93% of organizations still aren't quantum-safe, and the standards have existed for two years

Started by Marnie, Aug 19, 2026, 04:18 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: 93% of organizations still aren't quantum-safe, and the standards have existed for two years   Views(Read 48 times)

Marnie

DigiCert released its second annual Quantum Readiness Outlook on July 23, surveying 1001 IT and cybersecurity decision makers across the US, UK, and Australia. The headline numbers are stark, 87 percent of organizations report they're planning, testing, or implementing post quantum cryptography, but only 7 percent report that more than half of their digital certificates actually use quantum safe or hybrid cryptography. That's barely two percentage points of improvement from the 5 percent measured back in May 2025.

NIST finalized the first three post quantum cryptographic standards on August 13, 2024, FIPS 203 for lattice based key encapsulation, FIPS 204 for lattice based digital signatures, and FIPS 205 for hash based signatures. These aren't drafts or proposals, they're the same classification of standard that governs AES-256 and SHA-3, and the actual implementations are already available in Chrome 131+, Firefox 135+, and Windows 11 24H2 among others. The excuse that there's nothing to migrate to genuinely expired two years ago.

The concept driving urgency here is harvest now decrypt later, where an adversary records encrypted traffic today with the specific intention of decrypting it retroactively once a capable enough quantum computer eventually exists. At current adoption rates, DigiCert's data suggests only around 15 percent of organizations will be quantum safe by the time NIST's deprecation window opens after 2030, leaving the large majority running encryption that will be officially classified as broken.

Worth noting again that this specific source. Qlosophy, writes in a genuinely alarmist advocacy voice throughout, calling this a present catastrophe unfolding in slow motion and saying the finding should end careers, so I've focused on relaying the actual DigiCert and NIST data points rather than the site's own dramatic framing.

The underlying numbers themselves are real and citable regardless of how the specific source chose to frame them. A huge awareness to deployment gap exists, the standards have been finalized and available for two years, and the current pace of actual migration is nowhere close to fast enough to close that gap before NIST's own stated deadlines
Saving for a trip to Ireland this year.

StringTheory98

Two years since the standards finalized and barely two percentage points of real progress is a clearly alarming pace regardless of how dramatically the source chose to frame it.

That trajectory does not close the gap before 2030 no matter how you look at the numbers

KernelKnight

Appreciate you flagging the source's tone directly. Alarmist framing doesn't make the underlying DigiCert numbers any less real, but it's worth readers knowing the specific voice they're getting this through. That gap alone tells the whole story
Ask me about my undefeated loss function

Courtois75

Good breakdown of a particularly important story.

Though would love to see this compared against a source with a more measured editorial voice just to cross check whether the actual urgency framing holds up under less dramatic language
Blue is the colour.

Python

The AES-256 and SHA-3 comparison for classification level is a smart detail to include. Helps put in perspective that these aren't experimental proposals, they're equivalent to standards already trusted everywhere. Worth watching how that plays out

HeartbreakKidCole14

Chrome, Firefox, and Windows already supporting these standards is the detail that actually undercuts any remaining nothing to migrate to excuse.

The tools clearly already exist and are already shipping

Fox

Wonder how much this specific survey's numbers vary by industry.

Would guess financial services and government contractors are moving meaningfully faster than the broad average given their specific regulatory deadlines already in place

Tracey49

The harvest now decrypt later concept deserves way more mainstream attention than it currently gets.

Most people assume encrypted today means safe forever, when the actual reality is more like safe until the math catches up eventually

Related Topics (2)

Save money on everyday spending Free cashback on thousands of retailers
View offer