IDC - Experts & Thought Leaders
Latest International Data Corporation (IDC) news & announcements
DigiCert, a pioneer in intelligent trust, announces the general availability of DigiCert Quantum Central, part of the DigiCert ONE platform, that helps organizations manage and demonstrate progress toward post-quantum cryptography (PQC) readiness. First introduced in preview in July, Quantum Central offers expanded capabilities that help organizations move from finding cryptographic risks to managing them. Teams can bring together cryptographic data from multiple sources, apply their own security policies, initiate remediation workflows, assign ownership, and track progress from a central location. Trackable readiness program The launch comes as organizations struggle to turn PQC planning into execution. According to the 2026 DigiCert Quantum Readiness Outlook, 87% of organizations are planning, testing or implementing PQC initiatives, yet only 7% have deployed quantum-safe or hybrid cryptography. “Most organizations understand the quantum risk. Their challenge is coordinating action across legacy systems, fragmented data and multiple technology owners,” said Kevin Hilscher, Senior Director of Product Management at DigiCert. “Quantum Central turns cryptographic visibility into a prioritised and trackable readiness program. Teams can begin with a critical environment, act on what they find and expand over time, while giving leadership, auditors and regulators clear evidence of progress.” Cryptographic bills of materials Quantum Central helps security, IT, risk and compliance teams: Create a unified cryptographic inventory: Consolidate and normalise data from DigiCert ONE, network scans, certificate lifecycle management platforms, key vaults, uploaded CSV files and software or cryptographic bills of materials. Establish policies and priorities: Define cryptographic policies based on organizational requirements, industry standards, and regulatory guidance. Quantum Central evaluates inventory data, identifies policy violations and alerts teams when action is needed. Turn findings into remediation: Translate policy violations into recommended actions and create change requests through established workflows, including Jira. Integration with DigiCert Trust Lifecycle Manager enables teams to initiate certificate lifecycle actions directly from their readiness program. Interpret inventory data faster: Use an inventory-aware AI assistant to understand findings, explore cryptographic exposure and identify practical next steps. Measure and report progress: Track remediation status, policy compliance, and overall cryptographic posture through centralized dashboards. Organizations can also export inventory data as cryptographic bills of materials for audits, assessments, and reporting. Connect external systems: Import cryptographic data programmatically through an API, allowing organizations to continue expanding their inventory as their readiness programs mature. Post-quantum readiness “The market is entering the operational phase of post-quantum readiness, and enterprises need a way to connect cryptographic discovery with business context, policy and remediation,” said Jennifer Glenn, Research Director for Information and Data Security at IDC. “Tying inventory, workflows, and reporting to that policy in a single view gives organizations a practical operating model for the complex, multiyear transition to quantum-safe cryptography.” Quantum readiness requires organizations to manage a multiyear technology transition while standards, vendor capabilities and regulatory expectations continue to evolve. Organizations can make practical progress now by assigning accountable owners, establishing enough cryptographic visibility to set priorities, adopting PQC where supported and documenting results. An incremental approach allows teams to begin with a critical application environment or infrastructure layer and expand their program without waiting for a complete enterprise-wide inventory. Complex PKI transition Quantum Central is the management layer for enterprise quantum readiness, spanning cryptographic use cases beyond PKI. DigiCert ONE managers provide the automation layer for certificates, software, devices and content, while DigiCert Private CA and CertCentral provide the trust and issuance foundation needed to put new cryptography into production. That combination helps organizations manage the broader readiness program while preparing for the more complex PKI transition that will unfold over time. DigiCert Quantum Central is available now. Organizations can start a free trial, request a demonstration or contact DigiCert to discuss an enterprise deployment. Resources: Organizations can deploy PQC today to protect their network traffic from harvest now, decrypt later attacks. Read their white paper, Recommendations for Quantum Safe TLS, for more details. Check the quantum readiness of the organizations and others’ websites with their online PQC Checker. Learn the basics about post quantum cryptography and understand the urgency to start quantum readiness now in DigiCert’s PQC for Dummies Guide.
