Post-Quantum Cryptography Readiness: Planning Surges, But Deployment Lags
siliconangle.com

Post-Quantum Cryptography Readiness: Planning Surges, But Deployment Lags

Tech News
3 min read

Published by AINave Editorial • Reviewed by Ramit

TL;DRA DigiCert survey reveals 87% of organizations are planning post-quantum cryptography initiatives, yet only 7% have deployed quantum-safe protections across most digital certificates. The gap underscores the need for crypto-agility, automated certificate management, and integration into CI/CD pipelines, especially as AI agents introduce new cryptographic dependencies.

Most enterprises now have post-quantum cryptography initiatives underway. The problem is that very few have actually implemented them. A recent DigiCert survey found that 87% of organizations are planning, testing, or implementing post-quantum cryptography (PQC) initiatives, but only 7% have deployed quantum-safe or hybrid cryptography across most of their digital certificates. That gap is the central challenge of post-quantum cryptography readiness, and it has direct implications for AI builders and product teams shipping software today.

The Planning-Deployment Gap in Post-Quantum Cryptography

Cryptography is deeply embedded across applications, infrastructure, and business processes, often through dependencies that organizations don't fully understand. As theCUBE Research's Krista Case noted, post-quantum migration will test enterprise resilience as much as cryptographic strength. Crypto-agility, the ability to discover, prioritize, and change cryptographic dependencies without disrupting operations, is a capability that needs to be built before quantum risk becomes an operational deadline.

For AI builders, the challenge is compounded by the rapid adoption of AI agents. Reliance on agents for key enterprise tasks increases the need for identity-based governance and ways to validate model integrity. DigiCert's AI Trust architecture, introduced in April, embeds cryptographic verification across the AI lifecycle, spanning agents, models, and content. The AI Agent Passport allows organizations to define what an agent can access, what it can do, and where it can operate, creating enforceable, auditable boundaries for autonomous actions.

Why Crypto-Agility Matters for AI Builders

If you are building AI products or managing agent workflows, post-quantum cryptography readiness is not a distant compliance exercise. It is a software modernization problem that affects your CI/CD pipelines, certificate management, and the trust model for autonomous systems. TheCUBE Research's AppDev findings show that 75% of enterprises use multiple disparate tools across their development lifecycle, adding complexity to cryptographic inventory management.

Integrating crypto-agility into CI/CD pipelines means automating certificate management and security validation directly into the build and deploy process. This allows teams to switch algorithms without manual reconfiguration, reducing the risk of disruption when quantum-safe standards become mandatory.

Practical Steps: Inventory, Prioritize, Automate

The theme of DigiCert's upcoming World Quantum Readiness Day on Sept. 17 is "From Blueprint to Build." The event, featuring speakers from Microsoft, AWS, evolutionQ, Atea, and Thales, focuses on practical migration planning. Key takeaways for builders:

  • Inventory cryptographic assets. Map every certificate, key, and algorithm across applications, infrastructure, and firmware. You cannot protect what you do not know.
  • Prioritize migrations. Identify systems that handle long-lived data or have high security requirements. Start with hybrid cryptography where quantum-safe algorithms coexist with current ones.
  • Build crypto-agility into CI/CD. Automate certificate renewal and algorithm rotation so that switching to quantum-safe standards becomes a routine deployment change rather than a crisis.

Caveats and What Remains Uncertain

This analysis relies on DigiCert's survey and event coverage, which may overstate the urgency or underrepresent real-world deployment challenges. The 7% deployment figure reflects a specific survey methodology and may not capture hybrid or phased approaches that organizations use. Additionally, the AI Trust and AI Agent Passport are DigiCert products; alternative approaches exist from other vendors. Builders should evaluate their own cryptographic dependencies and threat models rather than relying solely on vendor timelines.

The transition to post-quantum cryptography will add complexity, but treating it as a software modernization initiative today positions teams to migrate without disrupting application delivery tomorrow.

FAQs

Post-quantum cryptography (PQC) refers to cryptographic algorithms designed to resist attacks from quantum computers, which could break current encryption like RSA and ECC. Enterprises need to plan migrations now because quantum computers could eventually decrypt sensitive data, and the transition takes years due to deeply embedded cryptographic dependencies across applications and infrastructure.

Sources

Latest Tech News