TL;DR: Post-quantum preparation is increasingly being treated as an operating discipline, with governance, cryptographic visibility, hybrid cryptography, and rapid certificate rotation at the centre of the response, according to DigiCert’s Quantum Readiness Awards highlighting how Migros and NTT DATA are approaching the issue.
Editorial analysis by NHI Mgmt Group, based on content published by DigiCert: “Migros Named Winner of the 2025 DigiCert Quantum Readiness Award”.
Key questions
Q: How should security teams prioritise quantum readiness work for certificate estates?
A: Start with the certificates that protect the most sensitive data and the longest-lived trust relationships, then work outward to lower-risk systems.
Q: Why does hybrid cryptography create governance complexity for IAM teams?
A: Because two trust modes have to coexist while policy, automation, and service dependencies remain stable.
Q: What are the warning signs that certificate governance is not ready for post-quantum change?
A: Common signs include incomplete certificate inventories, unclear ownership, long-lived trust paths, manual renewal steps, and no tested process for running multiple cryptographic modes together.
Practitioner guidance
- Map the certificate estate first Create an authoritative inventory of certificates, their owners, expiry dates, and the systems or data flows they protect before planning PQC transition work.
- Prioritise long-lived trust paths Rank certificates and dependent services by data sensitivity, exposure duration, and business criticality so the highest-risk trust paths move first.
- Run hybrid cryptography in controlled stages Test classical and post-quantum modes together in production-like conditions so teams can validate compatibility, resilience, and rollback behaviour.
Bottom line: Quantum readiness is being operationalised as a governance problem for certificates, trust chains, and lifecycle control rather than as a standalone cryptography task.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Quantum readiness has become a certificate governance discipline, not a distant cryptography project. The article shows that organisations are already treating trust inventory, lifecycle control, and policy enforcement as the operational work of post-quantum preparation. That moves quantum readiness into the same governance layer as identity lifecycle management, where ownership and timing matter as much as algorithm choice. For practitioners, the important shift is that trust assets now need the same management discipline as other identity-critical credentials.
A question worth separating out:
Q: What should organisations do when certificate rotation is still mostly manual?
A: Treat manual rotation as a readiness gap and test shorter lifecycles in a controlled way to expose where automation, approval paths, or service dependencies will fail. Manual handling scales poorly when trust transitions accelerate. The immediate goal is to prove that renewal can be repeated safely before the environment has to absorb wider cryptographic change.
👉 Read our full editorial: Quantum readiness is becoming an identity governance problem