top of page

DigiCert's 2026 Quantum Readiness Outlook

  • Writer: Brian Couzens
    Brian Couzens
  • 9 hours ago
  • 2 min read

Every week I see organisations announcing their Post-Quantum Cryptography strategy.


Strategies.


Roadmaps.


Working groups.


Steering committees.


Pilot programmes.


Then along comes some actual data.


DigiCert's 2026 Quantum Readiness Outlook surveyed 1,001 IT and cybersecurity decision-makers across the United States, United Kingdom and Australia.


87% say they are planning, testing or implementing PQC.


Only 7% have deployed quantum-safe or hybrid cryptography across most of their digital certificates.


Read that again.


87% talking about it.


7% actually doing it.


That's not a maturity gap.


It's an execution failure.


For the second consecutive year, deployment has barely moved. A two percentage point increase is not progress. It is evidence that enterprise migration has stalled.


This should concern every board.


Certificates underpin TLS, APIs, VPNs, code signing, machine identities and enterprise PKI. If your certificate estate hasn't materially migrated, your organisation hasn't materially migrated. It's that simple.


What worries me even more is another finding from the survey.


More than half of respondents believe today's encryption could be broken within five years.


So organisations believe the risk is real...


...yet the overwhelming majority have not deployed the controls.


That is the very definition of a governance failure.


This is why I keep saying that a PowerPoint presentation is not a security control.


Neither is a steering committee.


Neither is a roadmap.


Neither is a pilot.


Until quantum-safe cryptography is operating in production, risk has not been reduced.


As the NIST and UK NCSC migration timelines continue to close in, organisations need to stop confusing activity with achievement.


The board should be asking only a handful of questions:


• What percentage of our certificate estate has actually migrated?

• Can management prove it with evidence?

• What remains dependent on classical cryptography?

• What is preventing deployment?


If management cannot answer those questions with objective evidence, then they are not reporting progress.


They are reporting intent.


Intent does not protect organisations.


Deployment does.



 
 
 

Comments


bottom of page