Shielded · 2026-07-23 · 32 min
Key moments - from our scoring
Substance score
50 / 100
Five dimensions, 20 points each
The European Digital Identity Wallet represents a major regulatory push from the European Commission to give citizens control over their personal data through selective disclosure - sharing only the minimum information needed for specific transactions rather than exposing full datasets during registration. Wei Yan explains how EUDI Wallet is built on traditional cryptography (ECDSA for signatures, ECDH for key exchange) despite the known threat from quantum computing, creating a critical problem: the architecture must support diverse hardware implementations (secure elements, TPMs, remote HSMs) across millions of devices, yet any cryptographic migration would be extremely costly or impossible to reverse at scale. The EUDI Wallet deployment mandate runs to 2026, while the broader European quantum-safe migration timeline targets 2032, creating compressed timelines for vendors. ENISA, the European cybersecurity authority, is coordinating certification schemes that member states must adopt, with APP Laboratories and other accredited labs responsible for validating that components meet security requirements. The conversation highlights how standardization bodies, certification labs, and member states must align requirements and timelines while vendors face dual-market pressure from differing U.S. and European quantum transition dates.
The EUDI Wallet is a regulated initiative allowing EU citizens to store and selectively disclose identity data without exposing unnecessary personal information to service providers. Rather than providing full datasets during every registration, users control which attributes (age, citizenship, location) are verified and shared, protecting privacy rights.
All EU member states are mandated by the European Commission to deploy EUDI Wallet solutions by 2026, meaning rollout is already underway rather than a future plan.
The EUDI Wallet architecture currently uses ECDSA for digital signatures and ECDH for key exchange - both vulnerable to quantum computing attacks. While quantum-safe migration is recognized as critical, current specifications are still built on traditional cryptography.
The reference architecture supports secure elements as the preferred option, but the solution is flexible enough to accommodate TPMs, remote HSMs, or other technologies, creating different security profiles and certification challenges.
Crypto agility is the ability to switch from one cryptographic algorithm to another without major architectural redesign. It is critical for EUDI Wallet because mass hardware recalls are cost-prohibitive, so the system must be designed to support future quantum-safe algorithm migration.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode covers several substantive topics (EUDI Wallet architecture, quantum-safe migration timelines, certification complexity, and crypto-agility) with some concrete details about the regulatory landscape and deployment challenges. However, large portions are spent on small talk (weather, Barcelona tourism, Sagrada Familia construction), throat-clearing explanations, and repetitive elaboration that could have been compressed. Genuine operational insights are present but diluted by meandering conversational filler.
Many transitions are coming. All of them are colliding at the same moment in time and this creates a lot of uncertainties.
the issue has never been on the design of these algorithms. They are good, they are good to solve this problem. However, the issue is always about implementation.
The conversation hits established frameworks - regulatory compliance, certification schemes, quantum-safe migration timelines - without offering particularly fresh angles or contrarian takes. Wei's advice to 'choose the strictest scheme' is sensible but not novel. The discussion of crypto-agility and implementation risk as the real problem is valid but has been articulated in the PQC community for years. The specific focus on EUDI Wallet's complexity is relevant but not reframed in an original way.
so the question is uh, what should I choose? And I would choose the one that will live longer within this timeline.
crypto agility. That of course has been overused and trampled to death by many marketing departments.
Wei Yan has relevant credentials as Lab Manager and Director of Operations at what appears to be a certification lab, with direct involvement in EUDI Wallet standardization and ENISA working groups. This is solid practitioner-level expertise in a niche but important domain. However, Wei is not a household name, doesn't lead a major vendor, and the transcript reveals some communication gaps (speaker names are confused, some technical points are explained unclearly), which slightly undermines the authority signal.
Wei works at the intersection of high assurance evaluation and regulatory change, helping shape how digital identity systems are certified in a world moving towards post quantum security.
myself, I'm participating as an expert within the uh, other working group within enisa, which uh, in this case we are working to create a uh, certification scheme
The episode lacks concrete numbers, named examples, and specific metrics. Timelines are mentioned (2026, 2030 - 2035, 2056 mentioned then corrected to 2026) but often vaguely. The EUDI Wallet architecture is described conceptually (secure element, TEE, remote HSM) but without actual deployments, vendor names, or performance data. References to regulations (CRA, Cyber Resilience Act) are mentioned but not detailed with specific requirements or thresholds. The '10% or 15%' estimate about secure elements in mobile phones is the closest to concrete data but remains speculative.
