top of page
Diagram showing secure element technology components and platform architecture
Mobile view illustration of jNet Secure platform components

INDUSTRY ALERT

US Executive Order 14412: PQC key establishment by Dec 31, 2030. PQC signatures by Dec 31, 2031. Federal contractors on NIST PQC FIPS by end of 2030.

Licensed to card and token makers.
jNet provides the platform, not the cards.

Post-quantum Java Card, running today on Infineon SLC27 and SLC22

Javelin OS-PQC puts ML-KEM and ML-DSA in the OS core, with applets, Windows and mobile middleware, and developer tools.

Oracle Java Card licensee · Java Card Forum member · GlobalPlatform member · Infineon TEGRION SLC27 / SLC22 · Designed for FIPS 140-3

POST-QUANTUM MIGRATION

Why it matters now

Quantum migration is moving from long-term research into practical procurement planning. Secure element lifecycles, certification timelines, and cryptographic transition requirements mean teams need to prepare before algorithms become urgent to replace.

Dec 31, 2030

PQC key establishment, federal high-value systems (EO 14412)

Dec 31, 2031

PQC digital signatures (EO 14412) 

End of 2030

Federal contractors on NIST PQC FIPS 

FIPS 203 / 204 

ML-KEM and ML-DSA, final NIST standards 

jNet brings more than two decades of Java Card OS, secure element, identity, payment, and certification experience to this transition.

THE PLATFORM 

One toolkit
Four secure layers

A complete post-quantum Java Card toolkit across the OS, applets, deployment stack, and developer tooling.

OS-PQC

Javelin OS-PQC

ML-KEM and ML-DSA run in the OS core, with Java Card 3.2, Java Card 3.3* PQC APIs, GlobalPlatform 2.3.1, and in-field upgrades for OS, crypto library, and applets.

APPLET LAYER

PQC Applets

PIV and FIDO2 first, then crypto wallet, OpenPGP, EMV, ICAO, and mDoc applets for staged post-quantum migration.

DEPLOYMENT

Deployment Stack

Windows 11 minidriver, KSP, Credential Provider smart card logon, PKCS#11 for desktop platforms, and mobile SDK support over CCID and NFC.

DEVELOPER TOOLS

Developer Toolkit

The Eclipse PQC plug-in generates the applet CAP file and matching host bindings from one interface definition.

* Java Card 3.3 is not yet officially released by Oracle.

Why PQC. Why Now.

What the deadlines mean for your credentials

Federal procurement now sets dates for PQC key establishment and signatures. Credentials issued today will still be in service when those dates arrive.

EO 14412

PQC key establishment by 2030 and signatures by 2031 for federal high-value systems. Contractors on NIST PQC FIPS by end of 2030.

NSA CNSA 2.0

ML-KEM-1024 and ML-DSA-87 are the parameter sets for national security systems.

NIST

FIPS 203 (ML-KEM) and FIPS 204 (ML-DSA): final standards, August 2024.

google

Set 2029 as its own PQC migration target and is integrating ML-DSA into Android 17.

ALGORITHM TRANSITION MAP

ECDSA P-256 / secp256k1

Vulnerable to quantum

RSA 2048 / 4096

Vulnerable to Shor

ML-KEM (FIPS 203)

Used for key exchange

ML-DSA (FIPS 204)

Used for signatures

Hybrid ECC + ML-KEM

Used for transition

Abstract blue technology background

Production OS today
post-quantum ready

Javelin OS is a production Java Card 3.2 and GlobalPlatform 2.3.1 operating system. Javelin OS-PQC adds ML-KEM and ML-DSA in the OS core, running today at the jNet bench on Infineon SLC27 and SLC22

Solutions by vertical

PQC migration paths, by product category

Deep expertise in applet design, mobile integration, secure backend architecture, and product-specific PQC migration planning.

FIPS 140-3 

ICAO Doc 9303

Government ID & ePassport

Hybrid PQC migration for ePassports and government identity credentials, supporting ICAO standards and long-term protection of sensitive citizen data.

Secure element chip illustration

EMVCo 

PQC MIGRATION

Payment & EMVCo

Payment applets keep running MChip and qVSDC while PQC layers are prepared. Online authentication already relies on AES cryptograms; asymmetric PQC follows EMVCo specifications as they are published.

Smart card hardware module illustration

CTAP 2.3

ML-DSA ATTEST.

FIDO2 & Hardware Tokens

ML-DSA credentials using the IANA COSE algorithm registry, CTAP 2.3, and an in-field upgrade path for tokens already deployed.

USB security token illustration

jNet Wallet

PQC → ECC + PQC

Crypto Wallet & Blockchain

Hybrid ECDSA + ML-DSA signing, with the signing algorithm swappable in the field while Bitcoin BIP-360 and Ethereum post-quantum account designs settle.

Crypto wallet illustration for secure blockchain transaction signing

SP 800-73-5

ML-DSA

Enterprise PIV & Windows Logon

PIV with ML-DSA and hybrid ECDH. Windows 11 smart card logon through the jNet minidriver, KSP and Credential Provider.

icon.png

EVALUATION KIT

Three steps to your evaluation kit

01

See it at the jNet bench

Live demonstrations at TRUSTECH 2026, Paris Expo Porte de Versailles, December 1–3.

02

Request the kit from jNet

Submit an evaluation kit request so jNet can review your use case and access requirements.

03

Qualified partner delivery

Kits are supplied in cooperation with Infineon to qualified partners.

Abstract blue technology background for jNet Secure website section

Ready to request your evaluation kit?

Tell jNet about your Java Card OS, applet migration, and PQC deployment requirements.

bottom of page