Research report, September 2026

The State of Post-Quantum Readiness in Key GCC Markets

A survey of how enterprises across key GCC markets are preparing to replace quantum-vulnerable cryptography.

Survey findings at a glance

Across key GCC markets, 84% of senior technology and security leaders are planning or building a post-quantum transition and 64% carry a budget for it. Cryptographic discovery has been started by 35%.

Public-key cryptography protects almost every online transaction, and a sufficiently powerful quantum computer would break the algorithms behind it. NIST published replacement algorithms in 2024, and national authorities have since set migration deadlines. The exposure starts before any such machine exists, because encrypted data collected today can be stored and decrypted once one arrives, a practice known as harvest now, decrypt later. Cryptographic discovery, the inventory of where cryptography is used and which algorithms are at risk, is what turns that into a plan.

Exhibit 1 % of respondents, n = 125
Readiness across six measures
97%

know data collected today can be decrypted once a capable quantum computer exists

84%

are planning or building a transition

64%

carry a budgeted post-quantum initiative

42%

work to a defined roadmap

35%

have begun cryptographic discovery

6%

have identified a preferred implementation partner

Each figure comes from a separate survey question. Respondents did not pass through these stages in sequence. Source: QuantumGate Post-Quantum Readiness Survey, 2026, n=125.

Visibility and discovery

  • Reported visibility runs ahead of verified discovery. Visibility into the keys, certificates, algorithms, and protocols in use is reported by 66%, while 35% have conducted or initiated the cryptographic discovery that establishes which of those algorithms are quantum-vulnerable.
  • General familiarity is more common than a verified inventory. Among the 83 organizations reporting full visibility, 41% have conducted or begun a discovery exercise.
  • Reviews are infrequent. Cryptographic audits are run on a fixed schedule by 27%, and 22% check only when a major system is already being rebuilt. An inventory that is accurate on the day it is finished can be out of date within weeks.

Funding and capability

  • Funding is in place ahead of delivery capacity. Planning or actively building a transition covers 84% of respondents, with 42% working to a defined roadmap and 64% reporting a budgeted initiative.
  • Confidence and capability have not kept pace, with 34% rating themselves well or very well prepared.
  • Most migration timelines run three to five years or longer, which puts a premium on starting early.

Delivery and vendors

  • The vendor landscape is still forming. Evaluating multiple vendors covers 58% of respondents, 35% have not identified one at all, and 6% have identified a preferred partner.
  • Sovereignty is a baseline procurement requirement. Nearly all respondents, 98%, require cryptographic solutions that are nationally governed, kept under their own control, such as customer-managed keys, or both.
  • Partner selection is not the same as readiness. Each organization should define whether it will deliver internally, through a partner, or as a hybrid, and assign clear roles and responsibilities against it.

Five findings from the survey

The recommendations, in three phases

The report sets out six recommendations in a fixed order, because each depends on the one before it. Discovery comes before planning, and planning before migration.

None of this depends on when a capable quantum computer arrives. Each step takes time to build and fits inside existing budget cycles.

Now, 0 to 12 months

See your cryptography

Build an inventory of where cryptography is used across applications, devices, networks, certificates, and cloud services, and which algorithms are at risk. Then keep it current, with a named owner, rather than treating it as a one-off exercise.

1 to 3 years

Migrate in phases

Order the work by how long each system’s data has to stay confidential, not by how old the system is. The way systems agree their encryption keys is replaced first for long-lived data, with the new algorithms running alongside the existing ones so protection holds if either is later broken.

3 to 5+ years

Sustain crypto-agility

Crypto-agility is the ability to swap algorithms, keys, and certificates without a rebuild. More post-quantum standards are still coming, so build systems where the next change is a configuration change, backed by a funded mandate and a named owner.

Download the full research report

Four sections and 15 exhibits covering the quantum threat, where the world stands, the survey findings in full, and six recommendations in the order to take them.

  • Forewords from the UAE Cyber Security Council and QuantumGate
  • Nine findings, from how leaders read the threat to what each audience should do next
  • NIST standards, national mandates, enterprise adoption, and the UAE approach
  • What the findings mean for CISOs, boards and investors, and policymakers
  • Glossary and full references

Get the PDF

Enter your details and the report opens straight away. A copy is sent to your inbox as well.

About this report

Respondents hold C-suite roles, VP and director of IT positions, digital transformation leadership, and heads of cybersecurity and compliance, across financial services, energy, healthcare, telecommunications, technology, government, and travel.

Published by
QuantumGate and the UAE Cyber Security Council
Supported by
National Cryptography Center, Technology Innovation Institute
Evidence base
A survey of 125 senior leaders
Markets
United Arab Emirates, Saudi Arabia, and Qatar
Designed and fielded
By an independent third-party research partner, using its own respondent panel
Decision authority
Cybersecurity decision makers or members of the decision-making team account for 94%

Respondents were anonymous, were not QuantumGate customers or contacts, and QuantumGate had no role in selecting them. They were screened for familiarity with post-quantum cryptography, so findings should be read as the position of senior security leaders already engaged with this question rather than of the market as a whole. All findings are self-reported and reflect how respondents assess their own organizations. They are not an audit and may differ from what regulators or external assessments would observe. Figures are presented as the survey recorded them and are rounded to the nearest whole percentage, so some do not sum to 100. Findings are reported at regional level and are not broken down by country. The findings, analysis, and recommendations are those of QuantumGate and do not represent the views or position of any individual named in the report, or of the organizations those individuals represent.

Download the report