So this means that maybe you are not reacting the total population of Europe, you are only 10% or 15%.
if we focus on the specific of what happens if the different transition periods or the mandate zone migration of new technology would impact the world globally
The host (Joel Linson) asks reasonable open-ended questions and does follow up on some points (asking about deployment status, architecture breakdown, vendor maturity). However, the conversation lacks sharp probing and productive pushback. Many of Wei's longer answers trail off or become circular without the host drilling into specifics or challenging vague claims. The first 10+ minutes are spent on weather and tourism rather than establishing momentum on substance. Follow-ups are often confirmatory ('Right?', 'Yeah, exactly') rather than challenging or seeking clarification on contradictions or technical gaps.
Right. So protecting privacy and protecting all those important aspects of our digital lives really.
Well, and I would also imagine for you as a certification lab, it's a little bit of an awkward situation
Computed from the transcript - who did the talking, and the words that came up most.
What You’ll Learn Why the 2026 deployment mandate for EUDI Wallets creates immediate urgency The specific risks of storing biometric and identity data in a quantum environment How laboratories help vendors prove their security claims through independent review Why back-end systems adapt to new protocols faster than hardware devices The role of ENISA and the European Commission in shaping certification schemes How the Cyber Resilience Act affects both new and legacy products Why crypto agility is the only way to manage overlapping regulatory timelines The primary reason most security systems fail during real-world use Guest bio Wei Yuan is lab manager and director of operations at Applus+ Laboratories. Working at the boundary of high-assurance evaluation, hardware security, and regulatory policy, he serves as an expert within ENISA working groups, helping shape European digital identity certification standards and transition pathways to post-quantum cryptography. Shielded: The Last Line of Cyber Defense is handcrafted by our friends over at: fame.so
Transcribed and scored by The B2B Podcast Index.
Speaker A: Many transitions, uh, are coming. All of them are colliding at the same moment in time and this creates a lot of uncertainties.
Speaker B: Welcome to Shielded the Last Line of Cyber Defense by PQ Shield, the podcast where we are moving the conversation around post quantum Cryptography from the why to the how. Let's future proof your defenses together.
Speaker C: Welcome to Shielded the Last Line of Cyber Defense. I'm your host, Joel Linson and today we're joined by Wei Yan, Lab Manager and Director of Operations at APP Laboratories. Wei works at the intersection of high assurance evaluation and regulatory change, helping shape how digital identity systems are certified in a world moving towards post quantum security.
Speaker A: Thank you very much, Franz.
Speaker C: Absolutely. Welcome to the podcast and thanks for taking the time.
Speaker A: Yeah, it's up here.
Speaker C: Absolutely. So we are at the uh, at plus Headquarter I believe here in sunny, uh, Barcelona.
Speaker A: Yeah, indeed.
Speaker C: And I hear it's exceptionally sunny for this time of year. End of May. I came here and I thought what must this feel like in July or August?
Speaker A: Yeah, I would say that right now the weather is extremely hot. It's terrible actually. I really hope that it is not like this the whole summer but unfortunately think that it's not going to change.
Speaker C: It might stay like this or get even hotter.
Speaker A: Yeah, hopefully not all, but it will stay like this.
Speaker C: Fingers crossed.
Speaker B: Yeah.
Speaker C: Besides the weather, the other thing that I noticed walking through Barcelona, of course there's the Sagrada Familia.
Speaker A: Oh yeah, right.
Speaker C: Uh, but I've also noticed that thing is a big construction site.
Speaker A: Yeah, yeah.
Speaker C: Is that ever going to be finished or do you know, is it just ongoing forever?
Speaker A: Actually you should have noticed that the. Right now it's already finalized and the Pope is busy to give the first mass. I don't know the exact date. I think that it is now in June, but actually the uh, search itself is multi finalized. The thing is that the main entrance indeed is not finalized as there are some difficulties on um, the placements of it.
