64% of Organizations in GCC Are Ready for Post-Quantum Migration

Organisations in selected GCC markets are advancing their preparations for post-quantum cryptography, with funding and planning already underway, according to The State of Post-Quantum Readiness in Key GCC Markets, published today by QuantumGate and the UAE Cyber Security Council, with support from the National Cryptography Centre and the Technology Innovation Institute.

The research finds that 64% of surveyed organisations have a budgeted post-quantum initiative, and 84% are planning a transition. As programs move into execution, cryptographic discovery is emerging as a critical next step.

Cryptographic discovery establishes an inventory of the keys, certificates, algorithms, and protocols an organisation uses, together with what they protect. It has begun at 35% of surveyed organisations. A verified inventory helps identify quantum-vulnerablecryptography, prioritise systems and data, and size, sequence and budget migration.

The issue is time-sensitive because long-lived encrypted data can be at risk before a cryptographically relevant quantum computer exists. Under a harvest-now, decrypt-later model, an adversary can collect encrypted information today and retain it until a sufficiently capable quantum computer can break the public-key cryptography protecting its keys and, in other instances, the information.

H.E. Dr. Mohamed Al Kuwaiti, Head of Cyber Security for the UAE Government and Chairman of the UAE Cyber Security Council, said: “The UAE has always taken a proactive approach to emerging technologies, and post-quantum security is no different. As digital services, critical infrastructure and data become increasingly connected, quantum-safe cryptography must become part of the fabric of our national cybersecurity ecosystem. Our focus is on giving organisations a clear framework to assess their cryptographic environment, plan early and move forward in a coordinated way.”

Dr Najwa Aaraj, Chief Executive Officer of QuantumGate and the Technology Innovation Institute, said: “The research shows that organisations across the region are taking post-quantum security seriously. Funding is being committed, and planning is already underway. The next step is to translate that intent into an executable program. That starts with knowing where cryptography sits, what it protects and where the greatest exposure lies. With that visibility, organisations can make better decisions on priorities, investment and migration, and build the crypto-agility they will need for the years ahead.”

Awareness of that risk is already high, with 97% of respondents recognising the harvest-now, decrypt-later threat, while 58% believe a cryptographically relevant quantum computer capable of breaking today’s public-key cryptography could emerge within five years.

Planning is split evenly between organisations with a roadmap and those still building one: 42% are working to a defined roadmap, and another 42% are in the process of defining one. Alongside this, 34% rate their organisation as well or very well prepared to execute the transition.

The findings show a gap between reported visibility and verified discovery. While 66% say they have visibility into the cryptography they use, only 35% have conducted or initiated discovery. A further 54% plan to begin discovery.

Post-quantum delivery decisions remain open, with 58% of organisations evaluating multiple providers, 35% yet to identify one, and 6% having selected a preferred partner.

One requirement, however, is clear: 98% of respondents require cryptographic solutions that are nationally governed, locally controlled, or both. The report finds that sovereign or local control is therefore becoming a baseline procurement requirement across these markets rather than a point of differentiation between suppliers.

The report recommends that organisations begin with a cryptographic inventory, prioritise the data that has to stay confidential longest, assign clear ownership of the program, and design systems in which changing a cryptographic algorithm is a configuration change rather than a re-engineering effort.