Seven Weeks, One Owner, and Every Signed Artifact You Ship
A forced cryptographic migration lands inside the quarter you close revenue in, and the artifacts most likely to break are the ones you did not build.
The inventory is the hard part
Microsoft owns the migration. The inventory belongs to whoever ships the software, and it runs wider than the release train: installers, kernel drivers, endpoint agents, auto-updaters, build-time signing steps, and the signed third-party components a vendor redistributes without having written. Auto-updaters go first, because a client that cannot validate a new signature cannot deliver its own fix. After that point remediation takes a human touch per install, which makes it a support-cost problem rather than an engineering one.
Risky Business's reporting leaves no room on the developer warning. Microsoft has said apps will break, and has put completion at mid-October. That converts a cryptography roadmap slide into a release-calendar dependency with no negotiating counterparty. There is no extension to request, and by default nobody on the software vendor's side owns the date.
Why finding it late costs roughly ten times more
The same fix carries two prices. Found now, it is an inventory exercise and a test matrix. Found in a customer escalation, it becomes an emergency release, a support surge, a trust conversation with the largest accounts, and the opportunity cost of engineers who were supposed to be shipping Q4 features, all of it landing during quarter close. An internal cutover of October 1 buys two weeks of buffer against a date held by someone else.
Turn the fire drill into a capability
This is one in a series of forced cryptographic migrations, not a one-time event. Treated as an emergency each time, it carries the emergency premium annually. Funded as a named platform capability, crypto-agility gets paid for once: centralized signing, pluggable primitives, no hardcoded algorithm assumptions, and an enterprise security questionnaire that answers cleanly. That is the part with revenue attached: within three years, crypto-agility is a procurement question in regulated and enterprise deals, not platform hygiene competing for sprint capacity.
The concentration quantified
The same body of reporting covers a 10.0-severity remote code execution flaw in Entra ID (CVE-2026-69836), a one-click Copilot data-exfiltration bug (CoSnitch, CVE-2026-24301), an advisory published with an exploitation flag enabled by mistake, and this breaking change to the distribution trust those products depend on. All patched, and individually routine. Collectively they put a number on something most technology companies have never actually modeled: identity, agentic data access, and software distribution trust in one supplier.
A reasonable skeptic says Microsoft remains the safest place to hold those dependencies, and the skeptic is probably right. The question was never whether Microsoft is secure. It is the size of the blast radius, and whether detection survives a vendor advisory being wrong, which already happened. The detail worth sitting with is that the Copilot bug was surfaced by Copilot itself during normal use. AI assistants create self-revealing data paths existing monitoring was never designed to observe, which means the vendor's telemetry and a customer's own are not interchangeable.
Post-quantum cryptography stopped being a 2030 roadmap item the moment Microsoft put a mid-October date on it.
The board-reportable version is two lines: the date signed artifacts are verified against the new chain, and the detection held in-house that does not depend on a Microsoft advisory being accurate. Neither line requires a strategy change. Both require an owner.
What to do
Name one accountable engineering owner and produce a complete inventory of signed artifacts — installers, drivers, agents, auto-updaters and redistributed third-party components — by September 5.
Freeze the Q4 release calendar around an internal signing cutover of October 1, two weeks ahead of Microsoft's completion date.
Fund crypto-agility as a named platform capability in the next planning cycle: centralized signing, pluggable primitives, no hardcoded algorithm assumptions.