveloperPlayground
  • ›
    Command Center's filters are shareable
    OpsArchitect/business
  • ›
    Developers get a report built for developers
    Developer/report
  • ›
    A "Runs on this device" filter in the crypto lab
    DeveloperPlayground
  • ›
    Command Center's tool grid can be grouped by framework phase or CSWP.39 zone
    OpsArchitect/business
  • ›
    Crypto lab tools link back to the module that explains them
    DeveloperCuriousPlayground
Improvements5
  • ›
    First-visit install size cut by roughly 250 MB
    DeveloperOps
  • ›
    Search loads only when you open it
    Developer
  • ›
    The crypto lab grid shows browser-runnable tools by default
    DeveloperPlayground
  • ›
    Search finds workshop and business tools even on broad queries
    DeveloperOps/
  • ›
    The vendor roadmap tracker states its real denominator
    ExecutiveOpsMigrate
Bug Fixes9
  • ›
    Compliance's maturity and governance requirements are reconnected on every pillar
    ExecutiveArchitectOpsCompliance
  • ›
    Compliance detail tiles no longer overflow their own card
    ExecutiveCompliance
  • ›
    The CT Log simulator's Certificate Authority can now sign, not just verify
    DeveloperArchitectLearn
  • ›
    Eight real accessibility violations fixed across the business and crypto-lab tools
    OpsResearcher/businessPlayground
  • ›
    The Algorithms "FIPS-validated" and "NIST picks" quick views now show the right rows
    ResearcherArchitectAlgorithms
  • ›
    The homepage's "continue where you left off" banner is back
    CuriousDeveloper/
  • ›
    The executive algorithm card gives EU visitors EU-correct guidance
    ExecutiveArchitectAlgorithms
  • ›
    The side panel's tab row hints when there's more to scroll to
    DeveloperOps
  • ›
    Every row in the main navigation is reachable in one keyboard stop, not two
    OpsResearcher

August 2, 2026

v4.38.0–v4.41.0

Every role's home page now offers three different ways in rather than one, each pointing at its own tool, and the numbers those pages quote are computed rather than typed. The PKCS#11 playgrounds gained a live call log and a real view of what is on the token, and every crypto engine on the site was rebuilt current. · Text and controls across the light theme now meet the WCAG AA contrast standard, and the navigation loses three controls that duplicated the top bar. · A round of genuine bug fixes found by re-checking last week's UX audit against the actual code — a migration deadline that displayed a date in the past, filters that returned nothing, links that went nowhere, and a Share button that sent people to an empty page. Also roughly 26 MB less to download on your first visit. · A page-by-page pass across Algorithms, Compliance, Library, Migrate, Playground, Threats, Timeline, and the Command Center — unlocking content that was gated for no good reason, replacing hand-typed lists with the real catalogue behind them, and giving pages honest error states instead of silent blank ones.

New Features12
  • ›
    Your role's home page now offers three ways in, not one
    ExecutiveDeveloperArchitectResearcherOpsCurious/
  • ›
    OpenSSL Studio shows what the security token actually did
    DeveloperOpsPlayground
  • ›
    You can now read what is really stored on the token
    DeveloperOpsPlayground
  • ›
    The SSH simulator shows the keys it created
    DeveloperOpsPlayground
  • ›
    The TPM inspector shows how many temporary slots are in use
    DeveloperArchitectPlayground
  • ›
    Replaced keys show what they superseded
    OpsArchitectPlayground
  • ›
    Phone-sized browser testing
    Developer
  • ›
    Algorithms shows the ACVP verification claim up front
    DeveloperResearcherAlgorithms
  • ›
    Timeline shows how fresh each country's data is
    ResearcherOpsTimeline
  • ›
    Library shows corpus health at a glance
    ResearcherLibrary
  • ›
    Migrate covers vendors who have announced a roadmap, not just those with nothing
    ArchitectOpsMigrate
  • ›
    Command Center gains a first-visit board-pack walkthrough
    Executive/business
Improvements9
  • ›
    Every crypto engine on the site was rebuilt current
    DeveloperOpsArchitectPlayground
  • ›
    The MLS workshop says which implementation you are driving
    DeveloperPlayground
  • ›
    The assistant and your journey map are both in the top bar
    ExecutiveDeveloperArchitectResearcherOpsCurious/
  • ›
    The Reference group in the left bar starts open
    CuriousResearcher/
  • ›
    The Learn page is less crowded
    CuriousExecutiveLearn
  • ›
    Role pages promise what they actually deliver
    OpsExecutive/
  • ›
    About 26 MB less to download on your first visit
    Developer
  • ›
    The footer year is computed rather than hardcoded
  • ›
    The AI Assistant's anti-fabrication rules are stricter
Bug Fixes38
  • ›
    Fourteen tool links on the role home pages opened the wrong page
    ExecutiveDeveloperArchitectResearcherOpsCurious//business
  • ›
    The researcher's field watch reported zero updates to everyone, permanently
    Researcher/
  • ›
    The exposure card drew the wrong conclusion from its own numbers
    ExecutiveResearcher/
  • ›
    Opening a Learn module could complete it before you had read anything
    CuriousDeveloperLearn
  • ›
    A failed Root CA step left an unusable key behind
    OpsArchitectLearn
  • ›
    Boards pointed at tools they did not describe
    ExecutiveDeveloperArchitectResearcherOpsCurious/
  • ›
    Modern elliptic-curve keys were filed as symmetric keys
    OpsDeveloperPlayground
  • ›
    Resetting the VPN simulator left sessions open on the token
    OpsPlayground
  • ›
    Writing a key "to the token" could silently produce an exportable file instead
    DeveloperOpsPlayground
  • ›
    Small text is readable again throughout the light theme
    ExecutiveOpsCurious/TimelineLibraryComplianceMigrate
  • ›
    Cards, table rows and framework tiles work with a keyboard and a screen reader
    ResearcherOpsLibraryThreatsComplianceMigrate
  • ›
    The achievement celebration appears when you earn it, not later
    CuriousDeveloperLearn
  • ›
    Horizontally scrolling strips can be scrolled without a mouse
    Compliance
  • ›
    PQC 101's key generation works in both panes again
    DeveloperCuriousLearn
  • ›
    Learn is visible on the left bar without expanding anything
    CuriousDeveloper/
  • ›
    The Threats page no longer shows a migration deadline that has already passed as if it were upcoming
    ExecutiveArchitectThreats
  • ›
    The Algorithms region filter actually returns results
    ArchitectResearcherAlgorithms
  • ›
    Sharing your readiness report now sends a working link
    Executive/report
  • ›
    The Migration Workbench feeds the Roadmap Builder again
    OpsArchitectMigrate
  • ›
    Migrate's references to learning modules are clickable
    DeveloperOpsMigrate
  • ›
    Patent links to algorithms work for older patents
    Researcher/patents
  • ›
    First-time visitors can reach the whole site from the desktop menu
    Researcher/
  • ›
    The Compliance table view can open framework details
    ExecutiveCompliance
  • ›
    The Library's top pick for executives opens
    ExecutiveLibrary
  • ›
    OpenSSL Studio shows the right documentation for post-quantum algorithms
    DeveloperOpenSSL Studio
  • ›
    The curious mobile home screen's buttons work
    Curious/
  • ›
    The About page no longer describes a cloud-sync control that doesn't exist
    /about
  • ›
    Migrate's page header stays put
    Migrate
  • ›
    The Algorithms Protocol Support table is no longer locked for new visitors
    CuriousAlgorithms
  • ›
    Threats opens with the headline estimate, detail one click away
    ResearcherThreats
  • ›
    Compliance tells you when a load fails instead of looking empty
    ResearcherCompliance
  • ›
    Timeline says what actually went wrong
    ResearcherTimeline
  • ›
    Timeline's enrichment analysis is one click, not two
    ResearcherTimeline
  • ›
    The Playground's mobile tool list matches the real catalogue
    DeveloperPlayground
  • ›
    Sandbox-gated Playground tools are dimmed, not hidden
    DeveloperOpsPlayground
  • ›
    The Playground's engineering surfaces are hidden from non-engineering roles
    ExecutiveCuriousPlayground
  • ›
    Library detail restores its evidence links
    ResearcherLibrary
  • ›
    The "Start here" row on the Playground overview is 3 tools, not 6
    CuriousPlayground
Security1
  • ›
    Token isolation and login fixes
    OpsDeveloperPlayground

August 1, 2026

v4.35.0–v4.37.0

A full front-door and navigation redesign built around six personas — Executive, Developer, Security Architect, IT Ops, Researcher, and Curious Explorer — replacing the flat top nav with a two-section rail and giving every persona a real first win instead of a generic hero banner. · A three-phase mobile UX remediation: five app-wide root causes fixed once each, 28 high-severity page-specific bugs resolved, and a 51-finding touch-target sweep across 40 files — plus two real functional bugs caught along the way that weren't mobile-specific at all. · The Financial Services & Payments module gains a real Open Banking & PSD2 section, a revived BSI standard and 4 real evidence documents replace low-quality captures in the Library, and 22 broken glossary links across 9 modules are fixed.

New Features9
  • ›
    A new "Who's asking?" front door
    ExecutiveDeveloperArchitectOpsResearcherCurious
  • ›
    A real navigation rail, not a flat row
    ExecutiveDeveloperArchitectOpsResearcherCurious
  • ›
    One place to change who you are and where you work
    ExecutiveDeveloperArchitectOpsResearcherCurious
  • ›
    A single page-actions strip in the top bar
    ResearcherOps
  • ›
    The Sources panel now names the data file behind the page
    Researcher
  • ›
    Six persona boards, each with a real first win
  • ›
    A dedicated mobile experience for new/non-technical visitors
    Curious
  • ›
    Researchers can now watch specific topics for changes
    Researcher
  • ›
    New section: Open Banking & PSD2 Strong Customer Authentication
    DeveloperArchitectLearn
Bug Fixes30
  • ›
    The buttons on every persona board now actually go somewhere
    ExecutiveDeveloperArchitectOpsResearcherCurious
  • ›
    Switching roles no longer leaves you scrolled past the new page's buttons
    ExecutiveDeveloperArchitectOpsResearcherCurious
  • ›
    Persona board numbers are read from the real data, not typed by hand
    ExecutiveDeveloperArchitectOpsResearcherCurious
  • ›
    Board copy no longer prints internal code names at readers
    ExecutiveDeveloperArchitectOpsCurious
  • ›
    The Glossary and User Manual panels close when you click outside them
    Curious
  • ›
    Business Center opens straight into the Command Center
    Executive/business
  • ›
    Breadcrumb trails removed from every page
  • ›
    The "show me everything" escape hatch actually works now
    CuriousLearn
  • ›
    OpenSSL Studio no longer has two separate front doors
    DeveloperArchitectOpsPlayground
  • ›
    The AI Assistant no longer sends you to a dead personalization link
    Curious
  • ›
    Compliance no longer shows a generic Sources button
    ResearcherCompliance
  • ›
    The AI Assistant button no longer covers page content while you scroll on mobile
    Curious
  • ›
    The glossary panel no longer crowds out tool content on mobile
    DeveloperOpsPlayground
  • ›
    Mobile navigation hints when there's more to scroll to, and fits better
    Curious
  • ›
    A hidden Compliance tab is visible again on mobile
    ResearcherCompliance
  • ›
    Search is now reachable on mobile
    Curious
  • ›
    iPhone/iPad users get honest guidance on the VPN/SSH live-crypto gate
    CuriousLearn
  • ›
    Simulation's mobile locked-screen header and full-migration flow no longer clip or drop options
    Curious/simulation
  • ›
    The Algorithms "Transition Guide" tab is reachable again on mobile
    ResearcherAlgorithms
  • ›
    TPM Playground's EK Certs tab no longer hangs forever
    OpsDeveloperPlayground
  • ›
    Threats dashboard cards no longer take up to a minute to appear
    ResearcherThreats
  • ›
    Playground Workshop's tool list and detail modal now work on mobile
    DeveloperPlayground
  • ›
    The embedded (vendor-hosted) view's navigation and sidebar work correctly on mobile
    Developer
  • ›
    51 more controls across 40 files now meet the app's 44px mobile touch-target minimum
    Curious
  • ›
    Smaller mobile fixes
  • ›
    BSI-AIS-20-31 standard revived a second time
    ResearcherLibrary
  • ›
    4 more Library documents replaced with the real thing
    ResearcherLibrary
  • ›
    22 broken glossary links fixed across 9 Learn modules
    CuriousLearn
  • ›
    The financial sector's "no dated mandate" claim, qualified
    ResearcherLearn
  • ›
    "PQC Candidates & Lifecycle" title corrected
    CuriousLearn
Data Updates2
  • ›
    library_07312026_r2.csv and trusted_sources_07312026_r7.csv refreshed
    ResearcherLibrary
  • ›
    Search index refreshed

July 31, 2026

v4.33.0–v4.34.0

The Digital ID module gets real mdoc/SD-JWT credential flows and links back from the compliance frameworks it covers, 10 new real regulations and 17 certification schemes join Standardization & Compliance, and this week's Financial Services quiz and module content is corrected. · Learn modules and Playground tools now show a real, working revision history instead of a button that always claimed everything was up to date.

New Features6
  • ›
    Digital ID module: real mdoc selective disclosure and the share chooser
    DeveloperArchitectLearn
  • ›
    Compliance frameworks link back to the module that teaches them
    CuriousDeveloperCompliance
  • ›
    Deadlines can now derive from the timeline
    ResearcherComplianceTimeline
  • ›
    Compliance deadlines: separate start and finish dates, sortable by finish
    ExecutiveOpsCompliance
  • ›
    The Simulation routes Digital ID from the government sector track
    Curious/simulation
  • ›
    Learn modules and Playground tools now show their real review status
    DeveloperArchitectResearcherLearnPlayground
Bug Fixes6
  • ›
    Digital ID module: corrected wrong facts, refreshed stale spec references, fixed a shared-session bug
    DeveloperLearn
  • ›
    The EUDI Wallet rollout date no longer overwrites the EU's PQC deadline
    ResearcherTimeline
  • ›
    3 fabricated PQC standards removed from the Library, a 4th corrected
    ResearcherLibrary
  • ›
    Financial Services & Payments module (LM-044): factual and consistency corrections
    ResearcherLearn
  • ›
    Financial Services & Payments quiz: 2 answers corrected, 2 learner paths now assessed
    CuriousAssess
  • ›
    5 modules' listed duration/difficulty corrected to match their actual content
    CuriousLearn
Data Updates8
  • ›
    10 new real compliance regulations added, across the US, EU, Canada, and 6 emerging markets
    ResearcherCompliance
  • ›
    17 new certification schemes added and cross-linked into trusted sources
    ResearcherCompliance
  • ›
    20 organization rows corrected after wrongly claiming a PQC mandate
    ResearcherCompliance
  • ›
    13 missing EU member states added to the jurisdictions registry
    ResearcherCompliance
  • ›
    Compliance industry filter fixed to return what you actually select
    ResearcherCompliance
  • ›
    Mastercard's 2025 PQC industry-awareness whitepaper added to Industry Landscape
    ResearcherAlgorithms
  • ›
    Search index refreshed
  • ›
    Corrected 4 mislabeled entries in the site's revision-history log
    Researcher/revisions

July 30, 2026

v4.30.1–v4.32.0

Two new Learn modules cover government/defense and trust-service PQC migration, community leaders are now cross-linked to their patents and open-source projects, and this week's vendor, certification, and threat-watch data is refreshed. · A new Industry Landscape tab on the Algorithms page shows what crypto mechanisms each industry actually relies on today — cross-referenced against real standards, official market-size figures, and live threat data. · Four Migrate catalog entries had the wrong company listed as their maker, and five Library/Compliance citations that pointed at inaccessible pages now resolve to the real source documents.

New Features5
  • ›
    Two new Learn modules: Government & Defense, and Trust Services
    ArchitectOpsLearn
  • ›
    Leaders now link to their patents and open-source projects
    Researcher/leaders
  • ›
    Product-id and inventor deep links into Patents and Migrate
    Researcher/patentsMigrate
  • ›
    Industry Landscape tab
    ArchitectExecutiveResearcherAlgorithms
  • ›
    "Learn: <industry>" links on industry pages
    CuriousAlgorithms
Data Updates9
  • ›
    Library, compliance, algorithms, migrate, assessment, and threats catalogs refreshed
    ResearcherLibraryComplianceAlgorithmsMigrate
  • ›
    Product certifications and CRQC-watch data re-synced
    ResearcherMigrateThreats
  • ›
    OpenSSH 10.4's composite signature support noted in the Protocol Support matrix
    DeveloperAlgorithms
  • ›
    34 industry standards, verified to actually name a crypto mechanism
    ResearcherAlgorithms
  • ›
    8 new Library documents added, each independently downloaded and verified
    ResearcherLibrary
  • ›
    Insurance industry re-grounded
    ResearcherAlgorithms
  • ›
    4 products' vendor attribution corrected
    ResearcherMigrate
  • ›
    5 Library and Compliance citations now resolve to real source documents
    ResearcherLibraryCompliance
  • ›
    A community leader's citation now points at a real, current document
    Researcher/leaders

July 29, 2026

v4.29.1–v4.30.0

The Simulation got a full accuracy, usability, and teaching pass: every factual claim was re-verified against its source, hands-on play is now a clearly named option (and phones can watch the narrated overview), and the game finally explains its own scoring. · Four organizations behind recently-added Library documents — an aviation standards consortium, an ISO committee, and Italy's and Japan's national cybersecurity bodies — are now tracked as verified sources instead of showing no source at all. · 52 Library documents that were sitting as bare, unreviewed stubs now show real information — document type, industries, authors, migration urgency, and more — instead of blank fields.

New Features6
  • ›
    "Play it yourself" is now a named way to play
    CuriousExecutive/simulation
  • ›
    Watch the Executive Overview on your phone
    Executive/simulation
  • ›
    Terms & glossary inside the sim
    Curious/simulation
  • ›
    The grade card explains its own math
    Curious/simulation
  • ›
    Save your roadmap at the finish line
    Executive/simulation
  • ›
    What happens after the migration closes
    ArchitectOps/simulation
Improvements3
  • ›
    Wrong picks now state their price
    Curious/simulation
  • ›
    Playback progress no longer disappears
    /simulation
  • ›
    Dialogs keep keyboard focus where it belongs
    /simulation
Bug Fixes4
  • ›
    Payment-industry claim brought up to date
    Executive/simulation
  • ›
    Deadline attribution corrected
    Researcher/simulation
  • ›
    The quantum-threat window now adds up
    Researcher/simulation
  • ›
    Fictional planning dates no longer read as overdue
    /simulation
Data Updates6
  • ›
    India moved out of the jurisdiction picker
    Researcher/simulation
  • ›
    Framework cross-references verified against source documents
    Researcher/simulation
  • ›
    4 new trusted sources registered
    ResearcherLibrary
  • ›
    6 cached evidence documents recovered
    Researcher
  • ›
    52 Library entries completed with real, cited detail
    ResearcherArchitectDeveloperLibrary
  • ›
    4 duplicate/superseded entries cleaned up
    ResearcherLibrary

July 28, 2026

v4.28.0–v4.29.0

The Algorithms catalog now describes hybrid key exchange properly — the pairing of a classical algorithm with a post-quantum one, which is how most real PQC deployments are rolling out. · A big data-accuracy and coverage pass across Migrate, Vendor Roadmaps, Timeline, Trusted Sources, Threats, and Algorithms — plus real fixes to broken certificate links, a mis-detected PQC algorithm, and several data-pipeline bugs found along the way.

New Features11
  • ›
    Hybrid key exchange is now catalogued beyond TLS
    ArchitectDeveloperOpsAlgorithms
  • ›
    X-Wing, the general-purpose hybrid
    DeveloperAlgorithms
  • ›
    Post-quantum SSH key exchange
    OpsDeveloperAlgorithms
  • ›
    Composite certificates for PKI
    ArchitectOpsAlgorithms
  • ›
    The SLSA v1.1 specification joins the Library
    DeveloperOpsLibrary
  • ›
    13 previously-broken product certificate links now resolve to the real NIST validation record
    DeveloperArchitectMigrate
  • ›
    New Migrate catalog entries
  • ›
    27 new authoritative sources
    ResearcherArchitect
  • ›
    18 new industry threat & compliance documents
    OpsArchitectThreats
  • ›
    New vendor roadmaps
  • ›
    14 new government PQC milestones on the Timeline
    ExecutiveOpsTimeline
Improvements4
  • ›
    The three existing TLS hybrids are relabelled to say they're TLS-specific
    Algorithms
  • ›
    The WireGuard sandbox walkthrough is retired
    OpsPlayground
  • ›
    Classic McEliece is now shown as a fully standardised algorithm
    Algorithms
  • ›
    9 NIST digital-signature candidates (UOV, SQIsign, FAEST, SNOVA, MAYO, HAWK) now show Round 3 status
    Algorithms
Bug Fixes6
  • ›
    83 more Migrate catalog products now show up under the right migration step
    ArchitectOpsMigrate
  • ›
    76 catalog entries were missing their internal product identifier
    Developer
  • ›
    A product with LMS/HSS hash-based signatures was incorrectly marked as having no post-quantum support
    Developer
  • ›
    Three catalog entries had inaccurate claims corrected
  • ›
    A threat-database document's evidence file was corrupted at the source
  • ›
    Several internal consistency checks (duplicate source entries, stale playground scenario references, and a couple of new-algorithm classification gaps) were caught and fixed before release.
Data Updates1
  • ›
    Two SSH entries deliberately leave key sizes blank. Their specification doesn't state them and the sizes depend on an encoding defined in a different document, so the field says nothing rather than showing a number that looks more authoritative than it is.

July 26, 2026

v4.27.0

The Library page now shows who reviewed each document and when, four documents that had been silently showing site-navigation text instead of their real content are fixed, and seven Timeline milestones get their review badge back.

New Features1
  • ›
    Library documents now show their review status
    DeveloperArchitectResearcherLibrary
Improvements1
  • ›
    The About page's Trust Engine section now explains the actual review pipeline
    CuriousExecutive/about
Bug Fixes3
  • ›
    Four recently-added Library documents had broken extracted content
    ResearcherLibrary
  • ›
    Brand-new Library documents no longer sort to the bottom of "Newest first"
    DeveloperLibrary
  • ›
    Seven Timeline milestones show their review badge again
    OpsResearcherTimeline

July 25, 2026

v4.25.5–v4.26.0

OpenSSL Studio gets a working hardware-token workbench backed by a genuinely independent PQC engine, the TPM 2.0 Playground stops corrupting itself when two panels are used at once, and seven Learn modules get the infographic they were missing. · OASIS published the next revision of the KMIP 3.0 spec since our last update; this release moves the Protocol Matrix and the KMIP 3.0 Playground onto it.

