All posts

Fintech Regulatory Brief

The Quantum Execution Gap: What New Survey Data Means for Financial Services

September 16, 2026 ·  PQCClear  ·  6 minute read

A new independent survey of 1,001 IT and security leaders puts a hard number on something we’ve said in different words for months: the gap between planning for post-quantum cryptography and actually deploying it is enormous, and financial services isn’t exempt from it.

DigiCert’s second annual Quantum Readiness Outlook, based on an independent survey run by Propeller Insights across the US, UK, and Australia, calls the finding an “execution gap,” and the data backs that framing up plainly.

The Number That Matters Most

87%

Planning, testing, or implementing post-quantum cryptography

7%

Have deployed quantum-safe cryptography across most of their certificates

< 2 pts

Movement in that deployment figure across a full year of reporting

That second number moved less than two percentage points in a full year. Whatever is slowing organizations down, it isn’t a lack of activity. Half of the same respondents have completed a quantum risk assessment, 45% have a transition plan, and 44% have built a cryptographic inventory. The work is happening. It just isn’t converting into deployed protection at anywhere near the same rate.

Why This Is a Financial Services Story Specifically

The survey also asked respondents which categories of data attackers are most likely to target first under a harvest-now-decrypt-later strategy, capturing sensitive data today in the hope of decrypting it once a capable quantum computer exists. The answer should get a bank’s attention directly.

Financial transaction and banking data

58%

Cryptocurrency private keys and wallets

53%

Corporate IP and trade secrets

40%

Government classified documents

38%

Military systems

34%

Financial data ranks first, ahead of even cryptocurrency assets. That’s not a surprising result in the abstract, but it’s a useful, dated data point to have on hand the next time harvest-now-decrypt-later comes up in a board conversation and someone asks whether this is really a near-term concern for a bank specifically, rather than a general industry issue.

It’s Not an Awareness Problem Anymore

The more useful part of the survey, for anyone trying to figure out what’s actually slowing deployment down, is the barrier breakdown. A year ago, the implicit story was that organizations simply didn’t grasp the risk yet. That’s no longer what the data shows.

Complexity across legacy systems

26%

Performance impact

19%

Budget constraints

19%

Skills gap

10%

Executive buy-in

8%

Standards uncertainty

8%

Interoperability

8%

Uncertainty where to start

3%

Only 3% of respondents said they don’t know where to start. Only 8% point to leadership buy-in. The real barriers cluster around complexity, performance, and budget, the practical cost of actually executing a migration across a sprawling estate of systems, certificates, and vendors. Organizations have largely figured out what needs to happen. The struggle is doing it at scale.

Not a maturity gap. It’s an execution failure.

Marin Ivezic, an independent quantum security researcher, commenting on the same findings.

Where Financial Services Actually Stands

DigiCert’s report also broke readiness down by industry, scoring each on how prepared respondents feel relative to the full sample. BFSI, banking, financial services, and insurance, came in at +16.2: ahead of the middle of the pack but well behind MedTech’s +24.0, and nowhere close to Retail’s -7.9, the only industry surveyed with a net-negative score.

IndustryScoreRelative to the full sample
MedTech+24.0The best-prepared sector in the survey, and the distance between it and BFSI is the room finance still has.
BFSI+16.2Banking, financial services, and insurance. Ahead of the middle, behind the leaders.
Retail-7.9The only industry surveyed with a net-negative score, included here for the span rather than the comparison.

What This Means Practically

01Don’t mistake activity for progress.

A completed risk assessment, a transition plan, and a cryptographic inventory are all real, useful steps, but none of them are deployment. If your institution has done the planning work, the next honest question is whether that’s translated into anything actually running in production.

02Extend the same question to your vendors.

If 87% of organizations are planning but only 7% have deployed, a vendor telling you they’re “working on it” is describing the vast majority of the industry, not a meaningful signal on its own. Ask what’s actually been deployed, not just planned.

03Use the financial-data targeting stat directly.

If harvest-now-decrypt-later still feels abstract to a board or risk committee, “financial data ranks as the single most likely first target, ahead of cryptocurrency assets” is a concrete, dated, third-party number worth using.

Know which side of the execution gap your vendors are on

PQCClear helps banks, credit unions, and payment processors verify what’s actually deployed across their vendor portfolio, not just what’s been planned.

Request access
quantum readiness survey 2026post quantum execution gapharvest now decrypt later financial dataBFSI quantum readinesspost quantum cryptography banking

This post represents the editorial analysis of PQCClear as of September 16, 2026. It should not be construed as legal or investment advice.

Key sources: DigiCert, “The Quantum Execution Gap: Key findings from DigiCert’s Quantum Readiness Outlook,” research report (2026); Marin Ivezic, commentary on the same report (September 2026). Figures are described here, not reproduced.