{"id":6466,"date":"2026-08-10T08:00:00","date_gmt":"2026-08-10T06:00:00","guid":{"rendered":"https:\/\/www.eadtrust.eu\/?p=6466"},"modified":"2026-08-26T09:54:31","modified_gmt":"2026-08-26T07:54:31","slug":"hybrid-certificates-quantum-resistance","status":"publish","type":"post","link":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/","title":{"rendered":"Hybrid Certificates: The Technical Bridge Needed for Quantum Resistance"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The transition to <strong>post-quantum cryptography (PQC)<\/strong> will not be a switch that is turned off and on overnight. There is a dangerous transition period in which legacy systems must coexist with the new security standards.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The technical solution that guarantees simultaneous interoperability and security is <strong>hybrid certificates<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These cryptographic artefacts allow organisations to begin deploying defences against the quantum threat today without breaking compatibility with the current internet infrastructure, which still depends on <strong>RSA and ECC<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They are, in essence, the missing link between the classical present and the quantum future.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Exactly Is a Hybrid Certificate?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the context of <strong>Public Key Infrastructure (PKI),<\/strong> a hybrid certificate (sometimes referred to as a &#8220;Composite Certificate&#8221; or &#8220;Cross-Certificate&#8221; in IETF drafts) is a digital credential that incorporates multiple public keys or signatures based on different cryptographic algorithms within the same X.509 structure.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Technical Anatomy of a Hybrid Certificate<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For an engineer to understand how it works, it must be viewed as a container with a dual payload:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Classical (traditional) layer:<\/strong> contains a standard public key (e.g. RSA-4096 or ECDSA P-256). This layer ensures that any current browser, server or application can validate the certificate without errors.<\/li>\n\n\n\n<li><strong>Post-Quantum (PQC) layer:<\/strong> contains a public key or signature based on the new NIST standards (such as FIPS 203\/ML-KEM or FIPS 204\/ML-DSA). This layer provides long-term security against quantum attackers.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The objective is to achieve an <strong>&#8220;AND&#8221;<\/strong> security model: for the communication to be compromised, the attacker must break <strong>both<\/strong> the classical algorithm <strong>and<\/strong> the post-quantum algorithm.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Interoperability Problem: Why Not Move Directly to PQC?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If NIST has already standardised the algorithms, why not abandon RSA immediately? The answer is <strong>interoperability<\/strong>.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The current ecosystem:<\/strong> billions of devices (IoT, routers, older mobile phones and legacy servers) do not know what a lattice-based algorithm is. If a web server changed its certificate today to a purely PQC certificate (FIPS 204), 99% of users would see a &#8220;Connection not secure&#8221; or &#8220;Invalid certificate&#8221; error.<\/li>\n\n\n\n<li><strong>The hybrid solution:<\/strong> when a hybrid certificate is presented, the client (browser or device) negotiates the connection.\n<ul class=\"wp-block-list\">\n<li>If the client is <strong>old<\/strong>, it ignores the PQC part and validates only the RSA\/ECC part. The connection works (although it is not quantum-resistant).<\/li>\n\n\n\n<li>If the client is <strong>modern<\/strong> (PQC-compatible), it validates both parts or prioritises the PQC part, establishing a tunnel that is secure against quantum computers.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Technical Implementation Strategies (IETF and X.509)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">There is no single way to construct a hybrid certificate. The industry is currently discussing and standardising two main approaches through the IETF (Internet Engineering Task Force).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Composite Keys Approach<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In this model, a new cryptographic algorithm is defined that is actually a combination of two algorithms.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>How it works:<\/strong> a &#8220;super-algorithm&#8221; is created (e.g. RSA-with-Dilithium). The public key within the certificate is a concatenation of the RSA key and the Dilithium key.<\/li>\n\n\n\n<li><strong>Advantage:<\/strong> conceptual simplicity. It is a single object.<\/li>\n\n\n\n<li><strong>Disadvantage:<\/strong> the software must explicitly understand this new &#8220;composite&#8221; OID (Object Identifier). If it does not, it will fail.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">2. X.509 Extensions Approach (Non-Critical Extensions)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is the most compatible and recommended approach for the early transition phase.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>How it works:<\/strong> the main certificate is a standard RSA\/ECC certificate. The post-quantum key is embedded within an <strong>X.509 extension<\/strong> marked as &#8220;non-critical&#8221;.