DigiCert post-quantum cryptography survey reveals only 7% of firms ready
DigiCert is hosting a virtual event on September 17 to address the industry's slow adoption of post-quantum cryptography, noting that only 7% of organizations have implemented protections. The company is also promoting its new AI Agent Trust architecture and AI Agent Passport, which aim to provide identity-based governance for autonomous systems.
Key Takeaways
- Only 7% of surveyed organizations have implemented quantum-safe or hybrid cryptography across digital certificates.
- DigiCert is introducing AI Agent Passport to establish auditable boundaries and identity-based governance for autonomous agents.
- TheCUBE Research reports that 75% of enterprises use disparate tools across development lifecycles, complicating cryptographic inventory.
- World Quantum Readiness Day on September 17 will feature experts from Microsoft, AWS, and Thales discussing migration strategies.
Why It Matters
The massive gap between planning and implementation suggests that most enterprise infrastructures remain vulnerable to future quantum-based decryption. For the streaming industry, which relies on secure content delivery and digital rights management, this transition requires moving beyond awareness to active crypto-agility within CI/CD pipelines. As AI agents increasingly manage autonomous tasks at machine speed, the shift toward identity-based governance becomes a critical layer of the security stack. This move connects to the broader trend of software modernization where security is no longer a perimeter concern but an architectural requirement. Watch for whether major cloud providers like AWS and Microsoft accelerate the release of standardized quantum-safe algorithms to bridge this 93% deployment gap.
Additional Context
DigiCert's push into post-quantum readiness arrives amid a broader industry scramble to prepare cryptographic infrastructure for the quantum era. The National Institute of Standards and Technology finalized its first three post-quantum cryptographic standards in August 2024, selecting CRYSTALS-Kyber for key encapsulation and CRYSTALS-Dilithium and FALCON for digital signatures, giving enterprises concrete algorithms to begin integrating into their systems. NIST published the final versions of FIPS 203, 204, and 205 after a multi-year evaluation process that drew submissions from cryptographers worldwide. For streaming platforms and content delivery networks that depend on TLS handshakes and certificate chains, these standards define the migration path that DigiCert's readiness event is designed to accelerate.
On the AI agent governance front, DigiCert's AI Agent Trust and AI Agent Passport products enter a market where identity management for autonomous systems is still largely undefined. The OpenID Foundation launched its OpenID Connect for Identity Assurance specification to provide standardized identity verification frameworks, though it does not yet address machine-to-machine agent authentication at the scale DigiCert envisions. Meanwhile, the Cloud Native Computing Foundation has been advancing SPIFFE and SPIRE as workload identity standards for distributed systems, which could serve as complementary infrastructure for the kind of agent-level trust DigiCert is proposing. The convergence of post-quantum cryptography with AI agent identity suggests that certificate authorities are positioning themselves as trust anchors for a new class of autonomous workloads.
From a technical and competitive standpoint, DigiCert faces pressure from both hyperscalers and specialized security vendors racing to commercialize quantum-safe solutions. Microsoft announced in 2025 that Azure Key Vault and Azure Confidential Computing would support post-quantum hybrid key exchange, combining classical and quantum-resistant algorithms to protect data in transit. Google similarly integrated ML-KEM hybrid key exchange into Chrome and its Cloud infrastructure, making post-quantum TLS available to billions of users by default. These moves from cloud providers mean that DigiCert's differentiation lies not in the algorithms themselves but in the orchestration layer: helping enterprises inventory their cryptographic dependencies, prioritize migration, and extend trust frameworks to that operate across organizational boundaries. The 7% implementation figure DigiCert cites underscores how far most organizations remain from even beginning that orchestration work.
Read full article at siliconangle.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source