{"id":"d195231d-9af6-4868-9979-5cc7f790fff6","arxiv_id":"2509.01731","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":3.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A survey-based review concludes that enterprise readiness for quantum-safe cryptography is uneven and generally insufficient, with fewer than 5% having transition plans.","lead":"This paper reviews industry surveys and expert reports to assess whether companies are ready for future quantum computers that could break current encryption. It concludes that most enterprises have no formal transition plan and recommends starting migration efforts immediately.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The 'fewer than 5% of enterprises' statistic rests on a single ISACA survey with no published methodology, and §3.1 shifts from 'technology professionals' to 'enterprises,' so the central quantitative claim lacks adequate support.","rationale":"The reader's weakest_assumption identifies exactly the same concern: the central 'fewer than 5%' statistic is sourced to a single ISACA press release without methodology, and the paper generalizes it to global enterprises. This is the most load-bearing issue because the abstract's quantitative claim is the paper's main novel datapoint and the basis for the urgency argument in Sections 5 and 6. Other parts of the paper, such as the NIST PQC standards and the Capgemini sector survey, are independently plausible, but they do not rescue the specific 'fewer than 5%' figure. The paper's overall qualitative conclusion — uneven readiness — is likely correct, so the appropriate response is not rejection but conditional acceptance: the central quantitative claim must be corrected or caveated before the synthesis is relied upon. A single concrete check — retrieving the underlying ISACA survey report and recomputing the figure with a definition and confidence interval — would settle whether the concern lands. The verdict should remain CONDITIONAL, consistent with the reader, because the paper can be revised without losing its overall contribution.","tokens_in":26274,"tokens_out":1771,"duration_ms":21455,"concrete_test":"Obtain the full ISACA 2025 survey report or methodology behind reference [56]. Check the sample size, sampling frame, respondent roles (e.g., CISOs vs. IT staff), response rate, and the exact survey question that produced the '5% roadmap' figure. Then recompute a defensible global enterprise estimate, reporting a confidence interval or range. If the ISACA sample is not representative of all enterprises, replace the unqualified 'fewer than 5%' in the abstract with a caveated range, e.g., 'roughly 5% of surveyed technology professionals' or 'between 3% and 10% of enterprises depending on definition.'","verdict_should_be":"CONDITIONAL","load_bearing_attack":"The abstract's headline claim — 'fewer than 5% of enterprises have formal quantum-transition plans' — is the paper's central quantitative anchor. Section 3.1 attributes this to ISACA 2025 [56], but the cited source is a press release with no sample size, sampling frame, margin of error, or definition of 'quantum computing strategy or roadmap.' The paper also conflates two different statistics: the press release reports that 5% of organizations made quantum threats a 'high business priority' and separately that 5% have a 'defined quantum computing strategy or roadmap'; the abstract converts the latter into 'formal quantum-transition plans' for 'enterprises.' Moreover, the survey population appears to be 'technology professionals' (likely ISACA members), not a representative sample of enterprises globally. The text itself notes 62% of technology professionals are worried, but the conclusion generalizes to enterprises broadly. If the ISACA survey is a self-selected, professional-membership sample or defines 'roadmap' narrowly, the 'fewer than 5%' figure could be an overstatement, and the urgency argument built on it loses its numerical precision. This is not a technical inconsistency, but it is a load-bearing evidential weakness because the paper offers no other independently documented statistic for this specific claim.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper assesses enterprise readiness for quantum-safe cybersecurity by reviewing three perspectives: technology maturity (PQC and QKD), enterprise organizational readiness, and threat-actor dynamics. It synthesizes recent standards, surveys, and threat intelligence into a SWOT analysis. The central claim is that readiness is uneven and generally insufficient: PQC standards and niche QKD deployments show technical progress, but fewer than 5% of enterprises have formal quantum-transition plans, many underestimate harvest-now/decrypt-later risks, and most sectors remain exploratory or stalled by cost, complexity, and skills gaps. It closes with recommendations: build crypto-agility, create transition roadmaps, prioritize PQC deployment, and upskill teams.","tokens_in":26579,"tokens_out":2823,"duration_ms":34371,"significance":"The paper provides a useful, up-to-date synthesis of a fast-moving topic and correctly distinguishes PQC from QKD in terms of maturity and practical deployability. Its strength is the breadth of recent references and the balanced discussion of technical constraints. However, the paper contributes no original data or systematic methodology; its value is as an organized review. The headline quantitative claim—fewer than 5% of enterprises have formal quantum-transition plans—rests on a single press release and is generalized beyond the surveyed population. Because the paper's urgency argument depends on this number, the evidential weakness is load-bearing. The recommendations are sensible but generic. Overall, the central narrative is defensible if