A joint report by QuantumGate and the UAE Cyber Security Council reveals that 64% of organisations in key GCC markets have allocated budgets for post-quantum cryptography migration. While awareness of quantum threats like “harvest now, decrypt later” is high at 97%, the research highlights a critical need for verified cryptographic discovery to secure long-term data and infrastructure.
The research finds that 64% of surveyed organizations have a budgeted post-quantum initiative, and 84% are planning a transition. As programs move into execution, cryptographic discovery is emerging as a critical next step.
Cryptographic discovery establishes an inventory of the keys, certificates, algorithms, and protocols an organization uses, together with what they protect. It has begun at 35% of surveyed organizations. A verified inventory helps identify quantum-vulnerable cryptography, prioritize systems and data, and size, sequence and budget migration.
The issue is time-sensitive because long-lived encrypted data can be at risk before a cryptographically relevant quantum computer exists. Under harvest now, decrypt later, an adversary can collect encrypted information today and retain it until a sufficiently capable quantum computer can break the public-key cryptography protecting its keys and in other instances the information.
H.E. Dr. Mohamed Al Kuwaiti, Head of Cyber Security for the UAE Government and Chairman of the UAE Cyber Security Council, said: “The UAE has always taken a proactive approach to emerging technologies, and post-quantum security is no different. As digital services, critical infrastructure and data become increasingly connected, quantum-safe cryptography must become part of the fabric of our national cybersecurity ecosystem. Our focus is on giving organizations a clear framework to assess their cryptographic environment, plan early and move forward in a coordinated way.”
Dr. Najwa Aaraj, Chief Executive Officer of QuantumGate and the Technology Innovation Institute, said: “The research shows that organizations across the region are taking post-quantum security seriously. Funding is being committed and planning is already under way. The next step is to translate that intent into an executable program. That starts with knowing where cryptography sits, what it protects and where the greatest exposure lies. With that visibility, organizations can make better decisions on priorities, investment and migration, and build the crypto-agility they will need for the years ahead.”
Awareness of that risk is already high, with 97% of respondents recognizing the harvest-now, decrypt-later threat, while 58% believe a cryptographically relevant quantum computer capable of breaking today’s public-key cryptography could emerge within five years.
The planning divides evenly between organizations that have a roadmap and those still building one: 42% of respondents are working to a defined roadmap, and a further 42% are in the process of defining one. Alongside this, 34% rate their organization as well or very well prepared to execute the transition.
The findings show a gap between reported visibility and verified discovery. While 66% say they have visibility into the cryptography they use, only 35% have conducted or initiated discovery. A further 54% plan to begin discovery.
Post-quantum delivery decisions remain open, with 58% of organizations evaluating multiple providers, 35% yet to identify one, and 6% having selected a preferred partner.
One requirement, however, is clear: 98% of respondents require cryptographic solutions that are nationally governed, locally controlled, or both. The report finds that sovereign or local control is therefore becoming a baseline procurement requirement across these markets rather than a point of differentiation between suppliers.
The report recommends that organizations begin with a cryptographic inventory, prioritize the data that has to stay confidential longest, assign clear ownership of the program, and design systems in which changing a cryptographic algorithm is a configuration change rather than a re-engineering effort.