New Features4
  • ›
    OpenSSL Studio has a new PKCS#11 (HSM) workbench you can actually generate keys in
    DeveloperArchitectOpsOpenSSL Studio
  • ›
    The token behind OpenSSL Studio is now a genuinely independent implementation
    DeveloperResearcherOpenSSL Studio
  • ›
    Seven Learn modules now show their infographic
    CuriousExecutiveArchitectLearn
  • ›
    The TPM 2.0 Playground now proves the spec revision it claims, instead of asserting it
    DeveloperResearcherTPM 2.0 Playground
Improvements5
  • ›
    Changelog entries now name the page they affect instead of showing a raw path
    Curious/changelog
  • ›
    The Algorithms page's Protocol Matrix now cites the published KMIP 3.0 spec, not the earlier draft
    DeveloperArchitectResearcherAlgorithms
  • ›
    The KMIP 3.0 Playground's tour, glossary, quiz, and command reference now cite the published spec throughout
    DeveloperArchitectKMIP 3.0 Playground
  • ›
    The Revoke reason picker in the KMIP 3.0 Playground now offers all 10 real revocation reasons, up from 5
    DeveloperKMIP 3.0 Playground
  • ›
    The KMIP 3.0 Playground's in-browser engine was rebuilt against the latest published spec
    DeveloperArchitectKMIP 3.0 Playground
Bug Fixes6
  • ›
    The TPM 2.0 Playground no longer corrupts its own results when two panels run at once
    DeveloperArchitectTPM 2.0 Playground
  • ›
    Certificate steps that use an EC key in OpenSSL Studio's HSM demos now work
    DeveloperOpsOpenSSL Studio
  • ›
    OpenSSL Studio's Workbench buttons no longer get pushed off the screen
    DeveloperOpenSSL Studio
  • ›
    OpenSSL Studio's Explore and Learn tabs now tell you when the engine fails to load
    DeveloperResearcherOpenSSL Studio
  • ›
    A data-refresh bug that could have un-published two RFCs on the Algorithms page is fixed
    DeveloperArchitectResearcherAlgorithms
  • ›
    Approving one Protocol Matrix correction no longer applies all of them
    OpsAlgorithms
Data Updates5
  • ›
    11 new standards documents added to the Library
    ResearcherArchitectLibrary
  • ›
    2 new industry threat framework entries
    ExecutiveArchitectThreats
  • ›
    3 government timeline entries retired because their source links no longer resolve
    ResearcherTimeline
  • ›
    Australia keeps its 2030 deadline
    ExecutiveResearcherTimeline
  • ›
    Three timeline entries now appear under their country again
    ResearcherTimeline

July 24, 2026

v4.24.1–v4.25.4

An OpenSSL Studio release: a new guided Learn tab and a live Algorithm Explorer, both running the real openssl.wasm engine bundled with the site (not simulated output). · A maintenance-pipeline accuracy pass: several standards, catalog, timeline, glossary, and leaders-profile corrections found and verified during a full end-to-end review of the data maintenance process.

New Features5
  • ›
    The TPM 2.0 Playground's Learn tab now shows each step's real wire exchange inline
    DeveloperArchitectTPM 2.0 Playground
  • ›
    The PKCS#11 Learn tab now shows each step's own call log inline
    DeveloperPKCS#11 PlaygroundLearn
  • ›
    OpenSSL Studio's Learn tab now shows the real command output under each step
    DeveloperResearcher/playground/openssl
  • ›
    New 11-lesson Learn tab for OpenSSL Studio
    DeveloperArchitectResearcher/playground/openssl
  • ›
    New "Explore" tab shows every algorithm this exact OpenSSL build actually supports
    DeveloperResearcher/playground/openssl
Bug Fixes7
  • ›
    Corrected 2 wrong spec-section citations in the KMIP 3.0 Playground
    DeveloperArchitectKMIP 3.0 Playground
  • ›
    Fixed a silently wrong algorithm codepoint in the KMIP 3.0 patch tables
    DeveloperKMIP 3.0 Playground
  • ›
    Added a completeness check for KMIP 3.0's WD19 draft delta
    DeveloperArchitectKMIP 3.0 Playground
  • ›
    The PKCS#11 Learn tab's call log no longer shows confusing internal housekeeping as failed calls
    DeveloperPKCS#11 PlaygroundLearn
  • ›
    OpenSSL Studio's Learn tab no longer breaks partway through multi-step lessons
    DeveloperResearcher/playground/openssl
  • ›
    OpenSSL Studio's failure detection and error messages are now accurate
    DeveloperResearcher/playground/openssl
  • ›
    The TPM Playground's compliance check no longer fails after visiting the Learn tab first
    DeveloperResearcherPlayground
Data Updates8
  • ›
    5 protocols advanced in the Standards Support Matrix, reflecting real IETF progress
    DeveloperArchitectAlgorithms
  • ›
    Corrected HAWK's post-quantum signature status in the Migrate catalog
    DeveloperResearcherMigrate
  • ›
    4 more Migrate catalog products now show a verified certification
    ResearcherMigrate
  • ›
    Fixed 2 Migrate catalog products linked to the wrong company
    Migrate
  • ›
    2 more Timeline milestones now show a verified source organization
    ResearcherTimeline
  • ›
    Fixed 3 broken "learn more" links in the Glossary
    Library
  • ›
    Cleaned up 37 mislabeled entries in the authoritative sources directory
    ResearcherLibrary
  • ›
    10 more Leaders profiles now show a verified peer-review credential
    Researcher/leaders

July 23, 2026

v4.24.0

A TPM 2.0 Playground release: a new guided Learn tab teaching classical-vs-post-quantum TPM operations side by side, and a fix to the underlying crypto bridge that had been silently substituting placeholder data for real ML-DSA signatures and ML-KEM key exchanges.

New Features1
  • ›
    New guided Learn tab for the TPM 2.0 Playground
    DeveloperArchitectResearcherPlayground
Bug Fixes3
  • ›
    The TPM Playground's post-quantum cryptography is now genuinely real
    DeveloperResearcherPlayground
  • ›
    The TPM Playground's Command Builder no longer sends made-up data for multi-step operations
    DeveloperPlayground
  • ›
    The TPM Playground's compliance checklist can no longer misreport a passing score
    DeveloperOpsPlayground

July 24, 2026

v4.22.1–v4.23.0

A PKCS#11 Learn tab release: a new lesson on key-trust policy, and a more trustworthy call log across the whole HSM playground. · Small accuracy pass: Ops nav reachability, a persistence fix on mobile Timeline, softer Patents copy, several stale-citation and dead-link corrections across Learn, and a CACP KMIP 3.0 playground accuracy fix.

New Features1
  • ›
    New "Trust & wrapping policy" lesson in the PKCS#11 Learn tab
    DeveloperArchitectPKCS#11 Playground
Improvements3
  • ›
    Added Algorithms to the IT Ops navigation
    OpsAlgorithms
  • ›
    The mobile Timeline's "All phases" view now stays selected
    OpsTimeline
  • ›
    Softened the /patents preview banner for curious visitors
    Curious/patents
Bug Fixes8
  • ›
    The PKCS#11 workshop and Learn tab's call log now shows what actually happened, by default
    DeveloperLearnPKCS#11 Playground
  • ›
    A skipped lesson step could display as "refused, correctly" when it had actually crashed
    DeveloperPKCS#11 Playground
  • ›
    Refreshed the HSM playground's underlying crypto engines
    DeveloperOpsPKCS#11 Playground
  • ›
    Corrected a stale 2024 data-breach citation
    ExecutiveLearn
  • ›
    Corrected the "10-50x larger certificates" claim in the last two places it survived
    ArchitectCuriousLearn
  • ›
    Replaced personal email contact links on the About page
    /about
  • ›
    Reviewed and corrected 8 Learn modules' internal citation lists
    DeveloperArchitectOpsLearn
  • ›
    Corrected spec citations and a dormant algorithm-mapping bug in the CACP KMIP 3.0 playground
    DeveloperArchitectKMIP 3.0 Playground
Data Updates2
  • ›
    Resolved 7 library entries flagged for URL review
    ResearcherLibrary
  • ›
    Backfilled related-standards links on 3 compliance entries
    ResearcherCompliance

July 19, 2026

v4.22.0

A major Simulation release: a six-wave accuracy and gameplay overhaul, real hub data flowing through the sim's documents and events, and a refreshed NIST library entry.

New Features6
  • ›
    Simulation results now appear on the Executive Report
    Executive/report/simulation
  • ›
    One unified scoreboard for the Simulation
    /simulation
  • ›
    Hover/tap definitions for Simulation terms
    CuriousExecutive/simulation
  • ›
    Simulation achievements and shareable challenge replays
    ExecutiveCurious/simulation
  • ›
    Edge migration is now a first-class Simulation step, reachable by everyone
    /simulation
  • ›
    Events with real stakes
    /simulation
Improvements3
  • ›
    The Simulation's demo documents are now the real tools' own output
    ExecutiveArchitect/simulation
  • ›
    The Simulation's event pool now partly reflects real, current data
    /simulation
  • ›
    Several Simulation surfaces read your real data
    /simulationMigrate
Bug Fixes3
  • ›
    Corrected a wrong standards citation in the Audit Readiness Checklist
    Researcher/business
  • ›
    Fixed a text-overflow bug in the PKCS#11 HSM Learn tab
    DeveloperPlayground
  • ›
    Removed a false product claim from the Simulation's event pool
    /simulation
Data Updates1
  • ›
    NIST CSWP 39 refreshed to Update 1
    ResearcherLibrary

July 18, 2026

v4.21.11

A guided Learn tab for the PKCS#11 HSM Playground, and a new Developer Sandbox card on the Playground overview.

New Features3
  • ›
    PKCS#11 HSM Playground now has a guided Learn tab
    DeveloperArchitectPlayground
  • ›
    Developer Sandbox card on the Crypto Lab overview
    DeveloperPlayground
  • ›
    Threats: top-level sections are now collapsible
    ResearcherExecutiveThreats
Bug Fixes5
  • ›
    KMIP Control Plane: mechanism panel now cites the spec section for every operation
    DeveloperPlayground
  • ›
    Leaders / PQC Community: every profile independently re-verified against live sources
    Researcher/leaders
  • ›
    KMIP 3.0 Playground: further compliance-audit gaps closed
    DeveloperPlayground
  • ›
    Trusted-sources registry: a 420-row divergence between two conflicting files reconciled
  • ›
    A duplicate vendor registration removed
Data Updates4
  • ›
    Library: large-scale re-verification
    ResearcherLibrary
  • ›
    Timeline and Threats: re-verification of documents flagged as changed
    ResearcherTimelineThreats
  • ›
    Compliance-landscape: related standards backfilled
  • ›
    5 more product certifications verified
    ResearcherMigrate

July 17, 2026

v4.21.7–v4.21.9

Spec-accuracy fixes across the KMIP 3.0 and HSM playgrounds, a batch of newly-discovered vendor roadmaps, and re-verified evidence across Timeline and Threats. · A routine maintainer-review pass adds new Compliance entries, fixes a Timeline citation error, and refreshes Library, Vendor Roadmaps, Product Certifications, and CVE data. · Compliance's trust panel and crosswalk registry now cover every active framework, Timeline's citations and trust links are fully verified across all 255 active milestones, and Migrate's vendor-risk cards now factor in real CVE exposure.

Bug Fixes7
  • ›
    KMIP 3.0 Playground documentation corrected against the actual OASIS draft
    DeveloperArchitectPlayground
  • ›
    HSM Playground: 2 spec-label corrections
    DeveloperPlayground
  • ›
    Timeline: a citation's date precision corrected
    ResearcherTimeline
  • ›
    Timeline: corrected an ETSI document-number error and improved date precision on 2 entries
    ResearcherTimeline
  • ›
    Compliance now shows a real Source & trust panel, with full traceability coverage
    ResearcherArchitectCompliance
  • ›
    Timeline citations and trust links fully verified across all 255 active milestones
    ResearcherTimeline
  • ›
    Migrate vendor-risk cards now reflect real CVE exposure
    ArchitectOpsMigrate
Data Updates12
  • ›
    40 vendor roadmaps reviewed, 1 new genuine find added
    ArchitectMigrate
  • ›
    Threats: 72 documents with confirmed content drift re-verified and re-enriched
    ResearcherThreats
  • ›
    1 Timeline entry deprecated
  • ›
    5 new Compliance entries added
    ResearcherCompliance
  • ›
    related_standards confirmed for 43 more Compliance rows
    ResearcherCompliance
  • ›
    8 new Library documents enriched
    ResearcherLibrary
  • ›
    5 vendor roadmap pages refreshed
    ArchitectMigrate
  • ›
    20 product certifications re-verified
    ResearcherMigrate
  • ›
    CVE database refreshed
  • ›
    27 Timeline-to-Compliance citation links backfilled
    ResearcherComplianceTimeline
  • ›
    420 missing entries backfilled into the trusted-sources registry
    Researcher
  • ›
    Migrate's certification and CPE cross-reference data fully regenerated
    ArchitectMigrate

July 16, 2026

v4.21.6

The Compliance page's CSWP.39 governance tags (the badges showing which frameworks touch crypto governance, inventory, observability, assurance, or lifecycle) now come from real, full document text instead of a truncated, noisy extraction — plus new content across Timeline, Threats, Library, and Migrate from a maintainer review pass.

Bug Fixes2
  • ›
    Compliance framework governance tags are now genuinely reflective of each document, not just partially filled
    ResearcherArchitectCompliance
  • ›
    5 Compliance entries that were never really about post-quantum cryptography are now hidden
    ResearcherCompliance
Data Updates5
  • ›
    New Timeline entry
  • ›
    New Threats entry
  • ›
    22 new Library documents
    ResearcherLibrary
  • ›
    Vendor roadmaps refreshed for Microsoft and Cloudflare
    ArchitectMigrate
  • ›
    13 more Migrate catalog products verified
    ResearcherMigrate

July 15, 2026

v4.21.5

The Compliance page's traceability drawer now shows only real, data-backed relationships instead of fabricated boilerplate, and the Library, Timeline, Threats, and Migrate catalogs pick up a large batch of newly verified content following a full review of the maintainer agent's pending proposals.

Bug Fixes1
  • ›
    Compliance traceability chains no longer show fabricated claims
    ResearcherArchitectCompliance
Data Updates4
  • ›
    17 new PQC-certified products added to Migrate
    ResearcherArchitectMigrate
  • ›
    18 new vendors registered with verified GLEIF legal-entity records
    ResearcherMigrate
  • ›
    20+ new documents added to Library and Timeline
    ResearcherLibraryTimeline
  • ›
    Fixed a duplicate timeline entry

July 14, 2026

v4.21.3–v4.21.4

Vendor Risk and certificate details get clearer in-place drill-downs on /migrate, the Protocol Support matrix picks up TLS 1.3's new RFC plus two new tracked protocols, and a data-quality pass recovers, verifies, and corrects more of the Migrate catalog's supporting evidence. · A large data-quality pass: hundreds of Migrate products got a real PQC-support assessment, Compliance framework tags now come from the actual regulation text instead of a one-line summary, and Library reference coverage is complete.

Improvements2
  • ›
    Vendor Risk matrix rows and dependencies now expand in place
    ArchitectExecutiveMigrate
  • ›
    Products with multiple certifications of the same type now show all of them
    ArchitectMigrate
Data Updates6
  • ›
    Protocol Support matrix updated for TLS 1.3, Wi-Fi, and Fibre Channel
    DeveloperArchitectAlgorithms
  • ›
    More Migrate products verified against their real supporting documents
    ResearcherArchitectMigrate
  • ›
    Hundreds of products on /migrate now have a real, evidence-backed PQC assessment instead of "Unknown"
    ResearcherArchitectMigrate
  • ›
    Compliance framework tags now reflect the actual regulation text, not a one-line summary
    ResearcherArchitectCompliance
  • ›
    Every Library reference document is now fully enriched
    ResearcherLibrary
  • ›
    In-app search now covers all of the above
    DeveloperCurious

July 13, 2026

v4.21.2
Data Updates2
  • ›
    Cleaned up vendor PQC-roadmap entries and verified trusted-source links
    ResearcherArchitectMigrateLibrary
  • ›
    Reconciled a forked same-day data lineage across 7 datasets
    ResearcherArchitectMigrateLibraryCompliance

July 11, 2026

v4.21.0–v4.21.1

Share buttons across every hands-on tool, a single-phase completion screen for the Simulation, deep-linkable Algorithms protocol-matrix views, and a broad data-quality pass that repairs document revision chains and tightens the data-integrity gates.

New Features2
  • ›
    Share buttons on every hands-on tool
    DeveloperExecutivePlayground/business
  • ›
    A completion screen for a single Simulation phase
    ExecutiveCurious/simulation
Improvements2
  • ›
    The Algorithms Protocol Matrix is now deep-linkable
    DeveloperArchitectAlgorithms
  • ›
    The PQC Assistant can now link to all 63 Playground tools
    DeveloperCuriousPlayground
Bug Fixes2
  • ›
    The Simulation's playback bar now closes when you dismiss it
    ExecutiveCurious/simulation
  • ›
    Repaired the Migrate workbench guided tour
    ArchitectDeveloperMigrate
Data Updates3
  • ›
    Recovered Library source documents and reconciled catalog data
    ResearcherArchitectLibraryMigrate
  • ›
    Repaired document revision chains and marked superseded editions
    ResearcherArchitectLibrary
  • ›
    Tightened the data-integrity gates

July 10, 2026

v4.20.0

A consolidation release: a hands-on KMIP Command Lab for certificate operations in the playground, a fix to the Report page's CBOM Builder link, and a broad data-quality sweep that rebuilds the site's trust-spine registries and refreshes the algorithm and learning-module data.

New Features3
  • ›
    A Command Lab for KMIP certificate operations
    DeveloperArchitectPlayground
  • ›
    Composite (hybrid classical+PQC) certificates end-to-end
    DeveloperArchitectPlayground
  • ›
    Cross-plane certificate showcases
    DeveloperArchitectPlayground
Improvements3
  • ›
    Refreshed the algorithm reference data
    ResearcherDeveloperAlgorithms
  • ›
    Rebuilt the site's data trust-spine
    ArchitectResearcherLibrary
  • ›
    Added PKCS#11 v3.2 as a finalized OASIS Standard to the Library
    DeveloperArchitectLibrary
Bug Fixes6
  • ›
    The Report page's CBOM Builder link now lands in the right place
    ArchitectDeveloper/report
  • ›
    Corrected content across several PKI learning modules
    DeveloperCuriousLearn
  • ›
    Fixed a compliance KPI and cleaned up certification data
    ExecutiveArchitectCompliance
  • ›
    Tidied the Migrate catalog
    ArchitectDeveloperMigrate
  • ›
    Recovered broken Library sources and cross-references
    ResearcherArchitectLibrary
  • ›
    Re-enriched and recovered more Library documents
    ResearcherArchitectLibrary
Data Updates2
  • ›
    New canonical algorithm reference snapshot (July 2026)
  • ›
    Expanded the patents dataset
    ResearcherExecutive/patents

July 9, 2026

v4.16.0–v4.19.0

A hands-on release for the KMIP playground, the Report page, the Business Center, and the Simulation board: the in-browser KMIP engine is rebuilt from the real 0.13.1 engine with eight more operations now genuinely executed instead of simulated, the report gains a Cryptographic Bill of Materials section built on the new CycloneDX 1.7 standard, the Simulation board's framework references were audited line by line against what actually ships, and a sourcing sweep across the Business Center tools corrected several citation and data errors. · A cross-page accuracy release covering Editorial Independence, Simulation, Explore, the Landing page, and the Sponsor page: the Editorial Independence page's promises about sponsor badges and the anonymous tipline now match what's actually built, the Simulation board acknowledges when Researcher and Curious visitors are shown the Executive seat by default, the Explore launcher's "recommended for you" badges are now driven by a single source of truth instead of a hand-maintained list, the Landing page's headline facts and role-adaptation summary are now derived from live data instead of hardcoded text, and the Sponsor page's tier benefits now match what's actually delivered today. · A cross-page accuracy release covering Timeline, Compliance, Threats, Patents, Leaders, Learn, and the Library: deadline mandates on the Timeline are now individually sourced and labeled instead of guessed, the Compliance page covers the actual federal executive order behind the 2030/2031 deadlines, the Threats page's quantum-computer arrival estimate is now the same number everywhere it appears, Patents share links no longer lose your filters, Leaders profiles are split into a curated set and the full contributor list, several Learn modules got corrected facts and real quiz coverage, and dozens of Library references were re-verified, fixed, or retired. · A cross-page accuracy and trust release touching Report, Business tools, Revisions, Changelog, FAQ, Playground, OpenSSL Studio, Terms, About, and Migrate: shared report links now show the sender's real score, breach-cost defaults finally agree across three business tools, the revisions feed surfaces corrections that were previously invisible, the Playground and OpenSSL Studio get clearer status indicators and fewer dead ends, the Migrate workbench now shows which products are still awaiting verification proof, and several dead links and stale numbers are fixed across the site.

