MyID® CMS Enterprise 2026.1.0 is a significant release, adding new capabilities across three areas: preparing credentials for the post-quantum era, giving administrators more control over how strong credentials are issued, and tightening how permissions and multiple identity systems are managed. It also moves MyID CMS to a new calendar-based versioning scheme, so customers get clearer information about the age of a release and a predictable rhythm for upgrade planning.
The headline change is the beginning of our post-quantum support: MyID CMS 2026.1 can now issue software certificates using the algorithms NIST finalised in 2024. Alongside it, the release adds administrator-led FIDO passkey issuance, biometric-only passkey collection, Microsoft Entra ID permission control and tighter multi-tenant management. Here is what each change does and why it matters.
Post-quantum certificate support in MyID CMS 2026.1
MyID CMS 2026.1 can now issue software certificates built on the NIST-standardised post-quantum algorithms. Two algorithms are supported: ML-DSA (Module-Lattice-Based Digital Signature Algorithm) for signing, and ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism) for key establishment. Both were designed to replace the RSA and elliptic-curve cryptography that a large enough quantum computer could one day break.
The first step in a phased rollout across the MyID suite
Software certificates are the first stage in our roll out of Post Quantum support and will start to showcase our crypto agility capabilities. You can read more on our plans here.
The rest of the 2026.1 release strengthens day-to-day credential control
Beyond post-quantum support, MyID CMS 2026.1 adds practical control over how credentials are issued and who can issue them. Three changes stand out.
Administrator-led FIDO passkey issuance for faster onboarding
An administrator can now register a FIDO passkey on a security device, a step that is normally left to the end user. The administrator can set a randomised PIN and hand it over separately, require the user to change that PIN at first use, and, when the passkey is used within Entra ID, set a shortened lifetime that suits temporary access. For a new starter, it means a fully prepared security key can be waiting on day one instead of being set up after they arrive.
Biometric-only passkey collection to stop device sharing
MyID CMS 2026.1 also supports collecting a FIDO passkey that requires a fingerprint to authenticate, on biometric-enabled security keys. The device PIN is set to a random value and never distributed, so fingerprint is the only way to authenticate, and no fingerprints can be added without that PIN. The result is a credential that ties use to a specific person and makes casual device sharing far harder.
Entra ID security groups and multi-tenant control
Permissions in MyID CMS can now be driven by Microsoft Entra ID security groups, so policy set in Entra flows through to which credential profiles a user can receive and what an operator can do. Group membership synchronises on demand or on a schedule, and works with both static and dynamic Entra ID groups. Alongside this, a single MyID deployment can manage a mix of identity systems, including many Entra ID tenants at once, which suits organisations running separate business units or offering credential management as a service.
See MyID CMS 2026.1 in action. Book a demo to see how quantum-safe certificate issuance, administrator-led passkey enrolment and Entra ID policy control work on infrastructure you already run.
