DigiCert’s Global Survey Reveals a Slow Progress in Post-Quantum Cryptography Deployment
In its second annual global survey on post-quantum cryptography (PQC), DigiCert has highlighted significant findings that indicate while organizations are gearing up for the anticipated quantum era, the tangible advancement towards deployment remains sluggish. This survey is instrumental in understanding organizations’ readiness and highlights an unsettling gap between strategies devised and actual implementation.
The survey results, which drew insights from 1,001 IT and cybersecurity decision-makers across the United States, the United Kingdom, and Australia, reveal that an overwhelming 87% of organizations express intentions to plan, test, or implement PQC initiatives. However, an analysis of deployment figures unveils a disheartening reality: there has only been a two-percentage point increase since the previous year, with merely 7% of organizations having quantum-safe or hybrid cryptography integrated across a majority of their digital certificates.
DigiCert characterizes this phenomenon as an “execution gap.” It appears that while many organizations have transitioned past mere awareness of quantum risks, they are grappling with the challenge of actualizing their strategies into enterprise-wide execution. Such a discrepancy underlines a critical issue within the cybersecurity landscape, revealing the complexities and obstacles organizations face in effectively transitioning to more secure cryptographic measures.
Notably, the urgency for this transition has been fueled by the looming threat of “harvest now, decrypt later” (HNDL) attacks. In these scenarios, adversaries collect encrypted data ostensibly to decrypt it once quantum computing capabilities have advanced sufficiently. Alarmingly, 84% of respondents in DigiCert’s survey believe that a portion of their encrypted data is vulnerable to these types of attacks. Over a third of respondents have raised concerns that more than 25% of their encrypted data may already be at risk. An overwhelming majority foresee the shift to quantum-safe cryptography taking between three and five years, concurrently reinforcing the notion that the risks associated with quantum computing are increasingly perceived as immediate business threats, rather than distant technical challenges.
The survey also spotlighted which assets are most likely to attract the attention of attackers once quantum decryption becomes feasible. Financial transaction records and banking data emerged as the prime targets, closely followed by cryptocurrency private keys and wallets. Other areas of concern include corporate intellectual property, government and military data, and politically sensitive materials—especially relevant in the light of recent high-profile leaks, which underline the long-term value such information holds for potential attackers.
Among the additional findings, it was noted that while 50% of organizations have initiated quantum risk assessments, 44% have outlined transition plans and created comprehensive cryptographic inventories to navigate the impending quantum landscape. Intriguingly, complexity surrounding legacy systems emerged as the most significant barrier to deployment, as highlighted by 6% of respondents, overtaking budget constraints and the uncertain trajectory of standards as primary challenges. Certain sectors, such as retail, displayed alarmingly low levels of preparedness, while the manufacturing industry appeared divided, revealing varying degrees of readiness. Conversely, sectors like MedTech and Telecommunications & Media expressed the highest confidence in their preparedness.
Further complicating the landscape of quantum readiness is the escalating pressure from industry and regulatory bodies. DigiCert notes the tightening timeline as major technology players and governments expedite their migration toward post-quantum cryptography. For instance, Google has set a target year of 2029 for its transition, with Microsoft following suit in its commitments. A recent U.S. Executive Order also aims to hasten the federal government’s transition, alongside the anticipated publication of the National Institute of Standards and Technology’s (NIST) post-quantum cryptography standards in August 2024, which are expected to offer a clearer, technical roadmap for organizations.
Despite these developments, survey participants believe that a comprehensive deployment of quantum-safe encryption at enterprise level could take anywhere from three to five years, with legacy system complexity identified as the foremost barrier to achieving this goal.
Simon Pamplin, CTO of Certes, emphasized the implicit disconnect between awareness and action highlighted in the report. With 85% of IT and security leaders recognizing the high risk of quantum computing breaching current encryption methods within the next decade, yet only 7% having established large-scale quantum-safe solutions, it becomes clear that while organizations comprehend the risks, they struggle to translate their strategies into effective execution.
Pamplin further voiced the urgency of protecting sensitive data, particularly for organizations handling financial information, stating that the theft of data today could lead to significant repercussions in the years to come if adequate protective measures are not implemented. He specified that the challenge lies not merely in algorithm replacement but in enacting a data-centric, crypto-agile methodology that mitigates present risks while paving the way toward long-term quantum readiness.
In summary, while the DigiCert survey reveals a keen awareness among organizations about the impending quantum threat, it underscores a pressing need for effective strategies to bridge the gap between planning and execution in the journey towards post-quantum cryptography. As the landscape evolves, organizations must take proactive steps not just to adapt, but to secure their digital future effectively.

