SecurityBrief Canada - Technology news for CISOs & cybersecurity decision-makers
Canada
Post-quantum cryptography adoption stalls, DigiCert finds

Post-quantum cryptography adoption stalls, DigiCert finds

Tue, 28th Jul 2026 (Yesterday)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

DigiCert has published new research on enterprise adoption of post-quantum cryptography, showing that deployment progress has barely moved over the past year.

According to the survey, 87% of organisations are planning, testing or implementing post-quantum cryptography initiatives, yet only 7% have deployed quantum-safe or hybrid cryptography across most of their digital certificates. That is up just two percentage points from the previous year, suggesting many companies remain stuck in the preparation stage.

The findings point to a widening gap between awareness of quantum-related risks and the practical work needed to update security systems. More than half of respondents expect current encryption standards to be broken within five years, while 84% believe at least some encrypted data is already exposed to harvest now, decrypt later attacks.

That concern reflects a long-standing fear in cybersecurity: attackers could steal encrypted information now and hold it until more advanced quantum systems can read it. The largest share of respondents, 39%, said moving to quantum-safe cryptography would take between three and five years.

Financial transaction records and banking data ranked as the information most likely to be targeted first if encrypted material becomes readable. Cryptocurrency private keys and wallets followed close behind, suggesting respondents see immediate financial assets as the first point of pressure.

Half of the organisations surveyed said they had carried out quantum risk assessments. Another 44% said they had developed transition plans and built cryptographic inventories, both considered basic steps in identifying where vulnerable encryption sits within a business.

Execution gap

The data suggests the main challenge has shifted from recognising the issue to acting on it. Legacy complexity was cited by 25.6% of respondents as the biggest barrier to deployment, overtaking uncertainty around standards and executive backing.

That marks a shift in the post-quantum cryptography debate. Earlier discussions often focused on the lack of settled standards and the challenge of securing board-level attention. The latest responses suggest many organisations now see ageing systems and fragmented technology estates as the main obstacle.

Kevin Hilscher, Senior Director of Product Management at DigiCert, said the transition requires broader change than simply replacing encryption tools.

"The move to post-quantum cryptography is part of a broader modernisation journey versus just a technology upgrade," said Kevin Hilscher, Senior Director of Product Management at DigiCert.

"Organisations that invest in crypto-agility today are building the flexibility to evolve with changing standards, emerging technologies, and future business requirements. That's what creates long-term resilience. However, this is where the research suggests organisations are now struggling: how to translate strategy into enterprise-wide execution."

Sector divide

The survey also highlighted uneven levels of preparedness across industries. Retail reported the lowest readiness levels, while manufacturing showed the most mixed results, suggesting significant variation between companies in the sector. MedTech and telecommunications and media recorded the highest confidence in readiness.

Those differences matter because the work involved in replacing or updating cryptographic systems varies sharply by industry. Businesses with large numbers of connected devices, ageing software environments or long technology replacement cycles may find migration harder than sectors with more centralised systems.

Country results

Among the three countries surveyed, the United Kingdom had the highest proportion of organisations describing themselves as leading edge on quantum readiness, at 18%. The United States followed at 17%, while Australia stood at 10%.

The research was based on a survey of 1,001 IT and cybersecurity decision-makers in the United States, United Kingdom and Australia, conducted by Propeller Insights on behalf of DigiCert. The results suggest concern over the impact of quantum computing on encryption is now well established among large organisations, but turning that concern into implementation remains slow.

Long transition times, concern over harvest now, decrypt later risks and the persistence of old infrastructure mean many companies may spend the next several years trying to modernise cryptographic systems while still relying on existing standards. For security teams, that creates a difficult balance between preparing for a future threat and protecting systems already under pressure today.