FORTRESS takes the center stage at the CODE-Jahrestagung 2026: From Post-Quantum Research to Real-World Deployment
FORTRESS participated in CODE-Jahrestagung 2026, held on 14 and 15 July 2026 at the University of the Bundeswehr Munich.
Under the theme “Cryptography as a Strategic Key to Digital Defence,” this two-day event brought together representatives from research, industry, public authorities, and the cybersecurity community. The programme featured expert presentations, keynotes, panel discussions, interactive workshops, and a specialist exhibition covering cybersecurity, smart data, and quantum technology.
FORTRESS contributed to the programme through expert presentations, Project booth that presented a live implementation-security demonstration, exhibition activities, and a dedicated workshop on hybrid Roots of Trust and secure boot in the post-quantum era.

Day 1: Digital sovereignty, trusted hardware, and implementation security
A key highlight of the first day was the presentation by Dr. Axel Y. Poschmann from PQShield, titled: “Digital Sovereignty in Permanent Cyber Conflict: From Quantum-Safe Cryptography to Trustworthy Hardware.”
His presentation examined why digital sovereignty has become a central security concern in an environment of persistent cyber conflict. Dr. Poschmann emphasised that the adoption of quantum-safe cryptographic algorithms alone cannot guarantee sovereignty or resilience. Trusted hardware, secure supply chains, and control over critical Roots of Trust are equally important foundations for secure digital infrastructure.
At the FORTRESS booth, eShard delivered a live demonstration illustrating how side-channel leakage can threaten an ML-KEM implementation. The demonstration provided participants with a practical view of implementation-level security and reinforced an important message: post-quantum security does not end with choosing the right algorithm. It also requires secure implementations, thorough evaluation, and effective countermeasures against physical attacks.
Throughout the event, the FORTRESS booth provided a valuable meeting point for exchanges with researchers, cybersecurity practitioners, technology providers, and stakeholders interested in quantum-safe and resilient digital systems.
Day 2: Embedded security in real-world environments

The second day featured a presentation by Prof. Dr. Michael Hutter from the CODE Research Institute and the University of the Bundeswehr Munich, titled: “Embedded Systems Security: When Cryptography Is Deployed in the Field.” His presentation highlighted why cryptographic security depends not only on the mathematical strength of an algorithm, but also on the resilience of its implementation in real-world devices. Embedded systems such as controllers, sensors, and communication modules may operate in environments where attackers can gain physical access to the hardware. In such settings, adversaries often target implementations through side-channel analysis, fault injection, and other physical attack techniques rather than attacking the underlying algorithm directly.
Prof. Hutter also addressed the evolving role of artificial intelligence in embedded security. Machine-learning methods can be used to automate attacks, but they can also strengthen security analysis, verification, reverse engineering, and the development of more effective countermeasures. Drawing on research conducted by the Embedded Systems Security team and within the FORTRESS project, the presentation demonstrated the importance of crypto-agile and physically hardened post-quantum hardware.
The FORTRESS workshop: “PQ/T Hybrid Roots of Trust and Secure Boot in the Post-Quantum Era.”
The workshop participants were welcomed by Uwe Herzog from Eurescom. The workshop brought together researchers, technology providers, and cybersecurity practitioners to discuss recent advances in post-quantum cryptography and their integration into real-world systems. It was designed around the FORTRESS project with the objective of developing a scalable and efficient hybrid secure boot architecture based on a flexible Root of Trust that combines classical and post-quantum cryptographic algorithms with the focus on hardware-software co-design and the trade-offs between security, performance, and cost. These considerations are relevant for embedded systems, edge devices, and Critical National Infrastructure.
The workshop was organized by Prof. Dr. Michael Hutter and featured four complementary technical presentations, then followed by a panel discussion. The presentations were on the topics:

