Miami – – September 19, 2026 -- Qtonic Quantum Corp launched QShield, a software-only post-quantum packet runtime for Linux hosts, and opened paid, operator-led engagements to enterprise and government buyers following a completed 72-hour endurance run that logged 4,107 successful periodic checks and zero failures.
QShield Launches With a Published, Verifiable Test Record
The September 13-16 endurance run connected two Linux hosts across separate AWS availability zones in Oregon, checking connectivity, service status and a 64 KiB transfer roughly every 63 seconds. All 4,107 checks reported success, zero ping loss was recorded, and both daemon paths hashed to the identified build at harvest with zero restarts. The 72-hour gate closed at 04:29 UTC on September 16, and the operator left the overlay running. Qtonic published the run log, build hash, checksums and a verifier that passes 11 of 11 checks so buyers can inspect the result independently.
CNSA 2.0 Deadline Falls 106 Days From Launch
CNSA 2.0 requirements apply to new national security system acquisitions starting January 1, 2027 -- 106 days from the launch date -- while Executive Order 14412 directs covered federal high-value assets and high-impact systems to shift key establishment to post-quantum cryptography by December 31, 2030. Qtonic argues that adversaries can record encrypted traffic today and decrypt it once quantum computing matures, meaning every month of delay adds to what is exposed. A full post-quantum migration takes years; QShield is positioned to protect specific high-value connections in the interim.
Runtime Combines Highest-Tier NIST Parameter Sets
QShield runs a pure post-quantum asymmetric configuration combining ML-KEM-1024 (NIST FIPS 203) for key establishment, ML-DSA-87 (NIST FIPS 204) for endpoint authentication, and AES-256-GCM for packet encryption -- the highest parameter sets in NIST's post-quantum standards and the parameters CNSA 2.0 specifies for national security systems. The tested control channel negotiated ML-KEM-1024 rather than a pre-shared-key mode, and private keys remain on participating endpoints without dependence on a company-operated key-management service. The system is designed to fail closed, blocking protected traffic when required security conditions cannot be maintained. QShield is not represented as FIPS 140-3 validated or government-authorized.
Engagements Target Data-Center and Regulated-Traffic Links
Qtonic is scoping engagements to protect data-center interconnects carrying financial records, research transfers between institutions, clinical-system links, and server-to-server paths carrying regulated or mission information. Deployments begin on company-operated hosts without dedicated encryption appliances at customer endpoints, with each engagement defining supported environment, routing requirements and acceptance criteria. "Information stolen today can remain valuable to an adversary for decades. Organizations need a practical way to begin protecting it now," said Col. Reginald M. Harris, U.S. Army (Ret.), Government Affairs at Qtonic Quantum Corp and former Chief of Staff of U.S. Army Cyber Command. With customer approval, Qtonic will publish an agreed evidence package for each engagement, tying run logs to the tested build via cryptographic hashes.