• 8 mins read
  • Published

Sectigo Quantum Ready Maps the Enterprise PQC Migration

Daisy Shearer Physics and quantum technology editor Science.Report

Post by Daisy Shearer

Sectigo Quantum Ready Maps the Enterprise PQC Migration Science.Report © science.report
Sectigo Quantum Ready Maps the Enterprise PQC Migration © science.report

Sectigo announced Quantum Ready(TM) on 17 September 2026 as a Quantum Security Posture Management platform for discovering cryptographic assets, assessing post-quantum risk and prioritizing migration across hybrid enterprise environments.

Sectigo is turning the least visible part of post-quantum migration into a software inventory problem. Announced on 17 September 2026, Sectigo Quantum Ready(TM) is designed to continuously locate cryptographic assets across enterprise networks and connect that map to certificate management rather than relying on isolated security assessments. Sectigo describes the product as part of a broader Quantum Security Posture Management offering, with access initially limited to selected Early Access participants.

The timing reflects a transition in the field. In August 2024, NIST completed publication of the first major post-quantum cryptography standards, including ML-KEM for key establishment and ML-DSA for digital signatures. These standards do not require a quantum computer to operate: they are intended for deployment on conventional systems while resisting attack methods associated with sufficiently capable quantum machines. NIST's post-quantum standards program therefore frames migration as an engineering and governance task, not as a laboratory demonstration that a quantum attack has already occurred.

Seeing Hidden Cryptography

The platform targets a practical obstacle that sits before any migration plan: an organization cannot replace cryptographic assets it has not identified. Sectigo Quantum Ready(TM) scans hybrid cloud, application and network environments for PKI certificates, symmetric and asymmetric keys, active encryption algorithms and the application dependencies tied to them.

Its central output is an automated Cryptographic Bill of Materials, or CBOM. Unlike a static inventory assembled at one point in time, the system is intended to maintain a continuously updated record of where cryptography is deployed and how those assets relate to one another. Sectigo also presents the inventory as a continuously refreshed view of the enterprise cryptographic environment, including dependencies that may otherwise remain outside certificate-management workflows.

That distinction matters because certificates and keys do not operate in isolation. An apparently simple replacement can affect an application dependency, a network service or a certificate lifecycle process. The input material does not provide scan volumes, detection rates, confidence intervals or independent validation, so the platform should be understood as a newly launched enterprise software capability rather than a measured demonstration of migration success.

The scientific rationale for urgency is established but often simplified. Shor's algorithm shows, in theory, how a sufficiently large fault-tolerant quantum computer could threaten widely used public-key systems based on integer factorization or discrete logarithms. Grover's algorithm offers a quadratic speedup for generic search, which is generally addressed in symmetric cryptography through appropriate security margins and larger key sizes rather than by abandoning symmetric encryption altogether. Neither result constitutes evidence that present-day enterprise networks are being decrypted by quantum computers.

From Discovery to Action

Sectigo organizes the system around three operational stages. The discovery phase identifies assets and dependencies. The assessment and planning phase evaluates technical posture and exposure risk before producing prioritized migration roadmaps and baseline reports. The management and remediation phase connects those findings with Sectigo Certificate Manager for policy enforcement and certificate lifecycle updates.

That integration is the product's most consequential claim. A risk register that cannot trigger controlled changes remains an administrative exercise; linking discovery to certificate operations gives security teams a route from inventory to governed updates. The available information does not establish that the platform can automatically replace every cryptographic dependency or complete a PQC migration without human review.

Under Chief Product Officer Ian Hassard, the company is presenting Quantum Ready(TM) as an operating framework and continuous discovery engine. Sectigo separately promotes the QSPM and Quantum Ready(TM) combination as an enterprise quantum-readiness package. Its limited Early Access structure and requirement for participant selection place the launch at the evaluation stage rather than describing a broadly deployed commercial service.

What the Evidence Shows

The measurable information supplied with the announcement concerns the platform's scope rather than quantum performance. No qubit count, gate fidelity, coherence time, cryptographic benchmark, scan accuracy, migration duration or independently tested reduction in exposure is reported. There is also no physical quantum processor experiment in the material and no claim that Sectigo has demonstrated a quantum attack against current enterprise encryption.

That absence is important. Post-quantum cryptography runs on conventional computing infrastructure and its migration is primarily an inventory, integration, policy and lifecycle-management challenge. A QSPM platform can help an organization understand where algorithm changes may be required, but it does not itself establish that a future fault-tolerant quantum computer exists or that a particular cryptographic system has already been broken.

Research institutions such as MIT and CERN illustrate a different layer of the quantum ecosystem: developing and testing fundamental hardware, algorithms and physical systems. Quantum Ready(TM) addresses the enterprise control plane around those developments. Its value should therefore be judged by asset coverage, dependency analysis, interoperability, auditability and remediation workflow rather than by qubit performance or laboratory benchmarks. The distinction is consistent with the way Nature and other peer-reviewed journals separate theoretical quantum advantage from validated system-level capability.

The company is expanding this software launch alongside a dedicated hardware-backed sandbox initiative. The announcement does not specify the sandbox's architecture, operating conditions, performance or validation status. A related PQC migration report likewise illustrates why asset discovery and hardware trust are distinct parts of the security transition rather than interchangeable claims.

The Migration Bottleneck

For enterprise security teams, the immediate value of Quantum Ready(TM) is therefore visibility. A dynamic CBOM could give organizations a single place to track certificates, keys, algorithms and dependencies while they plan crypto-agile policy changes. That could be more operationally useful than a one-time audit if the discovery remains accurate as systems change.

The need for such planning is also becoming a governance issue. European legal and policy reviews published in 2026 repeatedly use 2035 as an indicative target for completing post-quantum encryption migration, while allowing exceptions for particularly complex technologies. Such timelines make discovery of long-lived data, embedded devices, legacy applications and third-party dependencies more important than a simple count of current certificates.

But visibility is not the same as readiness. The supplied material does not state which PQC algorithms the platform supports, how it handles legacy systems, how it measures exposure or how it validates discovered dependencies. It also does not report customer deployments, independent testing or completed migrations. Those missing details define the difference between a promising control layer and a proven enterprise standard.

Sectigo's launch is best read as a serious response to the accounting problem behind post-quantum security rather than as evidence that the quantum threat has arrived in operational networks. The strongest part of the announcement is its focus on maintaining a live cryptographic record and connecting that record to certificate operations; the weakest is the lack of disclosed performance and independent evidence. Until those details are available, Quantum Ready(TM) is a potentially useful migration framework in Early Access, not proof that an organization is already quantum safe.

A CBOM is simply an inventory of the cryptographic ingredients inside software and infrastructure. It can include certificates, keys, algorithms and the dependencies that make replacement risky. The inventory helps answer what must change and where, but it does not perform post-quantum cryptography itself, guarantee secure implementation or remove the need for testing and governance.

Related articles