That gap says a lot about where the PQC transition stands today. The challenge is increasingly less about convincing organisations that quantum readiness is important, but more about turning awareness, assessments and roadmaps into actual changes across complex technology environments.

Awareness is high, implementation is still low

The DigiCert research surveyed 1,001 IT and cybersecurity decision-makers in the United States, United Kingdom and Australia. The results point to a market that understands the issue. Half of respondents have already carried out a quantum risk assessment, 45% have developed a transition plan and 44% have created a cryptographic inventory.

But large-scale deployment remains limited. That difference matters because preparing for PQC is not the same as implementing it. An organisation can understand its exposure, agree on a strategy and even begin testing new algorithms without yet changing the cryptography embedded across its infrastructure, applications, certificates, devices and third-party services.

The journey from awareness to implementation is where much of the difficult work begins.

The biggest barriers are practical

The survey also gives an important indication of what is slowing organisations down.
Legacy system complexity was the most frequently cited deployment barrier, at 26%. Performance impact and budget constraints followed at 19% each. Skills gaps accounted for 10%, while standards uncertainty, interoperability and executive buy-in were each cited by 8%. Only 3% identified uncertainty about where to start as their biggest challenge.

That changes the nature of the conversation. If organisations broadly understand why PQC matters and where to begin, then another awareness campaign is unlikely to solve the problem. Migration now becomes an execution challenge involving architecture, procurement, budgets, dependencies, governance and long-term planning.

A cryptographic inventory is only the beginning

Knowing where vulnerable cryptography exists is a critical first step. But an inventory only becomes valuable when it informs action. Organisations need to understand which systems carry the greatest risk, which dependencies will be hardest to change, which vendors are responsible for upgrades and where hybrid approaches may be appropriate during the transition.

They also need to distinguish between different cryptographic use cases. Protecting confidentiality, securing digital signatures and maintaining trust in certificates do not necessarily follow the same migration path. The goal is not simply to replace one algorithm with another. It is to build an environment that can adapt as standards, threats and technologies continue to evolve.

Crypto-agility needs to become an organisational capability

That leads to a broader requirement: crypto-agility. A crypto-agile organisation can identify where cryptography is used, evaluate changing security requirements and replace algorithms or protocols without creating major disruption.

That capability becomes more and more important in a post-quantum world. The migration happening today may not be the last cryptographic transition organisations need to make. Standards will evolve. New research will challenge assumptions. Technology stacks will change.

PQC should therefore be approached as part of a longer-term cryptographic strategy instead of a single compliance project with a fixed end date.

Read the original analysis

Want to explore the DigiCert findings, deployment barriers and wider analysis of the PQC readiness gap?

Read the full analysis

Related posts