appropriately qualified, but the current presentation overstates confidence in the supporting evidence.","major_comments":[{"comment":"The abstract states that 'fewer than 5% of enterprises have formal quantum-transition plans.' This is attributed to the ISACA 2025 press release [56]. The press release reports two separate statistics: 5% of organizations made quantum threats a 'high business priority' and 5% have a 'defined quantum computing strategy or roadmap.' The surveyed population appears to be technology professionals (likely ISACA members), not a representative sample of global enterprises. The manuscript does not report the sample size, sampling frame, margin of error, or definition of 'roadmap.' The inference from a self-selected professional survey to 'enterprises' is not justified. Please soften the claim to 'surveyed technology professionals' or provide additional independent evidence.","section":"Abstract and §3.1"},{"comment":"The paper repeatedly invokes 'expert consensus' that a cryptanalytically relevant quantum computer (CRQC) will not appear before the 2030s, citing a RAND commentary [3] and a Cyber Defense Magazine blog post [8]. A single commentary, even by a respected analyst, does not constitute 'expert consensus.' This overstatement underlies the conclusion that '10 years is likely just enough to get ready.' Please either cite a systematic expert elicitation or multiple independent primary assessments, or clearly label this as one prominent expert view with a range of opinions.","section":"§4.1 and §6.1"},{"comment":"The main quantitative support for enterprise unpreparedness uses two sources of differing quality: the ISACA press release [56] and a Capgemini Research Institute report [59] that the reference itself marks as a 'fourth draft.' The manuscript presents these figures (e.g., 41% of organizations not planning to address quantum computing, 37% not discussing it, 51% citing organizational inertia) without discussing sampling or draft status. As these statistics drive the central conclusion, the authors should disclose known limitations of each source and indicate whether the Capgemini findings were updated in a final version.","section":"§3.1 and §3.2"},{"comment":"The paper has no methodology section describing how sources were selected, how surveys were evaluated for quality, or how conflicting statistics were reconciled. This is particularly important because the paper's conclusions are entirely derived from external reports. A short 'methods and limitations' subsection would allow readers to assess the evidence base and would also clarify that this is a narrative review, not a systematic literature review.","section":"Introduction and Section 2-4"}],"minor_comments":[{"comment":"Several typographical artifacts appear: 'F ALCON' should be 'FALCON'; 'T echnical Debt' should be 'Technical Debt'; 'c ompanies' should be 'companies' in §3.1; and Figure 1 contains 'uncertfainty' for 'uncertainty.'","section":"§2.1 and §3.2"},{"comment":"Reference [39] is a Wikipedia article; please replace with a primary or peer-reviewed source for the SIKE break. Reference [59] is a draft report with a versioned URL; cite the final version if available and provide an access date consistent with the reference style.","section":"References"},{"comment":"The term 'Y2Q' is introduced without definition; given that it appears only once, either define it on first use or consider removing it.","section":"§4.1"},{"comment":"The SWOT diagram is schematic and somewhat difficult to parse in its current form. Consider a higher-resolution figure with bullets for each SWOT category.","section":"Figure 1"}],"recommendation":"major_revision","confidential_remarks":"This manuscript is closer to a policy-oriented industry review than a novel research contribution. If the journal expects original technical or empirical content, the fit may be borderline. The main concern is that the headline statistic is over-generalized from a single press release; this is fixable by rephrasing and adding caveats, so I do not recommend rejection. The authors would also strengthen the paper by being transparent about source quality, particularly the draft status of the Capgemini report and the use of commentary articles to support 'consensus' claims."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"What you should know: this is a competent, current review of enterprise quantum-readiness surveys, but the headline \"fewer than 5% of enterprises\" is a press-release number with no published methodology, not a measured fact.\n\nThe paper does well organizing the material into three perspectives—technologist, CISO/CIO, threat actor—and the SWOT synthesis is a sensible framework. It correctly notes that PQC is the practical path while QKD is niche, and its recommendations (crypto inventory, crypto-agility, phased deployment) line up with NIST and NCSC guidance. For a practitioner wanting a 2025 snapshot, this is useful.\n\nThe soft spots are in the numbers. The load-bearing statistic, fewer than 5%, comes from a single ISACA press release with no sample size, sampling frame, or margin of error, and the paper moves from \"technology professionals\" to \"enterprises\" without acknowledging the jump. The \"expert consensus\" on CRQCs in the 2030s is actually one RAND commentary; the paper itself cites earlier and later estimates, so \"consensus\" is an overstatement. There is also no source-selection methodology—it's a narrative review, which is fine, but the reader should treat the survey percentages as indicative, not precise.\n\nThat said, the central qualitative claim—preparedness is uneven and generally insufficient—holds up. Multiple surveys (ISC2, Capgemini, ISACA, Forescout) point in the same direction. So the argument survives, but the paper would be more credible if the abstract and Section 3.1 were softened to acknowledge the limitations of the underlying sources.