Speaker C: There's always the finalization stages that take a little longer than expected and of course that is very true for an old cathedral, but it's also very true for your actual daily work. And ah, the topic at hand that we actually want to talk about. Of course we don't want to talk about construction at an old cathedral, but it kind of gets the point across. So you're working a lot in EU based projects that are driven by regulations in a strictly compliant regulatory environment. And between Cyber Resilience Act CRA and uh, Post Corner Cryptography that roadmap of transition. There's one big focus on an initiative that you're very involved with, which is the UDI Wallet. The European Digital Identity Wallet.
Speaker A: Correct. Yeah.
Speaker C: So maybe you can give a little high level introduction to that for the listeners that might not be familiar with it. What is it, why does it matter and where do we stand with it?
Speaker A: Sure. I mean I like the way that you have uh, phrased all the things, mostly because it's extremely exciting times within the cybersecurity world. I do believe that many transitions are coming. All of them are colliding at the same moment in time and this creates a lot of uncertainties. But there are also good things, uh, especially within Europe, which uh, compared to the United States or China, I think that we are ruled by regulation and this regulation always is uh, focusing on the benefit of the citizens. Right. So fighting for their rights. So we have kind of a better war. And EUD Wallet is one of the best examples of this governance, I would say, of this identity that Europe wants to regulate. And indeed it's going to provide uh, citizens a mean to store and to identify themselves in a secure manner so they don't have to expose their personal data freely to anyone that has to request it.
Speaker C: Right. So protecting privacy and protecting all those important aspects of our digital lives really.
Speaker A: Correct. Yeah. So for those that are not familiar with the wallet, I will explain a uh, use case which is very common for all of you. How many times have you registered anywhere where you have been asked for your data?
Speaker C: All the time.
Speaker A: Yeah, anywhere. Right. So you go to the gym, you need to register, they ask for lots of data, you need to register into some website. You are requesting most data and maybe the only data they need is to validate whether you are older than 9 years old. Maybe they only want to validate whether you are citizen of a specific country. Maybe the only one to validate whether uh, you are from a specific city or not. However, you have all those setup data which definitely it is not needed and
Speaker C: not request for every specific use case. So I mean this is uh, quite a specific area that you work in in sort of high assurance cybersecurity standardizations. How did you end up in this position? Like what drew you into this work in the first place?
Speaker A: Yeah, I believe that is mostly curiosity. Curiosity and maybe critical mindset, the one that likes to challenge the uh, status quo. And many times I'm the one that always asks why. I believe that the chance to work in the uh, certification landscape, especially window, uh, some cybersecurity lab Gives us the chance to understand how things work and especially to prove when a specific vendor makes a secure product and the claim that it's perfect, power is perfect. You have the chance to really dig into it, verify it, review it and really help them to prove their claim that indeed a uh, specific design or architecture, it's following what is expected or what they are actually claiming that they
Speaker C: can do so in a defined environment, they can actually rightfully claim. Then you help understand and tie that together and say if the environment is like this, then yes, this can reach a certain level of, provide a certain level of certainty.
Speaker A: Correct.
Speaker C: To the user.
Speaker A: Yeah. And linking it to the previous point, I think that uh, we are continuously trying to provide confidence to the consumers that their products are actually definitely secure by design many times and that they are using the good practice required. And also of course that they are following the law, especially within Europe.
Speaker C: So talking about best practices and sort of, you mentioned there's different areas of transitions, one of which certainly is the transition over to uh, quantum safe algorithms by a certain timeline that has been communicated around 2030, 2035 in parallel. You have the UDI wallet. How much or how little of those new standards are already in those standards for UDI wallet, Is it still relying on elliptic curves or is there already a thought in there to support quantitative algorithms as well?
Speaker A: Yeah, this question is difficult to answer. We've touched upon many different topics. So by one hand when we think about or discuss about the awareness of the different vendors of how we are preparing for post quantum cryptography, I will believe that we are still working on it. Uh, so definitely nowadays the industry is transitioning, they are working towards migration to post quantum cryptography. We will deeper later on this topic but we're still far from it. And the vendors, manufacturers are not facing only the transition of such important aspect that is actually the foundation of trust based on how we're working nowadays that also they are uh, having products like uh, the UD Wallet that has a very specific problem. And actually it's the data that they are dealing with has an importance that goes beyond the traditional life cycle or lifetime of what data could be important or not. Because we're talking about the identity data of a specific cv. And of course if we will be analyzing how bad it is that uh, payment system, it is a challenge which is bad. But uh, payments can be settled, right? Uh, right. However, how bad is it if someone gets your biometric data? Um.
