Today is World Quantum Readiness Day, and this year’s theme, “From Blueprint to Build,” says a lot about where the industry has landed. Three years ago, post-quantum cryptography (PQC) barely made it into security conversations. Today it sits on the C-suite agenda, but a plan on a slide and the operational capability to execute it are very different things. IT Security Guru spoke to a wide range of security leaders, spanning certificate authorities, network vendors, banks, standards bodies and consultancies. Here is a flavour of what they told us.
From blueprint to build
For Paul Holt, Group Vice President EMEA at DigiCert, moving from blueprint to build means going beyond the strategy document and “developing the operational capability to change cryptography across the organisation.” He points to DigiCert’s own research showing 87% of IT and security leaders are now planning, testing or implementing PQC initiatives, yet only a fraction have deployed quantum-safe or hybrid certificates at scale, a gap he calls the real story of where the industry stands today.
Vince Stoffer, Field CTO at Corelight, agrees that awareness has changed enormously over three years, and that the most advanced organisations are now “putting the tools, people and processes in place to actually do it.” He still sees a widespread in maturity, with government agencies and financial institutions further ahead because the sensitivity and longevity of their data makes the risk feel more immediate.
Callum Evans, Senior Solutions Architect for Cybersecurity at SHI, describes discovery as a process of unravelling a problem that keeps growing: the deeper you dig, he says, “it’s like unravelling a ball of string.” Organisations in heavily regulated industries, or those supporting critical national infrastructure, have been quickest to start, but he cautions that no organisation anywhere has complete visibility of where cryptography actually sits.
For Daryl Flack, Partner at Avella Security and cyber security advisor to the UK Government, the real dividing line is organisational rather than technical. It comes down to “whether quantum readiness has moved from being a security discussion to an enterprise programme.” He describes the organisations furthest ahead as those with executive ownership, active discovery work underway, and pilots already testing migration in the real world, where legacy dependencies and supplier gaps actually surface.
Kieran B., Head of Security Engineering at Bridewell, adds that in practice this looks like organisations testing and validating the deployment of quantum-safe cryptography in limited pockets of the business, now that candidate algorithms have moved beyond early validation and into standardised, implementable form, letting teams confirm performance impacts and start mitigating their highest-risk data first.
The misconception that won’t go away
Almost everyone we heard from flagged the same misunderstanding: that PQC migration is simply a matter of swapping one algorithm for another. Thomas Brunner, who works on Custody, Staking and DeFi at Sygnum Bank, argues the algorithms themselves are largely settled, and that “the hard part is coordination and governance across a sprawling, hybrid estate.” He also pushes back on the idea that quantum risk is a problem for the 2030s, pointing out that anything which must stay confidential for years and can be copied today is already exposed to harvest-now-decrypt-later collection.
Tim Hudson, President of OpenSSL Corporation, makes a related point about where organisations should actually start, noting that “the first stage of post-quantum preparation isn’t choosing a new algorithm.” OpenSSL Library 3.5 already supports the finalised NIST algorithms, but shipping standards is not the same as finishing the transition; the best-prepared organisations, in his view, will be those that understood their own dependencies rather than those that rushed to deploy first.
Aparna Rayasam, CEO of Atsign, pushes back on the idea that PQC is too costly to deploy today, insisting that “the bigger mistake is waiting.” She acknowledges real computational and message-size overhead in post-quantum algorithms, but argues that overhead is an engineering problem to measure and design around, not a reason to delay a migration that only gets harder the longer it is put off.
And Omer Kidron, Enterprise Security Consultant at Sygnia, warns against assuming vendors will quietly handle authentication upgrades the way they did with browser encryption, since for certificates and signing keys, “nothing upgrades itself.” Hybrid post-quantum key exchange for TLS arrived in most browsers unassisted, he notes, but re-keying certificate authorities and updating firmware have no equivalent negotiation path – that work belongs to the organisation.
Kieran B. of Bridewell frames the misconception slightly differently: PQC migration, he argues, is really just another legacy technology upgrade, except that “the obsolescence date is unknown and will arrive without fanfare or warnings.” His prescription is the same one any legacy upgrade programme would use; understand your exposure, prioritise the remediation, and work through it methodically, whatever the extra razzle-dazzle attached to the word “quantum.” He also cautions against writing off every objection as mere inertia: in legacy or operational technology environments, newer standards can genuinely outstrip what the hardware can support, forcing real trade-offs around hardware upgrades or extra protection for data that has to stay encapsulated for longer.
The first 90 days
Asked what a realistic first 90 days looks like, several respondents converged on the same advice: don’t aim for a perfect inventory, aim for visibility and ownership. David Mudd, Global Head of Digital Trust Assurance at BSI, frames the underlying risk as “harvest now, decrypt later” and says organisations need to “understand where their exposure lies” before they can prioritise. He points to systems with long lifespans, such as satellites and undersea cables, where a software patch alone won’t be enough.
