DigiCert has unveiled results from its second annual global survey on post-quantum cryptography (PQC), highlighting a growing awareness among organizations to prepare for the quantum era, though actual progress in deployment lags.
The survey indicates that while 87% of organizations are engaged in planning, testing, or implementing PQC strategies, the rate of deployment has only modestly increased by two percentage points compared to the previous year. Only 7% of organizations have implemented quantum-safe or hybrid cryptography for most of their digital certificates, illustrating the substantial effort still needed to move from planning to practical execution.
Future Business Requirements
The DigiCert Quantum Readiness Outlook reveals that organizations have surpassed the awareness phase but are encountering challenges in execution. Over 50% of organizations anticipate that current encryption standards will be compromised within five years, yet there has been only a 2% increase in becoming quantum-ready over the past year.
Kevin Hilscher, Senior Director of Product Management at DigiCert, noted, "The move to post-quantum cryptography is part of a broader modernization journey versus just a technology upgrade. Organizations that invest in crypto-agility today are building the flexibility to evolve with changing standards, emerging technologies, and future business requirements. That's what creates long-term resilience. However, this is where the research suggests organizations are now struggling: how to translate strategy into enterprise-wide execution."
Future Technology Challenge
Nevertheless, 25.6% cite legacy complexity as the primary obstacle to deployment
Urgency around quantum readiness is escalating, with 84% of organizations acknowledging that some encrypted data might be susceptible to "harvest now, decrypt later" (HNDL) threats. The majority of respondents, 39%, predict that transitioning to quantum-safe cryptography will require three to five years, reflecting a shift from viewing quantum as a future challenge to recognizing it as a present business risk.
Key findings from the survey reveal that financial transaction records and banking data are perceived as the most likely initial targets once decryptable, followed by cryptocurrency private keys and wallets. Half of the respondents have carried out quantum risk assessments, and 44% have developed transition plans and established cryptographic inventories.
Nevertheless, 25.6% cite legacy complexity as the primary obstacle to deployment, surpassing uncertainties about standards or executive endorsements. Among industries, Retail shows the lowest level of preparedness, whereas Manufacturing is the most polarized, with MedTech and Telecommunications and Media expressing the greatest confidence in their quantum readiness. Geographically, the United Kingdom leads in organizations viewing themselves as on the cutting edge of quantum readiness with 18%, followed by the United States at 17% and Australia at 10%.