Speaker B: Right.
Speaker A: As long as you are alive it's a threat to our show you someone can get this data a new D wallet. Nowadays, when we focus on the architecture, what we can see that even if the current specification it is still evolving, it's built and um, designed using traditional cryptography, which is not bad. So for the moment let's not take apostrophe of course the foundation of the catalog that database, indeed it is based on ecdsa for senator tool, ecd3herrma for the key exchange. But we know that quantum computers are coming. This means that the uh, traditional algorithms that are based on specific mathematical problems would not be safe anymore. The speed that they can resolve these problems, it's way faster. And we are facing a problem that the current architecture it's uh, designed for a specific usage of algorithms and we are looking for crypto agility, um, how industry will prepare if suddenly we need to move fast, um, or faster. There was a migration to post quantum cryptography.
Speaker C: Now looking at the timeline of the UDI wallet, besides I know there have been some early pilots in certain countries, certain regions. How far down an actual rollout are we actually already with the UDI wallet and is it already in production use case that we're talking about or is it something that is still in the future as well?
Speaker A: Yeah. The mandate from the European Commission is that all member states have to deploy their solutions by 2056. So this means this year. So it's not a future plan anymore. It means that the member states are already rolling out solutions.
Speaker C: 2036, you said 26. So second year. Yeah, 26. Oh, I think, yeah.
Speaker A: 66. Yeah, yeah, yeah. So the problem is not a future uh, problem, but it's already here. The solutions has been developing. There has been a lot of pressure from the European Commission for all the member states to prepare and the member states has been pushing the industry also very much to develop solutions, trying to couple with the demands of the European Commission. This means that myself, I'm participating as an expert within the uh, other working group within enisa, which uh, in this case we are working to create a uh, certification scheme that the different member states can adopt and will help to provide more confidence that the different components of the whole UD Wallet solutions is certified and would bring a minimum confidence and assurance that these are well protected
Speaker C: just to up the level to a certain degree and exactly be confident in putting that stamp on it, so to speak. So you've mentioned the various vendors that are part of that entire EODI wallet architecture ecosystem. You've also talked about components. Maybe this is a good point in time to break that Down a little bit. I'm imagining there is a backend, there's a front and that's running as an app. So there's probably multiple different vendors that are providing the solutions for this entire ecosystem.
Speaker A: You are absolutely right. Actually the EUD wallet solution is quite complex. I would say many stakeholders are involved with Ambulance itself as you mentioned within the packet we have the uh, service providers where uh, they are the ones that will provide the solution itself to the devices that they are going to use. We're also talking about the member states that are handling the citizens data that also needs to be deployed in some system that you can get access to. Then uh, as consumer citizens uh, you are going to use a specific front end or application where it is the one that will help you provide the uh, attestations of the information that you are requested by different entities and then they are also the consumers of this attestation. Right. So going back to the example before, when you go to the registry.
Speaker C: Right?
Speaker A: Yeah. They will request you. Right. Okay. Well I need you to confirm a different type of data then you are the ones. If we go a bit more in detail then specifically for the solution itself that as uh users of the UD wallet we are facing we are talking uh still about wallet secure KW device. So when talking about the uh specific hardware that it's capable to restore secret data with tamper resistance properties there is the wallet solution application that is application is running on top of this device and then you have the specific wallet instance that is the one that uh, you are going to interact and from this architecture which is quite common, it's not different to other type of solutions. The complexity and the difficulty is that this, the function itself can be deployed on different type of technologies. Uh so if we look into the secure device itself, the reference architecture at the moment is uh present they are defining already usage of uh secure elements as a uh good foundational solution to store the secrets. But we're also talking about a non limited tool, maybe a Te Hz, remote HSM or other solutions. So this means that it's not limited and you can imagine that when we're talking at such range of different solutions, all of them with different security challenges then for us the laboratories where we have to provide assurance and confidence that these products are well designed and well protected it becomes a big challenge mostly because requirements are still not ready. So this means that vendors are facing definition and um, setting the different requirements as they think are needed without the guidance yet published. And the different solution is that all of them faces different products. So for example we know that one of the devices that uh, can provide more confidence are a security m. However, what is the proportion of a mobile handset that actually contains a simple mp? So this means that maybe you are not reacting the total population of Europe, you are only 10% or 15%. So what about the recipe? If we talk about some solutions, maybe people are going to use these solutions to their web browsers. So maybe now uh, the solution turns to be that the most convenient one it is a remote HSM which then you are moving the uh, secure storage device outside the current device that they're using to a uh, different location and then it breaks all type of uh, challenges. Right. Now how you define the product that it's within your mobile or within your laptop. Uh, and so every type of solution have um, their trade off and it's difficult to solve. Maybe not from a technical perspective itself, but in terms of how to cover the security requirements. It's not the uh, easy discussion, especially when so many stakeholders are involved.