<\/li>\n\n\n\n<li><strong>Mechanism:<\/strong>\n<ul class=\"wp-block-list\">\n<li>Older software reads the certificate and sees an extension it does not recognise (the PQC extension), but because it is &#8220;non-critical&#8221;, it ignores it and proceeds to validate using RSA.<\/li>\n\n\n\n<li>Modern software specifically looks for this extension, extracts the PQC key and performs the additional validation.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Advantage:<\/strong> full backward compatibility. It does not break older systems.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Comparison Table of Approaches<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Feature<\/strong><\/th><th><strong>Composite Keys<\/strong><\/th><th><strong>X.509 Extensions<\/strong><\/th><th><strong>Multiple Certificates (Linked)<\/strong><\/th><\/tr><\/thead><tbody><tr><td><strong>Legacy Compatibility<\/strong><\/td><td>Low (breaks older clients)<\/td><td>High (transparent to older clients)<\/td><td>Medium (depends on the TLS protocol)<\/td><\/tr><tr><td><strong>Management Complexity<\/strong><\/td><td>Medium<\/td><td>Low<\/td><td>High (managing 2 certificates per entity)<\/td><\/tr><tr><td><strong>Certificate Size<\/strong><\/td><td>Large<\/td><td>Large<\/td><td>Variable (two files)<\/td><\/tr><tr><td><strong>Ideal Use Case<\/strong><\/td><td>Closed \/ Controlled Environments<\/td><td>Open Internet \/ Public Web<\/td><td>Complex Protocols (TLS 1.3)<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Performance Challenges and Considerations<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Implementing hybrid certificates is not free in terms of resources. CISOs must consider the impact on infrastructure.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Latency and size:<\/strong> PQC algorithms usually have larger keys or signatures than elliptic curves. A hybrid certificate combines the size of both keys. This can increase latency during the TLS <em>handshake<\/em> and bandwidth consumption, which is critical in IoT or mobile environments with poor coverage.<\/li>\n\n\n\n<li><strong>Server load:<\/strong> validating two different mathematical signatures consumes more CPU cycles. Load balancers and web servers will need to be sized to support this increase in computational demand.<\/li>\n\n\n\n<li><strong>Packet fragmentation:<\/strong> due to the size, the server <em>Hello<\/em> is likely to exceed the maximum transmission unit (MTU), causing TCP packet fragmentation and possible losses on unstable networks.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">The Role of Hybrid Certificates in a &#8220;Defence-in-Depth&#8221; Strategy<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">From a security perspective, the hybrid certificate is the ultimate expression of defence in depth for cryptography.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Mitigation of mathematical failures:<\/strong> even if quantum computers did not exist, hybrid cryptography would still be desirable. If a mathematician discovered a vulnerability in elliptic curves tomorrow (independent of quantum computing), the PQC layer (based on lattices) would maintain security, and vice versa.<\/li>\n\n\n\n<li><strong>Proactive compliance:<\/strong> it allows companies to comply with current regulations (which require approved classical algorithms) while demonstrating due diligence by protecting themselves against future threats, in alignment with the GDPR\u2019s <em>Accountability<\/em> principle.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions About Hybrid Certificates<\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1781253812695\"><strong class=\"schema-faq-question\">Are Hybrid Certificates Currently Mandatory?<\/strong> <p class=\"schema-faq-answer\">Not by law, but they are strongly recommended by national security agencies (such as the NSA in its CNSA 2.0 suite or Germany\u2019s BSI) for national security systems and critical infrastructure. In the private sector, they are a strategic decision for protecting long-term data.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1781253905046\"><strong class=\"schema-faq-question\">Which Browsers Support Hybrid Certificates Today?<\/strong> <p class=\"schema-faq-answer\">Support is experimental but growing. Google Chrome and Mozilla Firefox have conducted tests with hybrid extensions (generally using Kyber for key exchange). However, widespread native support will arrive as IETF standards (such as <em>X.509 v3 Extensions for PQC<\/em>) are finalised.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1781253914981\"><strong class=\"schema-faq-question\">Do Hybrid Certificates Affect My Website\u2019s Speed?<\/strong> <p class=\"schema-faq-answer\">Yes, but the impact depends on the implementation. The increase in certificate size may add a few milliseconds to the initial connection. However, for most business applications and modern websites, this delay is imperceptible to users and justified by the additional security.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1781253926858\"><strong class=\"schema-faq-question\">Can I Request a Hybrid Certificate from EADTrust?<\/strong> <p class=\"schema-faq-answer\">As a constantly evolving Trust Service Provider, at EADTrust we are adapting our infrastructure to issue next-generation credentials. We are currently in the pilot testing and consultancy phase for organisations that want to prepare their internal PKIs for this model.