Secure Boot and the Challenge of Post-Quantum Cryptography: Jakob Feldkeller, PQShield
The presentation examined the challenges of integrating post-quantum cryptographic mechanisms into secure boot architectures while maintaining the required levels of security, performance, efficiency, and operational flexibility. It highlighted the role of secure boot as a fundamental starting point for establishing trust within digital systems and explored how the transition to post-quantum cryptography affects existing boot processes and hardware architectures.
A Systematic Approach to the Security Validation of PQC Primitives: Aurélien Vasselle, eShard
This presentation focused on systematic approaches to evaluating the implementation security of post-quantum cryptographic primitives. The talk addressed the importance of analysing implementations for potential side-channel leakage and other physical vulnerabilities, demonstrating why rigorous validation is essential before post-quantum mechanisms can be deployed securely in operational environments.
Trust Doesn’t Stop at Boot: Post-Quantum Secure Communications Need a Living Root of Trust: David Blundell and Gina Zeelie, CyberHive
This contribution explored why trust must be maintained beyond the initial secure boot process and throughout the operational lifetime of a system. The speakers discussed the concept of a living Root of Trust and its role in supporting continuously protected post-quantum secure communications, particularly in distributed and dynamic environments where systems, devices, and communications may remain active for extended periods.
Resource-Sharing Strategies for Area-Efficient Crypto-Agile Hash Accelerators in PQC: Liga Anwar, University of the Bundeswehr Munich
The final technical presentation examined resource-sharing strategies for developing area-efficient and crypto-agile hardware accelerators. The contribution highlighted approaches for supporting multiple post-quantum cryptographic functions while reducing hardware resource requirements. Such flexibility and efficiency are important for embedded systems and edge devices with limited processing capacity, memory, and power.
Together, the four presentations addressed several interconnected aspects of the post-quantum transition, including secure boot, implementation validation, continuously maintained Roots of Trust, secure communications, crypto-agility, and efficient hardware acceleration.The workshop concluded with the panel discussion: “Bridging the Gap: Practical Challenges in Deploying PQ/T Hybrid Secure Boot and Roots of Trust.”
Moderated by Uwe Herzog , the panel brought together:
- Dr. Axel Y. Poschmann, PQShield
- Prof. Dr. Michael Hutter, CODE Research Institute and University of the Bundeswehr Munich
- David Blundell, CyberHive
- Aurélien Vasselle, eShard
The panel moved the conversation from research and technical development towards real-world implementation and deployment. Participants discussed the challenges of integrating post-quantum mechanisms into existing systems, ensuring implementation security, enabling crypto-agility, and balancing security requirements with performance, hardware resources, energy consumption, and cost. The discussion also addressed standardisation, industry adoption, supply-chain considerations, and the practical transition from research results to deployable security solutions.
The panel highlighted that post-quantum migration cannot be addressed by researchers, technology providers, or system integrators in isolation. Successful deployment requires close cooperation between cryptographers, hardware developers, software engineers, security evaluators, standards organisations, policymakers, industry stakeholders, and end users.
Building the foundations of post-quantum security
FORTRESS participation in CODE-Jahrestagung 2026 reflected the project’s central mission: to develop a scalable and efficient hybrid secure boot architecture supported by a flexible Root of Trust that combines traditional and post-quantum cryptographic mechanisms.The discussions across both days reinforced that the transition to post-quantum security requires more than the selection of new cryptographic algorithms. It also demands:
- secure and thoroughly evaluated implementations;
- trusted and physically resilient hardware;
- flexible and crypto-agile architectures;
- efficient hardware-software co-design;
- secure supply chains;
- practical migration strategies;
- and close cooperation between research, industry, public authorities, and technology users.
FORTRESS thanks the CODE Research Institute, the University of the Bundeswehr Munich, all speakers, panelists, participants, and project partners who contributed to the event and made it a valuable opportunity for technical exchange and collaboration.
The insights, discussions, and connections developed at CODE-Jahrestagung 2026 will support FORTRESS as the project continues working towards trusted, resilient, and quantum-ready digital infrastructures for Europe.


