One PQC Playbook – with Kevin Hilscher of DigiCert | Ep. 110

One PQC Playbook – with Kevin Hilscher of DigiCert | Ep. 110

🎙 Kevin Hilscher 👥 1K 📅 August 20, 2025 ⏱ 32 min 👁 117 📄 expert opinion 🧭 2026-08-17
Available in: English (current) Français

Keywords

PQC migrationML-KEMML-DSAhybrid certificatescrypto discovery

Summary

In this episode of The Post-Quantum World, host Konstantinos Karagiannis interviews Kevin Hilscher, Senior Director of Product Management at DigiCert, about practical steps for migrating to post-quantum cryptography (PQC). They discuss the importance of upgrading to TLS 1.3, the role of new NIST-approved algorithms like ML-KEM and ML-DSA, and the challenges of implementing PQC on resource-constrained IoT devices. Hilscher outlines a six-step migration playbook: discovery of crypto assets, selecting a pilot application, building vendor checklists, deciding on upgrade/replace/retire, testing and measuring progress, and iterating. They also delve into the nuances of hybrid key exchange versus hybrid certificates, cautioning against premature adoption of hybrid certificates due to competing standards. The conversation highlights DigiCert’s platform, DigiCert One, and its tools for discovery and experimentation, including the Quantum Safe Playground. The episode provides actionable advice for organizations beginning their PQC journey, emphasizing that migration is a team sport requiring coordination across vendors and internal teams.

152 words

Critical Evaluation

Value of the Information & Strength of the Argument

The episode offers high practical value for organizations planning PQC migration. It provides a clear, actionable six-step framework that is both comprehensive and realistic, acknowledging the complexity and vendor dependencies. The argumentation is solid, grounded in real-world experience from a major PKI provider. Hilscher effectively explains technical concepts like ML-DSA and hybrid certificates, making them accessible without oversimplifying. The discussion of IoT challenges and the trade-offs between algorithms (e.g., ML-DSA vs. SLH-DSA) is particularly valuable. The advice to avoid hybrid certificates due to immature standards is well-reasoned, though it contrasts with some European regulatory recommendations, which is acknowledged. Overall, the content is credible and useful, though it is primarily based on expert opinion rather than new research.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate to high. The discussion is consistent with current NIST standards and industry practices, and references to TLS 1.3, ML-KEM, ML-DSA, and SLH-DSA are accurate. However, specific claims about vendor roadmaps (e.g., Microsoft, AWS) are anecdotal and not independently verified. The episode does not cite external sources beyond the mentioned tools and standards, but the expertise of the guest lends credibility. The title accurately reflects the content, which is a focused playbook for PQC migration. No comments were provided for analysis.

217 words

Title / Content Match

The title accurately reflects the content: a focused playbook for PQC migration, featuring a DigiCert expert.

Quality & Reliability

8/10

The discussion is grounded in practical expertise from a leading PKI provider, referencing NIST standards and industry practices. Claims are consistent with known developments in PQC, though some statements (e.g., specific vendor roadmaps) are anecdotal and not independently verified.

Key Moments

Cited Sources

Concurring Sources

Dissenting Sources

  • BSI Recommendations for PQC Migration — BSI has suggested considering hybrid approaches, which contrasts with the video's advice to avoid hybrid certificates. No specific URL provided.

Contribution & Novelties

The episode provides a practical, vendor-informed playbook for PQC migration, emphasizing the importance of discovery, vendor coordination, and iterative testing. It clarifies the distinction between hybrid key exchange and hybrid certificates, offering clear guidance to avoid premature adoption of immature standards. The discussion of IoT-specific challenges and the potential deprecation of devices adds a realistic perspective often missing in theoretical discussions.

Pour aller plus loin :

123 words

Radar Profile

The radar profile shows high scores across all dimensions, indicating a well-rounded and reliable episode. The high 'quantite_information' and 'qualite_information' reflect the depth and accuracy of the content, while 'niveau_technique' is appropriately high for the target audience. The 'fiabilite_globale' is strong due to the guest's expertise and alignment with NIST standards.

Reliability 8/10