Back
Amit Sinha
Chief Executive Officer, DigiCert, Inc.

Amit Sinha, DigiCert | World Quantum Readiness Day

🎥 Oct 09, 2025 📺 SiliconANGLE theCUBE ⏱ 18m
In this interview from DigiCert World Quantum Readiness Day, Amit Sinha, CEO of DigiCert, joins theCUBE's John Furrier to ...
Watch on YouTube

About Amit Sinha

In a July 2026 interview with ETCIO, Amit Sinha discussed DigiCert's AI trust architecture and the concept of "agent passports" for autonomous AI systems. Sinha argued that as AI agents move from simple assistants to autonomous operators, enterprises need verifiable digital identities, strong authentication, and policy-led access before allowing agents to interact with sensitive systems. He described agent passports as a way to establish who created an agent, how it was trained, what it is authorized to access, and which actions it can take. Sinha also discussed DigiCert's work on confidential computing and content trust. He noted that DigiCert has been working with Google on third-party attestation for confidential computing environments, explaining that the company brings the same core third-party attestation used in certificate issuance to AI workloads running in cloud infrastructure. Additionally, he mentioned DigiCert's content trust platform, which uses the C2PA standard to provide media provenance for AI-generated videos and images.

Source: AI-verified profile updated from Amit Sinha's recent appearances. Browse all interviews →

