• 4 mins read
  • Published

Keyfactor revenue doubles as post-quantum migration accelerates

Daisy Shearer Physics and quantum technology editor Science.Report

Post by Daisy Shearer

Keyfactor revenue doubles as post-quantum migration accelerates Science.Report © science.report
Keyfactor revenue doubles as post-quantum migration accelerates © science.report

Keyfactor reports annual recurring revenue above $200 million as regulatory deadlines and post-quantum cryptography migration drive rapid adoption of automated certificate management and trust infrastructure

Keyfactor's annual recurring revenue has surged past $200 million, a figure that signals not just commercial momentum but a shift in how enterprises and public agencies are preparing for the cryptographic demands of the post-quantum era. This doubling of revenue in less than two years is not a routine growth story-it reflects a scramble among major institutions to overhaul digital trust infrastructure before quantum computers threaten classical encryption standards.

Regulatory pressure and migration deadlines

The catalyst for this acceleration is clear: regulatory mandates are forcing organizations to act. In June 2026, the White House issued executive orders requiring all federal agencies to expedite their transition to post-quantum cryptography (PQC), with a hard deadline set for 2030. This policy has immediate operational consequences for government and defense, but the effect is rippling through the private sector as well. Keyfactor's FedRAMP-certified platform is now positioned as a default choice for agencies and multinational corporations seeking automated certificate discovery, crypto-agility frameworks, and cloud-native public key infrastructure (PKI) capable of supporting PQC algorithms.

Technical adoption and measurable growth

Concrete adoption metrics underscore the scale of this migration. Keyfactor now claims active PKI certificate growth of 200% compared to 2025, a 168% increase in EJBCA SaaS certificates, and a 207% rise in automated certificate issuance over the previous year. The company reports that its technology is deployed by half of the top U.S. and European banks, 80% of leading U.S. retailers, and more than 40% of Fortune 100 enterprises. These figures are not just marketing milestones-they represent a measurable shift in how cryptographic assets are managed across hybrid and cloud-native environments.

Strategic investment and acquisition moves

In July 2026, Keyfactor secured a strategic growth investment exceeding $1 billion, led by Summit Partners. This capital is earmarked for global expansion and targeted acquisitions, including the planned purchase of UK-based Cofide. The integration of Cofide's SPIFFE/SPIRE-based workload identity verification is intended to extend Keyfactor's Trust Control Plane, enabling direct support for cloud-native workloads and AI agents. Such moves are designed to address the complexity of cryptographic management as organizations transition from legacy algorithms to PQC standards.

Operational impact and remaining challenges

Keyfactor's partner ecosystem now supports the deployment of PQC Centers of Excellence, allowing enterprises to audit cryptographic assets and establish post-quantum trust architectures. However, the technical and operational hurdles remain significant. Automated certificate management and crypto-agility frameworks are necessary but not sufficient for a complete migration. The transition to PQC algorithms requires careful inventory of existing cryptographic assets, validation of new standards, and ongoing monitoring for vulnerabilities. As seen in recent field deployments, the gap between laboratory demonstration and robust operational integration is often underestimated.

Keyfactor's rapid revenue growth and aggressive acquisition strategy reflect a market that is finally treating post-quantum migration as an urgent engineering problem rather than a distant theoretical risk. Yet the evidence shows that most organizations are still in the early stages of inventorying cryptographic assets and validating PQC readiness. The real test will be whether these platforms can deliver reliable, scalable, and independently verified security as quantum computing capabilities advance. For now, the numbers point to a market in transition-one where regulatory deadlines and technical uncertainty are driving both investment and operational overhaul, but where the engineering work of secure migration is only just beginning.

Post-quantum cryptography refers to cryptographic algorithms designed to resist attacks from quantum computers, which could break widely used public-key systems such as RSA and ECC. Unlike quantum key distribution, PQC algorithms run on conventional hardware and are being standardized for broad deployment. Migration to PQC requires not only new algorithms but also comprehensive inventory and replacement of existing cryptographic assets, careful validation of implementations, and ongoing monitoring for vulnerabilities. The complexity of this transition is compounded by the need to maintain compatibility, performance, and regulatory compliance across diverse systems and environments.

Related articles