Legal scales

The Quantum Liability You Already Have

Quantum computer

I was preparing for a call with the board of a post-quantum cryptography (PQC) company and, as a part of preparing, reviewed all my prior research into PQC. I’m sharing my thoughts here – not about the specific company – but rather what CISOs should do, because we’re going to keep hearing the PQC drumbeat. And this isn’t new. CISOs have heard roughly the same pitch since 2005: quantum computers will break encryption in five years. That pitch was wrong then, and it’s still wrong now, but the liability is real anyway. This is the harvest-now, decrypt-later problem: data stolen today, held, and decrypted once the hardware catches up.

We’re going to set aside questions of statutes of limitations for civil liability, as many CISOs of companies in 2026 will be CISOs of different companies in 2032. For this article, assume liability is still attributable to the CISO who made a decision in 2026 (or 2028, or whenever happened before a data breach due to a viable quantum computer). As a final reminder, I’m not an attorney, and if you’re not friends with your CLO or GC, go fix that relationship before getting started.

Here’s the trap. If you dismiss post-quantum cryptography as vaporware, you’ll defend negligence when a 2026 breach gets decrypted in 2032. But if you champion it too aggressively without proof of actual quantum capability today, you lose the budget fight because you’re selling science experiments instead of meaningful risk reduction.

There is a way out of this trap. Regulatory deadlines aren’t waiting for quantum computers.

JurisdictionDeadlineBasis / Authority
France (ANSSI)2027 certification banProcurement compliance, not quantum capability
US Federal ContractorsEnd of 2030Executive Order 14,412
UK NCSC2028 dependency inventory; priority transitions by 2031Published guidance, March 2025
Global convergence~2030-2035Supply chain cascade

France’s cybersecurity agency ANSSI announced it would stop certifying security products lacking quantum-resistant encryption starting in 2027, with full procurement compliance expected by 2030. The US Executive Order 14,412, titled “Securing the Nation Against Advanced Cryptographic Attacks,” requires federal contractors to be compliant with NIST PQC standards by the end of 2030. The UK NCSC published its guidance in March 2025, mandating cryptographic dependency identification by 2028 and priority transitions by 2031. These are procurement gates, not technology predictions.

Google suggested cryptanalytically relevant quantum computers could arrive by 2029 in their blog earlier this year. Keep in mind that Google is also one of the largest quantum investors, so their forecast might be more intended towards market valuation than technical audiences. The timelines that you have to follow are coming from regulators and procurement offices, not venture capital announcements. You don’t need to believe any particular arrival date; the regulatory deadlines bind you regardless, and the legal reclassification is simply the tail risk that makes today’s long-lived data a problem.

Your Encryption Safe Harbor Has an Expiration Date

Most state breach notification laws treat encrypted data as non-reportable when the key wasn’t compromised, but the European Data Protection Board’s guidelines on personal data breach notification already warn that this may change over time and the risk would have to be re-evaluated if the encryption algorithm becomes vulnerable. That’s regulatory speak for “we’ll look at this again later.” When cryptanalytically relevant quantum computers arrive, the encryption protecting your 2026 data stops being “secure” for legal purposes. A breach that would have been classified as non-reportable today becomes a reportable event six years later when post-quantum cryptography attacks work.

And one quantum-enabled incident triggers multiple enforcement fronts simultaneously:

AgencyTriggerConsequence
40+ State AGsMaterial risk of harmIndividual fines per jurisdiction
FTCUnfair/deceptive practices20-year consent orders, audits
SEC (public companies)Materiality determination8-K filing within 4 business days
HHS/OCR (healthcare)PHI compromisePer-violation penalties
InsurersNon-compliant legacy systemsCoverage denial or exclusion

The Standard of Care Is Already Locking In

NIST published FIPS 203, 204, and 205 in August 2024 covering ML-KEM, ML-DSA, and SLH-DSA. CISA released product-category guidance in January 2026 helping organizations identify where post-quantum adoption matters. Multiple government bodies have now issued PQC migration guidance – NIST, CISA, NSA, UK NCSC, EU NIS2 Cooperation Group.

Once migration becomes standard practice, enterprising litigants can frame a continued reliance on outdated encryption as negligence.

Courts are increasingly treating NIST frameworks as the benchmark for “reasonable security.” That matters because the reasonable-security defense only works if you followed published guidance, not if you waited for quantum capability to materialize. The standards exist now. Ignoring them creates liability regardless of whether any quantum computer can actually break RSA yet.

How to Fund This Without Getting Called Out for FUD

Selling pure theoretical risk dies in budget meetings where CFOs reject science experiments. Two angles are far more likely to work where fear-based pitches will fail.