Speaker C: Well, and I would also imagine for you as a certification lab, it's a little bit of an awkward situation because you're in the middle of almost like a translator of bringing all those stakeholders together and sort of draw that line of like if we look at a common criteria validation for the certain backend, it's going to look different to something that's using the secure element versus the remote hsl.
Speaker A: Yeah.
Speaker C: So if you look at sort of that whole technology stack, where would you say between backend technology, HSM vendors, PKI vendors, certificate lifecycle management, whoever else plays a role, where do you see the maturity in those solutions today?
Speaker A: So I would say that when we discuss about maturity nowadays we need to first think about uh, again to a concept of a cryptogeneity. So who is the one that is able to adapt quickly? And here I would say that usually the backends are the ones that can adapt to a uh, new solution easier. Mostly because the different type of solution itself, it could be a different protocol, it could be set on different technical specifications, but they can adapt. Here the challenge is how do we define new requirements for specific hardware that will be deployed over potentially millions of devices. Like here is where there is a lot of uncertainty because any change could be extremely costly or even impossible to solve, which would imply a mass uh, recall potentially. Ah, which is a big challenge.
Speaker C: Uh, so talking about deployments and ease of upgrade, of course you mentioned crypto agility and how important it is to think about that concept as you build and design those solutions. And of course like you said, a ribbon replace is cost prohibitive. That's likely not going to happen. How much or how little influence? I mean you're working in a standardization group at anisa, uh, and you also work for a lab. So it seems like you're in a good position to make sure that all these things are well thought after.
Speaker A: Indeed, this is not a small problem, it's a big problem. And I do believe that it's within the mind of all stakeholders that are working within the industry. So it's not something taken lightly. The impact is huge. To solve this problem, many entities are involved, but uh, especially mark those that are the standardization bodies, they are the ones that actually they are working towards interoperability. So the different vendors where they have to develop and design their products are considering designs and interfaces that later on could be easily migrated or sufficiently flexible as to take into account a potential future migration or change. So standardization bodies are extremely important to set the basis of how everyone should be working in order that interaction among them in the future is maintained. Then the issue of every change is, um, how the specific technical change might impact the existing solutions. And here is where certification schemes are. Ah, this word, to translate this word into specific requirements that vendors can understand and implement specific solutions that later on we solve that issues in the past and then laboratories ourselves. Right. We need to understand what has been discussed, what are the future potential technologies that will come. We need to prepare, understand and align also with uh, certification schemes giving our opinion many times on how a specific requirement could or not impact that work within the laboratory and then to properly interpret and explain to the vendors because many times the requirements are uh, written in a certain way that are so cryptic, so difficult to understand or provide some sort of different interpretations that makes the whole thing difficult. And let's be honest here, we're always talking about time, right? If time will be free, there's no problem. They have good explain. But any port that is not clear could impact by month the deployment or development of certain product, which is very important.
Speaker C: Well, and then you have those accumulating timelines like you said, UDI wallet, in theory this year and then the PQC transition by 2030. And how do you align those different time zones under that? Scndi. Uh, so you mentioned standardization bodies in this specific context of UDI Wallet. What are the main standardization bodies that would need to be mentioned?