Entrust announces new capabilities for its Cryptographic Security Platform (CSP) that help organizations turn Cryptographic Bill of Materials (CBOMs) data into action. Government agencies, financial institutions, healthcare organizations, and other critical infrastructure operators are navigating increased cyber threats, shorter certificate lifecycles, the rapid growth of machine and AI identities, evolving compliance requirements, and the transition to post-quantum cryptography. Evolving compliance requirements Managing these changes depends on a comprehensive view of where cryptography resides and how assets and systems depend on it. Growing focus on cryptographic inventory and post-quantum readiness from industry groups, standards bodies, and regulators around the world, including the recent U.S. Executive Order and the EU’s DORA and NIS2 regulations requiring CBOMs-based inventories, reinforces the need for organizations to understand their cryptographic assets, dependencies and risk exposure. Organizations can now connect cryptographic discovery and inventory with governance, automation and post-quantum migration planning, helping them identify and address risks across complex environments. With new CBOM import and export capabilities, the Cryptographic Security Platform helps organizations build more complete cryptographic inventories, understand dependencies, and translate cryptographic visibility into operational action. On-premises deployment options For example, organizations can identify cryptographic assets that may be vulnerable or noncompliant, determine which systems and applications depend on them, assess the associated risk, and prioritise remediation efforts. Additionally, the platform can now be deployed as-a-service or on-premises, giving organizations a faster and more flexible way to access the new CBOM capabilities while retaining on-premises deployment options. “A CBOM is more than a static inventory,” said Michael Klieman, Global Vice President of Product Management at Entrust. “Security teams need to connect CBOM data with the systems and applications that depend on cryptography, understand where risk is concentrated and determine what actions to take next. The addition of CBOM support to the platform helps organizations move from documenting cryptographic assets to actively governing and securing them.” Reducing cryptographic risk Once organizations establish visibility into cryptographic assets and dependencies, they must translate that insight into governance, operational resilience, and readiness for future cryptographic change. CSP helps connect discovery with action across each of these areas: Strengthen governance and reduce cryptographic risk: Organizations cannot manage cryptographic risk without understanding where cryptography exists and how assets, systems and applications depend on it. New CBOM import and export capabilities, combined with cryptographic discovery, compliance, and operational health capabilities, help organizations build more complete inventories, correlate inventory data with discovered assets and dependencies, and strengthen governance across keys, certificates, and secrets across the enterprise. Scale certificate operations across complex environments with new Ansible-based capabilities: As certificate volumes grow across public and private PKI environments, organizations need automation that can keep pace with increasingly complex infrastructure. New Ansible-based capabilities extend certificate lifecycle automation, enabling teams to automate certificate deployment and management across highly customized environments at scale, reduce manual effort, and help minimize service disruptions. Prepare for post-quantum and emerging identity requirements with expanded support for composite algorithms and SPIRE-based capabilities: Preparing for post-quantum cryptography starts with understanding where cryptography exists and which systems depend on it. Expanded support for composite algorithms helps organizations pursue phased post-quantum migration strategies while new SPIRE-based capabilities support trusted identities for AI agents and other non-human workloads. CSP is now available as a service or for on-premises deployment, giving organizations greater flexibility to meet operational, security, and data sovereignty requirements. Data sovereignty requirements By connecting cryptographic inventory, governance, automation, and post-quantum readiness in a unified platform, Entrust helps organizations turn cryptographic visibility into action and build the operational foundation for long-term crypto-agility. "Knowing where cryptography lives isn't enough anymore. The number of certificates and other cryptographic material is growing rapidly. Machine and AI identities are multiplying, and the deadline to transition to post-quantum algorithms is closing in. Security teams cannot treat cryptographic inventory as a static exercise. Organizations that connect cryptographic inventory, governance, automation, and post-quantum readiness will be better positioned to manage crypto-agility as standards evolve," said Jennifer Glenn, Research Director for Information and Data Security, IDC.
