Back
Amit Sinha
Chief Executive Officer, DigiCert, Inc.

DigiCert World Quantum Readiness Day 2025: CEO Amit Sinha with The Cube's CEO John Furrier

🎥 Sep 24, 2025 📺 DigiCert ⏱ 18m
DigiCert CEO Amit Sinha opens World Quantum Readiness Day 2025 alongside moderator John Furrier. From the current state of ...
Watch on YouTube

About Amit Sinha

In a July 2026 interview with ETCIO, Amit Sinha discussed DigiCert's AI trust architecture and the concept of "agent passports" for autonomous AI systems. Sinha argued that as AI agents move from simple assistants to autonomous operators, enterprises need verifiable digital identities, strong authentication, and policy-led access before allowing agents to interact with sensitive systems. He described agent passports as a way to establish who created an agent, how it was trained, what it is authorized to access, and which actions it can take. Sinha also discussed DigiCert's work on confidential computing and content trust. He noted that DigiCert has been working with Google on third-party attestation for confidential computing environments, explaining that the company brings the same core third-party attestation used in certificate issuance to AI workloads running in cloud infrastructure. Additionally, he mentioned DigiCert's content trust platform, which uses the C2PA standard to provide media provenance for AI-generated videos and images.

Source: AI-verified profile updated from Amit Sinha's recent appearances. Browse all interviews →

