Skip to content

Security1 publisher3 min readPublished

Three-quarters claim a crypto inventory. Nearly half have nobody to hand it to.

Axiad's survey finds 75% of enterprises say they maintain a live cryptographic inventory while 46% have no single owner for post-quantum migration. That is an org chart problem, not a math problem.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Three-quarters claim a crypto inventory. Nearly half have nobody to hand it to.
Generated illustration

What happened

  • According to new research from Axiad, enterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography.
  • About 75% of respondents said they maintain a continuously updated inventory of certificates, cryptographic keys and algorithms.
  • Some 46% of organizations have no single person responsible for leading their PQC migration.
  • At least 21% of respondents both claim a continuously updated cryptographic inventory and have no single person responsible for leading PQC migration.
  • The report found that 39% said responsibility for PQC migration was shared across a team with no single owner.

Compiled by The WatchSomething wrong?How this is made

Why it matters

New survey research from Axiad reports that enterprises believe they are prepared for the security challenges quantum computing poses, but that gaps in ownership, testing and visibility could complicate their move to post-quantum cryptography [1]. The two headline numbers do not sit together comfortably: about 75% of respondents say they maintain a continuously updated inventory of certificates, cryptographic keys and algorithms [2], while 46% have no single person responsible for leading the migration [3].

Put those side by side and the floor is unavoidable. Even in the most favourable arrangement of the two groups, at least 21% of respondents both claim a continuously updated cryptographic inventory and have nobody who owns the work of acting on it [13]. An inventory with no owner is a document, not a program.

The ownership number is worth unpacking further. Of the 46 points with no single owner, 39 come from organizations that say responsibility is shared across a team with no single owner [4] - roughly 85% of the ownerless population [14], leaving about seven points that did not even describe it as shared [15]. Distributed responsibility is the default answer, and it is the answer that fails first when a program spans several years and touches encryption, digital signatures and authentication [5].

Testing tells the same story. Around half of respondents have never formally assessed whether their public-facing infrastructure supports post-quantum key exchange [6], which means at least a quarter of the sample claims a live inventory while having never checked the most externally visible property of it [16].

The seniority split is the tell. Axiad found that confidence rises with seniority but falls sharply among the PKI specialists who actually manage certificates and keys [7], while cautioning that the practitioner sample was small and the pattern directional rather than precise [8]. The vendor offers two readings: executives are reporting readiness their own teams cannot verify, or practitioners cannot see inventories and assessments done elsewhere [17]. Either way, the number on the board is not the number in the field. "PQC readiness cannot be based on what an organization believes it has under control," Axiad CEO David Canellos said. "It has to be based on what it can actually see, verify, and act on" [9].

The pressure to act is being framed around "harvest now, decrypt later" - collecting encrypted traffic today against future decryption - which matters most for healthcare, financial and classified data that must stay confidential for years [10]. About 67% call it an active priority with specific steps underway; one-third have taken no specific action [11]. And the most cited obstacle to migration was competing security priorities, followed by budget constraints and the desire for more regulatory guidance [12]. Competing priorities and missing budget are exactly what a program loses to when no one is accountable for defending its schedule.

What to watch: whether "readiness" claims come with a name. Ask who owns the migration, and if the answer is a team, ask who signs off on the plan. Ask to see the assessment artifact for post-quantum key exchange on public-facing endpoints, since half the field does not have one [6]. Ask whether the inventory is a continuous output from tooling or a snapshot someone refreshed for the survey [2]. And ask whether there is a budget line at all, given that budget was named as a top-three blocker [12]. Vendors will keep selling discovery. Discovery is the cheap half.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories