The code isn’t actually the hardest part but rather procuring a HSM with support for PQC. Believe it or not but Arch Linux doesn’t have the same financial backing as RedHat.
We did consider it though, you can see the exact list and reasoning at https://rfc.archlinux.page/0059-automated-digital-signing-of-os-artifacts/#alternatives-considered
If there are any hardware vendors that'd happily sponsor these I’m all ears.
The FOSDEM talk is definitely on our radar, thanks and have a nice day! 👋