Nearly half of U.S. security and IT leaders surveyed cannot name a single person leading their post-quantum cryptography migration, despite widespread awareness of looming quantum computing threats, according to new research from Axiad. The study of 315 leaders reveals a disconnect between confidence and action; 75% report maintaining a current cryptographic inventory, yet 51% have never tested public-facing infrastructure for post-quantum key exchange.
“PQC readiness cannot be based on what an organization believes it has under control,” says Axiad CEO David Canellos, “It has to be based on what it can actually see, verify, and act on.” This gap extends to senior leadership, with 90% of CISOs and CIOs claiming updated inventories, a figure that sharply contrasts with the 33% reported by security architects and PKI engineers.
Enterprise Confidence Exceeds PQC Migration Action
Nearly half of U.S. organizations surveyed lack a designated leader to guide their post-quantum cryptography (PQC) migration, despite escalating concerns about vulnerabilities to future quantum computing power. Axiad’s recent research, encompassing 315 security and IT leaders, revealed that 46 percent cannot identify a single person responsible for overseeing the complex transition to quantum-resistant algorithms. This absence of clear ownership underscores a potential operational bottleneck as organizations attempt to safeguard data against “harvest now, decrypt later” attacks, where encrypted information is intercepted and stored for decryption once quantum computers become powerful enough.
While 90% of Chief Information Security Officers (CISOs) and Chief Information Officers (CIOs) report maintaining a continuously updated cryptographic inventory, only 33% of security architects and PKI engineers, those directly responsible for managing those assets, affirm the same level of current inventory maintenance. This difference suggests a potential lack of consistent information flow and a possible overestimation of preparedness at the executive level, although the practitioner sample is small and should be considered directional.
The study also highlighted internal contradictions in self-assessed readiness; 22 percent of respondents provided conflicting answers within the survey itself. Some individuals who expressed high confidence in cryptographic asset ownership simultaneously identified unclear ownership as a significant obstacle to migration. These findings suggest that PQC migration presents not only technical challenges, but also substantial operational and identity-related hurdles requiring a clear, current view of cryptographic assets and accountable ownership to drive effective change.
PQC readiness cannot be based on what an organization believes it has under control. It has to be based on what it can actually see, verify, and act on.
David Canellos, CEO of Axiad
See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