Speaker A: Yeah, so if we talk purely about the uh, EOD wallet, then the entities that are working at the innisa, uh, on the other hand, the uh, European Commission, they are the ones that are writing the laws. Right? They are the ones that are regulated and these mandates are moved and reset to inisa. ENISA is a cybersecurity entity. They are the ones that has the mandate to make it happen on the European level. Exactly. Enisight is the one that ah, pushes forward and engages the different stakeholders that will be involved. Which here is where the different member states every country will have to participate, which every one of them have the mandate to create a specific certification scheme that can handle the different requirements and interpretations that ENISA is helping to shape. The different uh, member states later on will push requirements. So the different products deployed in their uh, are following the rules that uh, are defined by the username. And this implies then uh, another layer of complexity because it's when laboratories they are entering within the game because they need to accredit specific entities, laboratories and also certification bodies that by one hand can validate and test the solution according to requirements that have already been decided. And then you have the asset user bodies that are validated and gives confidence that the work door is following process. Ah, so in this way we can provide the whole set of confidence that we're breaking the conflict of interest. But I say that a specific vendor would try to bypass maybe the interpretation that human intake would manage tools. We go through certain interpretation offset allowed it. There would always be as a developer would try to standardize understanding among m all people. So this would be mostly the different entities ah, providing assurance the product size. Because then like that it becomes even more complex. We've deployed the product within the market because then all entities that are supplying this information and consuming this information becomes also quite complex.
Speaker C: And so ANISA is the European layer for EUDI Wallet. Is it also ANISA that is driving the quantum safe migration timeline on the European level?
Speaker A: Yeah. I'm not sure if I know how to answer this question, but definitely if we would make the separation to globally specific for the United States, I would say that compared to nist that they are the ones that actually defining these transgender periods within Europe right now. I would not say the exact entity that has decided the transient period.
Speaker C: Right?
Speaker A: Ah, transient period. If I'm not remembering wrong, they are stating that quantum safe solutions should be deployed uh, more or less along 2032.
Speaker C: But if uh, yeah, there's like a distinction between critical infrastructure and everything else.
Speaker A: Exactly, yeah. And if last time I checked I think that within Europe the requirements were not that deviated from the United States. So if I Don't remember wrong. It's maybe study later, but not so the videos. There's a difference of 5 years or 10 years. So still if we focus on the specific of what happens if the different transition periods or the mandate zone migration of new technology would impact the world globally and the industry is that indeed it would happen that potentially to access the market within the United States, you might have certain requirements that within Europe are not needed yet. So it creates a dual issue for the vendors. What do we do? Are we selling two type of products?
Speaker C: Exactly.
Speaker A: Ah, what about the new product? What should be focused to. So this type of question starts popping on.
Speaker C: Yeah, especially since you bring up the international interdependencies on different regulations, different jurisdictions. Of course that is always a topic for a vendor that provides solutions in that space because there are EID activities in other jurisdictions as well. In Asia there's a lot of projects that are quite active these days in uh, North America, the U.S. certainly. Uh, also following through on some of those activities. Yeah, that certainly goes hand in hand with the quantum safe migration in many regards. And then I think the other aspect that you mentioned is the certification bodies or certification schemes. Do you see a big difference as well? Again in an international comparison where one jurisdiction maybe favors common criteria over something else?
Speaker A: Yeah, this topic is in detail. We should focus a bit on how different cultures are focusing on providing uh, assurance. And definitely there are differences. So the way especially within North America or the United States are focusing these issues are uh, driven by different interests than those that is happening within Europe. Europe is mostly through regulation perspective. So you have to do that either when you are not accessing the market in the United States, maybe the mindset is different. Uh, you need to be compliant, you need to be conformant. However, if you are not, then you will still be liable fit. So there is maybe certain differences on how they are focusing the problem. I would say that within this extinction where manufacturers I do believe that they know the main problem is that in the past there were maybe more multilateralism in terms of agreements on reuse of confidence. So this means that uh, something certified within Europe maybe could be recognized like in the United States, it's ego or being maybe it's recognized within your bearer. And nowadays these sort of agreements are ongoing. So this means that uh, it's creating a double cost for many vendors that in order to access different markets they see that the different certification bodies and schemes are looking at uh, the assurance that they can provide independently, which creates twice the testing world that might be Needed so they can get the certificates and comply with the different regulations for
Speaker C: those different regions and requirements. So uh, if I'm a vendor and I'm considering a solution in this space, what is your best recommendation, where to start? If I haven't already?
