Skip to Main Content
09/21/2026|6 minute read

This is the third installment in a series examining quantum computing risk from a legal and compliance perspective. The first post covered the technical foundations. The second addressed the legal risks. This post offers practical guidance for organizations seeking to manage the risks.

Cryptographic migrations can be slow, complex and expensive, and the timeline for the quantum threat is compressing faster than most had anticipated. With newly formalized post-quantum standards and regulatory guidance, including migration roadmaps, the time for orderly preparation is now.  

Organizational Quantum Readiness

The following foundational steps are appropriate for organizations with material dependence on cryptography, which includes most organizations that rely on public-key cryptography to secure sensitive customer, employee or business data or sensitive transactions:

  • Appoint a post-quantum cryptography (PQC) program owner. Migration to PQC is a long-horizon, cross-functional initiative spanning IT, security, legal, compliance and procurement. It calls for an identifiable owner with executive support. This does not need to be a dedicated role, but it should be someone’s responsibility. Appointing an individual to this role will not only help drive the work forward but also demonstrate to regulators, boards and other stakeholders that the organization has committed resources to this issue.
  • Conduct a quantum risk assessment. Assess your organization’s overall quantum exposure. The assessment will help your organization prioritize quantum readiness projects against each other and relative to the organization’s greater goals. Consider questions such as:
    • What types of data does the organization hold or transmit, and for how long must that data remain confidential?
    • Has the organization experienced past data incidents involving encrypted data or intercepted communications?
    • Does the organization rely on blockchain or smart contract technology?
    • What are the organization’s most sensitive systems, and what cryptography protects them, especially public-key algorithms?
  • Build a cryptographic inventory. Identify every system, application, device and service in your environment that uses public-key cryptography – RSA, ECC, Diffie-Hellman, ECDH, ECDSA – for any purpose, including encryption, authentication, digital signatures, key exchanges, certificates and code signing. Include cryptography embedded in third-party products and services. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA) and National Institute of Standards and Technology (NIST) have all identified this inventory as the necessary first step; without it, you cannot prioritize. For critical systems, develop a cryptographic bill of materials (CBOM) – a structured inventory of every cryptographic component, algorithm and key length in use, analogous to a software bill of materials (SBOM).
  • Develop a quantum readiness roadmap. Map your migration priorities against both regulatory, government (e.g., NIST) and industry (e.g., Google, Cloudflare) timelines. Prioritize systems by comparing the time required to migrate, the period for which affected data must remain protected and the anticipated quantum-threat horizon, including Harvest Now, Decrypt Later exposure. Include performance and interoperability testing, staged deployment and rollback planning before production migration.
  • Engage vendors and service providers. Most quantum exposure tends to run through third-party systems: cloud providers, SaaS platforms, security tools, hardware vendors and certificate authorities. Map your vendor relationships against your cryptographic inventory and begin asking about their PQC roadmaps. For new procurement, begin incorporating PQC readiness requirements into vendor evaluation criteria and contract terms.
  • Plan for cryptographic agility. Design systems to support multiple cryptographic algorithms, with the ability to swap them without full system replacement. Cryptographic agility – the ability to substitute algorithms as standards evolve – is the insurance policy against future vulnerabilities in newly standardized PQC algorithms. During the transition period, consider hybrid approaches that combine classical and PQC algorithms in parallel where appropriate.
  • Begin deploying available PQC protections. NIST’s standards (FIPS 203, 204, 205) are finalized and being integrated into major platforms. Organizations do not need to wait and should enable these protections where feasible, according to their roadmaps.

Additional Steps for Technology Companies

Organizations that develop software, hardware, connected products or cryptography-dependent services face quantum risk not only as an internal security issue but also as a matter of product security and supply chain responsibility, with PQC obligations that extend beyond protecting their own internal systems.

For these types of organizations, key steps include:

