TL;DR: A CHF 40-60 million centre could build Swiss capabilities for post-quantum semiconductor personalization, cryptographic root-of-trust injection and secure provisioning, with up to 250 direct jobs over eight years, according to WISeKey. The governance issue is not the project alone but the shift toward hardware-rooted trust, which changes how identity, device authenticity and provisioning controls must be managed across IoT and critical systems.
NHIMG editorial — based on content published by WISeKey: WISeKey, SEALSQ and Canton of Jura sign MoU to establish a Swiss post-quantum semiconductor and cybersecurity center
By the numbers:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
Questions worth separating out
Q: How should teams govern device identities created by software roots of trust?
A: Teams should govern them like any other machine identity: assign ownership, record lifecycle state, track key material, and define revocation paths.
Q: Why do post-quantum migrations matter for long-lived IoT and embedded systems?
A: Long-lived devices can outlast the cryptographic assumptions they were built on, which creates future exposure even if today’s controls look sound.
Q: What breaks when provisioning evidence is not linked to device ownership?
A: You lose the ability to prove which entity injected keys, issued certificates or personalized the hardware.
Practitioner guidance
- Map device trust anchors end to end Document where root-of-trust keys, certificate chains and firmware-signing credentials are created, injected, stored and rotated across the manufacturing and deployment lifecycle.
- Build a post-quantum migration inventory Identify embedded systems, tokens and IoT platforms that rely on legacy public-key algorithms, then prioritise them by replacement difficulty and exposure window.
- Tie provisioning evidence to identity records Require auditable links between personalization events, hardware serial numbers, attestation data and the owning service identity before devices enter production.
What's in the full analysis
WISeKey's full article covers the strategic and commercial detail this post intentionally leaves for the source:
- Indicative investment structure, financing model and public-private partnership roles for the Jura Center
- Planned job creation, local employment mix and regional industrial development assumptions
- Next-step governance work including site selection, academic partnerships and certification roadmap
- The relationship between the Jura initiative and WISeKey's earlier Murcia model
👉 Read WISeKey's announcement on the Swiss post-quantum semiconductor and cybersecurity centre →
Post-quantum semiconductor trust roots: what changes for IAM teams?
Explore further
Hardware trust is becoming an identity governance problem. When trust anchors move into semiconductor personalization, the question is no longer only whether a device is secure at manufacture. The real issue is whether identity, key material and attestation can be governed across the full lifecycle of the hardware. That aligns device assurance with NHI governance logic, where lifecycle control matters as much as initial issuance.
A question worth separating out:
Q: How do security teams decide whether to prioritise hardware trust or software controls?
A: They should prioritise the control that protects the longest-lived and hardest-to-replace trust anchor. For many IoT and industrial systems, that is hardware-based identity and key provisioning, because software controls cannot fully recover if the underlying device trust chain is compromised.
👉 Read our full editorial: Swiss post-quantum semiconductor centres shift NHI trust models