New Features12
  • ›
    Three new KMIP lessons with a guided tour, glossary, and knowledge checks
    DeveloperArchitectPlayground
  • ›
    A rollback recipe for batch key migrations
    OpsArchitectPlayground
  • ›
    The Report page now includes a Cryptographic Bill of Materials (CBOM) section
    ArchitectExecutive/report
  • ›
    Search on the Changelog page
    /changelog
  • ›
    Explanatory tooltips on the Changelog page's freshness indicators
    /changelog
  • ›
    Filters by zone, phase, and audience on the Business tools grid
    Executive/business
  • ›
    FAQ questions aimed at your role now float to the top of their section
    /faq
  • ›
    The Business Center's learning module list now collapses by default for advanced users
    Developer/business
  • ›
    The Playground's algorithm picker now shows a "Draft" badge with an explanatory tooltip for algorithms that aren't yet finalized standards
    DeveloperPlayground
  • ›
    Executive-persona guidance banners added to three more Playground tools
    ExecutivePlayground
  • ›
    Products in the Migrate workbench now show a verification badge and last-verified date
    Migrate
  • ›
    The Migrate workbench's asset guidance is now tailored for executive and developer views
    ExecutiveDeveloperMigrate
Improvements3
  • ›
    The site's CBOM now follows CycloneDX 1.7
    ArchitectDeveloper/report
  • ›
    Eight KMIP operations promoted from simulated to real
    DeveloperPlayground
  • ›
    Reorganized the Report page's internal code for easier maintenance
    DeveloperArchitect/report
Bug Fixes95
  • ›
    Corrected several sourcing and citation errors across Business Center tools
    ExecutiveArchitect/business
  • ›
    Simulation framework references now match what actually ships
    /simulation
  • ›
    Simulation jargon is now explained where it appears
    CuriousExecutive/simulation
  • ›
    Closed topical gaps in Simulation phase content
    /simulation
  • ›
    The Editorial Independence page's "Sponsor" badge claim is now real
    Executive/editorial-independenceMigrate
  • ›
    The anonymous tip line promise is now honest about its status
    /editorial-independence
  • ›
    Funding-source language on the Editorial Independence page now matches the real Sponsor page
    /editorial-independence/sponsor
  • ›
    Added a table of contents with jump-links to the Editorial Independence page
    /editorial-independence
  • ›
    The Simulation board now explains why Researcher and Curious visitors start in the Executive seat
    ResearcherCurious/simulation
  • ›
    Fixed mismatched phase recommendations in the Simulation board's "keep learning" prompts
    ArchitectOps/simulation
  • ›
    Corrected stale "coming soon" labels on several Simulation framework references
    Researcher/simulation
  • ›
    Added a cross-reference between the Simulation board's "TNFL" label and the Report page's "HNFL" label
    /simulation/report
  • ›
    Explore page's "recommended for you" badges no longer drift out of sync with the rest of the site
    /explore
  • ›
    Added a Migrate tile to the Explore launcher
    Ops/explore
  • ›
    Fixed the Explore page's Command Center tile for the Curious persona
    Curious/explore
  • ›
    Corrected a stale "2-minute questionnaire" claim on the Explore page's Assess tile
    /explore
  • ›
    The Landing page's headline facts are now pulled from live data
    ExecutiveResearcher/
  • ›
    The Landing page's persona welcome modal now lists your recommended pages from a single source
    /
  • ›
    Renamed the misleading "Standards Tracked" stat on the Landing page to "Library Documents"
    /
  • ›
    Replaced browser popup alerts with the site's normal notification style
    /
  • ›
    Removed a non-functional Google Drive sync option
    /
  • ›
    Fixed the Landing page's ?picker=open link
    /
  • ›
    Sponsor page benefits now match what's actually delivered
    Executive/sponsor
  • ›
    Sample-report link on the Sponsor page now opens a real example report
    /sponsor/report
  • ›
    Replaced a personal email address with the official contact address
    /sponsor
  • ›
    Funding-goal line items on the Sponsor page now link to where you can verify them
    /sponsor/revisions/editorial-independence
  • ›
    Every deadline on the Timeline now shows whether it's a binding legal mandate, informal guidance, or still-draft language
    ExecutiveArchitectTimeline
  • ›
    The Timeline's chart no longer clips future or historical entries to a fixed 2024–2035 window
    Timeline
  • ›
    Malformed dates in the Timeline's underlying data no longer silently render as blank bars
    Timeline
  • ›
    The Compliance page now covers the actual U.S. executive order behind the post-quantum migration deadlines
    ExecutiveCompliance
  • ›
    Several "plain-English summary" blurbs on the Compliance page were overstating what their underlying framework actually requires
    Compliance
  • ›
    The Compliance Records tab no longer shows a live-sounding "Refresh Data" button that does nothing on the deployed site
    Compliance
  • ›
    The Compliance page's "New to PQC compliance?" intro banner no longer reappears every visit
    Compliance
  • ›
    Threat-horizon (Q-Day) estimates now agree across the whole Threats page
    Threats
  • ›
    Fixed a false-positive bug in the Threats page's "harvest-now" vs. "forge-now" risk classification
    Threats
  • ›
    The Threats page now shows why each threat was vetted the way it was
    ResearcherThreats
  • ›
    Merged two near-duplicate industry categories on the Threats page
    Threats
  • ›
    Threat classification definitions are now readable on touchscreens
    Threats
  • ›
    Fixed a data-loading bug that could conflate "this patent has no post-quantum relevance score" with "this patent scored zero"
    /patents
  • ›
    Sharing a filtered Patents view now preserves what you were actually looking at
    /patents
  • ›
    Corrected the classification of Classic McEliece across the Patents catalog
    /patents
  • ›
    Patent search now finds algorithms by either their original filing-era name or their finalized NIST name
    /patents
  • ›
    Added a small glossary for patent-specific terms
    Developer/patents
  • ›
    The Leaders page now separates the curated, individually-vetted profile set from the larger auto-imported contributor list
    /leaders
  • ›
    Refreshed and spot-checked Leaders profile data
    /leaders
  • ›
    Fixed a bug where an executive's explicit "sort by name" choice on the Leaders page was silently overridden back to a relevance-based order
    Executive/leaders
  • ›
    Added a Skeptic/Critic filter category to the Leaders page
    /leaders
  • ›
    Fixed two overstated claims in Learn module content
    ExecutiveLearn
  • ›
    Learn checkpoints now only count as "passed" once you've actually scored well enough on them
    Learn
  • ›
    Fixed a Learn progress-tracking bug where browsing a "curious mode" module's workshop steps counted as completing them
    Learn
  • ›
    Three previously-orphaned Learn modules (governance/risk, team staffing, and SOC incident response) now have quiz coverage and are properly routed into the relevant role-based learning path
    Learn
  • ›
    Retired a redundant Learn module that duplicated a newer, fuller one on team staffing
    Learn
  • ›
    Learn module reference panels now show when each module's content was last reviewed
    ResearcherLearn
  • ›
    Filled in missing descriptions for 29 Library entries
    Library
  • ›
    Re-checked every Library link that was flagged as broken or unverified
    Library
  • ›
    Fixed a Library entry that incorrectly implied FN-DSA (FIPS 206) has already been published
    Library
  • ›
    Corrected a mismatched document title on a Library reference
    Library
  • ›
    Normalized a handful of Library confidence scores that were on the wrong 0–1 scale
    Library
  • ›
    The Library can now be filtered by why you're looking something up
    Library
  • ›
    Shared and example report links now show the exact score the sender saw
    /report
  • ›
    Viewing someone else's shared report can no longer overwrite your own saved assessment
    /report
  • ›
    ROI and vendor-risk figures now flag when they're using default estimates
    Executive/report
  • ›
    Breach-probability defaults now agree across the ROI Calculator, Breach Cost Model, and Cost of Inaction tools
    Executive/business
  • ›
    Fixed a stale year in the ROI Calculator's source citation
    /business
  • ›
    The Roadmap Builder now cites the actual federal order and deadlines behind the PQC transition mandate
    Executive/business
  • ›
    The "data" category on the Revisions feed was invisible
    /revisions
  • ›
    The Revisions feed was missing about seven weeks of real corrections
    /revisions
  • ›
    Freshness date labels on the Changelog page were showing the wrong file's date
    /changelog
  • ›
    Cleaned up mislabeled role tags on several changelog entries
    /changelog
  • ›
    Fixed a dead reference link on the FAQ page
    /faq
  • ›
    Merged two near-duplicate FAQ questions about the Cryptography Bill of Materials
    /faq
  • ›
    Fixed an inconsistent step count on the FAQ page
    /faq
  • ›
    Fixed the project's GitHub repository name
    /faq
  • ›
    Replaced a few exact module/document/product counts on the FAQ page with wording that won't go stale
    /faq
  • ›
    The Docker-based playground tool no longer shows a dead, unresponsive embedded window when the sandbox isn't reachable
    DeveloperPlayground
  • ›
    Renamed the KMIP control-plane tool consistently across the Playground
    Playground
  • ›
    Replaced a personal email link for sandbox-access requests with a trackable request form
    Playground
  • ›
    Fixed OpenSSL Studio's documentation links
    DeveloperOpenSSL Studio
  • ›
    Removed a non-functional option from OpenSSL Studio's configuration-file helper command
    OpenSSL Studio
  • ›
    OpenSSL Studio's post-quantum key/signature tools now note the OpenSSL version they require
    DeveloperOpenSSL Studio
  • ›
    Fixed OpenSSL Studio's key-decapsulation example, which was using the wrong output flag
    OpenSSL Studio
  • ›
    OpenSSL Studio now shows a clear error and retry option if the underlying engine fails to load
    OpenSSL Studio
  • ›
    Marked two OpenSSL Studio example commands as reference-only
    OpenSSL Studio
  • ›
    Fixed the Terms page's binding-acceptance clause, which pointed to a retired mirror site that no longer resolves
    /terms
  • ›
    Added a table of contents with jump-to-section links to the Terms page
    /terms
  • ›
    Added plain-language summaries above the Terms page's export-control section and its "don't use generated keys in production" guidance
    /terms
  • ›
    The About page's platform statistics (module counts, dataset sizes, and similar figures) are now computed from the live data
    /about
  • ›
    Fixed an overstated "refreshed weekly" claim about compliance data on the About page
    /about
  • ›
    Fixed the About page's "last security audit" date, which no longer matched the actual audit report it was describing
    /about
  • ›
    The About page's changelog link now navigates within the app instead of triggering a full page reload
    /about
  • ›
    The Migrate workbench now labels NIST IR 8547 as a draft
    Migrate
  • ›
    Vendor roadmap entries in Migrate now show when they were last verified, plus a "new" or "updated" marker
    Migrate
  • ›
    Fixed a duplicate Migrate workbench address
    Migrate
  • ›
    Each migration wave in the Migrate planner now explains why it's sequenced where it is
    ArchitectMigrate
  • ›
    Fixed a handful of product records in the migration catalog with inconsistent verification labels
    Migrate
Data Updates1
  • ›
    Refreshed the Timeline, Compliance, Patents, Leaders, and Library datasets with new dated snapshots and re-verified sourcing; added quiz question coverage for previously-untested Learn topics (software bill of materials, cryptography bill of materials, crypto-algorithm registry naming, and post-quantum verification/closure).

July 8, 2026

v4.15.0

A Learn modules and Patents refresh release: two new modules close a cross-reference gap that's existed since earlier modules started pointing at them, the Patents page now highlights what's new since your last visit, and Algorithms defaults to only showing FIPS-validated results.

New Features3
  • ›
    A "recently added" view for Patents, and click-to-drill on the filing-year chart
    Researcher/patents
  • ›
    A CycloneDX Cryptography Registry learning module
    Developer/learn/crypto-registry
  • ›
    A Software Bill of Materials (SBOM) learning module
    Developer/learn/sbom
Bug Fixes1
  • ›
    The Algorithms page now defaults to showing only FIPS-validated algorithms
    Algorithms
Data Updates1
  • ›
    Added CycloneDX, NTIA, OASIS CSAF/VEX, and SPDX reference entries to the library catalog backing the new SBOM and Crypto Registry modules.

July 7, 2026

v4.13.0–v4.14.0

A Migrate data accuracy release: a broad, evidence-based cleanup of the product and vendor catalog closes hundreds of unproven or vague claims, fixes mistagged vendors and duplicate listings, and restores a site-wide data-quality check that had been silently broken for months. · A Threats page redesign: one continuous page instead of a hidden second tab, a consolidated actions menu, and a simplified view-mode set. Plus a refreshed SEO feature list reflecting the site's current surface.

New Features1
  • ›
    The Threats page's most decision-forcing number — the CRQC migration deadline — is now visible without clicking a tab
    Threats
Improvements5
  • ›
    Threats page actions consolidated into one menu
    Threats
  • ›
    Mobile Threats view now uses the same component as desktop
    Threats
  • ›
    Removed the "Industry Stack" view mode on Threats
    Threats
  • ›
    The Shor-tier badge moved from the Criticality column to the crypto-at-risk row it actually describes
    Threats
  • ›
    The landing page's feature list is up to date
    /
Bug Fixes8
  • ›
    Two product listings had quietly reverted to disproven claims
    OpsMigrate
  • ›
    429 product and vendor entries cited a source that didn't actually exist
    Migrate
  • ›
    ~175 product listings said "yes, it supports this" with no specifics
    Migrate
  • ›
    A dozen products were tagged to the wrong company
  • ›
    Several duplicate product listings merged
    Migrate
  • ›
    Two products were claiming current support for something their own documentation says is still just a future plan
    Migrate
  • ›
    The site's overall data-quality checking tool had been silently broken since April
  • ›
    A "successful" evidence download was actually a bot-block page in disguise
Data Updates3
  • ›
    Closed the evidence-download backlog for the migrate catalog's trust-score archive from 580 missing entries down to 10.
  • ›
    Removed 117 leftover categories from the migration-priority dashboard that predated a recent category reorganization, after individually checking each one so nothing intentional was deleted.
  • ›
    Added a new automated check ensuring every product and vendor entry's cited source actually resolves to something real, mirroring an existing check already used elsewhere on the site.

July 6, 2026

v4.12.0

A crypto-agility, algorithms, and Migration Workbench release: FrodoKEM and Classic McEliece now run for real in the CACP Playground per BSI TR-02102-1; the Migration Workbench gets a search-and-confirm UX pass; several algorithm data gaps are closed; and the Breach Scenario Simulator / Cost of Inaction Analyzer are rebuilt on a verified 2025 risk model with realistic migration timing.

New Features12
  • ›
    A "Memory space required" section in the HSM Capacity Calculator
    Architect/playground/hsm-capacity
  • ›
    New Deep Dive learning content on three more simulation phases
    /simulation
  • ›
    A signature-forgery risk panel in the Breach Scenario Simulator
    Executive/learn/pqc-business-case
  • ›
    A "latest safe migration start year" and "cost of waiting" reading in the Breach Scenario Simulator and Cost of Inaction Analyzer
    /learn/pqc-business-case
  • ›
    A "crossover year" reading in the Cost of Inaction Analyzer
    /learn/pqc-business-case
  • ›
    Search in the Migration Workbench's asset list
    ArchitectMigrate
  • ›
    A "See all" option when the asset list is narrowed to your role
    Migrate
  • ›
    A "Check vendor roadmaps instead" link when a category has no mapped catalog products yet
    Migrate
  • ›
    A "Your vendors" section at the top of Vendor Roadmaps
    Migrate
  • ›
    A "Research needed" filter on the Algorithms page
    ResearcherAlgorithms
  • ›
    A "No known implementation" badge on the Algorithms browse table
    Algorithms
  • ›
    FrodoKEM and Classic McEliece now run for real in the crypto-agility playground
    DeveloperKMIP 3.0 Playground
Improvements6
  • ›
    Deep-dive resources on the Simulation page are now visually distinct from required steps
    /simulation
  • ›
    Migration in the Cost of Inaction Analyzer now takes realistic time to complete
    /learn/pqc-business-case
  • ›
    An empty Migration Workbench now invites you to build a plan instead of showing a 0% score
    Migrate
  • ›
    Clearing a plan or removing a multi-product asset in the Migration Workbench now asks for confirmation
    Migrate
  • ›
    The Vendor Risk supply-chain matrix's optional pipeline-documentation fields are now collapsed by default
    Migrate
  • ›
    The Threats page shows one persona signal instead of three at once
    Threats
Bug Fixes5
  • ›
    The Breach Scenario Simulator and Cost of Inaction Analyzer no longer assume a quantum computer already exists
    /learn/pqc-business-case
  • ›
    Breach cost figures were citing a stale 2024 report and had drifted from it for 8 of 11 industries
    /learn/pqc-business-case
  • ›
    Cost of Inaction's regulatory deadlines and fines were invented, flat per-industry constants
    /learn/pqc-business-case
  • ›
    Switching industries between the Breach Scenario Simulator and Cost of Inaction Analyzer could silently keep the previous industry's numbers
    /learn/pqc-business-case
  • ›
    About a quarter of Threats entries could never appear in any role's default view
    Threats
Data Updates4
  • ›
    Filled several composite/hybrid and HPKE-PQ algorithm data gaps
    Algorithms
  • ›
    Corrected LAC's standardization status
    Algorithms
  • ›
    Fixed an inconsistent RSA key-size encoding on a composite algorithm row
    Algorithms
  • ›
    Added BIKE-1/3/5 implementation cross-references
    Algorithms

July 5, 2026

v4.10.0–v4.11.0

A crypto-agility and simulation release: the CACP playground gains a new **Migration** tab that walks a seven-key business estate from classical crypto through hybrid to full post-quantum, a full KMIP 3.0 operation tester and a real OASIS conformance-corpus replay; the simulation gets one unified PLAY entry point with new sector-specific deep-dive content; and the HSM Capacity Calculator's fleet-sizing formula is corrected after being found to undercount by up to 46%. Backed by a rebuilt engine (v0.10.0) that adds Ed25519 signing and real classical X25519/X448 key agreement. · A crypto-agility, simulation, and accuracy release: the CACP playground gains real Ed25519/ECDH operations with an in-app guide, the simulation adds country-specific standards guidance and a reflective run-complete ending, and a wave of accuracy fixes corrects a report-sharing bug that could silently overwrite a recipient's own assessment, a fabricated compliance evidence chain, a stale CVE feed, and several other content and accessibility issues.

New Features21
  • ›
    A new "Migration" tab in the crypto-agility playground
    ArchitectKMIP 3.0 Playground
  • ›
    A migration map
    KMIP 3.0 Playground
  • ›
    A live key-object inspector in the Migration tab
    KMIP 3.0 Playground
  • ›
    A KMIP log inside each key tile
    KMIP 3.0 Playground
  • ›
    Guided "Learn" walkthroughs and an operation Reference in the playground
    KMIP 3.0 Playground
  • ›
    Test any of KMIP 3.0's 66 operations directly in the crypto-agility playground
    DeveloperKMIP 3.0 Playground
  • ›
    Replay the real OASIS KMIP 3.0 conformance test corpus in your browser
    DeveloperKMIP 3.0 Playground
  • ›
    One unified "▶ PLAY" entry point for the simulation
    /simulation
  • ›
    The crypto-agility (CACP/KMIP) workshop is now playable from inside the simulation
    /simulationKMIP 3.0 Playground
  • ›
    New Deep Dive learning content for Phase 5, tailored by sector
    /simulation
  • ›
    A plain-language verdict card, a hybrid-signing transition toggle, and a sizing headroom slider in the HSM Capacity Calculator
    Architect/playground/hsm-capacity
  • ›
    The Crypto Architecture PDF export now includes the actual diagram
    Learn/business
  • ›
    Compare Ed25519 and ECDH key operations in the crypto-agility playground
    KMIP 3.0 Playground
  • ›
    A "Key tags" field in the crypto-agility workbench
    KMIP 3.0 Playground
  • ›
    An in-app guide for the crypto-agility playground
    KMIP 3.0 Playground
  • ›
    A "Recover" column in the crypto-agility policy coverage matrix
    KMIP 3.0 Playground
  • ›
    Two new implementation-attack categories in the Algorithms view
    Algorithms
  • ›
    Germany, France, and UK now have their own cited standards guidance in the simulation
    /simulation
  • ›
    The simulation's run-complete ending now offers a reflection and next steps
    /simulation
  • ›
    A "Practice in the Simulation" link from Learn now jumps to the exact phase you just studied
    Learn/simulation
  • ›
    The Verification & Closure phase's reference tool now opens inside the simulation
    /simulation
Improvements5
  • ›
    The About page's software bill of materials now lists the current engine
    /about
  • ›
    The Crypto Architecture diagram is easier to read
    Learn/business
  • ›
    The Vendor Scorecard and its exported reports now show vendor names instead of internal vendor IDs
    ExecutiveLearn
  • ›
    The Architecture diagram in the simulation now reflects your real migration progress
    /simulation
  • ›
    Small text in the disclaimer banner and the homepage tagline is now easier to read
    /about/
Bug Fixes19
  • ›
    Signature verification after a post-quantum migration
    KMIP 3.0 Playground
  • ›
    A key-agreement error after switching to a post-quantum policy
    KMIP 3.0 Playground
  • ›
    The guided sign-and-verify lessons
    KMIP 3.0 Playground
  • ›
    The HSM Capacity Calculator was undercounting how many HSMs you need, by up to 46%
    Architect/playground/hsm-capacity
  • ›
    The PQC Assistant chat no longer gets permanently stuck after the browser reclaims GPU memory from a backgrounded tab
    Developer
  • ›
    The Crypto Vulnerability Watch tool's CVE data was 66 days stale
    Developer/business
  • ›
    Corrected a citation mismatch for where vulnerability management sits in the CSWP 39 framework
    /business
  • ›
    Fixed an overlapping layout in the About page's software bill-of-materials section
    /about
  • ›
    The crypto-agility policy engine no longer blocks unrelated operations because of an unrelated governance rule
    KMIP 3.0 Playground
  • ›
    The Migration Verification tool no longer cites the wrong standard for key destruction
    /business
  • ›
    Several accuracy corrections to the simulation's narration
    /simulation
  • ›
    The Executive Overview walkthrough now presents the budget case before the program charter
    Executive/simulation
  • ›
    Fixed onboarding never appearing for anyone who started the simulation via a direct run link
    /simulation
  • ›
    The simulation's destructive confirmations (reset, start over) are now accessible, styled dialogs
    /simulation
  • ›
    A shared assessment link no longer silently overwrites your own in-progress report
    /report
  • ›
    The Algorithms page's suggested "Standardized" filter for developers no longer leads to a dead end
    DeveloperAlgorithms
  • ›
    Common Criteria certificates that were never checked for PQC support no longer look identical to ones checked and found clean
    Compliance
  • ›
    The compliance mandate detail no longer shows a fabricated migration-evidence trail for mandates that don't actually specify one
    Compliance
  • ›
    The compliance glossary no longer cites a draft NIST specification as published
    Compliance

July 4, 2026

v4.9.0

A business-case and report release: PQC cost models get an honest rebuild with a new side-by-side comparison tool, the exec-tour's financial docs are now generated from that same math, and the assessment report gains discovery, vendor-risk, and program-ownership sections alongside several accuracy corrections.

New Features6
  • ›
    Compare six PQC cost-estimation methods side by side
    ExecutiveLearn/business
  • ›
    A "Choosing a Costing Model" methodology guide
    Learn
  • ›
    Search and filter the Roadmap Builder's regulatory deadline list
    Executive/business
  • ›
    A program-level ownership block in the assessment report
    Executive/report
  • ›
    A cryptographic discovery / inventory section in the report
    /report
  • ›
    A third-party & vendor PQC risk section in the report
    /report
Improvements7
  • ›
    Exec-tour and board-deck financial figures are now generated from the same math as the real tools
    Executive/simulation
  • ›
    Breach Simulator, Cost of Inaction Analyzer, and Cost Model Explorer are now full Command Center tools
    /business/simulation
  • ›
    Program Charter and Initial Scoping Assessment now match the migration framework more completely
    ExecutiveLearn
  • ›
    Quick assessments no longer silently upgrade to "comprehensive"
    Assess
  • ›
    The report's table of contents now covers every section
    /report
  • ›
    The report's persona-aware summary appears once, at the top
    /report
  • ›
    The report footer's next-step suggestions now reflect your actual result
    /report
Bug Fixes9
  • ›
    The Breach Scenario Simulator's cost model was inflated roughly 2.5–10x
    /businessLearn
  • ›
    The Cost of Inaction Analyzer's regulatory penalty never actually applied
    /businessLearn
  • ›
    The ROI Calculator now cross-checks its estimate against an independent method
    /business
  • ›
    Removed a fabricated standards quote and an overstated outcome claim from the Roadmap Builder
    /business
  • ›
    Report's Share, Print, and Board-pack buttons now give honest feedback
    /report
  • ›
    The report's harvest-now-decrypt-later narrative no longer conflates your regulatory migration deadline with the separate quantum-computer arrival estimate
    /report
  • ›
    The Framework Risk Lens panel was silently blank on every comprehensive assessment
    /report/simulation
  • ›
    An inverted-polarity bug in the organizational-readiness score could show the best-prepared organizations as highest-risk
    /report
  • ›
    The example report shown to first-time visitors used invalid data tokens and rendered as a near-empty report
    /report

July 3, 2026

v4.8.0

A crypto-agility and business-tools release: the CACP playground gains scripted policy test-scenarios and a workbench picker, a persona deep-link bug is fixed, and 30 Command Center business tools are corrected after a fresh accuracy audit.