Market access. If your organization supplies federal contractors, large enterprises, or European customers, PQC is a procurement requirement cascading down the supply chain. France’s 2027 mandate signals where global standards head regardless of headquarters location, because losing contracts probably costs more than migrating cryptographic stacks.

Legal partnership. Frame the budget ask with the help of your General Counsel or Chief Risk Officer. They own breach notification exposure and negligence liability while you own execution. Together you own the budget line item. This isn’t security wanting a new shiny toy. It’s legal exposure requiring technical mitigation.

Avoid saying “quantum computers will break everything someday.” Lead with “regulatory guidance issued in 2024-2026 establishes a duty to begin migration.” The NIST frameworks and EO 14,412 deadlines are the hook, not Shor’s algorithm.

Vendor Vetting: Five Questions That Separate Reality From Hype

Most PQC vendors ride the same hype cycle that Google and the VC market are leaning into. Your job is to figure out which ones actually ship deployable software versus which ones are selling PowerPoint slides to boards they assume don’t understand the difference between physics science experiments and products.

Ask these five questions. Push past the sales gloss until you get numbers, references, and implementation details. If a vendor can’t answer cleanly, move on.

QuestionWhat Good Answers Look LikeRed Flags
1. Which specific NIST-approved algorithms does your solution implement?Names FIPS 203, 204, 205 specifically with ML-KEM, ML-DSA, SLH-DSA variants. Shows code-level integration documentation.“Proprietary quantum-safe encryption” or vague hand-waving references to lattice-based cryptography without NIST alignment.
2. Can you demonstrate crypto-agility, or are we locked into your stack for the next ten years?Supports algorithm swapping without code rewrites. Documented migration paths tested with customer environments.Custom APIs that require deep integration. No documented exit strategy if you switch providers.
3. What are the performance characteristics compared to RSA-2048 or ECC-256?Benchmarks for handshake latency, certificate size increase, and bandwidth overhead in production-like environments.Marketing claims like “minimal impact” without supporting data from real deployments.
4. Name three customers who’ve completed production migration, not pilot projects.Customer names, contact info, and scope of deployment. Willingness to provide references.Case studies that stop at proof-of-concept. NDAs preventing any customer contact.
5. What happens to our data if your company disappears or pivots?Open-source fallback, escrow arrangements, documented key recovery procedures. Proprietary lock-in disclosure upfront.“Trust us” or legal terms that let them walk away from obligations.

As a reminder, the Pitchbook Q2 2026 report showed global quantum computing funding hit $3.9 billion in 2025, with Q4 alone pulling in $1.5 billion. The median quantum startup valuation sits at $32.8 million, but the average reaches $537.4 million because a handful of late-stage deals are inflating the numbers. A few companies are being showered with cash, but most are scraping by looking for funding. Your vendor due diligence protects against backing the latter group that won’t survive any market corrections or consolidation.

What CISOs Should Do in Their FY 2027 Budget

Your budget should fund four phases with clear sequencing. Inventory launches immediately on FY 2027 funding; classification follows within a year; vendor validation runs continuously; and piloting occupies the 12 – 18 month window before any major commitment. If you already have a cryptographic inventory and a data inventory, skip those steps and go straight to evaluating vendors.

Phase 1: Inventory

Map all asymmetric cryptography across your stack:

  • TLS handshakes and VPN tunnels
  • Code signing and certificates
  • Mobile apps and vendor connections
  • Identify crypto-agile systems versus hardcoded dependencies

This costs the least and delivers the highest value because without knowing where your cryptography lives, prioritization becomes impossible. Your CLO or GC can help you to phrase this in terms that your CFO & board (or other budgetary approvers) will understand.

Phase 2: Classify Data by Lifespan

Not all data deserves equal treatment. Prioritize what matters:

  • Trade secrets, medical records, source code
  • Merger documents and privileged communications
  • Session logs expiring in 90 days don’t qualify for emergency funding

Long-lived sensitive data attracts harvest-now, decrypt-later attacks while short-term data doesn’t warrant immediate migration spend.

Phase 3: Vendor and Contract Pressure (Ongoing)

Update your contracts to include cryptographic agility obligations, vulnerability notice requirements, and replacement rights for non-migratable products. Use the questions in the table (above) when evaluating vendors.

The phrase “military-grade encryption” stopped being an acceptable answer months ago.

Phase 4: Pilot Before Committing

Post-quantum algorithms affect handshake timing, certificate size, and embedded device constraints. Testing quietly before declaring victory prevents costly mistakes later.

The question isn’t whether post-quantum cryptography matters. It’s whether your organization will know where to put it when regulatory pressure arrives. Start with the inventory. Everything else flows from there.

Similar Posts