Speaker A: Yeah. I would say that if I would have to give a recommendation is that right now it's best to go for the most strict scheme because it will provide you more flexibility later on to reduce cost. Especially when if you have to make two different products and we introduced additional issue, problem or complexity of different transgenders with different type of technology, then I think the question is uh, what should I choose? And I would choose the one that will live longer within this timeline. Even though today nowadays going through for instance traditional cryptography, you have many solutions that you can pursue, potentially reduce them to market. To put a product on the market quick lava is not a requirement. Things go fast, the lifestyle of this product is small. And then what could happen in the future is that you face in four, five, six years time suddenly are uh, urgent need to migrate the solution. And we all know that it's maybe it's right now slightly more expensive to move towards newer technology. Even if nowadays the coin itself are ah, still some way evolving. But on the long term I believe that the total overall cost of a uh, potential ah, mass migration is still smaller. So the problem later might be impossible.
Speaker C: Yeah, uh, those are good thoughts, good recommendations and I want to tie it back to Barcelona as we wrap it up and I have this question for you. Is it easier to navigate the European landscape of certifications regulations in your space or is it easier to find your way around the old parts of Barcelona with all those small, little, specific little pathways?
Speaker A: Yeah, uh, yeah, this is a funny question as you're talking to someone that has grown within Barcelona. For me it's not a problem anymore to navigate through that small streets. I would say that nowadays regression with Europe is. Countries cannot be taken lightly. There are many things ongoing. Cyber Resilience act, for instance, the Cybersecurity act, the future AI Act. There's many things ongoing, all of them with US requirements. Europe is trying to make it as easy as possible. But let's be honest, it's not easy to write anything you're facing reading of uh, at least from 300 to 500 pages, at least just to get some understanding of what things are going on.
Speaker C: Well and we haven't even talked about the timelines of the CRA and the Cybersecurity act and the AI Act. So I Think that would probably give us enough to talk about for yet another episode.
Speaker A: Oh yeah, indeed. I think that services 7% art. It's a topic that many vendors are um, getting interested not from now, but already, possibly from a year before this year again, 2026 is important year. There are obligations that will move to manufacturers from September this year where these assessments are there for all their products, all of them, those that already deployed and filtered ones. And this is a worry. And then from next year the whole service will enter into force. Which means that they need to eat the bread.
Speaker C: Yeah, yeah, especially the requirements for the already existing ones. I think they uh, create some specific headaches with service providers and vendors in that space.
Speaker A: Correct. I think that's one main problem that we face with vendors is that they need to report potential issues they have within their products. And the uh, problem possibly is not that much with big manufacturers where they might be able still to do algorithm and to do a good sbond just to discover their products and define maybe quicker potentially what products might be impacted by similarity. But let's talk about all the small and medium enterprises. What happened with them? Maybe they have Dynasty products that they don't know anymore. They have used open source products. Their service has changed. Some companies are not existing anymore. It's really difficult for all of them
Speaker C: to solve design a lot of operational challenges. Uh, well, thank you so much for sharing your insights Wei, it's been a pleasure and any last words of advice, any call to action that you want to give to our listeners as we wrap up.
Speaker A: Yeah, I think that one thing that we didn't have time to talk about is especially when we talk about post quantum cryptography, I think that we have talked about migration and that definitely post quantum cryptography is solving a few, few problems that we will have, uh, hundred computers. But I would like to remark that the issue has never been on the design of these algorithms. They are good, they are good to solve this problem. However, the issue is always about implementation. And therefore my main point for vendors is that take it seriously, all problems comes with a bad implementation, usually not from a bad design.
Speaker C: Right, yeah, uh, that's a very good point. And I think you earlier on used the term crypto agility. That of course has been overused and trampled to death by many marketing departments. But I think that's really key to think about. How can we migrate towards an architecture that will allow us to continuously change those algorithms as they become available. And yes, your point on implementation, um, that's usually the first thing that breaks. It's not the algorithm itself. It's a very valid point. Thanks for sharing that and um, it's been a pleasure to talk to you
Speaker A: today from you also.
Speaker C: Thank you.
Speaker A: Thank you.
Speaker B: To find out more about PQ Shield and how our cutting edge solutions can help you secure your data against the Quantum thread, visit pqshield.com don't forget to click subscribe so you never miss an episode. On behalf of the team here at PQShield, thanks for listening.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.