New Features3
  • ›
    Try validated test scenarios in the crypto-agility playground
    KMIP 3.0 Playground
  • ›
    A Q-Day horizon stat in the simulation's KPI row
    Executive/simulation
  • ›
    ENISA hybridization report added to the library
    Library
Improvements1
  • ›
    CACP playground A-grade UX pass
    KMIP 3.0 Playground
Bug Fixes6
  • ›
    30 Command Center business tools corrected after a fresh accuracy audit
    Executive/business
  • ›
    ?persona= deep links no longer lose the chosen persona
    ExecutiveDeveloperLearn
  • ›
    Restored the Executive Report reference in Verification & Closure
    Executive/simulation
  • ›
    CACP Lesson 3's rekey sequence had a genuine ordering bug
    KMIP 3.0 Playground
  • ›
    Clearer error when a KMIP batch step references an unset ID placeholder
    KMIP 3.0 Playground
  • ›
    Corrected the AWS-LC FIPS certificate number
    Migrate

July 2, 2026

v4.7.0

An accuracy, learning, and crypto-agility release: a hub-wide factual re-audit corrects roughly 150 errors, learners get a shorter essentials-first path, executives can watch the whole migration play out as a guided walkthrough, and the crypto-agility playground gains a visual policy editor plus hybrid key exchange.

New Features6
  • ›
    Watch the whole migration play out as a guided executive walkthrough
    Executive/simulation
  • ›
    A shorter, essentials-first learning path
    DeveloperExecutiveLearn
  • ›
    Try hybrid (classical + PQC) key exchange in the playground
    KMIP 3.0 Playground
  • ›
    See your crypto-agility policy as a flowchart
    KMIP 3.0 Playground
  • ›
    Watch a request travel through your policy
    KMIP 3.0 Playground
  • ›
    Catch policy mistakes before they bite
    KMIP 3.0 Playground
Improvements2
  • ›
    The product catalog is easier to browse and better sourced
    Migrate
  • ›
    Crypto-agility policies stay in sync and match the standards
    KMIP 3.0 Playground
Bug Fixes3
  • ›
    A hub-wide accuracy sweep
    AlgorithmsLearnCompliance/faq/aboutMigrateLibrary
  • ›
    Learning paths send the right roles to the right modules, with correct standards
    DeveloperLearn
  • ›
    Straight talk about what the playground preview does
    KMIP 3.0 Playground
Data Updates1
  • ›
    Refreshed datasets and search index
    /exploreMigrate/leaders

June 30, 2026

v4.6.0

A simulation-fidelity and executive-experience release: every simulation phase now matches the published migration framework exactly, executives get a purpose-built view across the whole hub, the protocol support matrix is updated to what's actually shipping today, and the product catalog had an accuracy sweep.

New Features3
  • ›
    The simulation now opens workshops and learning modules at exactly the right step
    ExecutiveArchitect/simulationLearn
  • ›
    Executives and business leaders now get a tailored path through every part of the hub
    ExecutiveAlgorithms/leadersTimeline/explore/revisions/simulation/business/about
  • ›
    Security Level in the algorithm comparison panel now explains what "112 bits" means
    ArchitectDeveloperAlgorithms
Improvements2
  • ›
    The simulation's guided content for all eight phases now matches framework v2.1
    ExecutiveArchitect/simulation
  • ›
    The PQC Protocol Support Matrix is updated to reflect what's actually deployed today
    ArchitectDeveloperResearcherAlgorithms
Data Updates2
  • ›
    Migration product catalog refreshed with proof sweep (06302026_r1)
    ArchitectMigrate
  • ›
    CBOM refreshed with vendor accuracy caveats
    ArchitectDeveloperKMIP 3.0 Playground

June 29, 2026

v4.5.0

A mobile-ready and data-consistency release: the hub now works on phones across all pages, jurisdiction data is unified into one source of truth, the simulation generates industry-specific artifacts, and compliance facts in your report warn you when deadlines have been updated since your assessment.

New Features5
  • ›
    The hub now works on a phone
    ExecutiveArchitectDeveloperAlgorithmsComplianceLibraryMigrateLearn/simulationTimelinePlayground
  • ›
    The simulation now shows optional learning steps tailored to your sector
    ExecutiveArchitect/simulation
  • ›
    The migration simulation generates artifacts matched to your sector
    ExecutiveArchitect/simulation
  • ›
    Your assessment results now appear inside the simulation
    ExecutiveArchitect/simulationAssess
  • ›
    Related compliance frameworks now navigate directly to the right entry
    ExecutiveArchitectResearcherCompliance
Improvements4
  • ›
    Jurisdiction data is now consistent across every part of the hub
    ExecutiveArchitectAssess/simulationComplianceTimeline
  • ›
    Compliance deadlines and facts in your report now stay in sync with the live data
    ExecutiveArchitect/reportAssessCompliance
  • ›
    Fixed compliance deadline errors across several frameworks
    ExecutiveArchitectCompliance/report
  • ›
    HSM vendor comparison in the Crypto Management module stays current automatically
    ArchitectDeveloperLearn

June 27, 2026

v4.4.0

A playground-and-feedback release: the crypto playground is reorganized around what you want to do, the SSH simulator now runs a genuine post-quantum handshake, you can endorse or flag any resource again across the hub, and the in-browser HSM's self-tests run reliably with live progress.

New Features1
  • ›
    Endorse or flag any resource again, everywhere
    ArchitectResearcherAlgorithms/patentsComplianceLibraryThreatsMigrate
Improvements2
  • ›
    A clearer crypto playground, organized around what you want to do
    ArchitectDeveloperPlayground
  • ›
    The SSH playground now runs a real OpenSSH post-quantum handshake
    DeveloperArchitect/playground/pqc-ssh-sim
Bug Fixes4
  • ›
    The in-browser HSM self-tests run reliably and show live progress
    ArchitectDeveloperPKCS#11 PlaygroundKMIP 3.0 Playground
  • ›
    "Exit to hub" is a visible button in the simulation
    ExecutiveArchitect/simulation
  • ›
    The simulation stops offering to resume a run that isn't there
    Executive/simulation
  • ›
    All in-browser HSM self-tests now use published, authoritative test vectors
    ArchitectDeveloperPKCS#11 Playground

June 26, 2026

v4.3.0

A consolidation release that brings several in-flight improvements together: a faster way into the standards Library, a new policy-and-batch workbench in the crypto playground, clearer "binding versus guidance" labelling on migration deadlines, a more consistent learning-module layout, and refreshed, better-sourced timeline and library data.

New Features6
  • ›
    Start the Library from what you're here to do
    ExecutiveArchitectResearcherLibrary
  • ›
    See which migration deadlines are legally binding versus guidance
    ExecutiveArchitectTimelineAssess/report
  • ›
    Explore and compare crypto policies in the playground
    ArchitectResearcherKMIP 3.0 Playground
  • ›
    Test what the selected policy actually does — preview or for real
    ArchitectResearcherKMIP 3.0 Playground
  • ›
    Run several KMIP operations as one request
    ArchitectResearcherKMIP 3.0 Playground
  • ›
    Your report now points you to the right next step
    ExecutiveArchitectResearcher/report
Improvements4
  • ›
    A cleaner, easier-to-read migration simulation
    ExecutiveArchitect/simulation
  • ›
    A more consistent layout across the learning modules
    ArchitectDeveloperLearn
  • ›
    The guided simulation playthrough now starts quiet
    ExecutiveCurious/simulation
  • ›
    A refreshed crypto engine in the playground
    ArchitectDeveloperKMIP 3.0 Playground/about
Data Updates3
  • ›
    Refreshed and re-sourced the national PQC timeline
    ExecutiveResearcherTimeline
  • ›
    A cleaner, better-sourced standards Library
    ArchitectResearcherLibrary
  • ›
    Better-sourced compliance landscape with every regulator named
    ExecutiveArchitectResearcherCompliance

June 25, 2026

v4.2.0–v4.2.1

A correctness-and-polish release: a broad accuracy pass across the learning modules and the reference data behind them, plus shareable links that restore where you left off, an on-site assistant that links you straight to the right place, and a more realistic migration simulation. · Version 4.2.0 adds two new hands-on learning modules — building a Cryptography Bill of Materials and running a clean program decommissioning and closure — and lands a large accuracy pass that corrects post-quantum standards facts, deadlines, and outbound links across the site. It also removes the old duplicate "legacy" pages and improves how reliably pages are indexed by search engines.

New Features1
  • ›
    Two new hands-on modules: building a CBOM and closing out a migration
    ArchitectDeveloperExecutiveLearn
Improvements5
  • ›
    Shareable links that reopen exactly where you left off
    ArchitectMigrateLearnAssessAlgorithmsTimeline
  • ›
    The on-site assistant links you straight to the right place
    ArchitectResearcher/
  • ›
    A more realistic migration simulation
    ExecutiveArchitect/simulation
  • ›
    A cleaner site with no duplicate "legacy" pages
    MigrateLibraryAssess/patents
  • ›
    More reliable search-engine indexing
    /
Bug Fixes9
  • ›
    A site-wide accuracy pass across the learning modules and their reference data
    ArchitectResearcherLearn
  • ›
    Accurate retirement deadlines in the Decommissioning & Program Closure module
    ExecutiveArchitectLearn
  • ›
    Source lists restored on two learning modules
    ArchitectResearcherLearn
  • ›
    Every entry in the Leaders directory shows its correct trust tier
    Researcher/leaders
  • ›
    The "What's New" pop-up closes when you click outside it
    /
  • ›
    More accurate post-quantum standards facts
    ArchitectResearcherLibraryAlgorithmsTimeline
  • ›
    Correct CNSA 2.0 deadlines and signature target
    ExecutiveArchitectComplianceMigrate
  • ›
    Honest framing of when a quantum computer could break today's crypto
    ExecutiveThreatsTimeline
  • ›
    Re-checked leadership profiles and repaired broken links
    Researcher/leaders
Data Updates2
  • ›
    Rebuilt and re-signed the searchable knowledge index, plus the OSCAL and CBOM artifacts, after the accuracy and reference updates, so on-site search and the provenance trail stay in sync.
  • ›
    Refreshed the searchable knowledge index and re-signed the attestable data files after the standards and timeline source updates, so on-site search and the provenance trail stay in sync with the corrected content.

June 23, 2026

v4.1.0–v4.1.1

Version 4.1.1 adds a dedicated CRQC Threat Horizon view and read-only inspection of the artifacts the simulation generates, makes the standards Library quicker to filter, extends the migration timeline to ten national programs, paces the "watch the full migration" auto-run by its narration, and is honest when a referenced document has no reachable source. · Version 4.1 lets you watch a complete post-quantum migration run itself in the Migration Simulation, rebuilds that run around three plain goals tied to the new US Executive Order, and brings the redesigned Library, Migrate, Assess, Compliance, Learn, Algorithms, Patents, Report and Threats pages — each rebuilt around a single role selector — out of preview.

New Features3
  • ›
    A dedicated CRQC "Threat Horizon" view
    ExecutiveArchitectResearcherThreats
  • ›
    Inspect what the simulation generates, in place
    ArchitectDeveloper/simulation
  • ›
    Watch your whole migration play out on its own
    CuriousExecutiveArchitect/simulation
Improvements21
  • ›
    The Library is faster to narrow down
    ExecutiveDeveloperArchitectLibrary
  • ›
    The migration timeline now covers ten national programs
    ExecutiveArchitectTimeline/simulation
  • ›
    "Watch the full migration" is now paced by its narration
    CuriousExecutive/simulation
  • ›
    The Simulation now tracks three clear goals instead of a countdown you couldn't win
    ExecutiveArchitect/simulation
  • ›
    A US run now follows the new Executive Order's deadlines
    ExecutiveArchitect/simulation
  • ›
    Backing up your progress to Google Drive is hidden for now
    CuriousExecutiveDeveloper/
  • ›
    Hands-on labs now open right inside the Simulation
    ArchitectDeveloper/simulation
  • ›
    Recording your progress in the Simulation now works the same way everywhere
    ArchitectDeveloper/simulation
  • ›
    The Library is far easier to navigate
    ExecutiveDeveloperArchitectLibrary
  • ›
    Migrate opens the redesigned Migration Workbench by default
    ArchitectDeveloperMigrate
  • ›
    The Patents page leads with answers instead of a wall of charts
    ExecutiveArchitectResearcher/patents
  • ›
    The Quantum Risk Report tells you what your result means and what you're missing
    ExecutiveArchitectDeveloper/report
  • ›
    The Algorithms page is rebuilt as "Post-Quantum Algorithms & Protocols"
    ArchitectDeveloperExecutiveAlgorithms
  • ›
    The migration plan reads consistently and every product opens its details
    ArchitectDeveloperMigrate
  • ›
    The Assessment is now a guided two-pane wizard
    ExecutiveArchitectDeveloperAssess
  • ›
    The Compliance page is rebuilt around define → validate → mandate
    ExecutiveArchitectCompliance
  • ›
    Learn opens as a focused two-mode page
    CuriousExecutiveDeveloperArchitectLearn
  • ›
    Guided mode in the Simulation is now a genuinely simpler view
    CuriousExecutive/simulation
  • ›
    You can try the Simulation with a sample organization
    CuriousExecutive/simulation
  • ›
    The Threats page now opens with your own exposure
    ExecutiveArchitectOpsThreats
  • ›
    Threats filters and cards now match the rest of the hub
    ExecutiveArchitectDeveloperThreats
Bug Fixes11
  • ›
    Library documents with no reachable source now say so
    DeveloperArchitectLibrary
  • ›
    Finishing a Simulation phase now fully fills its readiness
    ExecutiveArchitect/simulation
  • ›
    Clicking a Patents chart now takes you to the matching patents
    ResearcherArchitect/patents
  • ›
    The Migration Simulation is now reachable from the top navigation
    ExecutiveCurious/simulation
  • ›
    The simulation keeps your place when you step out to a hub resource
    CuriousArchitect/simulation
  • ›
    You can now choose products in every Migrate category, and pick more than one
    ArchitectDeveloperMigrate
  • ›
    Payment products are no longer mis-filed under Blockchain
    ArchitectMigrate
  • ›
    Algorithm comparison shows the real limit and never traps a filter
    DeveloperArchitectAlgorithms
  • ›
    Protocol Support spec links open the in-app Library entry
    ArchitectDeveloperAlgorithms
  • ›
    The reports you download from the Business Center are more accurate and cleaner
    ExecutiveArchitect/business
  • ›
    NIST IR 8547 and FIPS 206 status corrected app-wide
    ExecutiveDeveloperLearnMigrateCompliance
Data Updates4
  • ›
    More Library documents open with a full summary
    DeveloperArchitectLibrary
  • ›
    The new US Executive Order on post-quantum cryptography is in the Library and on the Timeline
    ExecutiveDeveloperArchitectLibraryTimeline
  • ›
    RFC 9980 (Post-Quantum Cryptography in OpenPGP) added to the Library
    DeveloperArchitectLibrary
  • ›
    NIST IR 8610 added to the Library
    DeveloperArchitectLibrary

June 20, 2026

v4.0.0

Version 4.0 makes the Migration Simulation the heart of the app — your learning modules, business tools, workshops, the product catalog, the timeline and the algorithm comparisons now run _inside_ the simulation instead of sending you elsewhere — and adds a real in-browser KMIP control plane + PKCS#11 HSM, a much-expanded and re-validated protocol-support matrix, and new SOC / GRC / Team learning modules. The PQC VPN simulator now also runs the post-quantum IKEv2 handshake for real — hybrid key exchange, message fragmentation, and tunnel (CHILD_SA) negotiation all execute in the browser instead of being narrated — and every byte is inspectable in a new live packet capture.

New Features28
  • ›
    The Protocol Support matrix is fresher, clearer, and covers more ground
    ArchitectDeveloperAlgorithms
  • ›
    A real key-management control plane you can run in your browser
    DeveloperArchitectKMIP 3.0 Playground
  • ›
    A Guided vs Expert view for the in-browser control plane
    CuriousDeveloperKMIP 3.0 Playground
  • ›
    A refreshed Crypto Lab landing that's easier to start from
    DeveloperCuriousPlayground
  • ›
    The NICE Framework is now a searchable library reference
    ExecutiveDeveloperLibrary
  • ›
    Watch real VPN packets on the wire
    DeveloperResearcher/playground/vpn-sim
  • ›
    Hybrid mode runs a real second key exchange
    ArchitectDeveloper/playground/vpn-sim
  • ›
    Real IKEv2 message fragmentation
    Ops/playground/vpn-sim
  • ›
    The tunnel itself is now negotiated
    Architect/playground/vpn-sim
  • ›
    Learn section and mode comparison for the VPN workshop
    CuriousDeveloper/playground/vpn-sim
  • ›
    Follow a guided migration program across the whole app
    ExecutiveArchitect/businessAssess/report
  • ›
    Get a board-ready Quantum Readiness Assessment
    Executive/report
  • ›
    See your urgency as Mosca's Inequality
    ExecutiveResearcherAssessThreatsTimeline
  • ›
    Three new Command Center tools to stand up the program
    Executive/business
  • ›
    Export a CycloneDX CBOM from the product catalog
    DeveloperArchitectMigrate
  • ›
    A CNSA 2.0 lens on the algorithm catalog
    ArchitectDeveloperAlgorithms
  • ›
    Crosswalk the framework to NIST CSF, PQCC, ETSI and the Dutch handbook
    ExecutiveCompliance
  • ›
    Three new learning modules: SOC, GRC and Team
    OpsExecutiveLearn
  • ›
    Planning instruments on Threats and Timeline
    ArchitectThreatsTimeline
  • ›
    Your program maturity now tracks your progress automatically
    Executive/simulation
  • ›
    Play the always-on Foundations track in the simulation
    ExecutiveArchitect/simulation
  • ›
    Four more Command Center tools to run the program
    ArchitectOpsExecutive/business
  • ›
    Your assessment's risk dimensions now show in the simulation
    ExecutiveArchitect/simulation
  • ›
    Compare and commit your PQC algorithms without leaving the simulation
    ArchitectExecutive/simulation
  • ›
    The migration program now has a finish line
    Executive/simulation
  • ›
    In-sim study now pays off
    CuriousExecutive/simulation
  • ›
    Key fingerprints in the Crypto Lab
    DeveloperArchitectPlayground/report
  • ›
    Tune the vendor scorecard's weights live
    ExecutiveArchitect/scorecard
Improvements7
  • ›
    Cybersecurity workforce mappings refreshed to the current (2025) NICE Framework
    ExecutiveDeveloperLearn
  • ›
    The simulation now runs on your own assessment
    ExecutiveArchitect/simulationAssess
  • ›
    A quick assessment now gives you the full risk view
    CuriousExecutiveAssess/report
  • ›
    Delegating a phase to your AI team is now honest
    ExecutiveArchitect/simulation
  • ›
    Wrong moves now teach instead of just buzzing
    ArchitectDeveloper/simulation
  • ›
    A clearer first-run guide for the simulation
    Curious/simulation
  • ›
    Jump from a sandbox scenario to its PQC Protocol Matrix row
    DeveloperArchitectPlaygroundAlgorithms
Bug Fixes8
  • ›
    Compliance timelines now read phased deadlines correctly and only mark a deadline "met" with real proof
    Executive/business/simulation
  • ›
    VPN workshop facts corrected across the board
    Researcher/playground/vpn-sim
  • ›
    ML-DSA certificate authentication was always working — now the workshop says so
    Developer/playground/vpn-sim
  • ›
    Honest handshake sizing
    Architect/playground/vpn-sim
  • ›
    A readable event feed with reduced motion
    Curious/simulation
  • ›
    Trustworthy timeline and national-guidance facts in the simulation
    ExecutiveResearcher/simulation
  • ›
    The Vendor & Supply Chain phase is correctly continuous
    Executive/simulation
  • ›
    The Playground sandbox lists only scenarios that actually run
    DeveloperArchitectPlayground
Data Updates4
  • ›
    Two foundational frameworks added to the Library
    ExecutiveArchitectLibrary
  • ›
    Product catalog accuracy overhaul
    ArchitectDeveloperMigrateCompliance
  • ›
    The hands-on sandbox catalog now matches what actually runs
    DeveloperArchitectPlayground
  • ›
    Every persona can now find the sandbox
    ResearcherExecutiveCuriousPlayground

June 9, 2026

v3.19.5

The Threats page is fresher and more accurate — corrected post-quantum standards status, more sources you can open, and consistent severity labels.

Improvements1
  • ›
    More threats link to a primary source you can actually open
    Threats
Bug Fixes2
  • ›
    Corrected the status of NIST's fourth signature standard
    ArchitectThreats
  • ›
    Consistent severity labels across every threat
    Threats
Data Updates1
  • ›
    Refreshed quantum-threats dataset (2026-06-09)
    Threats

June 8, 2026

v3.19.3–v3.19.4

Compliance frameworks now say plainly whether PQC is required or just recommended, and sector names read in plain English. · A cleaner, more accurate Algorithms page — no duplicate entries, corrected standardization labels, and a live algorithm count.

Improvements1
  • ›
    Readable industry names in the compliance views
    Compliance
Bug Fixes2
  • ›
    Compliance frameworks no longer over-state legal force
    Compliance
  • ›
    Algorithms page now shows the real count and a working "Top picks" link
    Algorithms
Data Updates1
  • ›
    Duplicate algorithm rows removed and standardization labels corrected
    Algorithms

June 7, 2026

v3.19.0–v3.19.2

Restored 12 compliance regulation documents that previously failed to open in the Library. · Corrected the dataset counts shown on the About page. · A broad update across Timeline, Library, Migrate, Patents, and Threats — new filters, tidier Library tiles, fully sourced timeline events, and corrected vendor data.

