By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: WISeKeyPublished September 21, 2026

TL;DR: A CHF 40-60 million centre could build Swiss capabilities for post-quantum semiconductor personalization, cryptographic root-of-trust injection and secure provisioning, with up to 250 direct jobs over eight years, according to WISeKey. The governance issue is not the project alone but the shift toward hardware-rooted trust, which changes how identity, device authenticity and provisioning controls must be managed across IoT and critical systems.


At a glance

What this is: The MoU outlines a Swiss post-quantum semiconductor and cybersecurity centre focused on secure personalization, root-of-trust injection and certified provisioning.

Why it matters: It matters because hardware-rooted cryptographic trust increasingly shapes how IAM, NHI and device identity programmes authenticate systems, provision credentials and manage long-lived trust anchors.

By the numbers:

👉 Read WISeKey's announcement on the Swiss post-quantum semiconductor and cybersecurity centre


Context

Post-quantum semiconductor manufacturing is increasingly an identity and trust problem, not just a hardware strategy. When cryptographic roots of trust, provisioning, and firmware personalization move into sovereign production lines, organisations must treat device authenticity, key material handling and lifecycle assurance as part of the security architecture from the start.

This matters for NHI and IAM programmes because machines, embedded systems and service-to-device trust all depend on credentials that are often provisioned once and left in place for years. The centre described here signals a broader shift toward hardware-backed identity controls for IoT and industrial systems, which is typical of emerging post-quantum planning rather than an isolated Swiss case.

As a reference point for machine identity governance, see the [Ultimate Guide to NHIs](https://nhimg.org/the-ultimate-guide-to-non-human-identities) for lifecycle, rotation and offboarding fundamentals.


Key questions

Q: How should teams govern device identities created by software roots of trust?

A: Teams should govern them like any other machine identity: assign ownership, record lifecycle state, track key material, and define revocation paths. The fact that the trust anchor is software-derived does not remove the need for inventory, recovery, and retirement controls. If anything, it makes governance more important because the identity can proliferate into legacy estates.

Q: Why do post-quantum migrations matter for long-lived IoT and embedded systems?

A: Long-lived devices can outlast the cryptographic assumptions they were built on, which creates future exposure even if today’s controls look sound. Post-quantum migration matters because firmware signing, certificate chains and update validation all depend on algorithms that may become vulnerable before the hardware is retired.

Q: What breaks when provisioning evidence is not linked to device ownership?

A: You lose the ability to prove which entity injected keys, issued certificates or personalized the hardware. That weakens incident response, complicates offboarding and makes it harder to distinguish legitimate devices from impersonators when trust is challenged.

Q: How do security teams decide whether to prioritise hardware trust or software controls?

A: They should prioritise the control that protects the longest-lived and hardest-to-replace trust anchor. For many IoT and industrial systems, that is hardware-based identity and key provisioning, because software controls cannot fully recover if the underlying device trust chain is compromised.


Technical breakdown

Cryptographic roots of trust in semiconductor provisioning

A cryptographic root of trust is the foundational hardware anchor that lets a device prove who it is and whether its firmware has been altered. In semiconductor personalization, that root can be injected during manufacturing or post-manufacturing provisioning, then used to secure boot, attestation and key storage. Post-quantum designs aim to protect those trust anchors against future cryptanalytic compromise, which matters because device identities often outlive the algorithms that created them. Once embedded, the trust anchor influences downstream authentication, update validation and lifecycle management across the device estate.

Practical implication: Treat root-of-trust injection as an identity control, not only a manufacturing step, and bind it to provisioning governance and attestation validation.

Post-quantum algorithms and machine identity longevity

Post-quantum cryptography addresses the risk that current public-key systems could become weak when large-scale quantum computing matures. For device identity, the issue is longevity: certificates, signing keys and firmware trust chains may remain operational long after the original cryptographic assumptions have aged out. That creates a governance gap between the lifespan of hardware and the lifespan of the algorithms protecting it. NIST-standardised algorithms such as ML-KEM and ML-DSA are relevant because they shape how future devices negotiate secure identity and integrity over long deployment periods.

Practical implication: Inventory which device identities depend on legacy algorithms and define a migration path before those trust anchors become hard to replace.

Secure provisioning and certification for sovereign hardware supply chains

Secure provisioning is the controlled process of assigning identity, keys and policy to a device before it enters service. In sovereign semiconductor programmes, this extends into certification, traceability and supply-chain assurance because the device’s identity chain must remain verifiable from fabrication through deployment. The operational challenge is that trust can fail at several points, including personalization, firmware signing, third-party handling and offboarding of device credentials. That makes provisioning a lifecycle discipline, not a one-time production task.

Practical implication: Align procurement, manufacturing and security teams around a shared provisioning record so device identity, firmware trust and decommissioning stay auditable.


Threat narrative

Attacker objective: The attacker wants to subvert the device trust chain so compromised hardware appears legitimate across deployment and update lifecycles.

  1. Entry occurs when adversaries target device supply chains, personalization stages or firmware signing processes rather than the live endpoint itself.
  2. Credential access or trust abuse follows when a compromised signing key, root certificate or personalization workflow lets attackers impersonate legitimate devices.
  3. Impact appears as durable compromise of device authenticity, enabling tampered firmware, fraudulent attestation or persistent access to connected systems.

NHI Mgmt Group analysis

Hardware trust is becoming an identity governance problem. When trust anchors move into semiconductor personalization, the question is no longer only whether a device is secure at manufacture. The real issue is whether identity, key material and attestation can be governed across the full lifecycle of the hardware. That aligns device assurance with NHI governance logic, where lifecycle control matters as much as initial issuance.