  • Treat PQC as a product feature, not just an internal control. For technology companies, cryptography choices shape product durability, customer risk and legal exposure. Customers, particularly enterprise and government customers, are beginning to evaluate products based on their ability to remain secure over the full data confidentiality period. PQC readiness thus increasingly functions as a product feature, procurement criterion and trust signal, not merely a backend security enhancement.
  • Assess exposure across the product lifecycle. Long‑lived products – including embedded devices, medical devices, industrial control systems, enterprise appliances and IoT hardware – present heightened quantum risk because cryptographic weaknesses may not be practically remediable post‑deployment. Organizations should pay particular attention to cryptographic algorithms hard-coded into hardware or firmware and assess whether PQC migration can be achieved by software or firmware update or whether product replacement is necessary.
  • Map PQC responsibilities within the shared responsibility model. Cloud service providers should carefully evaluate where responsibility for cryptographic controls sits between the provider and the customer. Where a provider controls the cryptographic stack, the provider ordinarily bears primary technical responsibility for PQC readiness. Where customers control cryptographic implementation, providers should ensure their platforms support PQC‑capable configurations and encourage customers to enable them, including by making PQC the secure default.
  • Align product roadmaps with emerging procurement criteria. Government and critical‑infrastructure customers are beginning to incorporate PQC expectations into procurement criteria. CISA’s quantum‑safe product categorization efforts, CNSA 2.0 requirements for government systems, and parallel initiatives in other industries and jurisdictions signal a shift toward market access consequences for products that lag behind anticipated PQC timelines.
  • Design for cryptographic agility. As above, given the novelty of standardized PQC algorithms and the likelihood of future refinements, products should be architected to support cryptographic agility. Hybrid approaches that pair classical and PQC algorithms can manage near‑term risk as standards mature.

Steps for Legal Departments

In-house counsel will play an important role in guiding and enabling organizational quantum readiness programs by translating post-quantum security requirements into governance, managing supply chain exposure and aligning technical processes with evolving legal and regulatory expectations.

Counsel must navigate not just quantum risk but also regulatory expectations. Although quantum computing risk is fairly universal, legislatures and regulators may express their quantum readiness expectations through jurisdictionally and sectorally limited frameworks. Expectations may vary based on differences in regulatory mandate, risk tolerance and enforcement posture, leading to differences in expected timelines and prescriptiveness for risk mitigation and consequences for delayed or insufficient action.

In addition to supporting the above quantum readiness activities, in-house counsel should consider the following steps:

  • Compliance posture. Confirm that organizational quantum readiness programs are defensible against evolving legal and regulatory expectations. This includes tracking developments across cybersecurity authorities and relevant regulators, assessing how published roadmaps and guidance influence the applicable standard of care, and documenting rationale where organizational timelines or technical constraints diverge from published expectations. As with other emerging cyber risks, regulatory alignment is not static and should be revisited as standards mature and guidance evolves.
  • Legislative and regulatory monitoring. Assign responsibility for tracking PQC developments across the jurisdictions where the company operates. PQC will increasingly be required by law, regulation and contract. This is a fast-moving area; multiple jurisdictions have already published material guidance or initiated rulemaking processes, and the future only holds more.
  • Past incident review. Work with privacy counsel and information security teams to determine whether the organization needs a process to evaluate past incidents that were assessed as low risk because the data was encrypted. Monitor regulatory authorities’ approach in this space and, where indicated, consider proactive engagement with relevant authorities before the question becomes urgent.
  • Vendor review. Review key vendor agreements – particularly cloud, SaaS and security service agreements – for cryptographic requirements, security warranties and notification obligations. Consider whether PQC readiness language should be added to standard vendor contract templates, RFP templates and vendor due diligence processes, and support vendor negotiations.
  • Litigation and regulatory risk assessment. Assess whether use of legacy cryptography in specific high-risk applications creates regulatory risk or litigation exposure under negligence, product liability or contractual theories.
  • Board and audit committee reporting. For many organizations, quantum risk may be significant enough to warrant inclusion in information security risk reporting to the board and audit committee. Consider developing a quantum risk briefing that accurately characterizes the timeline, identifies the organization’s most significant exposures and describes the migration program.
  • Cyber insurance. Quantum risk is starting to appear in cyber insurance underwriting. Insurers are beginning to ask about PQC migration plans and could impose exclusions or higher premiums for organizations without demonstrable progress. Review policy terms for any exclusions relevant to encryption failures or quantum events and provide accurate disclosure of your current posture where appropriate.
  • Product liability, warranties and representations. Work with product and engineering teams to evaluate the liability implications of long-lived hardware or software. Ensure marketing claims around security, encryption and product durability accurately reflect actual post-quantum capabilities.
  • Readiness for customer, regulator and litigant scrutiny. As awareness of quantum risk increases, companies – especially technology companies – should expect questions about whether product design choices appropriately considered long‑term cryptographic risk. Internal documentation of design decisions, migration constraints and roadmap assumptions can be critical in responding to regulatory inquiries, customer audits and, ultimately, litigation premised on foreseeable cryptographic obsolescence.

Conclusion

The quantum threat is real. Industry standards and regulatory roadmaps have been published. The organizations that will be best positioned – legally, operationally and competitively – for the arrival of Q-Day are those that treat PQC migration as a structured program starting now.

We help clients globally and across sectors navigate quantum readiness and build legally defensible programs. This includes helping clients operationalize their quantum programs through key initiatives such as quantum risk assessments and cryptographic inventories, product and platform design, vendor and supply chain risk management, and litigation readiness.


Featured Insights