New Features2
  • ›
    Timeline — filter by organization type
    Timeline
  • ›
    Library — multiple versions of a document collapse into one tile
    Library
Improvements3
  • ›
    About page data counts corrected
    /about
  • ›
    Timeline — retired events no longer clutter the Gantt
    Timeline
  • ›
    Playground — Sandbox category hidden when the sandbox is offline
    Playground
Bug Fixes1
  • ›
    Workshop player — gap-audit fixes: fixtures fetch, reload flow pinning, persona-aware step lists, Finish CTA, a11y
    workshop-panel
Data Updates7
  • ›
    12 compliance documents restored in the Library
    Library
  • ›
    Timeline — every event now backed by an authoritative source
    Timeline
  • ›
    Timeline — Gantt ordering and sources cleaned up
    Timeline
  • ›
    Library — freshness sweep: 100 confirmed updates across 794 documents
    Library
  • ›
    Migrate — corrected vendor roadmaps and a bigger product catalog
    Migrate
  • ›
    Threats — 7 blocked evidence sources recovered
    Threats
  • ›
    Patents — corpus grown to 928 with verified data
    /patents
Other2
  • ›
    Guardrail against wrong vendor-roadmap links
    CI
  • ›
    Trust-engine signature verification now actually runs in CI
    CI

June 4, 2026

v3.18.0

Playground gets Learn-style views and filtering plus a live sandbox-availability check, with eight learn-module fact corrections and a multi-source data refresh.

New Features2
  • ›
    Playground — Learn-style views and filtering
    Playground
  • ›
    New library reference — _Exploiting ML-DSA bugs_ (Bernstein, 2026)
    Library
Improvements2
  • ›
    Playground — live sandbox availability with click-for-access
    Playground
  • ›
    Learn — NICE role view hides irrelevant modules
    Learn
Bug Fixes5
  • ›
    Trust-engine exports are now reproducible
    MigrateCompliance
  • ›
    Playground no longer crashes on load
    Playground
  • ›
    Playground sandbox terminal accepts input again
    Playground
  • ›
    Learn modules — eight factual corrections
    Learn
  • ›
    Module "Complete" button now sticks
    Learn
Data Updates4
  • ›
    Protocol Matrix → Library links all resolve
    AlgorithmsLibrary
  • ›
    Migrate — catalog and certification refresh
    MigrateAlgorithms
  • ›
    Migrate — product catalog integrity sweep
    MigrateAlgorithms
  • ›
    Library — corrected G7 central-bank quantum report source
    Library

June 2, 2026

v3.17.5

Fixed 10 reported issues across the Learn catalog and crypto workshops, plus several in-browser HSM engine corrections.

New Features1
  • ›
    Two new library references
    Library
Bug Fixes6
  • ›
    KMS workshop — ML-KEM envelope encryption works again
    /learn/kms-pqcPlayground
  • ›
    Playground — XMSS and ECDSA P-521 self-tests pass
    Playground
  • ›
    Hybrid Crypto workshop — pure ML-KEM certificate generation fixed
    /learn/hybrid-crypto
  • ›
    Network Security workshop — step 6 no longer crashes
    /learn/network-security-pqc
  • ›
    "Complete Module" now works across 20 modules
    Learn
  • ›
    Playground — mechanism inspector shows readable names
    Playground
Data Updates1
  • ›
    Compliance exports refreshed
    ComplianceMigrate

May 30, 2026

v3.17.2

Every learning persona path now includes the recently added modules.

Improvements1
  • ›
    Learning paths now include all current modules
    Learn

May 31, 2026

v3.17.1

Fixed duplicate-looking products in the Migrate catalog and re-activated five products.

Bug Fixes1
  • ›
    Migrate — no more duplicate-looking products
    Migrate
Data Updates1
  • ›
    Five products re-activated in Migrate
    Migrate

May 30, 2026

v3.17.0

Role-aware ("persona") personalization across all seven main pages, a NICE Framework workforce view, a TLS downgrade-attack workshop, and many new references.

New Features9
  • ›
    NICE Framework view in the learning workshops
    ExecutiveArchitectDeveloperLearn
  • ›
    TLS downgrade-attack walkthrough
    Learn
  • ›
    Role-aware default filters across all seven main pages
    ExecutiveDeveloperArchitectOpsCuriousLibraryComplianceMigrateAssessPlaygroundThreatsTimeline
  • ›
    More NIST Round 2 signature algorithms in the Playground
    PlaygroundAlgorithms
  • ›
    Executive Board Pack export
    Executive/report
  • ›
    Compliance "For You" views for every role
    DeveloperOpsCuriousCompliance
  • ›
    Less overwhelming Compliance and Library pages
    ComplianceLibrary
  • ›
    "For me" filter on the changelog
    Curious/changelog
  • ›
    New products, references, and a community profile
Bug Fixes1
  • ›
    Various page fixes
    PlaygroundLibraryMigrate
Data Updates1
  • ›
    Product catalog enrichment
    Migrate

May 19, 2026

v3.16.0

Deep UX improvements to the Algorithms, Compliance, and Learn pages, a NICE workforce gap report, real in-browser PKI enrollment — and a critical browser-crypto security fix.

New Features4
  • ›
    NICE workforce gap report in Assess
    ExecutiveArchitectAssess
  • ›
    PKI Enrollment Protocols module
    DeveloperArchitectLearn
  • ›
    Composite certificates in the S/MIME workshop
    DeveloperLearn
  • ›
    Bigger Protocol Support matrix
    Algorithms
Improvements2
  • ›
    Algorithms page redesign
    Algorithms
  • ›
    Compliance and Learn page improvements
    ComplianceLearn
Bug Fixes2
  • ›
    In-browser HSM workshops fixed
    Learn
  • ›
    Compliance and Command Center show the right country's rules
    Compliance/business
Data Updates1
  • ›
    Accuracy and evidence sweeps
Security1
  • ›
    Critical — browser AES-GCM authentication fixed
    Learn

May 12, 2026

v3.15.0

A richer HSM Capacity Calculator and an overnight content-enrichment refresh.

New Features1
  • ›
    HSM Capacity Calculator — per-region view and a "how many HSMs?" explainer
    Playground
Data Updates1
  • ›
    Overnight content-enrichment refresh
    LibraryTimelineThreats

May 11, 2026

v3.12.1–v3.14.8
New Features8
  • ›
    ASC-X9-TR-50-2019-Quantum-Techniques-CMS.pdf → 3 candidates (RFC 5990, NIST PQC Project, RFC 5652)
  • ›
    ASC-X9-IR-F01-2022-Quantum-Computing-Risk-Study.pdf → 3 candidates (DHS PQC Roadmap, Mosca's Theorem, NIST NCCoE)
  • ›
    ASC-X9-PQC-Financial-Readiness-2025.pdf → 3 candidates (FIPS 203, FIPS 204, NSA CNSA 2.0)
  • ›
    ASC-X9-Financial-PKI.html → 3 candidates (FIPS 203, FIPS 204, RFC 8446)
  • ›
    NY-DFS-23-NYCRR-500-A2.pdf → 3 candidates (NIST CSF, ISO/IEC 27001, FIPS 140-3) After staging in pqctoday-priv/cowork/concept_xwalk_candidates_05082026.csv and running scripts/merge-xwalk-candidates.ts:
  • ›
    9 of 15 newly mergeable
  • ›
    1 invalid-vocab finding: Mosca's Theorem row used rationale_type=semantic which the merge script's vocab validator rejects (it lags v3.14.0's IR 8477 alignment). Known issue, separate fix.
  • ›
    Final: **957 rows** in concept_xwalks_05112026_r2.csv (was 948 in v3.14.5).
Bug Fixes25
  • ›
    IR 8477 xwalk enrichment: sentinel rows for zero-yield docs
  • ›
    Framer Motion: v12.27.5 → **v12.35.0** (restored)
  • ›
    Tailwind CSS: v4.1.17 → **v4.2.4** (also picks up the new patch since the original SBOM)
  • ›
    React Router: v7.12.0 → **v7.13.1** (restored)
  • ›
    Zustand: v5.0.10 → **v5.0.12** (picks up new patch)
  • ›
    ESLint: v9.39.2 → **v9.39.4** (restored)
  • ›
    Prettier: v3.8.0 → **v3.8.1** (restored) **Other corrections from running node -p require('pkg/package.json').version**:
  • ›
    @mlc-ai/web-llm: v0.2.81 → **v0.2.83** (was a guess; resolved is newer)
  • ›
    lodash: v4.17.23 → **v4.18.1** The user-corrected entries from v3.14.3 stay (those were genuine fixes, not downgrades):
  • ›
    Lucide React (v0.577.0 → v1.14.0) — was a stale carry-over from the legacy 0.x scheme
  • ›
    Playwright (v1.58.2 → v1.59.1) — was understated
  • ›
    pqctoday-tpm caption (v0.2.0 → v0.3.0) — matched the linked URL
  • ›
    New entries: @xyflow/react, dagre, @tanstack/react-virtual, @noble/post-quantum, @peculiar/x509, jspdf+autotable, docx, pptxgenjs, cborg, lodash, Local AI & Embeddings section
  • ›
    Compliance Concept Graph now populates for tiles whose compliance.id differs from the long-form display label the xwalk uses
  • ›
    Minimum needle length 4
  • ›
    Concept Graph icon now appears on every Landscape framework card
  • ›
    build-concept-registry.ts kebab function
  • ›
    migrate-xwalk-ids.ts re-migration safety:
  • ›
    Provider chip in the chat header now shows just the model name.
  • ›
    Action icons in the chat header no longer wrap to a second line.
  • ›
    Context Window preset cards no longer collapse into one mashed line.
  • ›
    Duplicate "Model" label removed.
  • ›
    Help text updated
  • ›
    /about page no longer crashes in production.
  • ›
    /compliance "For You" tab — industry filter now actually filters.
Data Updates6
  • ›
    +92 new edges
  • ›
    Post-merge cleanup dropped **83 duplicate xwalk_id rows** (merge-tool collision; first occurrence kept) and **5 not_related rows** (the IR 8477 vocabulary includes not_related but project convention is to omit those — they're documented as edges that aren't edges).
  • ›
    Final row count: **948** (was 944).
  • ›
    public/data/rag-corpus.json — **10,847 chunks, 16.1 MB** (10s regen). PROV-DM 100% on was_attributed_to; all 10,788 deep-links validated.
  • ›
    public/data/embeddings.bin + embeddings-meta.json — **15.9 MB / 420 KB** (173s regen). Re-aligned with the regenerated corpus via npm run generate-embeddings (bge-small-en-v1.5 quantized int8, 384-dim).
  • ›
    public/data/pqctoday-oscal*.json + pqctoday-cbom.json — regenerated by npm run build.
Other83
  • ›
    src/data/concept_xwalks_05112026_r2.csv — restored to v3.14.5 state (948 rows, was 957 after v3.14.6).
  • ›
    src/data/concept_xwalks_05112026_r1.csv — restored to v3.14.5 state (1037 rows, was 1045 after v3.14.6).
  • ›
    src/data/concept_xwalk_candidates_05112026.csv — public mirror restored to v3.14.5 state.
  • ›
    The 15 Gemini-emitted rows in pqctoday-priv/cowork/concept_xwalk_candidates_05082026.csv are kept but marked review_status=rejected, reviewed_by=auto-revert-v3.14.7, reviewed_date=2026-05-11, with a notes field appended explaining the trust reason. Preserving them in cowork — rather than deleting — keeps the audit trail intact: future SME review can re-promote any row after verifying the evidence quote is a verbatim substring of the source PDF.
  • ›
    Gemini will not be used for IR 8477 xwalk evidence extraction going forward.
  • ›
    Gemini may still be used for non-evidence-bearing tasks
  • ›
    Future hardening (separate PR):
  • ›
    ASC X9 Financial PKI & PQC Standards
  • ›
    NY DFS 23 NYCRR 500
  • ›
    Other ASC X9 docs (TR-50, IR-F01-2022, Financial-PKI) gain graph entry-points where they didn't have edges before.
  • ›
    80 unresolved endpoint references
  • ›
    PQC Coalition
  • ›
    SOC 2
  • ›
    Merger vocab validator stale
  • ›
    New hasGraphEdges(centerConceptId) helper
  • ›
    Matcher in equivalentCanonicals relaxed
  • ›
    No new edges for SOC 2, ASC X9, NY DFS, PQC Coalition.
  • ›
    80 unresolved endpoint references
  • ›
    Framer Motion: v12.35.0 → **v12.27.5**
  • ›
    Lucide React: v0.577.0 → **v1.14.0**
  • ›
    Tailwind CSS: v4.2.2 → **v4.1.17**
  • ›
    React Router: v7.13.1 → **v7.12.0**
  • ›
    Zustand: v5.0.11 → **v5.0.10**
  • ›
    ESLint: v9.39.4 → **v9.39.2**
  • ›
    Prettier: v3.8.1 → **v3.8.0**
  • ›
    Playwright: v1.58.2 → **v1.59.1** (was understated)
  • ›
    pqctoday-tpm caption corrected v0.2.0 → **v0.3.0** to match the linked release URL. **New entries** that were shipping in production without appearing in the SBOM:
  • ›
    @xyflow/react v12.10.1
  • ›
    @tanstack/react-virtual v3.13.24
  • ›
    @noble/post-quantum v0.6.1
  • ›
    @peculiar/x509 v2.0.0
  • ›
    jspdf + jspdf-autotable
  • ›
    New "Local AI & Embeddings" section
  • ›
    No new dependencies introduced — this is a doc-truth-update only. The 5 About-page tests still pass; tsc silent.
  • ›
    New equivalentCanonicals(center) helper in src/utils/conceptXwalkGraph.ts — ~25 LOC. Uses the existing conceptRegistry export.
  • ›
    concept_registry CSV gains an aliases column
  • ›
    Cards whose id doesn't directly match an xwalk endpoint (e.g. clicking CNSA 2.0 → centerConceptId is guidance:cnsa-2, but xwalk uses display*label NSA CNSA 2.0 → canonical guidance:nsa-cnsa-2-0) will see an empty graph with the message *"No concept-xwalk edges for this framework."\_ This is correct given the current canonical-id assignment — the deeper fix is a curated equivalence table in the registry, or a runtime "equivalent canonicals" lookup in the graph builder. Tracked for the next release.
  • ›
    Knowledge-model alignment to NIST IR 8477.
  • ›
    Concept graph icon on every compliance framework card.
  • ›
    XwalkRationaleType enum now matches doc §3.2 closed set exactly:
  • ›
    17 rows rewritten
  • ›
    12 candidate rows rewritten
  • ›
    Loader + validator vocab sets
  • ›
    New standard_implements_algo_xref table
  • ›
    Full NIST PQC matrix seeded: ML-KEM-512/768/1024 (FIPS 203), ML-DSA-44/65/87 (FIPS 204), and all 12 SLH-DSA variants (SHA2 × 3 levels × s/f + SHAKE × 3 levels × s/f, FIPS 205). The three D3-canonical defaults — ML-KEM-768, ML-DSA-65, SLH-DSA-SHA2-128f — are flagged is_default=yes.
  • ›
    New loader
  • ›
    New validator
  • ›
    New concept_registry_05112026.csv
  • ›
    Programmatic builder
  • ›
    New loader
  • ›
    New validator
  • ›
    Xwalk migration to canonical ids
  • ›
    New validator
  • ›
    **conceptIdFor* accessors added** to libraryData.ts, complianceData.ts, timelineData.ts, and standardImplementsAlgoXref.ts so hub components holding a domain row can resolve its canonical id in O(1).
  • ›
    ConceptXwalkRecord interface gains
  • ›
    New Network icon on every framework card
  • ›
    FrameworkConceptGraph component
  • ›
    Graph builder utility
  • ›
    Modal wrapper
  • ›
    ComplianceTable was intentionally skipped
  • ›
    CM-2 + CM-Xwalk-VOCAB extended to enforce IR 8477 §3.2 closed rationale_type set (existing checks now reflect new vocab).
  • ›
    CM-ALGO-XREF-STD, CM-ALGO-XREF-PARAM, CM-ALGO-XREF-FAM, CM-ALGO-XREF-DEFAULT — referential integrity for the new algorithm xref.
  • ›
    CM-REGISTRY-TYPE, CM-REGISTRY-DUP, CM-REGISTRY-REF — referential integrity for the new concept registry.
  • ›
    CM-CONCEPT-FROM, CM-CONCEPT-TO — xwalk canonical-id resolution (WARNING).
  • ›
    The duplicate-check tests and the Q&A semantic-check tests overwrite public/data/rag-corpus.json with synthetic data during their setup phase. They do attempt a backup/restore (.qa-semantic-test-backup) but there's no SIGTERM handler — if the test is killed mid-run (CI timeout, OOM, manual abort), the production corpus is left corrupted. Will be fixed in a separate PR.
  • ›
    All Trust Engine model alignment changes verified by 53/53 → 337/337 → 330/330 progressively widening test runs; production npm run build clean.
  • ›
    New dependency: dagre@^0.8.5 + @types/dagre (~30 KB, MIT) — first graph-layout library in the hub bundle, not a crypto library (outside CLAUDE.md's "no new crypto libs without permission" rule).
  • ›
    Local AI is now framed as exploratory and gated behind explicit consent.
  • ›
    Local catalog narrowed to one model — Qwen 3 8B.
  • ›
    Chat panel can now expand to ~85vw
  • ›
    Double acknowledgement required before any local-AI session.
  • ›
    Cloud (Gemini Flash) card now badged as Recommended
  • ›
    Local card now badged as Experimental
  • ›
    Catalog reduced from five models to one.
  • ›
    Every catalog entry's maxContextLength corrected to 4096.
  • ›
    Qwen 3 0.6B VRAM corrected
  • ›
    Persistence migration v8 → v9 → v10 → v11
  • ›
    Single-model UI affordance:
  • ›
    /no_think is now injected into both the system prompt and the trailing user turn
  • ›
    Empty post-strip output now surfaces a partial reasoning excerpt with a notice
  • ›
    New maximize / minimize toggle in the panel header.
  • ›
    WebLLM catalog file (src/services/chat/WebLLMService.ts) carries an explicit header comment documenting the rationale for the single-model catalog and the criterion for re-expansion.
  • ›
    All chat / local-AI / right-panel changes verified by npx tsc --noEmit and 391 passing tests across src/services/chat/, src/store/, src/components/Chat/, and src/components/RightPanel/.

May 10, 2026

v3.8.0–v3.12.0
Bug Fixes13
  • ›
    The **"Why shown?" popover** on derived compliance standards no longer gets clipped by the page shell. Renders via React portal with viewport-aware positioning (flips above/below the trigger based on available space, clamps horizontally to viewport).
  • ›
    Test runs no longer silently corrupt the RAG corpus.
  • ›
    The RAG corpus and its embedding sidecar now stay byte-stable through commits.
  • ›
    Validators no longer crash mid-enrichment.
  • ›
    Counter-claim output explicitly framed as candidates, not declarations.
  • ›
    Deprecated leaders no longer appear in the corpus.
  • ›
    Timeline events register all their lookup keys
  • ›
    Enrichment chunks routed by their collection
  • ›
    Classical algorithms excluded from trust scoring
  • ›
    49 missing PQC algorithm variants added
  • ›
    Timeline event titles no longer get truncated to 50 characters
  • ›
    Trusted-source cross-reference deduplication
  • ›
    3 cached library documents re-fetched
Data Updates13
  • ›
    Missing-reference candidates
  • ›
    Trusted-source cross-reference proposer
  • ›
    Semantic data-quality checks
  • ›
    Pair-wise duplicate detector
  • ›
    Counter-claim auto-discovery
  • ›
    9 more library documents enriched
  • ›
    Validator warnings: 31 → 21
  • ›
    Trusted-source map refreshed
  • ›
    Three new columns
  • ›
    Rows are never deleted.
  • ›
    Loader helpers
  • ›
    Eight new validators in CI
  • ›
    All eight ship as WARNING.
Other66
  • ›
    Trust badges are now meaningful across the whole site.
  • ›
    New /agility dashboard
  • ›
    Citations now show provenance.
  • ›
    Library research coverage jumped from 73% → 92%
  • ›
    Cross-page industry filter actually works now
  • ›
    The trust-engine roadmap is complete.
  • ›
    Products
  • ›
    Algorithms
  • ›
    Leaders
  • ›
    Overall corpus:
  • ›
    New top-level route rendering the NIST CSWP 39 Cryptographic-Agility Maturity grid — 4 levels (Partial → Risk-Informed → Repeatable → Adaptive) across 5 pillars (inventory, governance, lifecycle, observability, assurance).
  • ›
    KPI bar above the grid shows grid coverage %, mean confidence, and source-record count so you can see at a glance how complete the extraction is.
  • ›
    Empty-state copy points operators at the enrichment script when the CSWP 39 slice has no rows. _Internal detail: src/components/Agility/AgilityView.tsx reuses the existing MaturityEvidenceGrid component over a CSWP-39-filtered slice of maturityRequirements. Route registered in src/App.tsx as a lazy-loaded child of MainLayout._
  • ›
    155 documents fully re-enriched against the latest dimension model — library coverage **92% (726/787)** up from 73% (571/787). PQC-dense documents (KEM/signature specs, TLS ML-KEM, XMSS/LMS, IKEv2 PQC drafts) averaged 15 of 28 dimensions populated.
  • ›
    RAG search corpus rebuilt — **10,845 chunks**, +217 versus the previous build. Document-enrichment chunks are 1,611 of the total.
  • ›
    Every chunk now ships with full PROV-DM provenance metadata (entity_id, was_generated_by, was_attributed_to, was_derived_from, source_doc, source_passages) so chat and search citations can show exactly where an answer came from.
  • ›
    Embedding index (15.9 MB) rebuilt against the new corpus; corpusHash invariant restored and verified by corpus-trust-invariants.test.ts (10 tests, all green).
  • ›
    The industry filter dropdown on **Compliance** now shows human-readable labels — "Finance & Insurance (52)" instead of bare "52". Out-of-vocab values seeded from cross-page state still surface so you can see exactly what the active filter is.
  • ›
    Cross-page industry filter actually matches now. URL parameters and persona-store values like "Finance & Banking" are auto-resolved to the matching NAICS code ("52") before filtering, so navigating from a persona-aware page into Compliance no longer mysteriously empties the view.
  • ›
    Trust-tier filter on **Compliance → Landscape** now applies to the facet partitioning — selecting "Authoritative" correctly filters per-facet counts for bodies / standards / certifications / regulations. _Internal detail: SectorFilter.tsx exports NAICS_LABELS and a resolveToNaics() helper backed by the existing INDUSTRY_TO_NAICS alias table. ComplianceView.tsx routes two useState initialisers and one tab-switch effect through it. LandscapeTab.tsx consumes useTrustTierFilter + matchesTrustTierFilter before partitioning frameworks._
  • ›
    The **trust-engine implementation roadmap is now 13 / 13 ✅** — all sub-plans complete on this branch: foundation, learn-module + workshop-tool review gates, library + algorithms + compliance + timeline + migrate + threats + assessment + leaders data domains, enrichment pipeline + PROV-DM, Compliance-For-You trust paths, timeline-claims evidence layer, UI trust layer, persona filtering, OSCAL export, and the new /agility maturity dashboard.
  • ›
    The CSWP 39 + Q&A citation validators (CM-W, CM-C, QA-S, QA-CSWP) are operational. They currently surface **38 modules** with stale lastReviewed dates and **707 Q&A rows** missing citation references — these are the SME-review queue the validators were designed to produce, not bugs to fix in code.
  • ›
    Trust-tier baseline snapshot captured at reports/trust-tier-snapshot.json for ongoing measurement; re-run via npx vitest run …measure-tier-distribution.test.ts whenever data changes meaningfully.
  • ›
    Search now understands what you mean, not just what you type.
  • ›
    Free-text Compliance suggestions in the Assessment.
  • ›
    Five new behind-the-scenes data-quality watchers
  • ›
    Trust-tier baseline captured
  • ›
    Single shared useSemanticSearch hook wired into **8 list-driven views** (Library, Patents, Migrate, Compliance Landscape, Threats, Timeline, Community, Algorithms — both transitions and filteredAlgorithms slices) plus the Assessment wizard's Compliance step.
  • ›
    Lexical floor preserved everywhere.
  • ›
    Score interleave on Patents
  • ›
    Improved empty-state copy
  • ›
    Small "✨ Expanded with semantically related matches" hint
  • ›
    Trust-tier baseline snapshot
  • ›
    Genuinely deferred to a later cycle
  • ›
    Trust tier filter on five views.
  • ›
    Chat citations now show trust tier.
  • ›
    ⌘K command palette is tier-aware.
  • ›
    Timeline events show a freshness pill
  • ›
    A long-tail of broken trust links is fixed.
  • ›
    TrustTierFilter chip
  • ›
    Records tab on Compliance
  • ›
    CitationTierChip
  • ›
    ⌘K palette tier-aware ranking
  • ›
    TimelineEvidenceBadge freshness pill
  • ›
    Corpus invariant CI gate
  • ›
    C1–C10 acceptance contract
  • ›
    ESLint config extended to lint scripts/** cleanly without per-file env directives.
  • ›
    "Leaders" is now called "Community"
  • ›
    Clicking a community member expands their detail inline
  • ›
    Behind-the-scenes data quality improved
  • ›
    Renamed across **all UI surfaces**: main navigation, breadcrumb, embed layout, route presets, About page discussion panel.
  • ›
    Inline expand/collapse on Community detail
  • ›
    Deprecated rows hidden from listings
  • ›
    Records can no longer silently disappear from the data files.
  • ›
    318 records restored or formally preserved
  • ›
    CI now refuses pull requests that would silently drop records.
  • ›
    8 new validator gates
  • ›
    Enrichment writers
  • ›
    Cross-reference generators
  • ›
    Promotion script
  • ›
    Generic backfill tool
  • ›
    Phase 3 orchestrator
  • ›
    Enrichment merger
  • ›
    80 restored library records re-enriched
  • ›
    RAG corpus regenerated
  • ›
    21 CSVs and 51 enrichment MDs archived to src/data/archive/ and src/data/doc-enrichments/archive/ (the "keep 2 versions" rule from CSVmaintenance.md). Safe to archive because each latest file is now independently self-sufficient. _Internal detail: 22-task implementation plan + tracker + schema spec at pqctoday-priv/docs/platform/data/data-self-containment-implementation-{plan,tracker}.md and csv-status-schema.md._