<\/p> <\/div> <\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Hybrid certificates are not a passing \u201ctrend\u201d, but the standard architecture that will dominate the internet over the next decade. They represent technical pragmatism: recognising that the quantum future is inevitable, while the classical present must continue to function.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For companies, adopting a hybrid strategy is the only way to avoid a traumatic \u201cBig Bang\u201d migration in the future. It enables a smooth, controlled and secure transition. <strong>Is your organisation prepared to manage dual-algorithm certificates?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At EADTrust, we can help you design a proof of concept (PoC) to integrate hybrid certificates into your critical environment without disrupting your current operations.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The transition to post-quantum cryptography (PQC) will not be a switch that is turned off and on overnight. There is a dangerous transition period in which legacy systems must coexist with the new security standards. The technical solution that guarantees simultaneous interoperability and security is hybrid certificates. These cryptographic artefacts allow organisations to begin deploying [&hellip;]<\/p>\n","protected":false},"author":10,"featured_media":6467,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[60],"tags":[],"class_list":["post-6466","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-certificates"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\u25b7 Hybrid Certificates and Quantum Resistance - EADTrust<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u25b7 Hybrid Certificates and Quantum Resistance - EADTrust\" \/>\n<meta property=\"og:description\" content=\"The transition to post-quantum cryptography (PQC) will not be a switch that is turned off and on overnight. There is a dangerous transition period in which legacy systems must coexist with the new security standards. The technical solution that guarantees simultaneous interoperability and security is hybrid certificates. These cryptographic artefacts allow organisations to begin deploying [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/\" \/>\n<meta property=\"og:site_name\" content=\"EADTrust\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-10T06:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-26T07:54:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.eadtrust.eu\/wp-content\/uploads\/2026\/08\/Hybrid-Certificates.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1513\" \/>\n\t<meta property=\"og:image:height\" content=\"1040\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Iria Benito\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Iria Benito\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/\"},\"author\":{\"name\":\"Iria Benito\",\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/#\\\/schema\\\/person\\\/a3734067aec82e51658e0148f12b57c2\"},\"headline\":\"Hybrid Certificates: The Technical Bridge Needed for Quantum Resistance\",\"datePublished\":\"2026-08-10T06:00:00+00:00\",\"dateModified\":\"2026-08-26T07:54:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/\"},\"wordCount\":1189,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.eadtrust.eu\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Hybrid-Certificates.png\",\"articleSection\":[\"Certificates\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#respond\"]}]},{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/\",\"url\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/\",\"name\":\"\u25b7 Hybrid Certificates and Quantum Resistance - EADTrust\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.eadtrust.eu\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Hybrid-Certificates.png\",\"datePublished\":\"2026-08-10T06:00:00+00:00\",\"dateModified\":\"2026-08-26T07:54:31+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#faq-question-1781253812695\"},{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#faq-question-1781253905046\"},{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#faq-question-1781253914981\"},{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#faq-question-1781253926858\"}],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.eadtrust.eu\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Hybrid-Certificates.png\",\"contentUrl\":\"https:\\\/\\\/www.eadtrust.eu\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Hybrid-Certificates.png\",\"width\":1513,\"height\":1040,\"caption\":\"Hybrid Certificates\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Inicio\",\"item\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Certificates\",\"item\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/category\\\/certificates\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Hybrid Certificates: The Technical Bridge Needed for Quantum Resistance\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/\",\"name\":\"EADTrust\",\"description\":\"Prestador de Servicios Cualificados\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/#organization\",\"name\":\"EADTrust\",\"url\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.eadtrust.eu\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/LOGO-POSITIVO-EAD-VERTICAL.png\",\"contentUrl\":\"https:\\\/\\\/www.eadtrust.eu\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/LOGO-POSITIVO-EAD-VERTICAL.png\",\"width\":838,\"height\":806,\"caption\":\"EADTrust\"},\"image\":{\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/#\\\/schema\\\/person\\\/a3734067aec82e51658e0148f12b57c2\",\"name\":\"Iria Benito\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2c5644780e757c7bc6dc451181852e22a42d1cfa51811bbf9a590295ea97b544?