
Post-Quantum Cryptography Readiness: Planning Surges, But Deployment Lags
Published by AINave Editorial • Reviewed by Ramit
Most enterprises now have post-quantum cryptography initiatives underway. The problem is that very few have actually implemented them. A recent DigiCert survey found that 87% of organizations are planning, testing, or implementing post-quantum cryptography (PQC) initiatives, but only 7% have deployed quantum-safe or hybrid cryptography across most of their digital certificates. That gap is the central challenge of post-quantum cryptography readiness, and it has direct implications for AI builders and product teams shipping software today.
The Planning-Deployment Gap in Post-Quantum Cryptography
Cryptography is deeply embedded across applications, infrastructure, and business processes, often through dependencies that organizations don't fully understand. As theCUBE Research's Krista Case noted, post-quantum migration will test enterprise resilience as much as cryptographic strength. Crypto-agility, the ability to discover, prioritize, and change cryptographic dependencies without disrupting operations, is a capability that needs to be built before quantum risk becomes an operational deadline.
For AI builders, the challenge is compounded by the rapid adoption of AI agents. Reliance on agents for key enterprise tasks increases the need for identity-based governance and ways to validate model integrity. DigiCert's AI Trust architecture, introduced in April, embeds cryptographic verification across the AI lifecycle, spanning agents, models, and content. The AI Agent Passport allows organizations to define what an agent can access, what it can do, and where it can operate, creating enforceable, auditable boundaries for autonomous actions.
Why Crypto-Agility Matters for AI Builders
If you are building AI products or managing agent workflows, post-quantum cryptography readiness is not a distant compliance exercise. It is a software modernization problem that affects your CI/CD pipelines, certificate management, and the trust model for autonomous systems. TheCUBE Research's AppDev findings show that 75% of enterprises use multiple disparate tools across their development lifecycle, adding complexity to cryptographic inventory management.
Integrating crypto-agility into CI/CD pipelines means automating certificate management and security validation directly into the build and deploy process. This allows teams to switch algorithms without manual reconfiguration, reducing the risk of disruption when quantum-safe standards become mandatory.
Practical Steps: Inventory, Prioritize, Automate
The theme of DigiCert's upcoming World Quantum Readiness Day on Sept. 17 is "From Blueprint to Build." The event, featuring speakers from Microsoft, AWS, evolutionQ, Atea, and Thales, focuses on practical migration planning. Key takeaways for builders:
- Inventory cryptographic assets. Map every certificate, key, and algorithm across applications, infrastructure, and firmware. You cannot protect what you do not know.
- Prioritize migrations. Identify systems that handle long-lived data or have high security requirements. Start with hybrid cryptography where quantum-safe algorithms coexist with current ones.
- Build crypto-agility into CI/CD. Automate certificate renewal and algorithm rotation so that switching to quantum-safe standards becomes a routine deployment change rather than a crisis.
Caveats and What Remains Uncertain
This analysis relies on DigiCert's survey and event coverage, which may overstate the urgency or underrepresent real-world deployment challenges. The 7% deployment figure reflects a specific survey methodology and may not capture hybrid or phased approaches that organizations use. Additionally, the AI Trust and AI Agent Passport are DigiCert products; alternative approaches exist from other vendors. Builders should evaluate their own cryptographic dependencies and threat models rather than relying solely on vendor timelines.
The transition to post-quantum cryptography will add complexity, but treating it as a software modernization initiative today positions teams to migrate without disrupting application delivery tomorrow.
FAQs
Sources
- Post-quantum work: DigiCert plans world quantum readiness - SiliconANGLE
- Online Security Newsroom | DigiCert.com
- DigiCert Announces Speakers for World Quantum Readiness Day
- DigiCert unveils speakers for Quantum Readiness Day
- DigiCert Research Shows Quantum Security Deployment Remains...
- QIZ Security raises $17M seed round for post-quantum readiness platform
- TLS/SSL Certificate Authority | Leader in Digital Trust | DigiCert
- Ellen Boehm on Post-Quantum Readiness in Critical... - YouTube
- igiCert Announces Speaker Lineup for Third Annual World Quantum...
- DigiCert Announces Speaker Lineup for Third Annual World Quantum Readiness Day
- Post-quantum encryption gap: Enterprises plan but only 7% have deployed
- DigiCert Releases Second Edition of Post-Quantum Cryptography For Dummies Amid Growing Quantum Readiness Demands
- DigiCert Research Shows Quantum Security Deployment Remains Stuck Despite Enterprise Planning
- Post-Quantum Encryption Gap: Enterprises Plan but Only 7% Have Deployed
- Post-Quantum Cryptography




