May 9, 2026

v3.7.0
New Features19
  • ›
    Trust path traversal
  • ›
    useApplicabilityWithPaths hook
  • ›
    TrustPathPopover component
  • ›
    derived tier in ApplicabilityTier
  • ›
    Per-persona trustPathConfig
  • ›
    Timeline claims evidence
  • ›
    UI trust layer — revision signals
  • ›
    Vocab normalization — Plan 11
  • ›
    Faceted filter components
  • ›
    OSCAL assessment-results export
  • ›
    CM-G and CM-E validator gates
  • ›
    Status-column schema
  • ›
    loaderUtils.ts
  • ›
    CM-SC + CM-SC-MD validators
  • ›
    **CM-VT-\* vocab-tag validators** (DS19) — six checks: CM-VT-COUNTRIES, CM-VT-INDUSTRIES, CM-VT-REGION-SCOPE, CM-VT-THREAT-INDUSTRY, CM-VT-ROLES, CM-STATUS. All wired into the data-integrity validator. Current baseline: countries/industries/threat-industry pass; region-scope 2 G7 findings; roles 232 legal alias findings.
  • ›
    CM-ORPHAN trust-path pre-flight
  • ›
    promote-cowork.ts deletion audit
  • ›
    backfill-csv-self-containment.py
  • ›
    concept_xwalks_05092026_r1.csv
Bug Fixes2
  • ›
    SLH-DSA recall regression in golden-queries
  • ›
    useChatSend test failures after trust-engine refusal gate

May 7, 2026

v3.6.0
New Features14
  • ›
    Dataset 05062026 promotion
  • ›
    Migrate — click-to-detail on product tiles
  • ›
    Compliance — click-to-detail on landscape tiles
  • ›
    Compliance detail pane — CSWP.39 maturity requirements
  • ›
    Business Center — LearningFrameBanner replaces WIP warning
  • ›
    Business Center — persona-aware density system
  • ›
    Business Center — action items cap + personalisation copy
  • ›
    Compliance — LearningFrameBanner + GlossaryStrip
  • ›
    Compliance — unified Landscape tab
  • ›
    8 new learn module workshop steps
  • ›
    pqctoday-tpm listed in About SBOM
  • ›
    New compliance-checklist artifact builder
  • ›
    5 new FAQ entries
  • ›
    Vendor PQC roadmap pipeline
Improvements10
  • ›
    Learn modules — removed stale content.ts / curious-summary-curious.md files
  • ›
    Compliance For You tab — inline detail panes for resources
  • ›
    Country-specific deadline timeline on For You tab
  • ›
    Command Center artifact pre-fill — full coverage across all 22 artifacts
  • ›
    crypto-vulnerability-watch highlights tracked-algorithm CVEs
  • ›
    policy-draft rotation period seeded from cryptoAgility
  • ›
    vendor-scorecard opens roadmap dimension first for heavy vendor-dependency
  • ›
    contract-clause shows "High vendor exposure" hint above the editor
  • ›
    supply-chain-matrix filters industry threats to supply-chain scope
  • ›
    Chat assistant Bloch-sphere icon
Bug Fixes19
  • ›
    SourcesModal crash on new source_type values
  • ›
    Algorithm transition dates displayed in ISO format
  • ›
    Golden-queries Recall@15 regression after corpus growth
  • ›
    Migrate filter drawer clipped inside sticky toolbar
  • ›
    "Has PQC Roadmap" toggle missing from desktop filter
  • ›
    Assess quick-mode step count corrected to 8
  • ›
    Command Center crash opening Compliance Timeline artifact under /business#zone-governance
  • ›
    PQC 101 phantom "Hands-on 5/5" caption
  • ›
    Executive p-landing step referenced removed home-page sections
  • ›
    Executive Finance & Banking workshop — comprehensive accuracy, completeness, and audio review
  • ›
    TPM PQC Crypto Bridge (Issue #9)
  • ›
    TTS caption interruptions eliminated — generation counter
  • ›
    TTS audio still interrupted — speechSynthesis.speaking primary guard
  • ›
    TPM Playground full TCG V1.85 PQC compliance
  • ›
    References tab deduplicated across foundation modules
  • ›
    Assess wizard navigation broken after workshop reset
  • ›
    p-assess step: only 6 of 8 wizard steps driven; submit never fired
  • ›
    p-report step: wrong section order, hidden sections cited, all TOC clicks missed
  • ›
    Command Center artifact drawer "works only once"
Data Updates6
  • ›
    May 4 data accuracy refresh
  • ›
    OpenSSL 3.5.0 enriched
  • ›
    Vendor PQC roadmap data
  • ›
    Learn module reference and product mappings curated
  • ›
    Learn module search powered by topic-scope summaries
  • ›
    RAG search index regenerated
Other1
  • ›
    npx tsc -b clean; full vitest suite passes.

May 3, 2026

v3.5.64
New Features11
  • ›
    4 new persona workshop flows
  • ›
    Executive workshop flow gains 2 modules
  • ›
    Quiz showcase close step
  • ›
    20 PKI Learning module Introductions instrumented
  • ›
    Three new workshop cue kinds
  • ›
    6 governance sub-steps
  • ›
    TPM playground scenario flow tab
  • ›
    TPM V1.85 compliance suite extended to 16/16
  • ›
    TPM bridge error surfacing
  • ›
    useModuleStore.markLearnSectionRead(moduleId, sectionId)
  • ›
    Workshop voice "Test Voice" button
Improvements15
  • ›
    LearnStepper — sticky TOC + all-DOM render
  • ›
    LEARN_SECTIONS registry aligned to rendered DOM
  • ›
    Dynamic workshop caption timing
  • ›
    WaveNet / neural voice auto-pick
  • ›
    Workshop cue generator drops learnTabIsStepper flag
  • ›
    "Workshop N/M:" → "Hands-on N/M:"
  • ›
    Workshop speed picker → Preview vs Presentation modes
  • ›
    Workshop persona-driven flow matching
  • ›
    Stale ROLE_ADAPTATIONS strings
  • ›
    Caption-driven section auto-scroll
  • ›
    Workshop content cleanup
  • ›
    CuriousSummaryBanner.tsx
  • ›
    MainLayout.tsx
  • ›
    WorkshopPrereqList rewritten
  • ›
    Executive flow widened
Bug Fixes25
  • ›
    Workshop captions read 1/4 → 2/4 → 3/4 → 4/4 in cue order
  • ›
    Stale "Section 3 of 5" caption
  • ›
    52 caption rewrites
  • ›
    One HARD caption mismatch
  • ›
    Workshop region scoping
  • ›
    Workshop click cue retry
  • ›
    Workshop selectTab handles label/value mismatch
  • ›
    Workshop URL deep-link fixes
  • ›
    Workshop slow/fast math fix
  • ›
    Workshop no-cue step duration cap
  • ›
    Workshop persona region propagation
  • ›
    Workshop preview mode skips cues entirely
  • ›
    Workshop auto-scroll on navigate
  • ›
    Command Center bypass when workshop is active
  • ›
    Workshop voice on Chrome
  • ›
    Workshop voice priming on user gesture
  • ›
    Assess wizard auto-walks
  • ›
    TPM Playground V1.85 compliance
  • ›
    TPM V1.85 use-phase commands
  • ›
    TPM WASM stubs for use-phase crypto
  • ›
    TPM2_Encapsulate wire format
  • ›
    TPM2_SignDigest wire format
  • ›
    CommandBuilder
  • ›
    TPM SHA-2 hash table wrappers
  • ›
    TPM EMULATE_FUNCTION_POINTER_CASTS=1
Data Updates2
  • ›
    Patents data refresh
  • ›
    Infographics regeneration
Other4
  • ›
    Multi-Session Safety Rules
  • ›
    Semantic caption-vs-content audit
  • ›
    Workshop bug-fix wave + artifact-management cues
  • ›
    npx tsc -b clean; npx vitest run 2086/2086 pass.

May 2, 2026

v3.5.63

Playground UX audit Wave 2A/2B/2C: error UX hardening across workshop tools, WasmModeIndicator in HSM Key Derivation, isStepComplete gating in all three blockchain flows, and supporting UX additions (SSH hybrid KEX rationale, Source Combining FilterDropdown, HD Wallet mnemonic panel, Solana tamper toggle, Patents full-text search, 5G scenario intro strip, PKI Workshop artifact strip).

New Features9
  • ›
    Patents — full-text search panel
  • ›
    5G SUCI — scenario intro strip
  • ›
    PKI Workshop — artifact summary strip
  • ›
    HD Wallet — BIP-39 mnemonic word grid
  • ›
    HD Wallet — extractable-key security callout
  • ›
    Solana — tamper-signature toggle
  • ›
    SSH Sim — hybrid KEX rationale callout
  • ›
    SSH Sim — wire-packets view switcher
  • ›
    SSH Sim — beginner PKCS#11 mode
Improvements3
  • ›
    Bitcoin — isStepComplete step gating
  • ›
    Solana — isStepComplete step gating
  • ›
    HD Wallet — isStepComplete step gating
Bug Fixes5
  • ›
    VPN Simulator — translateCryptoError + <ErrorAlert>
  • ›
    Source Combining — translateCryptoError
  • ›
    SSH Sim — translateCryptoError + <ErrorAlert>
  • ›
    HSM Key Derivation — WasmModeIndicator
  • ›
    Library — staleness badge excludes Expired/Superseded
Other1
  • ›
    tsc --noEmit clean; 2021 unit tests pass.

May 1, 2026

v3.5.30–v3.5.62

Wave 3 UI audit completion: all P1, P2, and P3 items shipped. Learn module workshop UX fixes for EntropyTestingDemo, SuciFlow, and MerkleTreeCerts. · Wave 1 UX/UI implementation: 8 P0/P1 plans executed covering persona access, analytics instrumentation, filter UX, table virtualization, compliance tab overflow, and shareable report URLs. · Routine dependency hygiene: 5 Dependabot updates landed in one batch after local CI verification, plus a transitive override that closes the last remaining moderate-severity vulnerability flagged by GitHub Security. No runtime or visible behaviour changes. · A second data-substrate sweep on the same day: vendor partnerships now have a proper schema, SaaS-only products land in their own cross-reference family, the assessment wizard knows which compliance frameworks and threats each question maps to, the maturity corpus consolidates into a single canonical file, and the trust-score tooltip honestly distinguishes verified attribution from heuristic guesses. · This release closes a long backlog of cross-reference gaps in the data layer. The Library now contains every standard, RFC, and policy that the rest of the site already cited; the Migrate page knows the vendors behind 31 products it previously labeled with bare names; and the trust-source attribution badges catch up to the current data after a 32-day lag.

New Features38
  • ›
    OpenSSL Studio — persona cheat sheet strip
  • ›
    Library — citation staleness badge
  • ›
    Assess — "Save link" CTA
  • ›
    Algorithms — executive "Top 5" shortcut
  • ›
    Timeline — search auto-scroll
  • ›
    About — deploy timestamp
  • ›
    Compliance — cert-records cross-link
  • ›
    Patents — "Explore Related" cross-links
  • ›
    SuciFlow — SUPI input validation
  • ›
    SuciFlow — Perspective switcher in config panel
  • ›
    SuciFlow — HSM/OpenSSL mode indicator
  • ›
    MerkleTreeCerts — two-stage reset confirmation
  • ›
    MerkleTreeCerts — step-dependency warning
  • ›
    MerkleTreeCerts — workshop completion card
  • ›
    MerkleTreeCerts — step nav accessibility
  • ›
    Entropy Testing — paste-hex error state
  • ›
    Entropy Testing — mode-switch state preservation
  • ›
    QRNG Demo — live randomization
  • ›
    Envelope Encryption — per-sub-operation progress labels
  • ›
    Cert Capacity Calculator — relative-size toggle
  • ›
    Product catalog module mapping — 100% coverage
  • ›
    slh-dsa module fully stocked
  • ›
    scripts/generate-module-gap-report.py
  • ›
    crypto-mgmt-modernization module cleanup
  • ›
    WasmModeIndicator
  • ›
    Reset / Start Over buttons
  • ›
    Developer persona unlocked for /business
  • ›
    Analytics: persona-labeled events + 4 new event types
  • ›
    FilterDrawer
  • ›
    Table virtualization
  • ›
    Compliance tab overflow menu
  • ›
    Shareable report URL token
  • ›
    Removed curious dead config
  • ›
    Vendor partnerships table
  • ›
    SaaS cross-reference family
  • ›
    Assessment wizard FK columns
  • ›
    32 missing Library entries
  • ›
    30 new vendor profiles
Improvements18
  • ›
    Playground — "Crypto Workshop" → "Crypto Lab"
  • ›
    Compliance — Leaders cross-links
  • ›
    Patents — executive default sort
  • ›
    Learn Dashboard — "Path" terminology
  • ›
    Timeline — persona hint strip
  • ›
    Algorithms — persona hint strip
  • ›
    lucide-react 0.577.0 → 1.14.0
  • ›
    @tailwindcss/vite + tailwindcss 4.2.2 → 4.2.4
  • ›
    @mlc-ai/web-llm 0.2.81 → 0.2.83
  • ›
    zustand 5.0.11 → 5.0.12
  • ›
    Maturity governance corpus consolidated
  • ›
    Assessment wizard content refresh
  • ›
    Trust-score cross-reference scoring distinguishes verified vs heuristic attribution
  • ›
    Authoritative-source freshness sweep
  • ›
    Trusted-source cross-reference refreshed
  • ›
    migrate_purl_xref regenerated against the current product catalog
  • ›
    migrate_certification_xref regenerated
  • ›
    Catalog vendor IDs normalized to VND-XXX format
Bug Fixes7
  • ›
    TEEHSMTrustedChannel.tsx import syntax error
  • ›
    Workshop WASM error messages
  • ›
    cryptoErrorHints.ts deprecated
  • ›
    CHANGELOG version-number duplicates
  • ›
    Validator graph-consistency now recognizes vendor_partners
  • ›
    Two corrupted Library archive files removed
  • ›
    Trusted-source-xref test was rejecting legitimate cross-resource attributions
Security2
  • ›
    postcss 8.5.6 → 8.5.13
  • ›
    uuid pinned to ^14.0.0 via overrides
Other12
  • ›
    tsc --noEmit clean; 2021 Vitest unit tests pass.
  • ›
    tsc --noEmit clean; all 232 unit tests pass.
  • ›
    Added @tanstack/react-virtual dependency.
  • ›
    Global vitest setup mocks @tanstack/react-virtual so table tests pass in jsdom (no layout engine). Updated kpiCatalog.test.ts, ComplianceView.test.tsx, and ReportContent.test.tsx to reflect new developer KPI access and compact share token format.
  • ›
    All 2015 unit tests pass; tsc --noEmit clean.
  • ›
    Verified locally before push
  • ›
    Eslint group bump (#175) not yet adopted
  • ›
    Validator: 99 → 101 checks
  • ›
    Test suite: 2010/2012 → 2014/2014
  • ›
    Data integrity validator: 6 ERRORs → 0
  • ›
    CSV archive hygiene
  • ›
    RAG corpus regenerated

April 30, 2026

v3.5.27–v3.5.29

The app gets a new logo, the top navigation no longer overflows on standard laptop screens, and pages stop drifting sideways when wide content is on screen. The Compliance page is also tidier on phones — filters wrap into neat rows and overflowing strips show a soft fade so it's clear there's more to scroll to. · The CSWP.39 governance dataset on the Compliance page now covers 1,332 requirements from 189 source documents (up from 970 / 107). The Library page gained a CSWP.39 filter, and clicking any library card now shows the obligations extracted from that source inline — with the original quote that justifies each one. · A major Command Center upgrade: every zone is now wired, your assess answers and "My X" selections flow through to artifact builders, the page copy adapts to your persona, and artifacts gain an approval workflow + audit trail. Library cards link to their CSWP.39 zone and the CBOM tool now overlays live CMVP matches next to its illustrative cert numbers.

New Features25
  • ›
    Brand refresh across favicons, PWA icons, and social previews
  • ›
    Android adaptive home-screen icons
  • ›
    See every CSWP.39 requirement extracted from a library document, inline
  • ›
    "CSWP.39" filter on the Library page
  • ›
    +362 new CSWP.39 governance obligations
  • ›
    All six CSWP.39 zones now have data wires
  • ›
    Persona-aware Command Center copy
  • ›
    "Suggested by your assessment" badges on missing artifacts
  • ›
    Artifact builders auto-fill from your assessment
  • ›
    CBOM "From your assessment" mode
  • ›
    Live CMVP / Common Criteria match badges on cert numbers
  • ›
    "Sample" badges + disclaimer banner on illustrative data
  • ›
    Approval workflow on artifacts
  • ›
    Artifact audit trail
  • ›
    §3 / §4 / §5 / §6 NIST CSWP.39 section nav
  • ›
    §-reference hover popovers
  • ›
    "Learn this zone →" link in every Command Center zone header
  • ›
    Half-page / full-page toggle on every artifact builder
  • ›
    Glossary hover tooltips on jargon
  • ›
    Action Items "why" chips
  • ›
    "My X" selections from other pages now flow into Command Center
  • ›
    Bidirectional "Add to My X" chips inside builders
  • ›
    Source provenance chips on tracked frameworks
  • ›
    Library cards show CSWP.39 zone link + maturity tier
  • ›
    Quick assessment mode now covers all 5 CSWP.39 process steps
Improvements8
  • ›
    Top navigation no longer scrolls horizontally on typical laptops
  • ›
    Compliance filter chips on mobile
  • ›
    Compliance mobile tab strip and CSWP.39 framework matrix show a soft right-edge fade
  • ›
    Compliance → CSWP.39 explorer headline
  • ›
    CBOM and Vulnerability Watch artifacts re-classified to the Assets zone
  • ›
    Mobile navigation order tweaked
  • ›
    About page
  • ›
    Changelog page
Bug Fixes1
  • ›
    Pages no longer drift sideways on phones
Other3
  • ›
    Cyber Insurance Lens panel
  • ›
    New persisted store version (v14) with safe migrations for the audit trail and approval workflow fields. Existing artifacts keep their createdAt and default to draft approval status.
  • ›
    Two new test files (DocumentCard.test.tsx, cswp39ZoneData.test.ts) and a new E2E spec (library-cswp39.spec.ts) covering the Library ↔ Command Center cross-walk.

April 29, 2026

v3.5.21–v3.5.26

Fixed a production-only crash on the Command Center page. · Added an FAQ tab to the right panel and turned on usage analytics for several pages. · The VPN Simulator is out of "work in progress" — ML-DSA-65 dual-auth IKEv2 with ML-KEM-768 key exchange now establishes successfully every time. · Added a "work in progress" banner to the Command Center. · CVE snapshots now record total counts so the UI can show "showing 20 of N" when results are capped. · Major Command Center expansion: the NIST CSWP.39 zones are now an interactive diagram with per-zone artifact tracking. Adds a daily CVE feed, shared PDF export, and a new architecture diagram.

New Features10
  • ›
    FAQ tab in the right panel
  • ›
    Usage analytics for Explore, Report, and Business Tools
  • ›
    Command Center work-in-progress notice
  • ›
    CSWP.39 zone diagram in the Command Center
  • ›
    Live data wires inside Command Center zones
  • ›
    Daily CVE snapshot system
  • ›
    Shared markdown viewer
  • ›
    Shared PDF export utility
  • ›
    PKI Learning — crypto architecture diagram
  • ›
    Updated product–CPE cross-references
Improvements5
  • ›
    Analytics test coverage
  • ›
    CVE snapshots now carry total counts
  • ›
    PKI Learning artifacts now sync to the Business Center
  • ›
    CSWP.39 zone definitions consolidated
  • ›
    HSM Capacity Calculator — multi-location math corrected
Bug Fixes3
  • ›
    Command Center page no longer crashes in production
  • ›
    VPN Simulator — diagnostic noise removed
  • ›
    VPN Simulator — dual-authentication tests rewritten
Other1
  • ›
    VPN Simulator's "work in progress" banner

April 28, 2026

v3.5.20

Major milestone: ML-DSA-65 dual-auth IKEv2 in the VPN Simulator now completes a full handshake end-to-end with real ML-KEM-768 key exchange, all running in the browser.

