Review Paper: Fewer Than 5% of Enterprises Have a Quantum Transition Plan
September 5, 2025 – A review paper posted to arXiv on September 1 concludes that fewer than 5% of enterprises have formal quantum transition plans, even though 62% of technology professionals worry that quantum computers will break current encryption. Both figures come from ISACA’s April 2025 quantum poll, which the paper cites. Tran Duc Le of the University of Wisconsin–Stout and co-authors in Russia and Vietnam wrote it as a synthesis of standards, industry surveys and threat reporting; they collected no new survey data.
The study analyzed enterprise preparedness through three distinct lenses: technical maturity of quantum-safe solutions, organizational readiness from the CISO/CIO perspective, and the evolving threat landscape from potential adversaries’ viewpoint. Researchers employed SWOT analysis methodology to synthesize findings from recent NIST standards, industry surveys, and threat intelligence reports.
Citing a July 2025 Capgemini Research Institute study, the paper reports that 45–47% of banking and telecommunications respondents have budgeted and planned for PQC in the near term, with defense and high-tech close behind at 43%. Most other sectors remain in exploratory phases or have stalled entirely due to cost concerns, technical complexity, and workforce skill gaps.
Using the same ISACA data, the paper notes that 95% of organizations lack a quantum computing roadmap, despite expert consensus placing the arrival of cryptographically relevant quantum computers sometime in the 2030s. This disconnect between perceived threat timeline and actual preparation requirements represents a significant vulnerability, particularly given the “harvest now, decrypt later” attacks already underway.
Authors highlighted the uneven distribution of preparedness across industries and organization sizes. While large financial institutions and telecommunications providers have begun concrete migration efforts, small and medium enterprises largely lack awareness or resources to begin planning. The research identified crypto-agility, quantum transition roadmaps, and workforce development as critical immediate needs.
Among its sources, the paper cites my article on how CISOs can use quantum readiness to secure bigger budgets. The authors recommend prioritizing post-quantum cryptography deployment in high-value systems while building organizational capabilities for the broader transition ahead.
My Analysis
I’ve been tracking enterprise quantum preparedness for years, and this paper confirms what my conversations with security leaders have been telling me: we have a massive readiness gap. The 5% figure for formal transition plans actually feels optimistic based on what I’m seeing in the field.
The paper is a literature review. Its headline 5% comes from ISACA’s poll of technology professionals and its sector figures from Capgemini’s early-adopter study, so anyone quoting them should cite those sources directly.
Here’s the real problem. Organizations are treating quantum threats like Y2K was treated in 1995: everyone knows it’s coming, but it feels far enough away that other priorities take precedence. The difference? Y2K had a fixed deadline. Q-Day doesn’t.
That 62% worried versus 95% not prioritizing gap tells the whole story. Security professionals understand the threat intellectually but haven’t translated that understanding into action. Why? Three reasons keep coming up in my discussions with CISOs:
First, uncertainty about timelines creates paralysis. When experts say “sometime in the 2030s,” executives hear “not my problem yet.” They’re missing that data stolen today remains vulnerable for decades. A 10-year encryption lifespan for sensitive data means anything encrypted with RSA today needs protection from quantum computers arriving in 2035.
Second, the complexity overwhelms teams already stretched thin. Migrating cryptography touches everything: applications, infrastructure, certificates, protocols, third-party integrations. Most organizations don’t even have accurate cryptographic inventories. How can you plan a migration when you don’t know what you’re migrating?
Third, budget constraints hit hard when ROI calculations involve preventing future attacks rather than addressing current ones. The financial services sector gets it because they’re used to long-term risk modeling. Manufacturing? Retail? Healthcare? These sectors operate on tighter margins with shorter planning horizons.
The banking and telecom sectors leading at 45-47% budget allocation makes perfect sense. Banks handle financial records that need decades of protection. Telecoms run the infrastructure everyone else depends on. Both face regulatory pressure that’s only intensifying as governments wake up to quantum risks.
What surprised me was the paper’s finding about skill gaps. I expected budget and complexity issues, but the sheer lack of quantum-literate security professionals creates a bottleneck even for organizations ready to move. We’re asking teams trained in classical cryptography to suddenly become quantum experts. That’s like asking combustion engineers to design electric vehicles overnight.
The SWOT analysis framework the researchers used revealed something crucial: opportunities exist alongside the threats. Organizations that move early gain competitive advantages through enhanced trust, regulatory compliance, and operational resilience. Yet most focus only on the threat side of the equation.
I recently developed a PQC readiness self-assessment scorecard specifically because organizations need concrete ways to measure their preparedness. Abstract discussions about quantum threats don’t drive action. Specific metrics do.
The harvest-now-decrypt-later risk deserves special emphasis. Nation-states and sophisticated actors are already collecting encrypted data for future decryption. Every day organizations delay means more data becomes retrospectively vulnerable when quantum computers arrive. This isn’t theoretical. It’s happening now.
Small and medium enterprises face the biggest challenges. Large organizations at least have dedicated security teams and budgets. SMEs often outsource security or assign it as one of many responsibilities to overworked IT staff. They need simplified migration paths and managed service provider support that largely doesn’t exist yet.
The researchers’ recommendations align with what I’ve been advocating: start with crypto-agility. You can’t migrate what you can’t change. Building flexibility into cryptographic implementations today saves massive pain tomorrow. This means abstracting cryptographic operations, centralizing key management, and designing systems that can swap algorithms without architectural overhauls.
Creating quantum transition roadmaps sounds bureaucratic, but it’s essential. Deadlines are already being set by regulators and standards bodies. Organizations without plans will find themselves scrambling to meet compliance requirements with insufficient time and resources.
The workforce development angle can’t be ignored. Universities aren’t producing enough quantum-aware security professionals. Existing professionals need retraining. Organizations should be investing in education now, not waiting until the talent shortage becomes acute.
I’m encouraged that researchers referenced my previous analysis on CISO budget allocations. The conversation is building momentum in academic and industry circles. But momentum isn’t enough. We need acceleration.
For organizations reading this and wondering where to start, focus on three practical steps:
Inventory your cryptography. You can’t protect what you don’t know exists. Document every use of encryption, from TLS certificates to database encryption to proprietary applications.
Identify your most sensitive data. Not everything needs immediate protection. Focus initial efforts on data requiring decades of confidentiality: intellectual property, personal health information, financial records, strategic plans.
Build crypto-agility into new projects starting today. Every system you deploy with hard-coded classical cryptography becomes technical debt. Make algorithm flexibility a design requirement.
The 5% with formal plans will look prescient in five years. The 95% without them will scramble to catch up, paying premium prices for scarce expertise while managing emergency migrations under regulatory deadlines.
This paper should serve as a wake-up call. The quantum threat isn’t science fiction or vendor hype. It’s a mathematical certainty approaching at uncertain speed. Organizations have a choice: prepare methodically now or react chaotically later.
Based on this research and my ongoing conversations with security leaders, I predict we’ll see a sharp divide emerge by 2027. Forward-thinking organizations will have made substantial progress on quantum preparedness. Laggards will just be starting to understand the scope of work required.
The question for every CISO and CTO reading this: which group will your organization be in?