\n\nWho is this for? CISOs, policy people, and students needing a landscape summary. It is not a research contribution—no new data, no new methods, no falsifiable predictions. The review is honest about its own scope, which counts for something.\n\nRecommendation: I'd send it to peer review at a practitioner- or survey-friendly venue, but the authors should fix the overreach in the abstract and Section 3.1, and ideally report the ISACA methodology caveats. If the target venue is a top research conference, it's a desk reject. Either way, engage with it as a useful briefing, not as an authoritative data source.","headline":"Competent 2025 survey synthesis, but the headline 5% statistic is a press-release number without methodology; use it as an indicative briefing, not a rigorous measurement.","tokens_in":26985,"tokens_out":2795,"would_cite":false,"duration_ms":29216,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This review argues that enterprise readiness for quantum-safe cybersecurity is uneven and generally insufficient, with fewer than 5% of organizations holding formal transition plans and the threat of 'harvest now, decrypt later' already act","keywords":["quantum-safe cybersecurity","post-quantum cryptography","quantum key distribution","enterprise readiness","cryptographic agility","harvest now decrypt later","quantum threat timeline","SWOT analysis"],"falsifier":"A representative global survey of chief information security officers, with published methodology, that found more than 20% of enterprises holding formal quantum-transition roadmaps with budgeted post-quantum pilots would falsify the paper's central unpreparedness claim. A second check would be measuring whether large enterprises have completed cryptographic inventories: if most have, the 'long tail of unprepared firms' conclusion loses its quantitative support.","tokens_in":26234,"feed_emoji":"⚛️","tokens_out":10170,"duration_ms":105086,"temperature":0.7,"pith_summary":"This paper asks whether enterprises are actually ready for the collapse of classical public-key cryptography that a large quantum computer would cause. Its answer is a qualified no: the necessary technology exists, but enterprise adoption is far behind. Reviewing the situation from the vantage points of technologists, security executives, and threat actors, and folding the results into a SWOT analysis, the paper finds that fewer than 5% of organizations have a formal quantum-transition plan, that most sectors are still in an exploratory or stalled state, and that many enterprises underestimate the 'harvest now, decrypt later' tactic already being used by sophisticated adversaries. The reason the conclusion matters is that migration is a multi-year, whole-infrastructure effort, so the true deadline is not the arrival of a quantum computer but the moment today's encrypted data loses its protection.","feed_headline":"Fewer than 5% of enterprises have a quantum-safe plan","feed_subtitle":"Quantum-safe tech is ready; most enterprises are not, and data harvested today could be decrypted later.","key_machinery":"The paper's organizing machinery is a three-perspective stakeholder analysis — technologist, enterprise decision-maker, and threat actor — synthesized through a SWOT matrix. The SWOT is not decorative: it maps internal strengths and weaknesses (usable post-quantum standards vs. missing roadmaps and skills gaps) against external opportunities and threats (regulatory deadlines, harvest-now-decrypt-later) and thereby converts the three separate narratives into the single conclusion that readiness is uneven and generally insufficient. Inside the threat perspective, the load-bearing mechanism is the 'store now, decrypt later' dynamic, which turns a future quantum-computing risk into a present dat","core_discovery":"On the paper's own terms, the central claim is a readiness gap expressed as a mismatch of three timelines. The technological timeline is essentially ready: standardized post-quantum algorithms exist, initial deployments are running, and quantum key distribution is mature enough for niche links but is not a general replacement for classical cryptography. The adversarial timeline is already active: sophisticated actors are stockpiling encrypted traffic in anticipation of future decryption. The enterprise timeline is the laggard: most organizations lack a roadmap, budget, cryptographic inventories, or the skilled staff needed to migrate, and the sectors that are moving (banking, telecom, govern","pith_inferences":["Editorial extension: if the under-5% roadmap figure is roughly representative, demand for migration tools and trained integrators is likely to arrive as a synchronized shock around regulatory deadlines, so supply-side capacity needs to be built before enterprises feel the push.","Editorial extension: the paper's SWOT implies a testable sector-level prediction — organizations that already run cryptographic inventories for compliance reasons will adopt post-quantum cryptography faster than otherwise similar peers; a survey controlling for existing crypto-governance maturity could check this.","Editorial extension: an outcome the paper leaves underweighted is that cloud and software vendors may 'bake in' post-quantum support by default before most enterprises act, which could spare small organizations the worst of the transition while making vendor supply-chain diligence the new critical dependency."],"forward_implications":["Data with a long confidentiality shelf life is exposed today: if adversaries are already harvesting encrypted traffic, protecting archives and long-lived records with quantum-safe