Why it matters now
2029
Google's PQC migration deadline
10K qubits
Estimated to break classical P-256
91%
Of organizations lack a PQC roadmap
FIPS 203/204
ML-KEM and ML-DSA standardized
THE PLATFORM
Three layers
One quantum-safe stack
From ECC-hardened discrete secure elements to post-quantum native OS to certified applets — with a clear migration path for every deployed product.

PQC PLATFORM
Javelin™ PQC
ML-KEM — FIPS 203
ML-DSA — FIPS 204
SLH-DSA — FIPS 205
Hybrid key exchange
JavaCard API integration
FIPS 140-3 path
OS LICENSING
Javelin™ OS
JavaCard v3.0.5 / v3.2
GlobalPlatform 2.4
Infineon SLC series
STMicro ST33 support
CC EAL5+ / EAL6+ path
Crypto + PQC roadmap
APPLET SUITE
Javelin™ Applets
FIDO2 CTAP 2.3
PIV — SP 800-73-5
ePassport — ICAO 9303
OpenPGP 3.4
OATH TOTP / HOTP
PQC migration toolkit
THE PLATFORM
Three layers
One quantum-safe stack
From ECC-hardened discrete secure elements to post-quantum native OS to certified applets — with a clear migration path for every deployed product.

APPLET SUITE
Javelin™ Applets
FIDO2 CTAP 2.3
PIV — SP 800-73-5
ePassport — ICAO 9303
OpenPGP 3.4
OATH TOTP / HOTP
PQC migration toolkit
Why PQC. Why Now.
March 2026 changed the PQC procurement calculus
Google’s March 2026 research suggested ECC may be broken with far fewer qubits than previously expected. For secure elements and smart cards, PQC is no longer a roadmap topic — it is a procurement requirement.
Sets 2029 PQC migration deadline. Android 17 ships ML-DSA for digital signatures.
Cloudflare
Accelerates to 2029 Q-Day readiness. Cites 10,000-qubit P-256 break estimate.
NIST
FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA) — finalized standards.
NSA / CNSA 2.0
Suite B deprecated. ML-KEM and ML-DSA mandated for national security systems.
ALGORITHM TRANSITION MAP
ECDSA secp256k1
Vulnerable to quantum
RSA 2048 / 4096
Vulnerable to Shor
ML-KEM (FIPS 203)
Used for key exchange
ML-DSA (FIPS 204)
Used for signatures
Hybrid ECC + ML-KEM
Used for transition

Production OS today
post-quantum ready
Javelin™ OS is a production-proven JavaCard and GlobalPlatform operating system for smart cards and secure elements, with post-quantum cryptography on the roadmap.
contact@jnet-secure.com
Tel: +1 408 802 0640
16185 Los Gatos Blvd, Suite 205, Los Gatos CA 95032 USA
© 2026 jNet Secure. All rights reserved. JavaCard is a trademark of Oracle Corporation. GlobalPlatform is a registered trademark of GlobalPlatform Inc.
Solutions by vertical
PQC migration paths, by product category
Deep expertise in applet design, mobile integration, secure backend architecture, and product-specific PQC migration planning.
FIPS 140-3
ICAO PQC
Government ID & ePassport
Hybrid PQC deployment for payment applets, allowing MChip and qVSDC systems to keep operating while PQC layers are activated.

EMVCo
PQC MIGRATION
Payment & EMVCo
Hybrid PQC deployment for payment applets, allowing MChip and qVSDC systems to keep operating while PQC layers are activated.

CTAP 2.3
ML-DSA ATTEST.
FIDO2 & Hardware Tokens
ML-DSA attestation for hardware tokens, aligned with CTAP 2.3+ and Android Verified Boot migration requirements.

jNet Wallet
PQC → ECC + PQC
Crypto Wallet & Blockchain
Hybrid ECDSA + ML-DSA signing for blockchain transactions, supporting secure wallet migration before Q-Day.





