Key Findings
22% of security and IT leaders at U.S. organizations with 500 or more employees contradict their own PQC readiness claims within the same survey
90% of CISOs and CIOs report a continuously updated cryptographic inventory
74% of security and IT directors report a continuously updated cryptographic inventory
33% of security architects and PKI engineers report a continuously updated cryptographic inventory
33% of security and IT leaders at U.S. organizations with 500 or more employees report their organizations have taken no specific action on post-quantum cryptography
42% of security and IT leaders at U.S. organizations with 500 or more employees cite competing security priorities as a leading obstacle to PQC migration
36% of security and IT leaders at U.S. organizations with 500 or more employees cite budget constraints as a leading obstacle to PQC migration
63% of security and IT leaders at U.S. organizations with 500 or more employees are very confident that ownership of cryptographic assets is fully mapped
46% of security and IT leaders at U.S. organizations with 500 or more employees cannot name a single individual responsible for leading their PQC migration
51% of security and IT leaders at U.S. organizations with 500 or more employees have never formally assessed whether their public-facing infrastructure supports post-quantum key exchange
27% of security and IT leaders at U.S. organizations with 500 or more employees report meeting every PQC readiness measure examined
Among the security and IT leaders who report meeting every PQC readiness measure, 48% still cite competing priorities as a major obstacle
Among the security and IT leaders who report meeting every PQC readiness measure, 40% cite budget as a major obstacle
75% of security and IT leaders at U.S. organizations with 500 or more employees report their organizations maintain a continuously updated inventory of cryptographic assets
67% of security and IT leaders at U.S. organizations with 500 or more employees consider post-quantum cryptography an active organizational priority
30% of security and IT leaders at U.S. organizations with 500 or more employees are waiting for clearer regulatory guidance before moving forward on post-quantum cryptography
25% of security and IT leaders at U.S. organizations with 500 or more employees say their cryptographic inventory is stale, partial, or nonexistent