Transcript (18 segments)
J
John Furrier0:01
Hello everyone. Welcome to the World Quantum Readiness Day event. I'm John Furrier, host of theCUBE here in our Palo Alto studio. Today we've got a full lineup of speakers and two tracks, business and technology. We have a question and answer opportunity, so feel free to ask questions at any time. And to kick things off, we have the CEO of Digicert, Amit Sinha, to kick off the fireside chat. Welcome to theCUBE.
A
Amit Sinha0:24
Well, thanks John. It's always a pleasure being back at theCUBE. I love chatting with you. It seems only yesterday I was here at the First World Quantum Readiness Day event, and time has flown. And here we are at event number two.
J
John Furrier0:39
Well, great to have you on. To kick things off, we've got a great lineup of technical and business tracks. First question is, is the world ready? What's going on in the market? Take us through what's changed and what's going on.
A
Amit Sinha0:51
It's a great question, John. Moving to Quantum is a huge change for organizations. And whenever people and organizations are faced with a big change, they usually go through the five stages of grief. It starts with denial. So organizations will often say, well, Quantum's a boogeyman. It's 10 years out there, it doesn't concern us. And then they hear from experts about, well, it really impacts them and they have to do something about it. And they go from there to bargaining. And bargaining is usually around, do I really have to worry about it for the next five years? Is this really in scope? Maybe it only affects the National Security Agency and super top secret organizations, not us. And then they dive deeper and they find out, well, it touches everything. It touches authentication, encryption, their foundational digital trust fabric, and they have to go through all of that. So that leads to anger. And anger is followed by a bit of depression when people realize, well, I don't have the resources, I don't have the budget. I don't have the exact buy-in. Even if I start today, I run out of time before I'm able to upgrade my entire trust fabric to make it quantum safe. And then finally, you get to acceptance when you realize, well, you just have to keep calm, move along and adopt post-quantum cryptography. So we've been tracking this for a while now, and when I started talking about post-quantum cryptography, most organizations and people were in denial. I just wrapped up our seven city Digital Trust Summit Roadshow, and I had the opportunity to meet over 700 organizations, and we did a live poll. We asked them, where are you in these five stages of emotions around PQC? Well, the good news is about 43% of organizations are in acceptance. They accept and they are actually doing tangible things to move to quantum safety. I'd say about 5% of those organizations are really advanced. We still have about 24% of organizations in denial. And part of the reason we are doing this event is to make sure everyone understands the importance of migrating to quantum safety. And then they go through those stages. And my bet is this is the year where most organizations, the vast majority of them accept that the time to act is now, and they all have to move and upgrade their digital trust fabric to make it quantum safe.
J
John Furrier3:40
Last year was the year one we did this, and it was, hey, be ready. Get some attention on the topic. This year it's a lot more going on. The numbers you quoted, some of them, people are accepting it. There's a lot going on in the market that's forcing this. So give us an update on the state of quantum because the skeptics who are like, well, we'll get to it's way down the road. That number has shrunk to years now single digits and more people are realizing that's going to happen faster and it might not happen with the good guys. So this is a huge and this balancing between the two. So give us an update on the state of quantum computing. What's happening with the actual capabilities and why is that moving this faster into customer zero and more people digging in?
A
Amit Sinha4:32
Yeah, that's a great question and part of the reason why people are still in denial is because we've been talking about quantum computing for a while. IBM was a pioneer and continues to be a pioneer in quantum computing, chipsets and infrastructure. But more recently, if you look at all the hyperscalers, Google, Microsoft, AWS, and more recently Nvidia and Cisco, they've all announced their bigger, faster, better quantum processors. So in many ways, I feel like this is the early days of transistors. Remember the Intel 4004 and the first few chips. And so where we are is in those early days of quantum computing, but the rate at which advances are happening is staggering. And most of the companies are addressing two problems. One is, how do I have more qbits, quantum bits similar to the early days of transistors? How do I pack more transistors and get more memory and more processing capabilities? The other aspect is how do I fix error correction so I can get more logical qbits out of the same physical number of qbits? Because errors in quantum computing is a big problem that needs to be solved. So my thesis is that quantum computing will have a ChatGPT moment where one day people will get up and wonder, wow, how did this disruption happen? Well, it's been cooking for a while, and all of the big tech firms are in a race for quantum supremacy because they view this as the next big thing. Now, the challenges and the advantages and disadvantages, quantum computing is a double-edged sword. If you looked at the Google announcement, they claimed that their willow chip was able to do a computation in five minutes. That would've taken the lifetime of the universe on the fastest supercomputer that's available today. So that's the massive compute capabilities that quantum computing can unleash and it can solve problems that are just infeasible today. But the flip side that we've known for a very long time is that it breaks current cryptography. The current cryptography, John, like you and I discussed, is based on these one-way math problems, like factoring large numbers into primes or discrete logarithms. So we've known for a while that Shor's algorithm can break RSA. If RSA is broken today, the internet would melt down. Similarly, we know Diffie-Hellman can be broken, and these are foundational algorithms that allow us to share keys, do encryption, do authentication. Similarly, Grover's algorithm for search exists for quantum computers that can cut down SHA256 and make it only as effective as half the number of bits. So those are the challenges. What I'd say is we are still in the early days of quantum computing, but the rate of advance is very rapid and all the big tech firms are on this race for quantum supremacy, and it's going to happen on an unpredictable timeline.
J
John Furrier7:49
I love the stats and the commentary around the progress because most people think, oh, some big computer's going to do something. No, but they're targeting these equations and these keys and cryptography. It's proof that post-quantum cryptography's here, do we have everything that we need to protect them? Because if the internet melts down, forget Bitcoin or anything that's out there, the whole world would collapse if this happens. So it is last year I think we talked about as an event that would really be a disaster. So are we ready? Do we have everything that we need? Post-quantum cryptography is here. What's your thoughts?
A
Amit Sinha8:27
I mean, the short answer is yes. Post-quantum cryptography is here. DigiCert has been working along with other cryptography experts. We've been collaborating with the National Institute of Standards and Technology. NIST, last year was a big year in fall last year when we did our first World Quantum Readiness Day event, NIST had announced the first three post-quantum cryptography algorithms, one for encryption and two for authentication. They are the FIPS 203, 204 and 205 standards. So these algorithms have been cooking for almost a decade. They've been looked at by some of the foremost math experts, cryptography experts, and they're available now as standards. In fact, the Digicert one platform supports all of these algorithms today where customers can play around experiment, benchmark, performance, et cetera. So the short answer is PQC algorithms are here. Now, there's work being done in the IETF to leverage the TLS 1.3 standard, which is what is used for encryption and authentication on internet communications to migrate them to these PQC algorithms. And it's a matter of months where a TLS 1.3 PQC standard will be available. We're going to have lots of experts today in our technical tracks talk about the ML-KEM algorithm, the ML-DSA algorithms that are available today. So stay tuned and you're going to learn a lot about the state of the art as far as PQC is concerned.