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2c5644780e757c7bc6dc451181852e22a42d1cfa51811bbf9a590295ea97b544?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2c5644780e757c7bc6dc451181852e22a42d1cfa51811bbf9a590295ea97b544?s=96&d=mm&r=g\",\"caption\":\"Iria Benito\"},\"url\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/author\\\/iria-benito\\\/\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#faq-question-1781253812695\",\"position\":1,\"url\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#faq-question-1781253812695\",\"name\":\"Are Hybrid Certificates Currently Mandatory?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Not by law, but they are strongly recommended by national security agencies (such as the NSA in its CNSA 2.0 suite or Germany\u2019s BSI) for national security systems and critical infrastructure. In the private sector, they are a strategic decision for protecting long-term data.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#faq-question-1781253905046\",\"position\":2,\"url\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#faq-question-1781253905046\",\"name\":\"Which Browsers Support Hybrid Certificates Today?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Support is experimental but growing. Google Chrome and Mozilla Firefox have conducted tests with hybrid extensions (generally using Kyber for key exchange). However, widespread native support will arrive as IETF standards (such as <em>X.509 v3 Extensions for PQC<\\\/em>) are finalised.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#faq-question-1781253914981\",\"position\":3,\"url\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#faq-question-1781253914981\",\"name\":\"Do Hybrid Certificates Affect My Website\u2019s Speed?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes, but the impact depends on the implementation. The increase in certificate size may add a few milliseconds to the initial connection. However, for most business applications and modern websites, this delay is imperceptible to users and justified by the additional security.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#faq-question-1781253926858\",\"position\":4,\"url\":\"https:\\\/\\\/www.eadtrust.eu\\\/en\\\/blog\\\/hybrid-certificates-quantum-resistance\\\/#faq-question-1781253926858\",\"name\":\"Can I Request a Hybrid Certificate from EADTrust?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"As a constantly evolving Trust Service Provider, at EADTrust we are adapting our infrastructure to issue next-generation credentials. We are currently in the pilot testing and consultancy phase for organisations that want to prepare their internal PKIs for this model.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u25b7 Hybrid Certificates and Quantum Resistance - EADTrust","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/","og_locale":"en_US","og_type":"article","og_title":"\u25b7 Hybrid Certificates and Quantum Resistance - EADTrust","og_description":"The transition to post-quantum cryptography (PQC) will not be a switch that is turned off and on overnight. There is a dangerous transition period in which legacy systems must coexist with the new security standards. The technical solution that guarantees simultaneous interoperability and security is hybrid certificates. These cryptographic artefacts allow organisations to begin deploying [&hellip;]","og_url":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/","og_site_name":"EADTrust","article_published_time":"2026-08-10T06:00:00+00:00","article_modified_time":"2026-08-26T07:54:31+00:00","og_image":[{"width":1513,"height":1040,"url":"https:\/\/www.eadtrust.eu\/wp-content\/uploads\/2026\/08\/Hybrid-Certificates.png","type":"image\/png"}],"author":"Iria Benito","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Iria Benito","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#article","isPartOf":{"@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/"},"author":{"name":"Iria Benito","@id":"https:\/\/www.eadtrust.eu\/en\/#\/schema\/person\/a3734067aec82e51658e0148f12b57c2"},"headline":"Hybrid Certificates: The Technical Bridge Needed for Quantum Resistance","datePublished":"2026-08-10T06:00:00+00:00","dateModified":"2026-08-26T07:54:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/"},"wordCount":1189,"commentCount":0,"publisher":{"@id":"https:\/\/www.eadtrust.eu\/en\/#organization"},"image":{"@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#primaryimage"},"thumbnailUrl":"https:\/\/www.eadtrust.eu\/wp-content\/uploads\/2026\/08\/Hybrid-Certificates.png","articleSection":["Certificates"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#respond"]}]},{"@type":["WebPage","FAQPage"],"@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/","url":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/","name":"\u25b7 Hybrid Certificates and Quantum Resistance - EADTrust","isPartOf":{"@id":"https:\/\/www.eadtrust.eu\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#primaryimage"},"image":{"@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#primaryimage"},"thumbnailUrl":"https:\/\/www.eadtrust.eu\/wp-content\/uploads\/2026\/08\/Hybrid-Certificates.png","datePublished":"2026-08-10T06:00:00+00:00","dateModified":"2026-08-26T07:54:31+00:00","breadcrumb":{"@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#breadcrumb"},"mainEntity":[{"@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#faq-question-1781253812695"},{"@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#faq-question-1781253905046"},{"@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#faq-question-1781253914981"},{"@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#faq-question-1781253926858"}],"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#primaryimage","url":"https:\/\/www.eadtrust.eu\/wp-content\/uploads\/2026\/08\/Hybrid-Certificates.png","contentUrl":"https:\/\/www.eadtrust.eu\/wp-content\/uploads\/2026\/08\/Hybrid-Certificates.png","width":1513,"height":1040,"caption":"Hybrid