Windows hybrid-signing pilot
Enterprise application and endpoint teams
Introduce a controlled hybrid-signature profile without breaking existing Windows application workflows.
Architecture pattern
- Windows CNG/KSP provider
- Hardware-backed key custody
- Classical and PQC signature orchestration
- Signed corpus and independent verification
Success criteria
- Exact Windows/provider/application manifest
- Repeatable sign and verify result
- Performance and object-size report
- Documented fallback and rollback