J
John Furrier10:03
Last year we highlighted the importance of standards. So it's nice to see NIST and the standards come together and the industry come together. We're starting to see visibility now into readiness last year, readiness preparedness, operationalizing it now. What are the leaders doing? Starting to see momentum. People are saying, okay, it's here. What are the leaders doing? What are they saying? Are the analysts on board? And who are these leaders and what are they doing?
A
Amit Sinha10:29
Yeah, it's a great question, John. And look, industry leaders are acting. You use iMessage on your Apple device, probably use WhatsApp. All of these messaging protocols have adopted PQC for key exchange. That is because people are concerned about harvest now and decrypt later style attacks. Even though we don't have sufficiently stable quantum computers to break current cryptography, people are concerned that packets on the internet can be sniffed and stored offline so that they can be decrypted later on. And that's the harvest now and decrypt later attack. Bad guys doing that, states doing that. They're waiting to attack and unlock those keys. Exactly. So to prevent that, iMessage, WhatsApp, even Zoom recently, whenever an organization controls both sides of the communication link, it's easy for them to upgrade their classical algorithms to post-quantum because they're able to do it unilaterally. We're still waiting, as I said, for IETF to come up with a TLS version client server where you have browser-based or app-based clients and servers that are run by different organizations that can interoperate and talk with each other. But again, lots of companies are doing it. You're going to hear from Cloudflare, they have done some very innovative things from the CDN edge to the origin server, making sure that that link is quantum safe. Cloud infrastructure vendors, Google, Microsoft, others, they've all started experimenting with HSMs and KMS key management systems that are quantum safe. So progressive organizations know that PQC is here and they're adopting it. The enterprises, they need to start prioritizing budgeting and migrating all their infrastructure and systems to quantum safety.
J
John Furrier12:26
We're going to hear from Cloudflare be hosting that panel. These are experts. This isn't like, hey, just go research. These are the alphas in the companies that are doing this, and so they see it. That's good news. But Digicert, you guys are involved in a lot of classical stuff like certificates, they're impacted. So talk about that. A lot of change going on there too. That's the current situation and post-quantum is a whole nother ballgame, but there's two factors here. Talk about the certificates and that impact.
A
Amit Sinha12:57
First, it's a great question. I've said a few times that the PKI industry is going through renaissance because three or four massive disruptive changes that are happening at the same time. So first, these algorithms behind PKI, behind certificates, behind authentication, encryption need to move from classical, which is broken by quantum, to quantum safe versions that we talked about. But also, even in the current classical cryptography sense, big industry standard changes are happening. Apple and Google recently introduced a ballot that got approved, which is going to take certificates that are today issued for a year and shrink that to 47 days. And that's a huge change. It's eight times more certificate operational overheads for organizations because a certificate that was valid on a system for a year suddenly is valid only for 47 days, and that change is going to happen over the next few years. So today, certificates are valid for 398 days. Come March next year in 2026, they'll be valid for 200 days. March 2027, they'll be valid for a hundred days. And then finally in 2029, they'll be valid for 47 days. I haven't met a single organization that does not have outages related to expired certificates. So if you're having outages today, two or three outages a day, it is common for some of these bigger organizations. Imagine what happens when you go to 47 days. You're going to have eight times more unless you modernize your PKI, unless you have a platform that can give you crypto agility, unless you have a platform that can give you dynamic automation, so you're not doing all of these things manually. So shortening certificate validity periods are forcing the need for automation. They're forcing the need for crypto agility, and that prepares organizations naturally to adopt post-quantum cryptography as well. Because what do you need? Crypto agility is all about having an inventory, having the ability and automation to dynamically swap out certificates, cryptographic algorithms, keys, and if you're able to automate it, then this migration to post-quantum doesn't seem like a massive once in a third year upgrade cycle.
J
John Furrier15:23
Well, two things there. One is outages and disruption is mitigated. And two, you're getting at the muscle building for the transition, post-quantum cryptography. So let's talk about that. They have to address it too. That's like a critical path for businesses we know that. Build the muscle for the transition to post-quantum, what's that about?
A
Amit Sinha15:46
Yeah, so look, in fact, we did a recent survey and we had Forrester do a total economic impact analysis, and they found that if you prepare for crypto agility, if you have automation in place, you can get over 300% ROI from that investment because you have less outages, you're not spending money in manual certificate rotations and manual steps that are needed to run this infrastructure. Now, on the PQC side, what's interesting is analysts such as Gartner are coming back and saying, well, we never gave a date, but now let's put a date. Gartner, for example, has said current asymmetric cryptography must be retired by 2029, and that happens to be the same timeline for the certificate validities that shrink from 398 days to 47 days. So you can see that all of these roads lead to Rome, and that's PKI modernization. Even if you don't believe in PQC, you must have a modern PKI system to be able to deal with shortening validity periods. And if you do that, you naturally prepare yourself for post-quantum cryptography because then swapping a classical algorithm with a PQC one, swapping a certificate that used RSA with a certificate that used ML-KEM becomes easier.
J
John Furrier17:20
And hardcore infrastructure teams are on this. So I think that's the good sign. And the dates are interesting. The folks we talked to, first of all, is oh, 10 years now that people say eight. Our research shows that the experts saying three to five years. So that's the zone.
A
Amit Sinha17:37
I think 2029 is a great date. As I said, it aligns with classical cryptography, shortening certificate validity periods. It aligns with Gartner and other experts talking about retiring and moving to post quantum. So next three years are going to be game changer. And the reason we are doing this Quantum Readiness Day event is the reality is for most organizations, even if they start today, even if they drop a bunch of things, they'll run out of time before they're able to upgrade. Because this is a once in a generation upgrade to the core foundational PKI infrastructure. And we are here to help. You're not in this alone, and we're looking forward to the sessions. We have a great lineup of experts where you'll get both business insights as well as technical blueprints and know-how on how to approach this massive problem.
J
John Furrier18:31
I mean, thank you for your leadership, and I'd like to point out that this is not just a digital sort of, it's a community event. Everyone's involved. NIST is lining up in the timeframe. You mentioned that window. So appreciate what you do and people got to get ready and start deploying customer zero scenarios.
A
Amit Sinha18:47
Absolutely. Thanks, John.