Certificates"},{"@type":"BreadcrumbList","@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Inicio","item":"https:\/\/www.eadtrust.eu\/en\/"},{"@type":"ListItem","position":2,"name":"Certificates","item":"https:\/\/www.eadtrust.eu\/en\/blog\/category\/certificates\/"},{"@type":"ListItem","position":3,"name":"Hybrid Certificates: The Technical Bridge Needed for Quantum Resistance"}]},{"@type":"WebSite","@id":"https:\/\/www.eadtrust.eu\/en\/#website","url":"https:\/\/www.eadtrust.eu\/en\/","name":"EADTrust","description":"Prestador de Servicios Cualificados","publisher":{"@id":"https:\/\/www.eadtrust.eu\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.eadtrust.eu\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.eadtrust.eu\/en\/#organization","name":"EADTrust","url":"https:\/\/www.eadtrust.eu\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.eadtrust.eu\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.eadtrust.eu\/wp-content\/uploads\/2025\/02\/LOGO-POSITIVO-EAD-VERTICAL.png","contentUrl":"https:\/\/www.eadtrust.eu\/wp-content\/uploads\/2025\/02\/LOGO-POSITIVO-EAD-VERTICAL.png","width":838,"height":806,"caption":"EADTrust"},"image":{"@id":"https:\/\/www.eadtrust.eu\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.eadtrust.eu\/en\/#\/schema\/person\/a3734067aec82e51658e0148f12b57c2","name":"Iria Benito","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/2c5644780e757c7bc6dc451181852e22a42d1cfa51811bbf9a590295ea97b544?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/2c5644780e757c7bc6dc451181852e22a42d1cfa51811bbf9a590295ea97b544?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2c5644780e757c7bc6dc451181852e22a42d1cfa51811bbf9a590295ea97b544?s=96&d=mm&r=g","caption":"Iria Benito"},"url":"https:\/\/www.eadtrust.eu\/en\/blog\/author\/iria-benito\/"},{"@type":"Question","@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#faq-question-1781253812695","position":1,"url":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#faq-question-1781253812695","name":"Are Hybrid Certificates Currently Mandatory?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Not by law, but they are strongly recommended by national security agencies (such as the NSA in its CNSA 2.0 suite or Germany\u2019s BSI) for national security systems and critical infrastructure. In the private sector, they are a strategic decision for protecting long-term data.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#faq-question-1781253905046","position":2,"url":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#faq-question-1781253905046","name":"Which Browsers Support Hybrid Certificates Today?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Support is experimental but growing. Google Chrome and Mozilla Firefox have conducted tests with hybrid extensions (generally using Kyber for key exchange). However, widespread native support will arrive as IETF standards (such as <em>X.509 v3 Extensions for PQC<\/em>) are finalised.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#faq-question-1781253914981","position":3,"url":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#faq-question-1781253914981","name":"Do Hybrid Certificates Affect My Website\u2019s Speed?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes, but the impact depends on the implementation. The increase in certificate size may add a few milliseconds to the initial connection. However, for most business applications and modern websites, this delay is imperceptible to users and justified by the additional security.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#faq-question-1781253926858","position":4,"url":"https:\/\/www.eadtrust.eu\/en\/blog\/hybrid-certificates-quantum-resistance\/#faq-question-1781253926858","name":"Can I Request a Hybrid Certificate from EADTrust?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"As a constantly evolving Trust Service Provider, at EADTrust we are adapting our infrastructure to issue next-generation credentials. We are currently in the pilot testing and consultancy phase for organisations that want to prepare their internal PKIs for this model.","inLanguage":"en-US"},"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/www.eadtrust.eu\/en\/wp-json\/wp\/v2\/posts\/6466","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.eadtrust.eu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.eadtrust.eu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.eadtrust.eu\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.eadtrust.eu\/en\/wp-json\/wp\/v2\/comments?post=6466"}],"version-history":[{"count":2,"href":"https:\/\/www.eadtrust.eu\/en\/wp-json\/wp\/v2\/posts\/6466\/revisions"}],"predecessor-version":[{"id":6470,"href":"https:\/\/www.eadtrust.eu\/en\/wp-json\/wp\/v2\/posts\/6466\/revisions\/6470"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.eadtrust.eu\/en\/wp-json\/wp\/v2\/media\/6467"}],"wp:attachment":[{"href":"https:\/\/www.eadtrust.eu\/en\/wp-json\/wp\/v2\/media?parent=6466"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.eadtrust.eu\/en\/wp-json\/wp\/v2\/categories?post=6466"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.eadtrust.eu\/en\/wp-json\/wp\/v2\/tags?post=6466"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}