Infosecurity Magazine published a survey of over a dozen cybersecurity vendors, revealing a starkly uneven landscape for post-quantum cryptography readiness.
While Cloudflare, Palo Alto Networks, Certes, and Island have post-quantum cryptography (PQC) shipping in production today, others like Keeper and 1Password are mid-rollout, Bitdefender is still assessing, and Abnormal AI is explicitly waiting on its cloud vendors before setting any internal date. The finding underneath the survey is the one that should worry you.

The uneven landscape
The survey shows how uneven PQC readiness is across the cybersecurity industry:
- Cloudflare has already completed PQC migration within its internal systems when algorithms are available.
- Palo Alto‘s next-generation firewalls now feature built-in post-quantum capabilities. Certes offers PQC “available today” in its Data Protection and Risk Mitigation (DRRM) solution.
- Island has implemented post-quantum ciphers for data in memory and at rest.
- Keeper Security is executing a “multi-year, phased rollout prioritizing crypto-agility.”
- 1Password has enabled PQC across Application Programming Interface (API) endpoints and secured internet-facing traffic with hybrid post-quantum Transport Layer Security (TLS).
- Check Point has enabled post-quantum protection for site-to-site Virtual Private Networks (VPNs) and TLS session inspection.
- Bitdefender has completed its initial assessment phase but is “actively enhancing relevant components.”
- Abnormal AI has completed a full cryptographic inventory but is waiting on third-party readiness.

The supply chain risk
The survey highlights a critical supply chain risk: if you migrate to quantum-safe encryption while the vendors securing your network do not, you have reinforced the front door and left the window open.
Joe Ghalbouni of the EDHEC Quantum Institute says organizations lack a vendor-agnostic quantum risk assessment framework.
Thibaud Ecarot of the University of Sherbrooke warns that existing products provide “mere lists of Rivest, Shamir, and Adleman (RSA) keys, which are not helpful when undertaking a PQC migration”: a key list is not an inventory. An inventory tells you what is exposed, what you inherited from a vendor, and what to fix first.
For defenders, if there is a lesson on this is that you cannot migrate your vendors, but you can measure them.
The crypto blind spot: “Harvest now, decrypt later”
While the Infosecurity survey focuses on traditional enterprise security vendors, the implications for crypto are more urgent. The “harvest now, decrypt later” threat means adversaries can capture encrypted blockchain data today and decrypt it once quantum computers arrive. For crypto, this is not a future problem, but a present-day data protection concern.
Blockchain networks rely heavily on public-key cryptography [Elliptic Curve Digital Signature Algorithm (ECDSA), Ed25519] that quantum computers will eventually break.
In contrast to traditional enterprises that can rotate certificates, many blockchains have fixed cryptographic assumptions baked into their protocols. For instance, Bitcoin addresses that have never revealed their public key offer some protection, but most Bitcoin in circulation sits in addresses that have already exposed their public key.
The way the industry is reacting is pretty hit-or-miss: Bitcoin post-quantum migration is just starting to be discussed, while Ethereum is already building a plan and working on the tech.
This gap in vendor readiness is a huge deal for crypto custodians, decentralized finance (DeFi) protocols, and exchanges. These platforms count on outside vendors for everything from managing keys to secure monitoring.
Something to take into account here is that if your firewall vendor is not quantum-safe by 2027, your exchange is not quantum-safe, no matter how fast you migrate your wallet infrastructure.
The crypto world needs to get a better handle on its own “inventory” by figuring out exactly where it’s vulnerable and finding a way to see which vendors are actually ready for the quantum shift.
With AI being a strong tool to find vulnerabilities, it could also break the same security systems. Some big industry players are starting to think further. For example, Coinbase, BlackRock, and Fidelity launched the Bitcoin Security Consortium for quantum threats. Galaxy committed around $5 million to protect Bitcoin from these threats. BitGo launched quantum security tools for institutional Bitcoin wallets.
And finally, President Trump just signed a couple of new executive orders on quantum tech, pushing the government’s deadline for post-quantum crypto up from 2035 to 2031.