DigiCert, a pioneer in intelligent trust, introduces a new AI Trust architecture designed to help organizations secure AI systems and their outputs. The company is also unveiling new capabilities to help secure autonomous agents and AI models, along with separate capabilities to provide verifiable content authenticity in the age of AI. Artificial intelligence is accelerating innovation at an unprecedented pace while simultaneously breaking traditional models of trust. Autonomous agents act across enterprise systems at machine speed; AI models introduce new supply chain and IP risks; and digital content can no longer be trusted at face value. At the core of this challenge is a lack of cryptographically verifiable control over AI systems. Specifically, what they are, what they are authorized to do, and what they produce. Embedding cryptographic verification “AI has created a new trust challenge,” said Amit Sinha, CEO of DigiCert. “Organizations are relying on agents, models, and content they can’t always verify. At DigiCert, our purpose is to give people confidence in the security, privacy, and authenticity of their digital interactions. With our AI Trust solution, we help organizations confirm what’s real, secure, and approved so AI can be used with confidence.” To address this challenge, DigiCert is introducing a unified trust layer that spans AI agents, models, and content. By embedding cryptographic verification across the AI lifecycle, organizations can enforce identity-based governance for autonomous systems, validate model integrity, and establish content provenance all within a single, cohesive framework. This unified approach is realised through new DigiCert ONE enhancements: Ensuring verifiable origin Content Trust Manager enables organizations to cryptographically sign and verify digital content, providing tamper-evident provenance and transparency using the C2PA standard, which is adopted by Adobe, Microsoft, Google and more. This allows organizations to prove where content originated, how it was created, and whether it has been altered, helping combat misinformation, brand impersonation, and AI-generated fraud while strengthening confidence in digital media. Taking content authenticity even further, organizations can establish trust at the moment of capture through cryptographic signing and timestamping enabled by embedded C2PA certificates on trusted devices. Delivered through DigiCert Device Trust Manager, this capability allows imaging device manufacturers to embed trust directly into devices such as cameras, microscopes, and scanners. Content can be signed and timestamped at the source, ensuring verifiable origin and authenticity from the start and preserving trust throughout the content lifecycle. Audit autonomous systems AI Agent Trust - Provides discovery, identity, governance, and lifecycle management for AI agents, enabling organizations to authenticate, authorize, and audit autonomous systems. By issuing cryptographic identities and enforcing policy-based controls, DigiCert enables enterprises to govern AI agents like a new digital workforce, ensuring every action is attributable, controlled, and aligned with security and compliance requirements. AI Model Trust - Delivers cryptographic protection and verification for AI models, including secure packaging, signing, and runtime validation. By establishing a verifiable chain of custody for models, from development through deployment, organizations can create models that have not been tampered with, are running in trusted environments, and are handling sensitive data securely, even in distributed or third-party infrastructure. Automated trust architecture Together, these innovations help organizations move from fragmented, manual approaches with an automated trust architecture that delivers verifiable identity, tamper-evident integrity, and continuous validation across AI systems. “AI is forcing organizations to rethink trust from the ground up,” said Jennifer Glenn, Research Director for IDC Security and Trust Group. “Bringing cryptographic assurance to AI systems gives enterprises the ability to independently verify identity, integrity, and provenance of content, enabling these organizations to build trustworthy AI at scale.” Proven PKI principles With a unified AI Trust foundation, organizations can reduce reputational and regulatory risk while accelerating responsible AI adoption. They gain the ability to verify content provenance, ensure model integrity, and govern AI agents with accountability, transforming security and compliance from reactive processes into measurable, audit-ready capabilities. As AI adoption accelerates, the ability to establish and verify trust will become a defining requirement for enterprise success. DigiCert is defining the trust infrastructure required for AI, extending proven PKI principles to agents, models, and content.