Axiad Research Reveals Gaps in Post-Quantum Security Readiness

0
Axiad has released new research highlighting a disconnect between enterprise confidence in post-quantum cryptography (PQC) readiness and the actions organizations have taken to prepare. The findings show that nearly half of organizations lack a designated leader for PQC migration, while 51% have never formally tested their public-facing infrastructure for post-quantum key exchange, exposing potential gaps as enterprises prepare for quantum-era security risks.

The survey of 315 U.S. security and IT leaders found that 75% say their organizations maintain a continuously updated inventory of cryptographic assets, and 63% are very confident that ownership of those assets is fully mapped.

Yet nearly half (46%) cannot name a single individual responsible for leading their PQC migration, and 51% have never formally assessed whether their public-facing infrastructure supports post-quantum key exchange.

The research also found that 22% of respondents contradicted their own readiness claims within the same survey. For example, some respondents who said they were highly confident cryptographic ownership was mapped later identified unclear ownership as a top obstacle to migration.

Confidence also rose sharply with seniority. Ninety percent of CISOs and CIOs reported a continuously updated cryptographic inventory, compared with 74% of security and IT directors and 33% of the security architects and PKI engineers who manage those assets day to day.

The practitioner sample is small and the finding should be read as a directional pattern rather than a precise estimate, but the gradient held across every readiness measure in the study.

“PQC readiness cannot be based on what an organization believes it has under control. It has to be based on what it can actually see, verify, and act on,” said David Canellos, CEO of Axiad. “Organizations may believe they know where their certificates, keys, and cryptographic algorithms reside, but this research shows that confidence can fall apart when you ask who owns the migration, what has actually been tested, and where the organization remains exposed. The first step toward post-quantum readiness is establishing continuous visibility into the cryptographic environment so leaders can replace assumptions with evidence.”

Awareness Is High, but Action Is Lagging

Awareness of the “harvest now, decrypt later” threat is widespread, but action has not kept pace. While 67% of respondents consider it an active organizational priority, 1 in 3 organizations has taken no specific action, and 30% are waiting for clearer regulatory guidance before moving forward.

Other key findings include:

  • 25% say their cryptographic inventory is stale, partial or nonexistent.
  • 22% contradicted their own PQC readiness claims elsewhere in the survey.
  • 42% cite competing security priorities and 36% cite budget constraints as leading obstacles.
  • Even among the 27% who report meeting every readiness measure examined, 48% still cite competing priorities, and 40% cite budget as a major obstacle.

The findings suggest that PQC migration is as much an operational challenge as a technical one, and an identity problem before it is purely a cryptographic one. Knowing where cryptographic assets live is only the starting point.

The harder work is deciding which ones matter first, tying each to an accountable owner, understanding what each protects, and driving the change through the systems that depend on it without causing an outage. Organizations need a clear, current view of their cryptographic assets: where they reside, what they protect, and who owns the migration.

Readiness comes from acting on that evidence: knowing which cryptographic risks matter first, tying each to an accountable owner, and driving the fix through the systems you already run.

You can find the full report here.

Related News:

Zero Networks and Palo Alto Networks Expand Integration for AI Security

The MSP Trust Gap Reprt: AI and Security Redefine MSP-Client Trust

Share.

About Author

Leigh Porter's first love is to love people. Beginning her career as a neonatal RN was an obvious choice until life threw the curve ball to embark on a new IT endeavor. Pursuing this fresh career was a piece of cake with her resilient and steadfast character. Outside of the office, Leigh also diligently gives much of her time faithfully as a nationally awarded volunteer leader to a very dear to her heart organization.