That urgency is backed by hard numbers from Chad Thunberg, CISO at Yubico, who cites IBM research showing “69 percent of organisations have no plan in place for post-quantum cryptography.” He argues the real deadline isn’t when a cryptographically relevant quantum computer arrives, but how long a large enterprise needs to complete a multi-year migration across software, cloud workloads and supply chains.
Kieran B. at Bridewell agrees discovery has to come first, but stresses there is rarely one clean source of truth: cryptography is often poorly documented across years of systems, so the first 90 days should combine active scanning of code repositories and TLS-exposed systems, with organisational knowledge and passive detection tooling to get an asset inventory moving.
It takes an ecosystem
No organisation can migrate in isolation, and this came through repeatedly. Paulina Gomez, Director of Portfolio Marketing at Ciena, says the industry’s focus is shifting from assessing risk to “putting these protections into networks now,” even as many providers remain in early evaluation. Her firm’s research found just over half of service providers have already launched, or expect to launch, quantum-safe encryption services within a year.
Paul Savill, SVP and Global Practice Leader at Kyndryl Cyber Resilience & Connectivity, puts the dependency bluntly: “no company is truly quantum-safe unless its ecosystem is quantum-safe.” He frames the challenge as bigger than a technology upgrade, underpinning digital trust across billions of daily interactions, and notes that Kyndryl’s own research suggests as much as a quarter of mission-critical infrastructure is already end-of-service.
Frank de Jong, Quantum Safe Network Lead at Orange Business, wants World Quantum Readiness Day itself to function as “a prompt for action, not just another awareness moment,” given how long the underlying work takes. He argues no organisation can protect everything at once, so the priority has to be mapping where the most sensitive and longest-lived data sits and securing that first.
And Simone Giacomelli, founder and CEO of Prem AI, warns that reliance on third-party AI vendors carries its own exposure, since “quantum hackers could be harvesting your data at this very moment.” His concern is specific to the current AI boom: businesses renting AI infrastructure from third parties have little visibility into whether that provider is quantum-resilient.
Standards and mandates
A handful of contributors dug into which parts of the standards landscape are actually stable enough to build on. The consensus was that the core NIST algorithms (ML-KEM for key exchange, and ML-DSA and SLH-DSA for signatures) are finalised and safe to commit to, and that hybrid deployments combining a classical and a post-quantum algorithm are the sensible way to start. Less settled is everything built on top: protocol-level implementation, additional signature candidates still under evaluation, and vendor support across legacy hardware. Several respondents pointed to the withdrawal of one previously promising signature candidate this year, after a newly discovered structural weakness, as a reminder that algorithm choice belongs in configuration and policy, not hardcoded into applications.
Regulation is doing real work to concentrate minds. In the US, Executive Order 14412 has turned post-quantum preparation into a compliance requirement, pushing sensitive federal systems toward transition by 2030 for encryption and 2031 for authentication, with growing demand for cryptographic bills of materials from suppliers. The UK’s National Cyber Security Centre has its own phased milestones running through 2035, while the EU, Germany, France, Singapore, Japan and Australia are moving on broadly similar timelines. For multinational organisations, the effect is less a single global deadline than a patchwork of overlapping expectations to navigate at once.
Kieran B. of Bridewell makes a similar point about why mandates matter so much: in a world competing for attention with faster-moving technology like AI, a future threat such as quantum is easily deprioritised without a legal requirement forcing organisations to allocate budget.
Crypto-agility, not a finish line
Perhaps the clearest theme across every response was that “done” doesn’t really exist. Simon Pamplin, CTO of Certes, says the industry has moved past the point where a roadmap alone is sufficient: “we are past the point where just having a plan for quantum is enough.” He argues that sensitive data keeps moving while inventories and migration plans are still being built, and that protection has to be attached to the data itself.
Nguyen-Duy, CTO at Arqit, makes a similar case for urgency, arguing that “waiting for Q-day is not a good business plan.” The goal, in his view, isn’t a one-off migration project with a fixed end date, but lasting crypto-agility: the ability to identify, update and replace cryptography as standards, threats and business requirements continue to evolve.
Kieran B., Head of Security Engineering at Bridewell, offers a rougher way to grade progress toward that goal. “Good”, in his framing, is an organisation using only cryptographic standards not susceptible to known attacks, including from a quantum computer; “better” is one that also knows exactly where each standard is used and how long the data behind it needs to stay protected; and “best” is one that is crypto-agile everywhere and knows precisely how long each system would take to move to a new standard, should the current one fail against some future attack. “Done”, in other words, was never really the right thing to aim for.
The consistent message is that the real prize isn’t a completed migration to a fixed set of algorithms. It’s crypto-agility: the ability to find, understand and change cryptography across the estate without another multi-year scramble the next time the standards move. Given how many of today’s respondents pointed to the same execution gap, that capability looks like the actual test of “From Blueprint to Build” and not whether an organisation has a plan, but whether it can act on one.





