Post Quantum Cryptography Adoption
Where UK organisations have reached on post-quantum readiness
Intent has scaled and deployment has not. Surveys through 2026 show most organisations planning or piloting post-quantum cryptography, while measured deployment remains in single figures. Key agreement has moved because it required no coordination. Certificates have barely moved at all.
What the adoption data shows

Read together, these produce a coherent picture rather than a contradictory one. The two figures that look irreconcilable, 65 per cent of traffic protected and 0 per cent of certificates migrated, describe different halves of the problem.
Why key agreement moved and signatures did not
Post-quantum key agreement required no ecosystem coordination. A browser and a server negotiate a hybrid group, and if both support it the connection uses it. Browsers enabled it by default, content delivery networks and cloud providers enabled it server-side, and the traffic figure rose without most organisations taking any decision at all.
Server-side support has followed the same curve. Jan Schaumann's regular scans of the top 100,000 domains recorded 39 per cent supporting post-quantum key agreement in September 2025, against 28 per cent six months earlier, with adoption visible both across large service providers and, increasingly, self-hosted servers.
Signatures require the certificate ecosystem to move together. Root programmes must accept post-quantum roots, the CA/Browser Forum Baseline Requirements must permit the algorithms, and the X.509 encoding work must complete in the IETF. None of that has finished, which is why a scan of 32,011 domains in 2026 found no post-quantum TLS certificates in use.
The practical implication for a UK organisation is that a substantial part of its browser traffic is already protected against harvest now, decrypt later, through no effort of its own, while none of its authentication is. Mistaking the first for progress on the second is the most common misreading of the current position.
What the barrier data actually says
The 2025 explanation for low deployment was awareness. That explanation no longer holds: 87 per cent of organisations report activity, and more than half of DigiCert's respondents expect current encryption standards to be broken within five years. Concern is not the constraint.
The constraint is visibility and coordination. Ponemon's finding that 68 per cent of organisations consider cryptographic asset management extremely or very difficult identifies the actual blockage, and it aligns with what assessments consistently find: organisations cannot enumerate their cryptography, so they cannot plan its replacement.
A useful diagnostic, and one worth applying internally, is to ask which certificates expire in the next ninety days. If the answer requires investigation, the inventory is not in a state to support a migration plan, and any roadmap built on it will contain gaps.
Where UK organisations sit relative to others
UK organisations reported the highest share self-identifying as leading edge in DigiCert's 2026 survey, at 18 per cent against 17 per cent in the US and 10 per cent in Australia. That is a self-assessment rather than a measurement, and it should be read cautiously alongside the deployment figures.
Two structural factors plausibly support it. The NCSC published dedicated migration timelines in March 2025, earlier and more specifically than several comparable authorities, giving UK organisations a concrete schedule to plan against. And the NCSC has since moved beyond timelines into algorithm guidance, recommending ML-KEM-768 and ML-DSA-65 for most typical use cases and noting the particular value of hash-based signatures for software signing, which removes a decision organisations would otherwise have to make themselves.
Against that, UK guidance remains advisory for most commercial organisations, whereas US federal deadlines became binding under Executive Order 14412 in June 2026 and reach contractors through procurement. Regulatory pressure is arriving faster elsewhere, and for many UK organisations the binding requirement will come through a customer contract rather than a domestic regulator.
What the leading 7 per cent have done differently
The organisations that have deployed at scale share a pattern, and it is not that they started earlier or spent more.
They completed discovery first, producing an inventory covering internal certificate authorities, embedded keys and supplier interfaces rather than public certificates alone. They had certificate lifecycle automation already in place, so that an algorithm change propagates through renewal rather than requiring per-endpoint intervention. They ran bounded pilots in specific areas, typically TLS, VPN, internal PKI or code signing, to learn operational behaviour before committing. And they treated supplier engagement as a procurement workstream rather than a technical one.
None of that requires a view on quantum timelines. It is the same capability that prevents certificate outages and satisfies audit, which is why the 7 per cent tend to be organisations that invested in certificate management for unrelated reasons and inherited readiness as a consequence.
What the gap means for planning
Three conclusions follow from the data.
Being at the planning stage in 2026 is normal, and being at the deployment stage is unusual. Organisations benchmarking themselves against the 87 per cent should recognise that the figure covers planning and testing, not delivery.
The three-to-five year transition estimate held by 39 per cent of respondents is not comfortable. An organisation beginning in 2026 and taking five years arrives in 2031, which coincides with the NCSC's highest-priority milestone and with the internal targets of 2029 set by Google, Microsoft and Cloudflare. That is a race rather than a margin.
Discovery remains the binding constraint. Until an organisation can enumerate its cryptography, its migration duration is unknown, which means its position in any quantum risk assessment cannot be calculated. The measured difficulty of cryptographic asset management is the clearest signal in the data of where effort should go.
How Unsung helps
Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, defence, healthcare, financial services, nuclear and transport.
We deliver the discovery work that the adoption data identifies as the constraint, through our PKI health check and cryptographic bill of materials services, covering internal authorities, embedded keys and supplier dependencies rather than public certificates alone. We then design and deliver the certificate lifecycle management capability that distinguishes the organisations already deploying from those still planning.
For what to do with the platforms that have already shipped support, see where PQC support has already shipped.
Frequently asked questions
How many organisations have actually deployed post-quantum cryptography?
If most web traffic is post-quantum encrypted, why is deployment low?
Are UK organisations ahead or behind?
What is stopping organisations from deploying?
Is a three to five year migration realistic?
What distinguishes organisations that have already deployed?