Bug Fixes1
  • ›
    VPN Simulator — ML-DSA-65 dual-auth handshake completes successfully

April 27, 2026

v3.5.19

Major VPN Simulator milestone: full IKE_SA reaches ESTABLISHED with real ML-KEM-768 inside the browser. Also unifies the search service shared by ⌘K and the PQC Assistant, and adds a deep-link validator that ensures every link in the corpus actually works.

New Features6
  • ›
    Unified search service shared by ⌘K and the PQC Assistant
  • ›
    Deep-link grammar validator
  • ›
    Strict corpus invariants gate
  • ›
    ⌘K parity for 8 missing sources
  • ›
    Persona and intent boosts for 16 more sources
  • ›
    FAQ button on every content page header
Improvements5
  • ›
    RAG corpus deep links — 0 missing (down from 722)
  • ›
    PQC Assistant deep-link grammar refreshed
  • ›
    Track and persona filters on the Learn page now work from URL
  • ›
    Workspace persistence — visited routes and advanced-views unlock
  • ›
    Persona voice refresh
Bug Fixes2
  • ›
    VPN Simulator — full IKE_SA reaches ESTABLISHED in the browser
  • ›
    Service worker WASM cache staleness
Other1
  • ›
    VPN Simulator — ML-DSA cert-auth wiring (partial)

April 25, 2026

v3.5.12–v3.5.18

Updated GitHub organisation links throughout the app and swapped a brand icon that was removed in lucide-react v1. · Added 47 Common Evaluation Methodology requirements to the maturity governance corpus. · Resolved three soft-duplicate library entries with coordinated cite rewriting across library and compliance data. · Fixed a regression introduced in v3.5.14: the library dedup script was overwriting `reference_id` values, orphaning 20+ external citations. · Library catalog deduplicated: 543 → 531 rows. · Added a freshness check on the CSWP.39 source data, expanded the maturity governance corpus with CC 2022 and NERC CIP rows, and raised the offline cache size limit so the full bundle precaches. · Across-the-board mobile responsive fixes for PKI Learning, Patents, Playground, and embed views; iOS/Android safe-area insets; deep-link to specific changelog versions; and new data files for SLH-DSA Q&A and the governance corpus.

New Features9
  • ›
    Common Evaluation Methodology requirements
  • ›
    CSWP.39 source freshness check
  • ›
    Maturity governance corpus refresh
  • ›
    "Best on desktop" badge on Landing journey steps
  • ›
    Changelog deep links
  • ›
    Search corpus enriched with cross-reference fields
  • ›
    35 new golden queries
  • ›
    New data files
  • ›
    iOS/Android native platform detection
Improvements4
  • ›
    Search corpus and embed SDK refreshed
  • ›
    Library deduplication — Phase 2
  • ›
    Library deduplicated — 543 → 531 rows
  • ›
    Library archive
Bug Fixes9
  • ›
    GitHub organisation links updated
  • ›
    Icon compatibility
  • ›
    Library dedup — reference_id corruption fix
  • ›
    Offline cache size raised from 15 MB to 20 MB
  • ›
    Mobile responsive layouts across the app
  • ›
    Patents page mobile layout
  • ›
    iOS/Android safe-area insets
  • ›
    Narrow-viewport embed grids
  • ›
    Compliance frameworks enrichment refreshed

April 24, 2026

v3.5.8–v3.5.11

Removed unused Knowledge Graph module files left over from the v3.5.10 cleanup. · Removed the Knowledge Graph tab from the right-side panel. Existing user state is migrated automatically. · New Patents landscape explorer with 202 PQC-relevant patents. New CSWP.39 Maturity Evidence Grid on the Compliance page. Refreshed library and compliance data, plus a new compliance and standards-bodies enrichment pipeline. · Command Center reorganised around the NIST CSWP.39 5-step process (Govern → Inventory → Identify Gaps → Prioritise → Implement) with maturity tier badges. Closes coverage of every CSWP.39 (December 2025) requirement bullet — 26 of 26 — through reuse of existing site resources and extensions to existing planning tools, with no new tools added.

New Features10
  • ›
    New Patents page — PQC patent landscape explorer
  • ›
    CSWP.39 Maturity Evidence Grid on Compliance
  • ›
    3D infrastructure SVG generator
  • ›
    Compliance and standards-bodies enrichment pipeline
  • ›
    Library and compliance data refresh (April 23–24)
  • ›
    Search corpus and embed SDK refreshed
  • ›
    CSWP.39 5-step Command Center
  • ›
    CSWP.39 educational coverage — 26 of 26 requirement bullets
  • ›
    Existing builders extended with CSWP.39 sections
  • ›
    Cross-surface CSWP.39 continuity
Improvements4
  • ›
    Knowledge Graph orphan files removed
  • ›
    Knowledge Graph right-panel tab removed
  • ›
    Tier 4 maturity gating
  • ›
    Compliance and Command Center share the same step card
Bug Fixes1
  • ›
    Lint cleanup across new modules

April 23, 2026

v3.5.4–v3.5.7

New CSWP.39 Framework tab on the Compliance page lets users explore the NIST CSWP.39 (December 2025) Crypto Agility Strategic Plan in-place — overview, interactive process diagram, 5-step process cards, 4-tier maturity model, and a framework cross-walk to compliance frameworks already catalogued elsewhere on the page. · Realigned the Crypto Management Modernization module's maturity scale to NIST CSWP.39's 4-tier model and added a cross-walk between four industry frameworks. · Three CI fixes — type union completeness, exhaustive record coverage, and test expectations updated for revised HSM ops/sec defaults. · Fixed a Hybrid Signature workshop crash, corrected HSM ops/sec defaults to better match published vendor data, and routed ML-DSA hybrid signatures through the in-browser HSM where the standard mode applies.

New Features4
  • ›
    CSWP.39 Framework tab on Compliance
  • ›
    PQC maturity model cross-walk
  • ›
    Meta Engineering further reading
  • ›
    Library enrichment for the Meta PQC migration paper
Improvements2
  • ›
    Maturity scale realigned to NIST CSWP.39's 4 tiers
  • ›
    Hybrid Signatures — ML-DSA backend split by construction
Bug Fixes5
  • ›
    Quiz category type union completeness
  • ›
    Quiz category metadata exhaustiveness
  • ›
    HSM Capacity Calculator test expectations
  • ›
    Hybrid Signature workshop crash
  • ›
    HSM ops/sec defaults corrected

April 22, 2026

v3.4.0–v3.5.3

Three new workshop steps in the Crypto Management Modernization module that close the gap on CSWP.39 Identify Gaps → Prioritise → Implement, and a CSWP.39 process badge on every workshop step. · Realigned the Crypto Management Modernization module to NIST CSWP.39 (December 2025), framing it explicitly as the operational execution layer of the Crypto Agility Strategic Plan. · New Threshold Signing step in the Stateful Signatures workshop — educational simulation of the Haystack/coalition threshold construction for hash-based signatures, with configurable t-of-n thresholds. · Major release: a new Hybrid Signature Spectrums workshop demonstrating three hybrid signature constructions (concatenation, nesting, and Silithium fused Fiat-Shamir); SP 800-90B Entropy Source Validation status now tracked on libraries and HSMs; six new posture KPIs; and a complete cross-check remediation of the Crypto Management Modernization module to v1.1.0 with five corrected CMVP cert numbers and two new content sections. · Major release: SP 800-227 hybrid KEM coverage expanded from name-drop to spec-faithful teaching across the Hybrid Crypto module; new Cryptographic Management Modernization learn module (LM-052) — a 55-minute, 5-step executive-track module covering posture management; first WASM charon validation exports proving the ML-DSA + ML-KEM source patches are live; VPN Simulator gap-closure phase 1 (algorithm benchmark matrix, config-bundle export, IndexedDB session history, sandbox launch contract); and a major library refresh adding 26 authoritative references plus 13 newly tagged rows.

New Features22
  • ›
    Three new workshop steps in Crypto Management Modernization
  • ›
    CSWP.39 process badge on every workshop step
  • ›
    CSWP.39 process diagram on the Visual tab
  • ›
    Three new Learn tab sections
  • ›
    Maturity Self-Assessment CSWP.39 callout
  • ›
    Scenario 9 — "Crypto gateway or full migration"
  • ›
    Threshold Signing — Step 5 in Stateful Signatures workshop
  • ›
    Hybrid Signature Spectrums workshop
  • ›
    Entropy Source Validation status on libraries and HSMs
  • ›
    Six new posture KPIs
  • ›
    Crypto Management Modernization Q&A coverage
  • ›
    New learn module: Cryptographic Management Modernization
  • ›
    WASM charon validation exports (Phase 3a)
  • ›
    VPN Simulator gap-closure (phase 1 of 6)
  • ›
    SP 800-227 coverage expanded — Hybrid Crypto module
  • ›
    Google Quantum AI whitepaper added to library
  • ›
    secp256k1 added to Quantum Threats workshop
  • ›
    ECC qubit estimates revised
  • ›
    Fast-clock vs slow-clock CRQC distinction
  • ›
    Guided exercise — "ECC Blockchain Under Quantum Attack"
  • ›
    Calculator math disclosures
  • ›
    Library refresh — 26 new authoritative references plus 13 newly tagged rows
Improvements12
  • ›
    Crypto Management Modernization → v1.1.0 — cross-check remediation
  • ›
    HSM Capacity Calculator — multi-location support
  • ›
    Cert Capacity Calculator — bandwidth model corrected
  • ›
    Cert Capacity defaults — AVX2 cycle-accurate benchmarks
  • ›
    Certificate Lifecycle tools moved to PKI Workshop
  • ›
    VPN Simulator marked work-in-progress
  • ›
    VPN Simulator — ML-DSA private keys discoverable by PKCS#11 plugin
  • ›
    VPN Simulator — IPsec config hardened for tunnel mode
  • ›
    VPN Simulator — cert auth uses leftcert= for all algorithm types
  • ›
    Hybrid Crypto module — Composite Signatures section removed
  • ›
    Role guide — self-assessment checklist removed
  • ›
    Library CSV refresh
Bug Fixes8
  • ›
    Quiz answer buttons no longer truncate long options
  • ›
    HSM key inspection was silently broken for VPN simulation keys
  • ›
    Charon diagnostic lines no longer misclassified as errors
  • ›
    Hybrid Cert Inspector panel no longer overflows on narrow screens
  • ›
    ML-KEM-512 corrected to NIST Level 1
  • ›
    VPN sim RSA certs now carry SubjectKeyIdentifier extension
  • ›
    VPN sim ML-DSA cert auth fully wired end-to-end
  • ›
    Mobile / iOS Safari polish

April 20, 2026

v3.3.9

Major release. Highlights: a critical Learn page crash fixed for all visitors; an experimental WASM strongSwan v2 build with in-browser ML-DSA + ML-KEM selftest and cross-Worker handshake; a new HSM Capacity Calculator covering the top 10 enterprise HSM workflows; a Command Center overhaul including in-drawer artifact creation and a redesigned ROI Calculator; a complete compliance ↔ timeline consistency pipeline; a 5G SUCI playground UX overhaul with plain-English mode; the Right Panel migrated from a bottom drawer to a right sidebar; comprehensive PKI / TPM / TLS workshop additions; updated NIST CMVP scraper covering all security levels; and Implementation Attacks + KAT Validation tabs in the Detailed Comparison view.

New Features32
  • ›
    Experimental WASM strongSwan v2 — selftest + cross-Worker KEM handshake
  • ›
    HSM Capacity Calculator
  • ›
    PKI Workshop — Certificate Capacity Calculator overhaul
  • ›
    Command Center — in-drawer artifact creation with builder adapters
  • ›
    Deployment Playbook → Command Center save
  • ›
    Compliance Table — mandate deadline labels
  • ›
    FilterDropdown keyboard navigation
  • ›
    Manufacturing industry support in assessment
  • ›
    Compliance ↔ Timeline consistency pipeline
  • ›
    Compliance data — accuracy and completeness overhaul
  • ›
    Command Center — ROI Calculator overhaul
  • ›
    Command Center — KPI plan completion (E4 / D9 / E2 / E1)
  • ›
    VPN Simulator — ML-DSA authentication via draft standards
  • ›
    5G SUCI Playground — UX overhaul
  • ›
    Step Wizard — phase progress and plain-English rail
  • ›
    PKCS#11 Log Panel — Beginner Mode
  • ›
    PKCS#11 log panel — "Crypto Only" filter
  • ›
    Browser compatibility notice on VPN and SSH simulators
  • ›
    Secure Boot PQC — TPM 2.0 sandbox deep-link
  • ›
    Docker Playground — pqctoday-sandbox iframe embed
  • ›
    Glossary — TPM 2.0 / TCG V1.85 terms
  • ›
    PKCS#11 glossary terms
  • ›
    Library v04172026 entries
  • ›
    Implementation Attacks tab in Detailed Comparison
  • ›
    KAT Validation tab in Detailed Comparison
  • ›
    FN-DSA / Falcon attack profile
  • ›
    LMS / XMSS stateful signature attack profile
  • ›
    BIKE-1/3/5 added to algorithm reference
  • ›
    Cryptographic hardness assumptions in Security Levels view
  • ›
    "Why KATs Matter" explainer
  • ›
    "Quick Reference" panel in About modal
  • ›
    Curious persona — single-click experience shortcut
Improvements24
  • ›
    Right Panel layout — bottom drawer → right sidebar
  • ›
    strongSwan WASM rebuilt
  • ›
    strongSwan WASM — 44% size reduction
  • ›
    VPN Simulator — true MTU and fragmentation config logic
  • ›
    VPN Simulator — FlaskConical icon for ML-DSA draft warning
  • ›
    Module store — persisted version 12 migration
  • ›
    NIST CMVP scraper — all security levels
  • ›
    Compliance data re-scraped
  • ›
    Library v04152026
  • ›
    Product catalog v04162026
  • ›
    Vendors v04162026
  • ›
    Catalog enrichments
  • ›
    Library and timeline enrichments refreshed
  • ›
    SSH simulator — "Build in progress" notice removed
  • ›
    Playground Workshop — work-in-progress tools hidden by default
  • ›
    Performance baseline description fixed
  • ›
    Composite & Hybrid attack profile split into two tiles
  • ›
    NTRU+ attack reference clarified
  • ›
    Draft / Candidate badges added to Performance and Size views
  • ›
    Attack severity ratings replace uniform "Vulnerable" badges
  • ›
    Countermeasures section added to all attack profiles
  • ›
    SLH-DSA side-channel status corrected
  • ›
    Search corpus and embed manifest regenerated
  • ›
    OpenSSH WASM connector path
Bug Fixes8
  • ›
    Learn page crash on first visit
  • ›
    Compliance facets (Org / Industry / Region) derived from full dataset
  • ›
    VPN Simulator — daemon-default cert algorithm switched to RSA
  • ›
    VPN Simulator — visual SKF payload fragmentation slicing
  • ›
    VPN Simulator — ML-DSA raw pubkey configuration respected
  • ›
    VPN Simulator — WASM OOM and thread-pool exhaustion
  • ›
    What's New modal — View Changelog deep link
  • ›
    Bouncy Castle FIPS 140-3 cert #4943 security level corrected

April 14, 2026

v3.3.6–v3.3.8

Six new reference library entries covering government guidance and emerging standards, plus six new algorithm entries for the draft SLH-DSA limited-signature parameter sets from NIST SP 800-230. FAQ copy updated to reflect current module count and corpus size. · Picking a row from the Transition Guide now adds both the classical algorithm and its PQC replacement to the comparison panel in one click — select three RSA rows to benchmark RSA-2048/3072/4096 alongside ML-KEM-512/768/1024 all at once. · The algorithm comparison table now labels each column so you can tell at a glance which algorithms are classical, which are PQC, and which is the reference baseline. HSM engine upgraded to softhsmv3 v0.4.23.

New Features10
  • ›
    NIST SP 800-230 (IPD) in the Reference Library
  • ›
    ANSSI PG-083 v3.00 in the Reference Library
  • ›
    Applied Quantum PQC Migration Framework v1.1 in the Reference Library
  • ›
    Charter of Trust "Decrypting the Future" in the Reference Library
  • ›
    Cambridge JBS / CCAF quantum blockchain article in the Reference Library
  • ›
    Australian ACSC Quantum Technology Primer (Communications) in the Reference Library
  • ›
    Six SLH-DSA limited-signature algorithm variants in the Algorithms reference
  • ›
    Entropy & Randomness FAQ entry
  • ›
    Compare classical and PQC together from the Transition Guide
  • ›
    Classical / PQC / baseline labels in the comparison panel
Improvements5
  • ›
    FAQ copy refreshed
  • ›
    RAG corpus grown to 6,507 chunks
  • ›
    Older library and algorithm CSVs archived
  • ›
    HSM engine updated to softhsmv3 v0.4.23
  • ›
    HSM engine v0.4.22 improvements (included)
Bug Fixes4
  • ›
    ECDH P-384 benchmark now produces results
  • ›
    Comparison panel shows only what you selected
  • ›
    Certificate and compliance detail pop-ups now open centered on screen
  • ›
    Timeline pop-ups no longer get cut off on mobile

April 13, 2026

v3.3.3–v3.3.5

The algorithm benchmark now covers the full PQC and classical portfolio — SLH-DSA, RSA, ECDSA, Ed25519, ECDH, X25519, X448, LMS, and XMSS all run through the in-browser HSM engine alongside ML-KEM and ML-DSA. X448 was not benchmarkable at all before this release. · AI-powered analysis now covers all 535 products in the Migration catalog. Each product entry surfaces 19 dimensions of PQC readiness — algorithms in use, hybrid approaches, migration timeline, compliance alignment, and more. · Mobile fixes and algorithm comparison improvements.

Improvements2
  • ›
    Benchmark engine extended to the full algorithm portfolio
  • ›
    "Enriched" badge now reflects current AI analysis
Bug Fixes10
  • ›
    Timeline event pop-ups now have a proper backdrop
  • ›
    Migration Planner stack view
  • ›
    Stack view dark-mode contrast
  • ›
    Stack view active layer visibility in dark mode
  • ›
    Stack minimap dots
  • ›
    Stack minimap hidden in embedded widgets
  • ›
    Persona avatar displayed correctly on mobile
  • ›
    "What's New" panel centers correctly on iOS and Android
  • ›
    Update notifications no longer clip on narrow screens
  • ›
    Composite and Hybrid algorithm types now show the compare button
Data Updates7
  • ›
    19 additional migration catalog products enriched with AI analysis.
  • ›
    New products added: IBM z16 Crypto Express 8S HSM, AWS Certificate Manager.
  • ›
    7 new threats added: Grover attacks on AES-128, quantum halving of SHA-256 collision resistance, PRNG quantum entropy risks, PQC timing/power side-channel attacks, lattice cryptanalysis advances, fault injection on PQC key generation, and resource-constrained PQC deployment.
  • ›
    2 new timeline entries: Brazil's ITI federal mandate for ML-DSA and ML-KEM, ITU-T X.1811.
  • ›
    New library entry: Google/QuantumAI paper on securing elliptic curve cryptography against quantum attacks.
  • ›
    535 migration catalog products enriched
  • ›
    Library (315 entries), timeline (213 entries), and threat (80 entries) enrichments all refreshed to the current 19-dimension analysis schema.

April 12, 2026

v3.2.0–v3.3.2

Every operation in the HSM Playground now shows the exact bytes sent to and received from the HSM — see precisely what the PKCS#11 standard is doing at every step. · 22 additional ACVP test vectors now pass. · Role-specific exercise guides, an entropy workshop, and new dedicated panels in the HSM Playground. · OpenSSL engine upgraded to v3.6.2. · Mobile app foundation — the codebase now supports a future native iOS/Android build with zero impact on the web app. Changelog entries rewritten in plain language across all recent releases.

New Features8
  • ›
    Full parameter inspection across all HSM panels
  • ›
    Role-specific exercise guides
  • ›
    Entropy workshop
  • ›
    Dedicated ML-KEM panel in the HSM Playground
  • ›
    Stateful signature panel in the HSM Playground
  • ›
    Operation history
  • ›
    Native mobile app platform support
  • ›
    Unified platform detection
Improvements7
  • ›
    All HSM panels upgraded to the full inspectable log
  • ›
    In-browser HSM engine updated to softhsmv3 v0.4.21
  • ›
    In-browser OpenSSL engine updated to v3.6.2
  • ›
    Embedded widget SDK
  • ›
    Changelog dates are now human-readable
  • ›
    Changelog descriptions rewritten for plain language
  • ›
    App startup sequence
Bug Fixes5
  • ›
    Sign and Verify operations now show the actual data
  • ›
    Key Unwrap operations now decode correctly
  • ›
    Inspect toggle clearly shows when it is active
  • ›
    Embed error page
  • ›
    Auto-reload disabled in native WebView
Data Updates2
  • ›
    Library and catalog data refreshed; knowledge base regenerated.
  • ›
    Knowledge base refreshed: 5,881 indexed chunks.

April 11, 2026

v3.1.0–v3.1.4

Polish pass for embedded widgets and the learning module navigator — modals, tables, and step indicators now display correctly at all screen widths. · Bug fix for embedded widget brand theming, plus vendor certificate infrastructure cleanup. · Embed SDK: partner portals can now display custom logos, brand names, and navigation colors. · Fixed Migration Planner interactivity and improved embedded widget behavior across 18 components. · Visual consistency pass — gradient buttons and the shared Button component are now applied uniformly across every page.

