Industry

Fujitsu Surveyed 300 Executives. Cryptography Finished Last.

March 5, 2026 – Fujitsu published Quantum computing’s growing presence in the corporate world on March 5, 2026, a 15-page executive summary of research carried out by FT Longitude, part of the Financial Times. FT Longitude surveyed 300 senior executives drawn in equal numbers from Australia, Canada, India, Singapore, the United Kingdom and the United States, across financial services, manufacturing, healthcare and life sciences, retail and consumer goods, and public sector, government and defense. Of the respondents, 30% sat at C-level and the remainder one or two rungs below.

The report finds that 96% of executives expect quantum computing to benefit their organization at some point, and that 28% already claim worthwhile advantages from their exploration work. A further 20% regard the technology as too distant to be relevant to their business.

Roughly three in ten organizations have started building quantum readiness in a structured way. Fujitsu describes the remaining 67% as taking a wait-and-see position. Of the ten readiness measures the survey tracked, adjusting cyber security in preparation for post-quantum cryptography placed last, at 29%. Conference attendance, industry monitoring, talent recruitment and simulation pilots all placed higher.

Forward intentions run ahead of current activity. A majority, 56%, say they will act on quantum readiness within 12 months. Of those, 66% intend to attend conferences, 64% to monitor developments, 58% to fold quantum into strategic planning, and 50% to adjust cyber security for post-quantum cryptography.

Fujitsu splits respondents into a fast-mover group and a mainstream group. Among fast movers, 77% are already adjusting cyber security measures for the post-quantum transition, against 17% of the mainstream group. The report puts 98% of fast movers as involving cyber teams early in emerging-technology projects, and 55% as having identified at least one plausible quantum use case, against 23% of the mainstream group. Skepticism about quantum computing’s viability was named a main challenge by 45% of the mainstream group and 3% of fast movers.

Fujitsu places 48% of its fast movers in public sector, government and defense, and 5% in retail. By country, the United Kingdom, Singapore and the United States carried the highest proportion of fast movers.

Sector variation is wide across the five industry categories. Public sector, government and defense organizations reported 73% actively assessing use cases, against 55% in financial services, 30% in manufacturing, 27% in healthcare and life sciences, and 17% in retail and consumer goods.

On resourcing, 59% of executives report that their emerging-technology projects run long because of competing priorities. A further 63% report that their organization diverts attention or investment away from quantum computing toward nearer-term technologies such as AI.

Separately, 82% describe AI’s recent pace as a reality check on how fast technology can move, and 51% say such reality checks have become frequent.

Dr. Ellen Devereux, a quantum computing consultant at Fujitsu, writes in the report that a hands-off stance carries risk, and cites harvest-now-decrypt-later attacks as an example of a quantum impact organizations need to understand today. Shinji Kikuchi, project director at Fujitsu’s Quantum Laboratory, cautions that identifying practical quantum use cases requires deep knowledge of both the business and the technology.

My Analysis

The one item on the list with a statutory date

Nine of the ten items on Fujitsu’s readiness checklist are discretionary. Attending a conference is discretionary, so is recruiting a quantum physicist, and running a simulation pilot to see whether portfolio optimization gets faster is discretionary enough that most organizations should let it wait another year.

Adjusting cryptography is the tenth item, it is not discretionary anywhere, and it finished last.

The six countries FT Longitude surveyed have all published dates. Australia’s Signals Directorate disallows RSA, ECDH and ECDSA after 2030, one of the most aggressive deprecation schedules any government has published. Canada’s Treasury Board expects high-priority systems migrated by the end of 2031 and the remainder by 2035. The UK’s NCSC set discovery by 2028, high-priority migration by 2031, and completion by 2035. India’s DST Task Force wants critical information infrastructure fully quantum-safe by 2029, as I covered when the roadmap landed. Singapore’s CSA has since finalized its Quantum-Safe Migration Handbook, which puts CII owners on a three-date schedule, starting with a migration plan by March 31, 2027, new CII systems quantum-safe from January 1, 2028, and migration complete by December 31, 2031. The US has CNSA 2.0 and a 2035 federal target. I mapped how all of these are compressing rather than slipping earlier this year.

Six countries, 50 executives each, and not one jurisdiction where cryptographic migration is optional. The 67% are therefore not waiting to see whether quantum computing works. On the cryptographic side, they’re already behind a calendar that was published before FT Longitude called them. This is the argument I keep making and will keep making. The deadlines are set, and regulators, auditors, insurers and large customers set them, not anyone’s Q-Day forecast.

The SHA-1 migration is the closest precedent, and it ran the same way

The last time this industry replaced a cryptographic primitive at scale, cryptanalysis did not set the schedule either. Microsoft published its SHA-1 deprecation policy in November 2013. Browser vendors set their own dates afterward, and by early 2017 Chrome, Firefox and Edge had stopped trusting SHA-1 certificates outright. The demonstrated collision, SHAttered, arrived from CWI Amsterdam and Google on February 23, 2017, months after the deadlines had already forced the work.

Two populations went through that transition and came out differently. One treated SHA-1 as a cryptography question, spent 2014 and 2015 arguing about collision feasibility, and reissued certificates in a scramble. The other treated it as a certificate-lifecycle problem with a browser-release date attached, started in 2014, and finished without incident. Both groups faced identical mathematics, and what separated them was which department owned the calendar.

