Summary
- OpenSSL Conference 2026 takes place in Prague from 13 to 15 October, with technical tutorials on 12 October.
- Post-quantum cryptography, FIPS, regulation and open-source security feature across the programme.
- Cryptographic migration is becoming an infrastructure and supplier-management issue rather than a specialist research exercise.
OpenSSL will bring post-quantum migration, cryptographic regulation and the sustainability of critical open-source infrastructure together in Prague this October as the transition away from existing public-key algorithms moves deeper into technology planning.
OpenSSL Conference 2026 will run from 13 to 15 October at the Diplomat Hotel in Prague, with a separate technical tutorials day scheduled for 12 October. The programme brings maintainers, researchers, developers and policy specialists together around technologies that underpin encrypted communication across large parts of the internet.
The OpenSSL Library is embedded directly or indirectly in operating systems, applications, network appliances, cloud services and connected products. Changes to the cryptographic standards it supports can therefore propagate across technology estates far beyond organisations that consciously regard themselves as OpenSSL users.
Post-quantum cryptography makes those dependencies particularly difficult. A cryptographically relevant quantum computer capable of breaking widely used public-key algorithms has not yet emerged, but migration cannot begin only when such a machine becomes available.
Organisations may retain sensitive information for years, while hardware, industrial systems and embedded products can remain operational for a decade or longer. Cryptography is also frequently buried inside third-party components and software libraries, making it difficult to establish where vulnerable algorithms are still in use.
The practical work therefore begins with inventory and cryptographic agility: identifying where certificates, keys and algorithms are used, understanding which suppliers control them and determining whether systems can move to new schemes without being replaced wholesale.
OpenSSL has already been adding support for post-quantum technologies while maintaining compatibility with conventional deployments. The conference programme places that technical work beside questions around FIPS validation, national standards, regulatory divergence and the security responsibilities attached to open-source infrastructure.
Those issues are increasingly connected. A new cryptographic algorithm may be technically available before it is approved for a regulated deployment, while organisations operating across jurisdictions may face different assurance requirements. Migration programmes must therefore account for certification and procurement timelines as well as cryptographic strength.
The sustainability of open-source maintenance adds another dependency. Widely used components can be maintained by teams whose resources bear little relationship to the number or importance of downstream users. Introducing new algorithms, maintaining legacy interfaces and responding to vulnerabilities all increase the burden on those projects.
Governments and large technology suppliers have increasingly recognised that imbalance as a software supply chain issue. OpenSSL’s position near the bottom of the technology stack makes it a particularly clear example: organisations may depend heavily on the project even where no direct commercial relationship exists.
The conference is not itself a regulatory deadline, and post-quantum adoption will not occur on a single date. Its agenda instead reflects the point at which cryptographic transition is becoming a normal infrastructure concern involving architecture, suppliers, compliance teams and long-term asset planning.
Organisations that cannot identify where cryptography sits across their estate will struggle to determine which systems require migration, which suppliers must act and which dependencies cannot be changed quickly. By the time quantum capability becomes an immediate threat, much of that discovery work will already need to have been completed.




