Fri, 14 Aug 2026

Quantum security stuck in pilot mode as Australian firms lag on PQC rollout

Australian enterprises are preparing for post‑quantum cryptography (PQC) but remain stuck in pilot mode, with deployment advancing just two percentage points over the past year, according to DigiCert’s second annual global survey**.

** The global, while marked as global, mainly focused on three countries: the UK, the USA and Australia which combined represent 5.37% of the global population.

While 84.8% of organisations report they are planning, testing or implementing PQC initiatives, only 9.2% have deployed quantum‑safe or hybrid cryptography across most of their digital certificates, highlighting a widening execution gap between strategy and rollout.

Execution gap deepens as risk perception rises

Source: Digicert 2026

The DigiCert Quantum Readiness Outlook shows organisations have moved beyond awareness but are struggling to translate plans into enterprise‑wide action.

More than half (61.2%) expect today’s encryption standards to be broken within five years, and 95.2% believe at least some encrypted data is already vulnerable to “harvest now, decrypt later” (HNDL) attacks, where adversaries collect ciphertext today to decrypt once quantum computers arrive.

Three‑quarters (76%) anticipate transitioning to quantum‑safe cryptography within the same five‑year window, reinforcing that quantum is now viewed as a current business risk rather than a distant technology challenge.

“Quantum computing is rapidly moving from a future technology challenge to a current business risk for Australian organisations, and trust and security must remain central to this transition,” said Daniel Sutherland, area vice president, ANZ, DigiCert.

“As businesses move from planning and testing to enterprise‑wide deployment, they need the right foundations in place to understand, manage and secure their cryptographic environments.” Daniel Sutherland

Legacy complexity replaces standards uncertainty as top barrier

Progress is being held back less by doubt over standards and more by the practicalities of modernising entrenched systems. Some 29.2% cite legacy complexity as the biggest barrier to deployment, overtaking earlier concerns around standards uncertainty or executive support.

Related:  ExecOpinion: The strategic value of cybersecurity

Just over half (54.4%) have conducted quantum risk assessments, while 42.8% have developed transition plans and created cryptographic inventories—foundational steps that many still have not completed.

“The move to post‑quantum cryptography is part of a broader modernisation journey versus just a technology upgrade,” said Kevin Hilscher, senior director of product management at DigiCert.

“Organisations that invest in crypto‑agility today are building the flexibility to evolve with changing standards, emerging technologies, and future business requirements. That’s what creates long‑term resilience. However, this is where the research suggests organisations are now struggling: how to translate strategy into enterprise‑wide execution.” Kevin Hilscher

Sector readiness and data at risk

Financial transaction records and banking data are seen as the most likely targets once current encryption becomes decryptable, followed by cryptocurrency private keys and wallets. By sector, retail reported the lowest levels of preparedness, manufacturing was the most divided, and MedTech alongside telecommunications and media expressed the highest confidence in readiness. Globally, the United Kingdom led with 18% of organisations self‑identifying as “leading edge” on quantum readiness, ahead of the United States (17%) and Australia (10%).

Related Stories

MORE STORIES