Quantum Security & PQC

Entrust/Ponemon 2026: Only 38% of Organizations Are Preparing for Post-Quantum

January 27, 2026 — The 2026 Entrust/Ponemon Global State of Post-Quantum and Cryptographic Security Trends report reveals that enterprise readiness for post-quantum cryptography remains largely aspirational, with only 38% of organizations actively preparing for the quantum threat, down from 41% last year.

The study reports responses from 4,149 IT and security practitioners across the United States, Canada, the UK and Ireland, the DACH region, Indonesia and Singapore, and found that 51% of respondents believe quantum computers capable of breaking RSA and ECC encryption will arrive within five years. Yet despite this perceived urgency, organizations continue to struggle with fundamental preparedness challenges.

The most significant barrier to quantum readiness remains visibility into cryptographic assets. Forty-one percent of respondents cited the inability to discover and inventory their organization’s cryptographic estate as their top concern. Only 26% report having a fully implemented crypto-agility strategy, with another 31% partially implemented.

Geographic disparities in readiness have shifted dramatically. The DACH region (Germany, Austria, Switzerland) now leads global PQ preparedness at 45%, overtaking the United States which fell from 48% to 40% year-over-year. The UK and Ireland lag furthest behind at 31% actively preparing.

The report identified growing resource constraints as key impediments. Budget concerns jumped from 31% to 39% of respondents citing it as a major challenge, while lack of in-house expertise rose from 28% to 38%. These increases suggest organizations are moving past initial awareness into confronting the practical realities of PQC migration.

Beyond quantum threats, the study highlighted immediate operational pressures. The CA/Browser Forum’s Ballot SC081v3 will phase TLS certificate validity from 398 days currently to just 47 days by 2029, with staged rollouts beginning March 15, 2026. This change forces near-monthly certificate renewals, yet only 43% of organizations report having complete visibility into their certificate infrastructure.

Among organizations preparing for PQ, 38% are testing PQC algorithms while 33% have begun implementation. The community remains split between pure PQC approaches (35%) and hybrid implementations combining PQC with traditional cryptography (36%).

My Analysis

I’ve been tracking enterprise PQC readiness for years, and this report confirms what I’ve been hearing from CISOs: everyone knows they need to prepare, but few have the resources or roadmap to actually do it. The 3% year-over-year decline in active preparation is particularly troubling given the regulatory deadlines already set for 2030-2035.

One number in the report doesn’t add up. The headline sample is 4,149 respondents, but the report’s own country breakdown (552 + 573 + 396 + 553 + 369 + 482) sums to 2,925, which is also the “overall sample” in its methods table. The percentages may still hold, but anyone citing the study should quote the sample size with that caveat.

What jumps out immediately is the disconnect between threat perception and action. Three-quarters of respondents expect quantum computers to break current encryption within a decade. Half believe it’ll happen within five years. Yet less than 40% are actively doing anything about it. This gap between awareness and action has persisted for years, but I expected it to narrow by now.

The visibility problem is the elephant in the room. You can’t protect what you can’t see, and 57% of organizations lack complete visibility into their cryptographic assets. This has been the top challenge for two consecutive years. It tells me that organizations are stuck at the starting line, unable to even inventory what needs protecting before they can begin migration planning.

The crypto-agility numbers are even more concerning. Only 26% have fully implemented crypto-agility strategies. This means three-quarters of organizations lack the fundamental capability to swap out algorithms when needed. Given that Q-Day timing remains uncertain, crypto-agility should be priority one. You need the ability to pivot quickly when the threat landscape changes.

I found the geographic shift fascinating. DACH overtaking the US in PQ preparedness suggests European privacy regulations like GDPR might be creating stronger incentives for cryptographic modernization. The US dropping eight percentage points year-over-year is surprising given NSA’s aggressive 2033 timeline for government systems.

The budget and expertise constraints tell the real story. Organizations have moved past the “what is quantum?” phase into the “how do we actually do this?” phase. And they’re discovering it’s expensive and complex. The 10-point jump in budget concerns and expertise gaps shows teams are getting real migration estimates and experiencing sticker shock.

