DigiCert, a significant player in the field of intelligent trust, has published the results of its second global study on post-quantum cryptography (PQC). The research highlights that while numerous organisations are gearing up for the quantum era, measurable progress towards implementing these technologies remains limited.
According to the survey, 87% of organisations are involved in planning, testing, or implementing PQC projects. However, actual deployment has seen a marginal increase of only two percentage points since last year. Currently, just 7% of businesses have adopted quantum-safe or hybrid cryptography for the majority of their digital certificates, indicating a substantial gap between planning and action.
Future business requirements
The DigiCert Quantum Readiness Outlook findings demonstrate that, despite a widespread awareness of PQC, organisations face challenges in execution. Over half of the surveyed entities predict that current encryption protocols will become obsolete within five years. Nevertheless, enterprise advancement toward quantum readiness has grown by a mere 2% over the previous year.
Enterprise advancement toward quantum readiness has grown by a mere 2% over the previous year
Kevin Hilscher, Senior Director of Product Management at DigiCert, stated, "The move to post-quantum cryptography is part of a broader modernisation journey versus just a technology upgrade. Organisations that invest in crypto-agility today are building the flexibility to evolve with changing standards, emerging technologies, and future business requirements. That's what creates long-term resilience. However, this is where the research suggests organisations are now struggling: how to translate strategy into enterprise-wide execution."
Future technology challenge
The sense of urgency around quantum readiness is growing stronger as 84% of organisations believe that some encrypted information is exposed to harvest now, decrypt later (HNDL) threats. Most survey participants anticipate a three to five-year timeline for transitioning to quantum-safe cryptography, highlighting its status as a present-day business concern rather than a future issue.
Additional key findings indicate:
- Financial transaction records and banking information are considered the most immediate targets for post-quantum decryption, followed by cryptocurrency assets.
- Half of the organisations have undertaken quantum risk assessments, while 44% have created plans and inventories to manage the shift.
- Legacy system complexity is identified by 25.6% as the primary deployment hurdle, surpassing uncertainties regarding standards or lack of executive support.
- The retail sector demonstrates the least preparedness, in contrast to manufacturing, which presents a varied readiness level, and MedTech, Telecommunications, and Media industries show the greatest confidence in their quantum preparedness.
- The UK leads with the highest percentage of firms recognising themselves as advanced in quantum readiness (18%), succeeded by the US (17%) and Australia (10%).
