Research report, September 2026
A survey of how enterprises across key GCC markets are preparing to replace quantum-vulnerable cryptography.
Across key GCC markets, 84% of senior technology and security leaders are planning or building a post-quantum transition and 64% carry a budget for it. Cryptographic discovery has been started by 35%.
Public-key cryptography protects almost every online transaction, and a sufficiently powerful quantum computer would break the algorithms behind it. NIST published replacement algorithms in 2024, and national authorities have since set migration deadlines. The exposure starts before any such machine exists, because encrypted data collected today can be stored and decrypted once one arrives, a practice known as harvest now, decrypt later. Cryptographic discovery, the inventory of where cryptography is used and which algorithms are at risk, is what turns that into a plan.
know data collected today can be decrypted once a capable quantum computer exists
are planning or building a transition
carry a budgeted post-quantum initiative
work to a defined roadmap
have begun cryptographic discovery
have identified a preferred implementation partner
Each figure comes from a separate survey question. Respondents did not pass through these stages in sequence. Source: QuantumGate Post-Quantum Readiness Survey, 2026, n=125.
Full visibility of their cryptography is reported by 66%, and 41% of those have run a discovery exercise.
A majority of respondents expect a quantum computer capable of breaking today’s public-key encryption within five years.
Cost of implementation leads the barriers, ahead of the complexity of the transition and the demand for ready-to-deploy products at 47% each.
Evaluating multiple vendors covers 58% of respondents, and 35% have not identified one at all.
Nearly all respondents require cryptographic solutions that are nationally governed, kept under their own control, or both.
The report sets out six recommendations in a fixed order, because each depends on the one before it. Discovery comes before planning, and planning before migration.
None of this depends on when a capable quantum computer arrives. Each step takes time to build and fits inside existing budget cycles.
Now, 0 to 12 months
Build an inventory of where cryptography is used across applications, devices, networks, certificates, and cloud services, and which algorithms are at risk. Then keep it current, with a named owner, rather than treating it as a one-off exercise.
1 to 3 years
Order the work by how long each system’s data has to stay confidential, not by how old the system is. The way systems agree their encryption keys is replaced first for long-lived data, with the new algorithms running alongside the existing ones so protection holds if either is later broken.
3 to 5+ years
Crypto-agility is the ability to swap algorithms, keys, and certificates without a rebuild. More post-quantum standards are still coming, so build systems where the next change is a configuration change, backed by a funded mandate and a named owner.
Four sections and 15 exhibits covering the quantum threat, where the world stands, the survey findings in full, and six recommendations in the order to take them.
Enter your details and the report opens straight away. A copy is sent to your inbox as well.
Respondents hold C-suite roles, VP and director of IT positions, digital transformation leadership, and heads of cybersecurity and compliance, across financial services, energy, healthcare, telecommunications, technology, government, and travel.
Respondents were anonymous, were not QuantumGate customers or contacts, and QuantumGate had no role in selecting them. They were screened for familiarity with post-quantum cryptography, so findings should be read as the position of senior security leaders already engaged with this question rather than of the market as a whole. All findings are self-reported and reflect how respondents assess their own organizations. They are not an audit and may differ from what regulators or external assessments would observe. Figures are presented as the survey recorded them and are rounded to the nearest whole percentage, so some do not sum to 100. Findings are reported at regional level and are not broken down by country. The findings, analysis, and recommendations are those of QuantumGate and do not represent the views or position of any individual named in the report, or of the organizations those individuals represent.