PQC is that same problem multiplied across every protocol, every embedded device, and a decade of vendor lead time in place of three years. The failure mode carries over unchanged.

Doubt about the business case does not cover the cryptography

The 45% of mainstream respondents naming skepticism about quantum viability as a main challenge are not being unreasonable. Plenty of quantum business cases are thin, several vendor roadmaps have slipped, and the quantum panic industry has earned every ounce of the distrust it receives. When an executive tells me they are unconvinced that quantum optimization will beat their existing solver this decade, I usually agree with them.

The error is letting that doubt cover both halves of the problem. Whether a CRQC arrives in 2032 or 2040 changes little about what you must do in 2026, because harvest-now-decrypt-later is a present-tense exposure and because migrating a large enterprise estate takes the better part of a decade regardless. Organizations that expect nothing at all from quantum computing commercially still need crypto-agility, because certificates and firmware signing keys outlive the convictions of whoever approved them.

Fujitsu’s own segmentation shows the split, even where the report doesn’t draw it out. Fast movers report 58% concern about quantum security against 33% in the mainstream group, and 3% skepticism against 45%. The organizations doing the mandatory work stopped treating the threat question and the opportunity question as one bet.

AI is taking the budget, and that is a filing problem

The number to act on is 63%, the share admitting their organization pulls attention and investment away from quantum toward nearer-term technologies, AI above all. Another 59% concede that their emerging-tech projects run long for exactly this reason.

Every CISO I have worked with in the past two years recognizes the sequence. Quantum readiness proposals go into the innovation budget, the innovation budget goes to AI, and the cryptographic inventory that should have started in 2024 slides into next year’s planning cycle.

So the filing decides more than the funding does. PQC migration belongs with infrastructure and compliance work carrying a statutory clock, alongside a certificate authority migration or a mandated audit remediation, and it should never be presented as innovation spend. Filed correctly, it doesn’t compete with the AI program at all. Filed under emerging-technology exploration, it loses that competition annually, which is what the survey caught happening.

One arithmetic note, since Fujitsu never states the size of its fast-mover group. If 77% of fast movers and 17% of the mainstream group are adjusting cryptography, and the overall figure is 29%, the fast movers work out to roughly a fifth of the sample rather than the three in ten implied elsewhere. Small discrepancy, but the group carrying the good numbers is smaller than a skim suggests.

What Fujitsu left out

This is a more restrained piece of vendor-commissioned research than most. Fujitsu, which is building a 1,000-qubit superconducting machine this year and targeting 10,000-plus by 2030, had every commercial incentive to publish a Q-Day countdown and did not. No qubit-count theater, no broken-RSA scenario, and the urgency comes from organizational timelines rather than from threat panic. Devereux’s harvest-now-decrypt-later warning is accurate and proportionate. Fujitsu has been louder elsewhere, including a Forbes BrandVoice piece framing 2030 as the year of practical quantum computing, so the restraint here looks deliberate.

What Fujitsu leaves out is the deadline map. Across 15 pages arguing that passivity is risky, FT Longitude and Fujitsu name no regulatory milestone at all. No NIST, no NCSC, no ASD, no CSA, no CNSA 2.0. They surveyed six jurisdictions that have all published dates and then made the case for urgency without citing one.

That argument would move the mainstream group, and Fujitsu left it unused. Telling a retail CIO that 73% of defense agencies are assessing use cases produces a shrug, correctly. Telling the same CIO that PCI DSS already requires a documented cryptographic inventory, and that their certificate and HSM estate answers to a 2030 or 2031 date depending on jurisdiction, produces a budget line. Retail’s 17% on use-case assessment is defensible; retail’s exposure on payment cryptography is not.

What to do with it

Split the program in two and stop letting one number stand for both halves.

Run the opportunity track with the discipline Kikuchi describes, which means real use-case evaluation grounded in how the business actually works, benchmarked honestly against classical alternatives, and a willingness to conclude that nothing here is ready yet. For most organizations outside chemistry, logistics and a few corners of finance, that is the correct conclusion for now, and reaching it deliberately counts as a legitimate outcome.

The defensive track already has a date on it. Start with cryptographic discovery rather than strategy documents. Get vendor commitments in writing, since vendor lead times are the longest item on the critical path. Build agility into the architecture so the second migration costs less than the first. The PQC Migration Framework is free and covers the sequencing, and my practical starting guide is shorter.

Fujitsu’s 96% measures belief and its 29% measures compliance. Boards reading them as the same instrument will keep funding conference attendance and deferring the inventory, which describes roughly 200 of these 300 executives.

Marin Ivezic

I am the Founder of Applied Quantum (AppliedQuantum.com), a research-driven consulting firm empowering organizations to seize quantum opportunities and proactively defend against quantum threats. A former quantum entrepreneur, I’ve previously served as a Fortune Global 500 CISO, CTO, Big 4 partner, and leader at Accenture and IBM. Throughout my career, I’ve specialized in managing emerging tech risks, building and leading innovation labs focused on quantum security, AI security, and cyber-kinetic risks for global corporations, governments, and defense agencies. I regularly share insights on quantum technologies and emerging-tech cybersecurity at PostQuantum.com.