Security1 distinct publisher3 min readUpdated
Axiad's survey finds 75% of enterprises say they maintain a live cryptographic inventory while 46% have no single owner for post-quantum migration. That is an org chart problem, not a math problem.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
New survey research from Axiad reports that enterprises believe they are prepared for the security challenges quantum computing poses, but that gaps in ownership, testing and visibility could complicate their move to post-quantum cryptography [1]. The two headline numbers do not sit together comfortably: about 75% of respondents say they maintain a continuously updated inventory of certificates, cryptographic keys and algorithms [2], while 46% have no single person responsible for leading the migration [3].
Put those side by side and the floor is unavoidable. Even in the most favourable arrangement of the two groups, at least 21% of respondents both claim a continuously updated cryptographic inventory and have nobody who owns the work of acting on it [4]. An inventory with no owner is a document, not a program.
The ownership number is worth unpacking further. Of the 46 points with no single owner, 39 come from organizations that say responsibility is shared across a team with no single owner [5] - roughly 85% of the ownerless population [6], leaving about seven points that did not even describe it as shared [7]. Distributed responsibility is the default answer, and it is the answer that fails first when a program spans several years and touches encryption, digital signatures and authentication [8].
Testing tells the same story. Around half of respondents have never formally assessed whether their public-facing infrastructure supports post-quantum key exchange [9], which means at least a quarter of the sample claims a live inventory while having never checked the most externally visible property of it [10].
The seniority split is the tell. Axiad found that confidence rises with seniority but falls sharply among the PKI specialists who actually manage certificates and keys [11], while cautioning that the practitioner sample was small and the pattern directional rather than precise [12]. The vendor offers two readings: executives are reporting readiness their own teams cannot verify, or practitioners cannot see inventories and assessments done elsewhere [13]. Either way, the number on the board is not the number in the field. "PQC readiness cannot be based on what an organization believes it has under control," Axiad CEO David Canellos said. "It has to be based on what it can actually see, verify, and act on" [14].
The pressure to act is being framed around "harvest now, decrypt later" - collecting encrypted traffic today against future decryption - which matters most for healthcare, financial and classified data that must stay confidential for years [15]. About 67% call it an active priority with specific steps underway; one-third have taken no specific action [16]. And the most cited obstacle to migration was competing security priorities, followed by budget constraints and the desire for more regulatory guidance [17]. Competing priorities and missing budget are exactly what a program loses to when no one is accountable for defending its schedule.
What to watch: whether "readiness" claims come with a name. Ask who owns the migration, and if the answer is a team, ask who signs off on the plan. Ask to see the assessment artifact for post-quantum key exchange on public-facing endpoints, since half the field does not have one [9]. Ask whether the inventory is a continuous output from tooling or a snapshot someone refreshed for the survey [2]. And ask whether there is a budget line at all, given that budget was named as a top-three blocker [17]. Vendors will keep selling discovery. Discovery is the cheap half.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
According to new research from Axiad, enterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography.
About 75% of respondents said they maintain a continuously updated inventory of certificates, cryptographic keys and algorithms.
Some 46% of organizations have no single person responsible for leading their PQC migration.
The report found that 39% said responsibility for PQC migration was shared across a team with no single owner.
Defined ownership matters because PQC migration can span several years and affect systems used for encryption, digital signatures and authentication; without someone coordinating the work, organizations may struggle to turn security goals into migration plans, budgets and testing schedules.
Around half of respondents have never formally assessed whether their public-facing infrastructure supports post-quantum key exchange.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor survey, no methodology disclosed
All numbers come from one trade-press summary of one vendor-authored survey. Percentages are internally consistent and the derived overlaps follow by arithmetic, but there is no sample size, respondent geography, industry mix or fielding window, no link to primary instrument data, and no independent corroboration. The vendor itself downgrades the seniority finding to a directional pattern from a small practitioner sample.
Self-reported intent, thin verified execution
The only adoption signal is what respondents say about themselves. Inventory practice is claimed broadly (75%) and two-thirds claim active harvest-now-decrypt-later work, but the same survey shows no accountable owner in 46% of organizations and no formal post-quantum key exchange assessment in roughly half — so claimed practice substantially exceeds evidence of executed migration. No deployments, product rollouts, protocol enablement counts or spend figures appear in the sources.
Findings generalized beyond what the survey can carry
Direction of overstatement runs two ways and nets positive. Respondents' self-assessed readiness is overstated relative to their own ownership and testing answers, and the reporting generalizes an undisclosed-methodology vendor survey to 'enterprises' while quoting the vendor's remedy without noting its commercial alignment. The cluster's own framing is comparatively restrained — it foregrounds the ownership gap rather than a quantum doom scenario, and it repeats the small-sample caveat — which keeps the gap moderate rather than severe.
Vendor-authored survey whose conclusion is its product pitch
The research originates with Axiad, a supplier of credential and cryptographic-readiness capability, and its CEO frames the takeaway as needing continuous visibility into the cryptographic environment — the exact gap such tooling sells against. Survey findings that emphasize unowned migrations, untested infrastructure and harvest-now-decrypt-later urgency directly support that commercial narrative. Mitigating factors: the vendor volunteered a limiting caveat on its own practitioner data, and the reporting outlet has no disclosed stake.
Numbers reliably reported, underlying data unverifiable
Confidence is moderate-low. What the source says is unambiguous and quoted precisely, the percentage relationships are arithmetically coherent, and the derived overlap floors are certain given the reported figures. But the substrate is one self-interested survey with no disclosed methodology and one publisher, and the story's key interpretive question — whether executives overstate or practitioners lack visibility — is explicitly unresolved.
security
OpenAI's Computer History writes a plaintext log of the workday. Decide before staff opt in.1 distinct publisher
security
The customer is genuine and the payment is authorized: 55% of banks say scams dominate fraud1 distinct publisher
security
AWS gives email-validated certificates three 2027 deadlines, and the last one is a renewal cliff1 distinct publisher
product
France's tax agency lost 678,000 records through logins it had issued itself1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026