encryption becomes a present-day task, not a 2030s task.","Post-quantum cryptography is the workhorse of the transition; quantum key distribution remains a specialty tool for high-value point-to-point links, so enterprises should focus migration effort on software-upgradeable public-key systems first.","The multi-year nature of cryptographic migration means organizations that have not started inventories and crypto-agility work by the mid-2020s will likely face a rushed, more costly transition under regulatory or incident pressure.","Regulatory backstops will increasingly turn quantum readiness from a voluntary risk exercise into a compliance obligation, especially for critical infrastructure and financial services.","First movers in banking, telecom, and government will generate the integration lessons and vendor demand that make post-quantum adoption easier for latecomers, but those latecomers still need to plan rather than wait for turnkey fixes."],"supporting_citations":[{"why":"Supplies the central readiness metric: fewer than 5% of organizations have a quantum computing roadmap.","marker":"[56]"},{"why":"Supplies sector-level adoption data and the named barriers (skills, standards uncertainty, inertia) behind the readiness gap.","marker":"[59]"},{"why":"Reports the finalized selection of post-quantum algorithms, grounding the technologist assessment of maturity.","marker":"[4]"},{"why":"Documents the release of the first three finalized post-quantum standards, establishing that usable standards now exist.","marker":"[17]"},{"why":"Compares deployed QKD use cases with PQC and concludes QKD is niche while PQC is the primary migration path.","marker":"[5]"},{"why":"Provides the likely timeline for a cryptanalytically relevant quantum computer and the argument that a secret breakthrough is unlikely, shaping threat urgency.","marker":"[3]"},{"why":"Documents adversaries harvesting encrypted data now and the scale of outdated cryptographic infrastructure, linking threat and readiness.","marker":"[61]"}],"fun_headline_variants":["Enterprises lag as quantum threat looms","Quantum-safe tech is ready, enterprises aren't","Harvest now, decrypt later: most firms unprepared","Only 5% of enterprises have quantum transition plans","Quantum threat real, but corporate readiness is low"],"cache_read_input_tokens":2688,"weakest_assumption_plain":"The fewer-than-5% figure, which anchors the claim that most enterprises are unprepared, comes from a single industry survey that the paper does not describe in terms of sample size, sampling frame, or confidence, and it is then generalized to enterprises worldwide.","fun_headline_variants_meta":{"raw":{"variants":["Enterprises lag as quantum threat looms","Quantum-safe tech is ready, enterprises aren't","Harvest now, decrypt later: most firms unprepared","Only 5% of enterprises have quantum transition plans","Quantum threat real, but corporate readiness is low"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000221,"raw_usage":{"total_tokens":1304,"prompt_tokens":777,"completion_tokens":527,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":521,"completion_tokens_details":{"reasoning_tokens":465}},"tokens_in":521,"tokens_out":527,"duration_ms":5916,"temperature":1.0,"reasoning_tokens":465,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-05T12:13:47.681570+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A representative global survey of chief information security officers, with published methodology, that found more than 20% of enterprises holding formal quantum-transition roadmaps with budgeted post-quantum pilots would falsify the paper's central unpreparedness claim. A second check would be measuring whether large enterprises have completed cryptographic inventories: if most have, the 'long tail of unprepared firms' conclusion loses its quantitative support.","supporting_citations":[{"cited_title":"Despite rising concerns, 95% of organizations lack a quantum computing roadmap, isaca finds,","cited_arxiv_id":null,"evidence_quote":"Supplies the central readiness metric: fewer than 5% of organizations have a quantum computing roadmap."},{"cited_title":"Future encrypted: Why post-quantum cryp- tography tops the new cybersecurity agenda (fourth draft),","cited_arxiv_id":null,"evidence_quote":"Supplies sector-level adoption data and the named barriers (skills, standards uncertainty, inertia) behind the readiness gap."},{"cited_title":"Status report on the third round of the nist post-quantum cryptography standardization process,","cited_arxiv_id":null,"evidence_quote":"Reports the finalized selection of post-quantum algorithms, grounding the technologist assessment of maturity."},{"cited_title":"Nist releases first 3 finalized post-quantum encryption standards,","cited_arxiv_id":null,"evidence_quote":"Documents the release of the first three finalized post-quantum standards, establishing that usable standards now exist."},{"cited_title":"A critical analysis of deployed use cases for quantum key distribution and comparison with post-quantum cryptography,","cited_arxiv_id":null,"evidence_quote":"Compares deployed QKD use cases with PQC and concludes QKD is niche while PQC is the primary migration path."},{"cited_title":"When a quantum computer is able to break our encryption, it won’t be a secret,","cited_arxiv_id":null,"evidence_quote":"Provides the likely timeline for a cryptanalytically relevant quantum computer and the argument that a secret breakthrough is unlikely, shaping threat urgency."},{"cited_title":"Future of encryption in a quan- tum cryptography world,","cited_arxiv_id":null,"evidence_quote":"Documents adversaries harvesting encrypted data now and the scale of outdated cryptographic infrastructure, linking threat and readiness."}],"review_version":1}