Certificate lifecycle compression adds urgency to an already complex situation. The shift to 47-day certificates by 2029 means manual certificate management becomes impossible. Yet 57% of organizations lack complete certificate visibility today. This collision of shortened lifecycles and poor visibility will force automation investments whether organizations are ready or not.

The Harvest Now, Decrypt Later Reality

The report shows 59% of respondents worry about exposure of long-term sensitive data like health records and trade secrets. This concern is well-founded. Nation-state adversaries are almost certainly harvesting encrypted data today for future decryption. Yet only 48% have steps in place to secure data that needs protection beyond 10 years.

This disconnect reveals a fundamental misunderstanding about the quantum threat timeline. The risk isn’t just about when quantum computers arrive. It’s about how long your data needs protection. If you’re encrypting 30-year mortgages or decade-long pharmaceutical research today with RSA-2048, that data is already at risk.

The split between hybrid and pure PQC approaches (36% vs 35%) reflects ongoing debates in the security community. I lean toward hybrid approaches for most organizations. They provide quantum resistance while maintaining compatibility with existing systems. Pure PQC might be appropriate for greenfield deployments, but most enterprises need backward compatibility during long migration periods.

Why Progress Remains Slow

After analyzing this data, I see three core issues holding back PQC migration:

First, cryptographic ownership remains fragmented. The report shows 36% cite “no clear ownership” as a management challenge. When nobody owns the problem, nobody drives the solution. CIOs and CISOs share responsibility (24% and 22% respectively), but this split accountability creates gaps.

Second, the skills gap is widening. Only 47% have PKI specialists on staff. The rest rely on consultants and service providers. As enterprise PQC migration accelerates, this talent shortage will become acute. You can’t outsource your way through a fundamental architectural transformation.

Third, legacy systems create massive technical debt. The report notes 26% can’t change legacy applications. These systems often have cryptography deeply embedded, making algorithm replacement complex or impossible. Organizations face choices between accepting risk or expensive modernization projects.

What Organizations Should Do Now

Based on this data, I recommend organizations focus on three immediate priorities:

Build visibility first. You need a complete cryptographic inventory before anything else. This includes algorithms, certificates, keys, libraries, and dependencies. Use automated discovery tools where possible, but expect manual effort for legacy systems. This inventory becomes your roadmap for everything else.

Invest in crypto-agility infrastructure. Don’t wait for perfect PQC standards or quantum timeline certainty. Build the capability to change algorithms programmatically. This means centralizing key management, abstracting cryptographic operations, and automating certificate lifecycle management. The 47-day certificate requirement makes this investment mandatory anyway.

Start with high-value, long-lived data. Identify data requiring decades of protection and migrate those systems first. This includes healthcare records, financial data, intellectual property, and government classified information. These systems face immediate “harvest now, decrypt later” risks.

The Entrust/Ponemon report paints a picture of an industry that understands the quantum threat intellectually but struggles with practical implementation. The slight decline in active preparation suggests we might be entering a “quantum winter” where early enthusiasm meets implementation reality.

Yet the threat timeline continues to compress. IBM’s roadmap targets 200 logical qubits by 2029, and published resource estimates for breaking RSA-2048 keep falling. Government deadlines loom in 2030-2035. Certificate lifecycles shrink to weeks. Organizations can’t afford to wait for perfect clarity.

The enterprises succeeding at PQC preparation share common traits: clear ownership, adequate budgets, and foundational crypto-agility. They’re not waiting for quantum computers to arrive. They’re building resilient cryptographic infrastructures that can adapt to whatever comes next. The rest risk being caught flat-footed when mathematical assumptions that protected data for decades suddenly fail.

Marin Ivezic

I am the Founder of Applied Quantum (AppliedQuantum.com), a research-driven consulting firm empowering organizations to seize quantum opportunities and proactively defend against quantum threats. A former quantum entrepreneur, I’ve previously served as a Fortune Global 500 CISO, CTO, Big 4 partner, and leader at Accenture and IBM. Throughout my career, I’ve specialized in managing emerging tech risks, building and leading innovation labs focused on quantum security, AI security, and cyber-kinetic risks for global corporations, governments, and defense agencies. I regularly share insights on quantum technologies and emerging-tech cybersecurity at PostQuantum.com.