Organisations are stepping up preparations for the quantum era, but many are making little progress in deployment, according to a global survey on post-quantum cryptography (PQC) by security vendor DigiCert.
The study found that 87 per cent of organisations are planning, testing or implementing PQC initiatives, up two percentage points from last year’s findings. Despite the growing level of preparedness, deployment continues to lag, highlighting the challenge of turning strategy into implementation.
According to the survey, only seven per cent of organisations have deployed quantum-safe or hybrid cryptography across most of their digital certificates. According to DigiCert, the findings indicate that significant work is required to transition from planning to implementation.
The urgency of that transition is growing. Over 50 per cent of organisations expect today’s encryption standards to be broken within the next five years, underscoring the growing concerns over the impact of quantum computing on cybersecurity.

The research also found that 84 per cent of organisations believe at least some encrypted data is already vulnerable to harvest now, decrypt later (HNDL) attacks, where cybercriminals steal encrypted data with the hope of decrypting it when quantum computing capabilities mature.
Thirty-nine per cent of respondents expect the transition to quantum-safe cryptography to take three to five years, suggesting that quantum is viewed more as an immediate business risk instead of a future technology issue.
So far, 50 per cent of respondents have conducted quantum risk assessments, and 44 per cent have developed transition plans and created cryptographic inventories.
In terms of the biggest barrier to deployment, 25.6 per cent point to legacy complexity, ahead of uncertainty around standards or executive support.
The findings suggest that organisations have progressed beyond quantum awareness. However, they still face a gap between recognising the quantum threat and translating that to execution.
“The move to post-quantum cryptography is part of a broader modernisation journey versus just a technology upgrade,” said Kevin Hilscher, senior director of product management at DigiCert.
He said organisations that invest in crypto-agility will be better positioned to adapt to evolving standards, emerging technologies and future business needs, strengthening their long-term resilience.
“However, this is where the research suggests organisations are now struggling: translating strategy into enterprise-wide execution,” he added.
The survey also found that financial transaction records and banking data are the most likely to be targeted first once decryptable, followed by cryptocurrency private keys and wallets.
From the sector perspective, retail reports the lowest levels of preparedness, and manufacturing is the most divided industry. Surveyed as having the highest confidence in their readiness are the medtech, and telecom and media industries.
By country, the Britain has the highest number of organisations that say they are leading edge in terms of quantum readiness (18 per cent), followed by the United States (17 per cent) and Australia (10 per cent).
