DigiCert has released the findings of its second annual global survey on post-quantum cryptography (PQC), showing that while organisations are actively preparing for the quantum era, measurable progress toward deployment remains minimal.
According to the company’s newly published Quantum Readiness Outlook, 87% of organisations say they are planning, testing or implementing PQC initiatives. Yet deployment has increased by just two percentage points since last year’s survey, leaving only 7% of organisations with quantum-safe or hybrid cryptography deployed across most of their digital certificates.
The report, based on a survey of 1,001 IT and cybersecurity decision-makers across the United States, United Kingdom and Australia, points to what DigiCert describes as a widening “execution gap”: organisations have largely moved past the awareness stage, but are struggling to translate strategy into enterprise-wide implementation.
More than half of respondents (50%) believe current encryption standards could be broken within the next five years, while 85% expect them to be broken within a decade. Despite that shortening timeline, enterprise progress toward quantum readiness has increased by only two percentage points over the past twelve months.
“The move to post-quantum cryptography is part of a broader modernisation journey versus just a technology upgrade,” said Kevin Hilscher, Senior Director of Product Management at DigiCert. “Organisations that invest in crypto-agility today are building the flexibility to evolve with changing standards, emerging technologies, and future business requirements. That’s what creates long-term resilience. However, this is where the research suggests organisations are now struggling: how to translate strategy into enterprise-wide execution.”
The urgency behind the transition is also being driven by so-called “harvest now, decrypt later” (HNDL) attacks, in which adversaries collect encrypted data today with the intention of decrypting it once sufficiently powerful quantum computers become available. Eighty-four percent of organisations believe at least some of their encrypted data is already vulnerable to this type of attack, and more than a third believe over 25% of their encrypted data is exposed. The largest share of respondents (39%) expect the transition to quantum-safe cryptography to take between three and five years, reinforcing that quantum risk is increasingly viewed as a present-day business concern rather than a distant technical one.
Financial transaction records and banking data were identified as the assets attackers are most likely to target first once quantum decryption becomes feasible, followed by cryptocurrency private keys and wallets. Respondents also pointed to corporate IP, government and military data, and politically sensitive material, citing high-profile leak events as examples of information that could remain valuable to attackers for years to come.
Additional findings
- Financial transaction records and banking data were deemed most likely to be targeted first once decryptable, followed by cryptocurrency private keys and wallets.
- 50% of organisations have conducted quantum risk assessments, while 44% have developed transition plans and created cryptographic inventories.
- 6% of respondents identify complexity across legacy systems as the biggest barrier to deployment, ahead of budget constraints and performance impact, and displacing uncertainty around standards or lack of executive support as the primary obstacle.
- Retail reported the lowest levels of preparedness of any major industry, while Manufacturing emerged as the most divided sector, with respondents split between feeling highly prepared and not prepared at all. MedTech and Telecommunications & Media reported the highest confidence in their readiness.
- The United Kingdom reported the highest share of organisations identifying themselves as leading edge on quantum readiness (18%), followed by the United States (17%) and Australia (10%).
Industry and regulatory pressure building
DigiCert’s report notes that the window for organisations to prepare is narrowing as major technology vendors and governments accelerate their own timelines. Google has targeted 2029 for its migration to PQC, and Microsoft has since committed to a similar strategy, while a recent U.S. Executive Order is pushing the federal government to accelerate its own transition. The publication of the National Institute of Standards and Technology’s (NIST) post-quantum cryptography standards in August 2024 has also given organisations a clearer technical path forward, which DigiCert says has helped accelerate planning, though not yet deployment, across industries.
Most leaders surveyed believe it will take three to five years to deploy quantum-safe encryption enterprise-wide, with complexity across legacy systems cited as the top barrier to making that happen.
Commenting on the research, Simon Pamplin, CTO of Certes, said, “These findings highlight a growing disconnect between awareness and action. If 85 percent of IT and security leaders believe quantum computers will break today’s encryption within the next decade, yet only 7 percent have deployed quantum-safe solutions at scale, it’s clear that organisations understand the risk but are struggling to turn strategy into execution.
What’s particularly concerning is that more than a third of UK organisations believe over a quarter of their encrypted data is already vulnerable to ‘harvest now, decrypt later’ attacks. For organisations handling financial data, customer records and personally identifiable information, this is no longer a future planning exercise. Data being stolen today will be exposed years from now if it isn’t adequately protected.
The biggest obstacle isn’t awareness, it’s the absolute complexity of implementing cryptographic change across legacy applications, hybrid environments and edge infrastructure that were never designed with crypto agility in mind. That’s why organisations need to stop thinking about post-quantum cryptography as simply replacing algorithms. They should be focusing on protecting the data itself with a data-centric, crypto-agile approach that reduces risk today while creating a practical path to long-term quantum readiness.”

