Certes has released new survey-based research looking into quantum security risk awareness and preparation. Despite widespread awareness, confidence in delivering long-term quantum resilience remains critically low – nearly all respondents (97%) said that they are not fully confident they can meet crypto agility timelines.
The ‘Emerging PQC Imperative’ report also reveals that 78% of organizations identify legacy systems as their greatest quantum security risk, yet most are doing little to address it. These environments remain difficult to secure and even harder to upgrade, leaving critical data increasingly exposed.
The report found that nearly three-quarters (74%) of organizations view edge and IoT environments as a major quantum security risk, highlighting the growing exposure across distributed infrastructures. These environments are often difficult to upgrade or standardise, which can make them a critical weak point when it comes to implementing the cryptographic changes required for post-quantum readiness.
At the same time, 73% of organizations are actively evaluating the impact of ‘harvest now, decrypt later’ attacks, recognising that data stolen today could become a future breach once quantum capabilities mature. While evaluation is commended, it stops short of actually protecting the data at risk, says the report.
Other key findings from the report include:
- Only 2% are fully confident in achieving full crypto agility – most organizations lack the ability to adapt cryptography at scale, leaving them exposed to both current and future threats.
- 91% cite mitigation of material business risk as a key driver – quantum risk is now firmly viewed as a core business issue, not just a technical or security concern.
- Just one in four (25%) have a dedicated budget to act on quantum security – strategic intent is in place, but without funding, most initiatives are failing to progress beyond early-stage planning.
Methodology
The study, independently conducted by Freeform Dynamics and commissioned by Certes, is based on responses from 200 senior IT and security leaders across the UK and US, including CISOs, CIOs, and other decision-makers from large organizations spanning sectors such as financial services, healthcare, manufacturing, and the public sector.






