The PQC Execution Gap: 87% Plan, Only 7% Deploy

The PQC Execution Gap: 87% Plan, Only 7% Deploy

DigiCert's 2026 survey finds 87% of firms are planning post-quantum cryptography, but only 7% have deployed it. Here's what's actually blocking rollout.

DigiCert put out its second annual Quantum Readiness Outlook this week, and the headline number is the kind that makes you reread it twice. Eighty-seven percent of organizations say they’re planning, testing, or implementing post-quantum cryptography. Only 7% have actually deployed quantum-safe or hybrid crypto across most of their digital certificates. Last year that second number was 5%. Two points of real progress in twelve months, against a planning figure that’s been near-universal for a while now.

DigiCert calls this the “execution gap,” and it’s a useful label because it names something a lot of security teams already feel but haven’t put a number on: everyone has a PQC slide in their roadmap deck, and almost nobody has shipped anything.

The survey behind the number

Propeller Insights ran the study for DigiCert in May, polling 1,001 IT and cybersecurity decision-makers across the US, UK, and Australia. It’s a self-reported survey of organizational posture, not a technical scan of live traffic, which matters for how you read it. A study we covered here last week measured actual TLS handshakes across roughly 32,000 domains and found 49.3% already negotiating hybrid post-quantum key exchange. That’s a much higher number than 7%, and both can be true at once: enabling a hybrid key-exchange group on your TLS termination is a config change, while reissuing your certificate fleet on new algorithms is a fleet-wide project with a CA, a trust store, and a compliance team all needing to sign off. The gap between those two studies is basically the gap between key exchange and certificates, playing out again at the survey level.

What’s more telling than the deployment number is what respondents said is stopping them. In DigiCert’s first survey, the top blockers were the usual soft ones: uncertainty about which standards would stick, and lack of executive buy-in. This year, 25.6% point to legacy system complexity as the biggest barrier, and it’s now the top answer. That’s a different kind of problem. Standards uncertainty gets fixed by NIST publishing a FIPS number. Executive buy-in gets fixed by a good slide deck and a scary headline. Legacy complexity gets fixed by someone spending eighteen months finding every hardcoded RSA dependency in a codebase nobody’s touched since 2014, and that’s not a problem you solve by waiting.

Everyone agrees it’s urgent, which isn’t the same as acting

The survey’s other numbers back up the pattern. Eighty-four percent of respondents believe at least some of their encrypted data is already exposed to harvest-now-decrypt-later attacks, where an adversary records ciphertext today and waits for a quantum computer capable of breaking it. More than half expect current encryption standards to be broken within five years. Financial transaction records and banking data top the list of what people expect to be targeted first once that happens, with cryptocurrency wallets close behind.

So the risk perception is there. Half of organizations say they’ve run a quantum risk assessment, and 44% have built a transition plan and a cryptographic inventory. Those are the right first steps, and they’re also the easy half of the project: assessments and plans are documents. What comes next, actually rotating keys, reissuing certs, and validating that every downstream system can handle the new algorithm and its bigger handshake, is where organizations keep stalling out.

There’s a regional wrinkle worth a mention too. The UK reported the highest share of self-identified “leading edge” organizations at 18%, ahead of the US at 17% and Australia at 10%. Retail came in as the least prepared industry, while manufacturing was the most internally divided, some manufacturers well along, others barely started. MedTech and telecom reported the most confidence, which tracks with both sectors already living under heavier compliance regimes that force cryptographic inventory work regardless of quantum.

What to do with this if you’re the one running the migration

If your organization is sitting comfortably in the 87%, ask a sharper question than “are we planning.” Ask what your actual barrier is, and who owns removing it. If the honest answer is legacy complexity, that’s not a problem a policy document solves. It needs a named owner, a budget line, and a realistic multi-quarter timeline for finding and replacing hardcoded cryptographic dependencies, one system at a time.

DigiCert’s Kevin Hilscher framed PQC as part of a broader crypto-agility investment rather than a one-time algorithm swap, and that’s the right lens. The organizations that treat this as “buy new certs, flip a flag” are going to keep showing up in next year’s survey still stuck at single digits. The ones that treat it as an ongoing capability, inventory your crypto, build the tooling to rotate it without a fire drill, and keep that muscle exercised as standards keep shifting, are the ones who’ll actually close the gap instead of just measuring it again in July 2027.