Transcript (28 segments)
J
John Furrier0:00
Hello and I'm John Furrier here in the queue. Welcome to World Quantum Readiness Day. We're here in our Palo Alto studios. Thanks for joining today. We have a chat available so feel free to type questions in the chat all day. Got a great lineup. And to kick it off, we have the CEO of DigiCert, Amit Sinha, here. Welcome to the Cube back again for Quantum Readiness Part Two.
A
Amit Sinha0:20
Well, thanks John. It's always a pleasure being back at the Cube. I love chatting with you. It seems only yesterday I was here at the first World Quantum Readiness Day event and time has flown and here we are at event number two.
J
John Furrier0:35
Well, great to have you on to kick things off. We got a great lineup of technical and business tracks. First question is: Is the world ready? What's going on in the market? Tell us, take us through what's changed and what's going on.
A
Amit Sinha0:47
It's a great question. Moving to quantum is a huge change for organizations, and they often go through the five stages of grief: denial, bargaining, anger, depression, and acceptance. I just wrapped up a seven-city road show and polled over 700 organizations. About 43% are in acceptance and doing tangible things, 5% are really advanced, but 24% are still in denial. My bet is this is the year where the vast majority accept that the time to act is now and upgrade their digital trust fabric to make it quantum safe.
J
John Furrier3:48
You quoted some of them people are accepting it. There's a lot going on in the market that's forcing this. So give us an update on the state of quantum computing because the skeptics who say it's way down the road have seen that number shrink to single digits. And more people are realizing it's going to happen faster, and it might not happen with the good guys.
A
Amit Sinha4:27
That's a great question. Part of the reason people are still in denial is because we've been talking about quantum computing for a while, but the rate of advance is staggering. All the hyperscalers—Google, Microsoft, AWS, Nvidia, Cisco—have announced bigger, faster quantum processors. It's like the early days of transistors. Google's Willow chip did a computation in five minutes that would take the lifetime of the universe on today's fastest supercomputer. But the flip side is that it breaks current cryptography. Shor's algorithm can break RSA, and Grover's algorithm can cut SHA-256 effectiveness in half. We're still in the early days, but the race for quantum supremacy is on an unpredictable timeline.
J
John Furrier7:45
I love the stats and the commentary around the progress. Most people think some big computer is going to do something, but they're targeting these equations and keys. Post-quantum cryptography is here. Do we have everything we need to protect it? If the internet melts down, the whole world would collapse. So, are we ready? Do we have everything we need?
A
Amit Sinha8:23
The short answer is yes. Post-quantum cryptography is here. DigiCert has been collaborating with NIST. Last fall, NIST announced the first three PQC algorithms—FIPS 203, 204, and 205—for encryption and authentication. These have been cooking for almost a decade and are now standards. The DigiCert One platform supports all of them today. Work is being done in the IETF to leverage TLS 1.3 for PQC, and a standard will be available in months. Our technical tracks today will cover ML-KEM and ML-DSA algorithms.
J
John Furrier10:00
Last year we highlighted the importance of standards. Now we're starting to see visibility into readiness and operationalizing it. What are the leaders doing? Are the analysts on board? Who are these leaders and what are they doing?
A
Amit Sinha10:25
Industry leaders are acting. iMessage, WhatsApp, and even Zoom have adopted PQC for key exchange because of harvest-now-decrypt-later attacks. Even without stable quantum computers, packets can be sniffed and stored offline for later decryption. Cloudflare has done innovative things from the CDN edge to the origin server. Cloud infrastructure vendors like Google and Microsoft are experimenting with quantum-safe HSMs and KMS. Progressive organizations know PQC is here and are adopting it. Enterprises need to start prioritizing, budgeting, and migrating.
J
John Furrier11:03
Bad guys doing that. Nation states doing that.
A
Amit Sinha11:06
They're waiting to attack and unlock those keys. Exactly. So to prevent that, iMessage, WhatsApp, even Zoom—when an organization controls both sides of the communication link—it's easy to upgrade unilaterally. We're still waiting for IETF to standardize TLS for client-server interoperability, but many companies are already doing it.
J
John Furrier12:22
We're going to hear from Cloudflare hosting that panel. These are experts. This isn't like, hey, you guys go research this. These are the alphas in the companies that are doing this. So they see it.
A
Amit Sinha12:33
Yeah.
J
John Furrier12:33
So that's good news. But DigiCert, you guys are involved in a lot of classical stuff like certificates. They're impacted. So talk about that. A lot of change going on there too. That's like the current situation and post-quantum is a whole other ball game. But there's two factors here. Talk about the certificates and that impact.
A
Amit Sinha12:53
It's a great question. The PKI industry is going through a renaissance because three or four massive disruptive changes are happening at the same time. First, algorithms need to move from classical to quantum-safe. But even in classical cryptography, big changes are happening. Apple and Google introduced a ballot that will shrink certificate validity from one year to 47 days over the next few years. That's an 8x increase in operational overhead. I haven't met a single organization that doesn't have outages from expired certificates. Shortening validity periods force the need for automation and crypto agility, which naturally prepares organizations for post-quantum cryptography.
J
John Furrier15:20
Well, two things there. One is outages and disruption is mitigated. And two, you're getting at the muscle building for the transition.
A
Amit Sinha15:29
Yeah.
J
John Furrier15:29
Post-quantum cryptography. So, let's talk about that. Yes.
A
Amit Sinha15:31
Okay. They have to address it too. That's like a critical path for businesses. We know that.
J
John Furrier15:36
Get build the muscle for the transition to post-quantum. What's that about?
A
Amit Sinha15:42
We did a recent survey and had Forrester do a total economic impact analysis. They found that if you prepare for crypto agility and automation, you can get over 300% ROI from that investment because you have fewer outages and less manual work. On the PQC side, analysts like Gartner are now saying current asymmetric cryptography must be retired by 2029. That aligns with the certificate validity timeline. All roads lead to PKI modernization. Even if you don't believe in PQC, you must modernize your PKI to deal with shortening validity periods, and that naturally prepares you for post-quantum.
J
John Furrier17:16
Yeah. And hardcore infrastructure teams are on this. So I think that's a good sign. The dates are interesting. The folks we talked to—first it was 10 years, now people say eight, our research shows the experts saying three to five years.
A
Amit Sinha17:31
Um, so that's the zone.
J
John Furrier17:32
Yeah.
A
Amit Sinha17:33
I think 2029 is a great date. It aligns with classical cryptography shortening certificate validity periods and with Gartner and other experts talking about retiring and moving to post-quantum. The next three years are going to be game-changing. The reason we're doing this Quantum Readiness Day event is that for most organizations, even if they start today, they'll run out of time before they can upgrade. This is a once-in-a-generation upgrade to the core PKI infrastructure, and we are here to help.
J
John Furrier18:27
I mean, thank you for your leadership. And I'd like to point out that this is not just a DigiCert event; it's a community event.
A
Amit Sinha18:32
100%. Everyone's involved. NIST is lining up in the time frame. You mentioned that window. So appreciate what you do, and people got to get ready and start deploying customer zero scenarios. Absolutely. Thanks, John. Thank you.