DigiCert made Quantum Central generally available on September 24, 2026, giving enterprises a management layer for cryptographic inventories, CBOM generation, policy checks, certificate issuance and post-quantum remediation workflows.
DigiCert made Quantum Central generally available on September 24, 2026, as an enterprise platform for managing post-quantum cryptography migration within DigiCert ONE. The software is designed to turn scattered records of certificates, keys and cryptographic dependencies into an inventory that security and compliance teams can act on rather than merely review.
The platform was first shown in preview in July 2026. DigiCert now presents it as available for free trials, demonstrations and enterprise deployment, positioning the release as an operational milestone rather than a new quantum-computing or cryptographic research result.
The release arrives against a sharp imbalance in DigiCert's 2026 DigiCert Quantum Readiness Outlook. The report says 87% of enterprises are planning, testing or executing post-quantum cryptography initiatives, yet only 7% have put quantum-safe or hybrid cryptographic primitives into production environments. These figures are company-reported readiness metrics, not an independent prevalence study, so they should be interpreted within DigiCert's own survey and assessment context.
That gap is operational rather than theoretical. An organization can decide that it needs quantum-safe encryption and still lack a reliable account of which certificates, keys, applications and network services depend on vulnerable public-key cryptography. The concern is amplified by the harvest-now-decrypt-later model, in which encrypted traffic captured today could be stored for possible decryption after sufficiently capable quantum computers become available.
The underlying scientific rationale is established by quantum algorithms rather than by Quantum Central itself. Shor's algorithm shows why widely deployed public-key systems based on integer factorization or discrete logarithms require migration planning, while Grover's algorithm implies a quadratic, rather than exponential, search advantage against idealized brute-force attacks on symmetric constructions. Post-quantum cryptography therefore runs on conventional computers but uses mathematical problems selected to resist known quantum attacks. The NIST post-quantum program provides the broader standardization context for this transition.
Quantum Central does not demonstrate a quantum computer, measure qubit performance or introduce a new cryptographic algorithm. It is a conventional enterprise management layer for organizing the work required to move toward standards designed to resist attacks associated with future quantum computers. This distinction is important for readers comparing commercial migration products with laboratory research conducted at institutions such as MIT and CERN or discussed in journals including Nature.
Quantum Central can normalize information from network scans, certificate lifecycle management platforms, key vaults, software bills of materials and external application programming interfaces. DigiCert says the resulting view can consolidate public-key infrastructure records, vault data, comma-separated-value files and SBOM information in one dashboard.
It also generates Cryptographic Bills of Materials, or CBOMs. These records are intended to make cryptographic dependencies more visible and exportable, giving risk, security and IT compliance teams a common basis for tracking exposure and reporting migration progress. A CBOM can identify where algorithms, protocols, libraries, certificates and keys appear in an application or service chain, although its usefulness depends on how completely those components are discovered.
This architecture matters because cryptographic material is rarely managed in one place. Certificates may be handled through a dedicated lifecycle system while keys sit in separate vaults and software dependencies remain embedded in application inventories. A unified record can reduce that fragmentation, but the quality of the result will still depend on the completeness, freshness and accuracy of the connected data sources.
For readers tracking the wider enterprise security market, an earlier analysis described a comparable effort to map cryptographic risk before migration. DigiCert's announcement places the emphasis on orchestration across discovery, policy and issuance rather than on inventory alone.
Quantum Central combines a policy engine with Jira workflow integration. The stated purpose is to flag assets that do not meet selected post-quantum requirements and automate change requests that can move those assets into remediation pipelines. Policies may be organization-specific, which allows teams to account for application criticality, algorithm support, certificate lifetimes and staged deployment requirements.
An inventory-aware AI assistant is also included. DigiCert describes it as a tool for exploring exposure and recommending next steps. That function should be understood as decision support rather than independent proof that an asset is safe: recommendations remain dependent on the underlying inventory, the chosen policy and the organization's review process.
The execution layer connects the management suite with DigiCert Trust Lifecycle Manager, DigiCert Private CA and CertCentral. Through those services, teams can carry out certificate lifecycle changes and issue hybrid or quantum-safe TLS certificates. This connection is the platform's most consequential distinction from a static assessment dashboard because it links identification of migration work to certificate deployment.
Industry testing is moving in the same direction. In the reported 2026 World Quantum Readiness Day context, Microsoft disclosed a post-quantum TLS pilot through its Trusted Root Program involving seven certificate authorities, including DigiCert. Such a pilot is evidence of interoperability testing in a controlled environment, not proof that post-quantum TLS has been universally validated across production networks.
Under Senior Director of Product Management Kevin Hilscher, DigiCert presents the system as enabling an incremental migration. Organizations can prioritize high-value asset environments first and expand the program across the enterprise instead of attempting an undifferentiated replacement of every cryptographic dependency at once.
The announcement provides product capabilities and deployment pathways rather than an independent measurement of cryptographic protection. No qubit count, gate fidelity, security proof, production migration total or independent audit is supplied in the input material. The 87% and 7% figures come from DigiCert's own readiness outlook, so they describe the company's reported survey or assessment context rather than a measurement established here by an external study.
Quantum Central therefore should not be presented as evidence that post-quantum migration has been completed or that any particular organization is protected from harvest-now-decrypt-later exposure. Its reported role is narrower and more practical: discover cryptographic assets, generate CBOMs, apply policy checks, organize remediation, track progress and connect approved changes to certificate issuance.
That is still a meaningful piece of infrastructure. Post-quantum cryptography runs on conventional computing systems, and its deployment challenge is partly one of dependency mapping, governance and controlled replacement. A platform that links those steps can make migration auditable, but it cannot compensate for missing asset data, unsuitable policies, weak key management or untested changes in dependent applications.
The strongest case for Quantum Central is consequently not quantum performance but operational discipline. DigiCert has packaged a route from fragmented cryptographic records to managed certificate changes, addressing a real obstacle identified by its own readiness figures. The release is useful as a migration-management milestone, not as proof that the enterprise has solved post-quantum security; the decisive test will be whether organizations can turn the platform's inventories and workflows into verified production changes without disrupting the systems those certificates protect.