We're nowhere close to being able to do this, as we need Bouncy Castle and PKI.js to have implementations of post-quantum algorithms -- and, of course, they must be compatible with each other, so we also need RFCs that update CMS to support such algorithms. Nevertheless, I think it's important to start tracking this work.
As a stopgap solution, we could use RFC 8696, but we'd have to patch Bouncy Castle and PKI.js as I don't think they support that RFC.