DigiCert, a global pioneer in intelligent trust, today released findings from its second annual global survey on post-quantum cryptography (PQC), revealing that organisations are preparing for the quantum era but making little measurable progress toward deployment.
Although 87% of organisations report they are planning, testing or implementing PQC initiatives, deployment has increased by just two percentage points since last year's survey. As a result, only 7% of organisations have deployed quantum-safe or hybrid cryptography across most of their digital certificates, underscoring how much work remains to transition from planning to implementation.
Future business requirements
The findings, published in the DigiCert Quantum Readiness Outlook, suggest organisations have moved beyond awareness but are now facing an execution gap. More than half of organisations expect today's encryption standards to be broken within the next five years, while enterprise progress toward becoming quantum ready has only increased by 2% over the past year.
"The move to post-quantum cryptography is part of a broader modernisation journey versus just a technology upgrade," said Kevin Hilscher, Senior Director of Product Management at DigiCert. "Organisations that invest in crypto-agility today are building the flexibility to evolve with changing standards, emerging technologies, and future business requirements. That's what creates long-term resilience. However, this is where the research suggests organisations are now struggling: how to translate strategy into enterprise-wide execution."
Future technology challenge
The urgency continues to grow. Eighty-four percent of organisations believe at least some encrypted data is already vulnerable to harvest now, decrypt later (HNDL) attacks, while the largest share of respondents (39%) expect the transition to quantum-safe cryptography to take three to five years, reinforcing that quantum is no longer viewed as a future technology challenge but a current business risk.
Additional findings include:
- Financial transaction records and banking data were deemed most likely to be targeted first once decryptable, followed by cryptocurrency private keys and wallets.
- 50% have conducted quantum risk assessments, while 44% have developed transition plans and created cryptographic inventories.
- 25.6% identify legacy complexity as the biggest barrier to deployment, replacing uncertainty around standards or executive support.
- Retail reported the lowest levels of preparedness, while Manufacturing emerged as the most divided industry, and MedTech and Telecommunications and Media reported the highest confidence in their readiness.
- The United Kingdom reported the highest share of organisations identifying themselves as edge when it comes to quantum readiness (18%), followed by the United States (17%) and Australia (10%).