New Features1
  • ›
    Custom logos and brand names in embedded widgets
Improvements4
  • ›
    Vendor certificate registry simplified
  • ›
    Trust anchor certificates can be committed to version control
  • ›
    Consistent gradient button style across the entire app
  • ›
    Unified interactive button component throughout the codebase
Bug Fixes14
  • ›
    Pop-ups and overlays display correctly in embedded widgets
  • ›
    Tables and charts fit properly at narrow widths
  • ›
    More content visible on medium-size screens and in embedded views
  • ›
    Content fills the full width inside embedded portals
  • ›
    Learning module step indicators are more compact
  • ›
    Improved text legibility when switching between light and dark themes
  • ›
    Detail pop-ups no longer appear above unrelated content
  • ›
    Feedback and tooltip overlays stay within embedded widget boundaries
  • ›
    Custom brand colors in embedded widgets now load correctly
  • ›
    Migration Planner layer categories are now fully interactive
  • ›
    Migration Planner filter bar stays visible while scrolling through layers
  • ›
    Drawers, alerts, and navigation panels stay within embedded widget boundaries
  • ›
    Embedded widget height adjusts correctly for host pages
  • ›
    Vendor token is preserved when navigating within embedded widgets
Security1
  • ›
    No private key material is stored in the repository

April 10, 2026

v2.98.0–v3.0.0
New Features17
  • ›
    Embed SDK — left sidebar nav layout (navLayout: 'sidebar')
  • ›
    Embed SDK — VendorTheme v2 status/link color overrides
  • ›
    Embed SDK — cert color mode default (colorMode)
  • ›
    pqc-admin CertIssueWizard — Nav Layout control
  • ›
    test-vendor-custom-design cert updated
  • ›
    Embed SDK — VendorTheme full component theming
  • ›
    Embed SDK — nav bar color (sidebar/sidebarForeground)
  • ›
    Embed SDK — solid status badges (badgeFill: 'solid')
  • ›
    Embed SDK — INDUSTRY_SLUG_TO_LABEL mapping
  • ›
    test-vendor-custom-design cert preset
  • ›
    Embed SDK — granular route presets
  • ›
    Embed SDK — Algorithms and Threats nav items
  • ›
    Embed SDK — assistant URL param
  • ›
    Embed SDK — About page always accessible
  • ›
    Embed SDK — Right Panel scoped to iframe
  • ›
    Embed SDK — query-string passthrough on nav
  • ›
    CuriousSummaryBanner layout
Bug Fixes11
  • ›
    Embed mode — Compliance tables empty
  • ›
    Embed mode — Assessment industry not pre-populated
  • ›
    Embed mode — region validation
  • ›
    Embed mode — URL param bypass
  • ›
    Semantic token consistency
  • ›
    Embed modal positioning
  • ›
    Bookmark links in embed mode
  • ›
    Theme not applied in embed mode
  • ›
    Embed vendor cert import path
  • ›
    Assistant button styling
  • ›
    Back-to-modules button hidden in embed

April 9, 2026

v2.96.0–v2.97.0
New Features11
  • ›
    Embed SDK — policy enforcement
  • ›
    Embed SDK — VendorPolicy X.509 format
  • ›
    Embed SDK — module/tool path validation
  • ›
    GA4 analytics — embed mode coverage
  • ›
    GA4 analytics — assessment wizard
  • ›
    GA4 analytics — persona/personalization
  • ›
    GA4 analytics — module tab switches
  • ›
    Embed SDK — vendor iframe integration
  • ›
    Embed SDK — persistence and auth
  • ›
    Embed SDK — PQCEmbed JS client
  • ›
    Service worker — embed COOP header
Bug Fixes11
  • ›
    EmbedVerificationError TypeScript compile error
  • ›
    crypto.subtle.verify() type error
  • ›
    Pre-existing analytics test failures
  • ›
    consoleLogSpy unused variable lint error
  • ›
    Safari blank page
  • ›
    Safari EmbedState binding error
  • ›
    Nested <button> in MobileThreatsList
  • ›
    Leader avatars — CORP violation
  • ›
    CSP — flagcdn.com and frame-ancestors
  • ›
    Analytics noise
  • ›
    sdk.ts memory leak

April 8, 2026

v2.94.1–v2.95.0
New Features8
  • ›
    EUDI Wallet — pluggable CryptoProvider architecture
  • ›
    EUDI Wallet — X.509 certificate generation
  • ›
    EUDI Wallet — native CBOR encoding
  • ›
    Entropy — HMAC_DRBG Architecture Demo
  • ›
    Entropy — danger-zone gauge arc
  • ›
    Entropy — QRNG "Simulated" badge
  • ›
    Deep linking — ?flow= URL parameter
  • ›
    Digital ID E2E test
Improvements5
  • ›
    Playground workshop registry
  • ›
    PKCS#11 Log Panel
  • ›
    Workshop HSM key tracking
  • ›
    EdDSA PKCS#11 bindings
  • ›
    PKCS#11 Walkthrough removed from Playground
Bug Fixes3
  • ›
    useModuleDeepLink test suite
  • ›
    Rust WASM binary updated to v0.4.17
  • ›
    About page SBOM — softhsmv3 link and version updated to v0.4.16
Data Updates1
  • ›
    RAG corpus regenerated
Other2
  • ›
    SBOM: @pqctoday/softhsm-wasm updated to v0.4.17
  • ›
    SBOM: @pqctoday/softhsm-wasm updated to v0.4.16

April 7, 2026

v2.83.0–v2.94.0
New Features43
  • ›
    New SLH-DSA learning module
  • ›
    SLH-DSA Playground — context string support (FIPS 205 §9.2)
  • ›
    SLH-DSA Playground — deterministic mode toggle (FIPS 205 §10)
  • ›
    SLH-DSA Playground — FIPS 205 §6 internal parameter table
  • ›
    SLH-DSA — FIPS 205 §11 compliance labels on pre-hash options
  • ›
    KMS Envelope Encryption — three new KAT specs
  • ›
    KMS Envelope Encryption — envelope blob hex viewer
  • ›
    PKCS#11 v3.2 hedge variant constants
  • ›
    SLH-DSA Playground — SHA-2 vs SHA-3 hardware hint
  • ›
    PKI Workshop now in the Playground
  • ›
    Bitcoin Flow — quantum threat warning on public key export
  • ›
    Bitcoin Flow — clearer address and transaction explanations
  • ›
    HD Wallet Flow — expanded to 5 steps with live derivation tree
  • ›
    HD Wallet Flow — hardened vs non-hardened live demo (Step 3)
  • ›
    Solana Flow — explains how real wallet apps derive keys
  • ›
    Solana Flow — Ed25519 public key format explained
  • ›
    CRL Generator — revocation reasons and human-readable output
  • ›
    PKI Workshop — NIST security level shown next to algorithm picker
  • ›
    PKI Workshop — ML-DSA and SLH-DSA labels updated to final standard names
  • ›
    Cert Parser — fingerprint, CSR verify, and CRL verify
  • ›
    Hybrid Cert Formats — generated PEMs flow into Cert Parser and OpenSSL Studio
  • ›
    New in-app glossary tooltips for Solana transaction concepts
  • ›
    Blockchain Playground tools marked production-ready
  • ›
    MTC Workshop — shared tree state across Steps 1→2→3
  • ›
    MTC Workshop — Landmark MTC column in Step 4 size comparison
  • ›
    MTC Workshop — Step 4→5 bridge text
  • ›
    MTC Workshop — production-use context in ProofVerifier
  • ›
    MTC Workshop — padding divergence disclosure
  • ›
    MTC — Landmark MTC functions in mtcConstants.ts
  • ›
    Playground — 5G SUCI deep-link profile/pqcMode support
  • ›
    5G SUCI — deep-link URL encodes profile and pqcMode
  • ›
    5G SUCI — Profile B (P-256) dedicated step content
  • ›
    5G SUCI — Profile B compressed key encoding
  • ›
    5G SUCI — educational content: compressed vs uncompressed EC point encoding
  • ›
    5G SUCI — PKCS#11 mechanism accuracy
  • ›
    5G SUCI — Profile C visualization corrected
  • ›
    Library — 3 new records with proper titles and download links
  • ›
    5G SUCI — removed WIP badge
  • ›
    VPN Simulation — SKEYSEED key derivation step
  • ›
    VPN Simulation — IKE exchange phase labels on logs
  • ›
    VPN Simulation — payload size note
  • ›
    VPN Simulation — QKD toggle clarified
  • ›
    VPN Simulation — full IKEv2 + ML-KEM-768 handshake working end-to-end
Bug Fixes42
  • ›
    KMS Envelope Encryption — HKDF salt now follows SP 800-56C Rev 2 §4.1
  • ›
    SLH-DSA Workshop — C_GetAttributeValue removed from live PKCS#11 log
  • ›
    SLH-DSA Stateful Signatures Workshop — prehash options unified with Playground
  • ›
    Playground — default engine in URL state changed from cpp to rust
  • ›
    VPN Simulation and Token Setup panels migrated to Rust WASM module
  • ›
    HsmSetupPanel label corrected
  • ›
    PKCS#11 log panel — step header now appears above its commands
  • ›
    Step results accumulate newest-first
  • ›
    TLS comparison table — ML-DSA-65 signature size corrected
  • ›
    TLS Introduction — SLH-DSA-SHA2-128s signature size now shows exact byte count
  • ›
    TLS Handshake Diagram — removed misplaced encryption boundary marker
  • ›
    Internal: PKCS#11 CKA_PUBLIC_KEY_INFO constant corrected
  • ›
    MTC Workshop — KAT signing spec corrected
  • ›
    MTC Workshop — ECDSA standalone savings corrected
  • ›
    MTC Workshop — SCT count and traditional total corrected
  • ›
    MTC Workshop — ML-DSA-44 savings corrected to 60%
  • ›
    MTC Workshop — PROOF_VERIFIER_CERTS stabilised with useMemo
  • ›
    MTC Workshop — "Step 1 — Generate CA Key" label conflict
  • ›
    MTC Workshop — CA key label now includes size
  • ›
    MTC Workshop — Step 1 stats bar clarified
  • ›
    MTC Workshop — draft status disclosed
  • ›
    Playground — 5G SUCI Profile C hybrid mode URL sync
  • ›
    Playground — fixed race condition on Profile C switch
  • ›
    Playground — SuciFlow pqcMode state sync
  • ›
    Playground — SuciFlowRoute extracted to dedicated file
  • ›
    Playground — 5G SUCI URL stays in sync when switching profiles/modes
  • ›
    Playground — suci-flow deep-link actually works now
  • ›
    5G SUCI — deep-link URL now actually updates in the browser
  • ›
    5G SUCI — Profile C pure PQC no longer shows hybrid code snippets
  • ›
    VPN Simulation — C_CloseSession and C_Verify now emit RPC log entries
  • ›
    VPN Simulation — PKCS#11 log panel no longer shows bookkeeping operations
  • ›
    5G SUCI — profile transitions always reset to step 1
  • ›
    5G SUCI — profile state set before every step executes
  • ›
    5G SUCI — B→C transition no longer double-cleans
  • ›
    5G SUCI — HSM and OpenSSL cross-check now agree on key derivation
  • ›
    HSM — AES-GCM per-message encrypt/decrypt enabled on Rust engine
  • ›
    5G SUCI — dual-engine comparison uses real HSM output
  • ›
    5G SUCI Profile C — KEM ciphertext carried forward correctly
  • ›
    Stateful Signatures — default message aligned across panels
  • ›
    VPN Simulation — engine stability
  • ›
    HSM — encapsulation bug fixed in softhsmv3
  • ›
    HSM — 8 additional Rust engine functions now active
Data Updates3
  • ›
    RAG corpus regenerated
  • ›
    Compliance — ANSSI catalog re-scraped
  • ›
    RAG corpus updated
Other3
  • ›
    softhsmv3 Rust WASM
  • ›
    index.d.ts trailing-comma cleanup
  • ›
    SLH-DSA workshop link updated in Playground registry

April 6, 2026

v2.81.0–v2.82.0
New Features5
  • ›
    5G SUCI — 3GPP TS 33.501 reference vectors modal
  • ›
    Profile C hybrid mode — full TR 33.841 §5.2.5.2 implementation
  • ›
    Stateful Signatures — cross-engine sign and verify
  • ›
    VPN Simulation — RSA-3072 certificate generation and inspection
  • ›
    Download hybrid certificates
Improvements10
  • ›
    5G SUCI — spec-correct ANSI X9.63-KDF replaces HKDF
  • ›
    5G SUCI — AES-128-CTR with zero IV (was AES-GCM)
  • ›
    5G SUCI — authenticate-then-decrypt at SIDF
  • ›
    HSM slot initialization — reuses existing slot on conflict
  • ›
    softhsmv3 WASM updated
  • ›
    5G SUCI flow matches the real spec
  • ›
    Envelope Encryption — accurate sizes and wrap overhead
  • ›
    Bitcoin Playground — pure HSM path
  • ›
    Firmware Signing wizard
  • ›
    Key Derivation panel labels
Bug Fixes1
  • ›
    VPN Simulation works on the live site
Data Updates1
  • ›
    RAG corpus regenerated

April 5, 2026

v2.77.0–v2.80.0
New Features10
  • ›
    Algorithm region and status filters
  • ›
    Algorithm implementations
  • ›
    Work-in-progress badges on Playground tools
  • ›
    Migrate WIP filter
  • ›
    XMSS deterministic keygen test
  • ›
    VPN simulation — all crypto through the in-browser HSM
  • ›
    Complete LMS/LMOTS parameter support
  • ›
    VPN Simulation with ML-KEM-768
  • ›
    Configurable VPN pre-shared key
  • ›
    Stateful Hash-Based Signatures Workshop
Improvements3
  • ›
    VPN Simulation — isolated HSM slot management
  • ›
    Hybrid Encryption Demo
  • ›
    SLH-DSA sign panel
Bug Fixes3
  • ›
    Stateful Signatures workshop — key generation no longer crashes
  • ›
    LMOTS W4 signature size lookups corrected
  • ›
    VPN simulation no longer crashes on start
Data Updates6
  • ›
    New algorithm reference data with Region and Status fields.
  • ›
    New algorithm implementations cross-reference.
  • ›
    RAG corpus regenerated.
  • ›
    RAG corpus regenerated.
  • ›
    strongSwan product entry updated
  • ›
    RAG corpus regenerated
Other1
  • ›
    Standalone SLH-DSA demo

April 2, 2026

v2.75.0–v2.76.0
New Features12
  • ›
    Collapsible Analysis section in the Gantt chart modal
  • ›
    ACVP tests 23 & 24 — X25519/X448 ECDH round-trip
  • ›
    ACVP test 25 — X9.63 KDF with SHA3-256 / SHA3-512 (PKCS#11 v3.2 §5.2.12)
  • ›
    hsm_pqcEncap / hsm_pqcDecap wrappers (PKCS#11 v3.2 §6.3)
  • ›
    hsm_generateX25519KeyPair
  • ›
    hsm_importECPrivateKey
  • ›
    DerivedKeyProfile interface + buildDerivedKeyTemplate
  • ›
    ML-KEM keygen and import: optional CKA_LABEL support
  • ›
    GSMA TS 33.501 Annex C.4 Profile B KAT
  • ›
    5G SUCI dual-engine output viewer
  • ›
    Threats dashboard multi-view mode
  • ›
    Leaders sector stack view
Improvements9
  • ›
    Unified bookmark icon across all pages
  • ›
    Migrate catalog table cleanup
  • ›
    My filter connected to bookmark store (Migrate)
  • ›
    Stack view collapses empty layers when My filter is active
  • ›
    BookmarksPanel uses unified product store
  • ›
    Export CSV button icon-only
  • ›
    softhsm-wasm C++ engine rebuilt (0.4.3)
  • ›
    softhsm-wasm Rust engine rebuilt (0.4.3)
  • ›
    HsmKeyInspector display names updated
Bug Fixes1
  • ›
    CKK_EC_MONTGOMERY value corrected to 0x41
Data Updates2
  • ›
    Product catalog updated
  • ›
    Library updated

April 1, 2026

v2.69.0–v2.74.0
New Features19
  • ›
    CISA Stack view for the Migrate catalog
  • ›
    PQC readiness progress bars in Infrastructure Stack
  • ›
    License type filter in Migrate catalog
  • ›
    Quantum technology badges
  • ›
    Share links for library documents
  • ›
    Share links for migrate products
  • ›
    Share country timeline links
  • ›
    Share buttons in all HSM Playground panels
  • ›
    SLH-DSA context string support (FIPS 205 §9.2)
  • ›
    SLH-DSA deterministic signing (FIPS 205 §10)
  • ›
    ACVP tests 21 & 22 — SLH-DSA context binding and deterministic mode
  • ›
    Copy button on ACVP execution log
  • ›
    Proof details popup
  • ›
    Expanded validation status badges
  • ›
    Visual infographics for all 49 learning modules
  • ›
    "Next Stack" navigation in Curious mode
  • ›
    Source verification data in product catalog
  • ›
    Validation badges in product expanded view
  • ›
    AI assistant aware of validation results
Improvements5
  • ›
    Compliance Module Refactoring
  • ›
    Global Filter Consolidation
  • ›
    Resilient UI Testing
  • ›
    CISA category field added to all products
  • ›
    Enrichment merge improved
Bug Fixes2
  • ›
    SLH-DSA multi-message signing correctness
  • ›
    Chatbot blank screen after API key error
Data Updates4
  • ›
    Timeline data updated to April 2026
  • ›
    Product catalog updated
  • ›
    Product catalog expanded to 622 entries
  • ›
    All 521 catalog entries now have validation results

March 31, 2026

v2.67.0–v2.68.0
New Features7
  • ›
    Certificate Transparency Log Simulator
  • ›
    TLS 1.3 Simulator
  • ›
    Algorithm comparison sub-tab deep links
  • ›
    Compliance migrate-category filter
  • ›
    Library taxonomy refresh
  • ›
    Migration catalog "Work in Progress" notice
  • ›
    HSM key inspection improvements
Improvements4
  • ›
    Improved AI assistant navigation links
  • ›
    Firmware Signing Migrator rewritten
  • ›
    Envelope Encryption Demo expanded
  • ›
    PKCS#11 call log — expandable entries
Bug Fixes2
  • ›
    HSM attribute read errors resolved
  • ›
    Duplicate "Code Signing" tool removed from Playground
Data Updates3
  • ›
    New document enrichments
  • ›
    Data quality improvements across multiple datasets
  • ›
    Data integrity

March 30, 2026

v2.66.0
New Features3
  • ›
    Evidence warnings on products
  • ›
    Verification status filter
  • ›
    Evidence flags affect trust score
Bug Fixes6
  • ›
    21 products corrected to Unknown
  • ›
    4 products upgraded
  • ›
    Node.js corrected
  • ›
    Cisco IOS XE corrected
  • ›
    Algorithm names standardized
  • ›
    FIPS scope clarifications
Data Updates2
  • ›
    415 products in catalog
  • ›
    72 products independently verified

March 29, 2026

v2.63.0–v2.65.3
New Features18
  • ›
    Envelope encryption via HKDF
  • ›
    SLH-DSA pre-hash mismatch warning
  • ›
    PKCS#11 mechanism flag reference
  • ›
    KDF tool scenarios expanded
  • ›
    Trust score badges
  • ›
    9 new achievements
  • ›
    Curious learning path expanded
  • ›
    Google Drive CSRF protection
  • ›
    Business Center export improvements
  • ›
    Audit Checklist expanded
  • ›
    Deployment Playbook new sections
  • ›
    RACI Builder multi-accountable warning
  • ›
    Business Center keyboard navigation
  • ›
    Persona-aware Business Center
  • ›
    Real X.509 certificates in Hybrid Cryptography module
  • ›
    Alt-Sig / Catalyst as a distinct certificate format
  • ›
    SLH-DSA learn card
  • ›
    SLH-DSA IETF reference certificate
Bug Fixes13
  • ›
    Hybrid KEM + ECDH key derivation error
  • ›
    Google sign-in flow corrected
  • ›
    FrodoKEM benchmark crash
  • ›
    secp256k1 benchmark crash
  • ›
    Ed448 and X448 benchmarks removed
  • ›
    Diffie-Hellman benchmark crash
  • ›
    SoftHSM WASM import errors
  • ›
    ROI Calculator unrealistic defaults
  • ›
    CNSA 2.0 deadline labels corrected
  • ›
    Roadmap Builder export
  • ›
    RFC 9763 Related Certificates OID corrected
  • ›
    Alt-Sig factual error corrected
  • ›
    Certificate format count inconsistency

March 28, 2026

v2.58.0–v2.59.0
New Features5
  • ›
    Bookmarks
  • ›
    Product comparison panel
  • ›
    Breadcrumb navigation
  • ›
    Mobile Playground
  • ›
    Automated content integrity checks in CI
Improvements1
  • ›
    Page descriptions visible on more screen sizes
Bug Fixes1
  • ›
    Compliance framework website links corrected

March 27, 2026

v2.56.0–v2.57.0
New Features3
  • ›
    Migrate view URL sync
  • ›
    Google Drive cloud backup
  • ›
    Cloud sync privacy details on About page
Improvements2
  • ›
    Comprehensive mobile layout improvements (70+ components)
  • ›
    Navigation scrollbar restored

March 24, 2026

v2.50.0–v2.55.0
New Features9
  • ›
    Algorithm comparison — security level and key size badges
  • ›
    Mobile algorithm cards — function type and key size chips
  • ›
    OpenSSL Studio collapsible workbench
  • ›
    Curious Explorer persona content
  • ›
    Curious context banners
  • ›
    Key size display in Playground
  • ›
    Mobile compliance improvements
  • ›
    Mobile migration phase selector
  • ›
    Page header actions menu on mobile
Improvements4
  • ›
    Navigation header — text-only branding
  • ›
    Curious Explorer auto-completes onboarding
  • ›
    Playground simplified for Curious and Executive personas
  • ›
    Faster app updates
Bug Fixes3
  • ›
    App stayed on old version after deployment
  • ›
    HSM product PQC algorithm details corrected
  • ›
    Entrust nShield PQC support details corrected

March 23, 2026

v2.47.0–v2.49.0
New Features3
  • ›
    ACVP Testing expanded
  • ›
    Standard reference links in ACVP results
  • ›
    Crucible conformance harness added to PQC Testing module
Improvements2
  • ›
    Trail of Bits ml-dsa added to catalog
  • ›
    HSM vendor accuracy update
Bug Fixes1
  • ›
    HKDF mechanism constants corrected

March 22, 2026

v2.46.0
New Features9
  • ›
    Key Check Values (KCV) for all key types
  • ›
    ACVP multi-algorithm test suite
  • ›
    Visual tab for all 48 learning modules
  • ›
    WIP badge with community feedback
  • ›
    Enrichment previews in Timeline
  • ›
    PQC Testing & Validation learning module
  • ›
    "What's New" modal
  • ›
    Terms of Service page
  • ›
    Curious Explorer glossary
Improvements3
  • ›
    "In Simple Terms" summaries rewritten across all 48 modules
  • ›
    Module infographics standardized to 640×640
  • ›
    Tools & Products tab sources from live catalog
Bug Fixes2
  • ›
    Library "Relevant Features" links broken
  • ›
    Snapshot backup/restore data loss

March 13, 2026

v2.45.2
Improvements3
  • ›
    Library document popover — mobile sheet layout
  • ›
    Endorse and Flag buttons visible on mobile
  • ›
    Airplane Mode in mobile nav

March 14, 2026

v2.45.1
New Features1
  • ›
    Stateful Endorse/Flag with discussion links
Bug Fixes1
  • ›
    Flag button missing from several views

March 13, 2026

v2.45.0
New Features1
  • ›
    Flag issue button

Next step

Data corrections

Row-level corrections to the data live on the revisions page.