Post-quantum planning is forcing organisations to confront cryptographic debt. Devices and embedded systems often outlive the algorithms embedded in them, so post-quantum readiness is partly an inventory and migration problem. If teams cannot see where legacy cryptography is used, they cannot time the transition. Practitioners should treat algorithm agility as a governance requirement, not just a cryptography upgrade.

Supply-chain sovereignty only helps if provisioning remains auditable. A sovereign factory does not eliminate the risk of credential misuse, weak offboarding or untracked trust injection. The named concept here is provisioning trust debt: the accumulation of unverified personalization steps, stale keys and opaque handoffs that make later assurance difficult. Security teams should reduce that debt by tying manufacturing evidence to identity records and certificate governance.

Post-quantum hardware programmes will reshape how security teams think about IoT identity. Smart devices, industrial controllers and secure tokens all depend on long-lived trust chains that are difficult to replace once deployed. The implication for the field is that machine identity governance will increasingly overlap with semiconductor assurance, certification and sovereign supply-chain strategy. Practitioners should plan for that convergence now.

Regional industrial policy is now part of cyber risk management. The Jura initiative shows that governments are beginning to treat secure chips, cryptography and identity infrastructure as strategic assets. That broadens the governance surface for security leaders because procurement, certification and domestic manufacturing choices can affect trust assumptions downstream. Teams should evaluate those dependencies as part of resilience planning.

What this signals

Provisioning trust debt: semiconductor programmes will need to track how much unverified identity material accumulates across fabrication, personalization, certification and deployment. Once that debt exists, recovery becomes slower and more expensive because trust cannot be rebuilt by software controls alone. For practitioners, that means identity evidence and device provenance must be designed into the operating model from day one, alongside standards such as MITRE ATLAS adversarial AI threat matrix where AI systems rely on hardware-backed trust.

Security leaders should expect quantum-readiness discussions to migrate from cryptography teams into IAM, PAM and supply-chain governance. That shift will force better inventory of machine identities, better ownership of signing material and stronger links between procurement records and security telemetry. The organisations that prepare early will be able to rotate trust anchors and retire legacy algorithms with less disruption.


For practitioners

  • Map device trust anchors end to end Document where root-of-trust keys, certificate chains and firmware-signing credentials are created, injected, stored and rotated across the manufacturing and deployment lifecycle.
  • Build a post-quantum migration inventory Identify embedded systems, tokens and IoT platforms that rely on legacy public-key algorithms, then prioritise them by replacement difficulty and exposure window.
  • Tie provisioning evidence to identity records Require auditable links between personalization events, hardware serial numbers, attestation data and the owning service identity before devices enter production.
  • Review offboarding for hardware trust material Define who can revoke signing credentials, retire certificates and disable provisioning paths when a supplier, factory process or device line is decommissioned.

Key takeaways

  • Post-quantum semiconductor programmes are also machine identity programmes, because hardware trust anchors shape authentication, attestation and lifecycle control.
  • The practical risk is cryptographic debt, where long-lived devices outlast the algorithms and provisioning assumptions that secure them.
  • Security teams should connect manufacturing evidence, device provenance and revocation paths before sovereign hardware initiatives scale into production.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack surface, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Inventory and OwnershipThe article centres on provisioning, ownership and lifecycle control of device trust material.
Recommendation — Inventory device identities and their trust anchors before moving post-quantum hardware into production.
NIST CSF 2.0PR.AC-4 — Access Permissions and AuthorisationsSecure provisioning and root-of-trust injection depend on tightly governed access and authorisation.
Recommendation — Apply PR.AC-4 to restrict who can inject, sign and provision hardware trust material.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe piece discusses keys, certificates and cryptographic material that need lifecycle management.
Recommendation — Use IA-5 to govern issuance, protection, rotation and revocation of device authenticators.
MITRE ATT&CKTA0006; TA0040 — Credential Access; ImpactCompromise of signing keys or roots of trust enables credential abuse and durable device compromise.
Recommendation — Map trust-chain threats to TA0006 and TA0040 to prioritise detection around signing material and firmware integrity.
ISO/IEC 27001:2022A.8.2 — Privileged Access RightsPersonnel handling personalization and provisioning need tightly controlled privileged access rights.
Recommendation — Restrict privileged access to hardware provisioning workflows and review those rights regularly.

Key terms

  • Root Of Trust: A root of trust is the authoritative starting point that other identities and certificates rely on for validation. In distributed ecosystems, it determines which parties can establish trust, which can be revoked, and how consistent authentication remains across vendors and environments.
  • Secure Provisioning: Secure provisioning is the controlled process of assigning identity, keys and policy to a device or workload before it enters service. It is a lifecycle control that must be auditable, because errors at this stage often persist for the full operational life of the asset.
  • Post-Quantum Cryptography: Cryptographic algorithms designed to remain secure against attacks from sufficiently powerful quantum computers. In practice, PQC is a migration problem as much as an algorithm problem because organisations must replace trust anchors, certificates, and secrets without breaking identity-dependent systems.
  • Device Attestation: Device attestation is the process of checking whether a device and its software environment meet expected integrity conditions before trust is extended. For identity workflows, it should support the verification decision, not replace stronger evidence about whether the capture stream itself is authentic.

What's in the full analysis

WISeKey's full article covers the strategic and commercial detail this post intentionally leaves for the source:

  • Indicative investment structure, financing model and public-private partnership roles for the Jura Center
  • Planned job creation, local employment mix and regional industrial development assumptions
  • Next-step governance work including site selection, academic partnerships and certification roadmap
  • The relationship between the Jura initiative and WISeKey's earlier Murcia model

👉 WISeKey's full post covers the financing model, industrial partnerships and implementation roadmap in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management and machine identity security. It helps practitioners align identity lifecycle controls with the systems and trust anchors they already operate.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org