up:: 00 Start Here
For Business Leaders
Your organization is holding a dated obligation it probably can’t yet measure.
Regulators have set deadlines. The data you hold about customers stays sensitive for years or decades, and it can be copied today and read later. Meanwhile the first step in fixing any of it, knowing where your own cryptography lives, is something most large organizations discover they can’t do.
None of that requires a quantum computer to exist. It’s true right now, and it’s answerable with work rather than with technology purchases.
5 things you must understand about Q-Day
- Q-Day sets no deadline for you. Your own paperwork does. The date that binds a company almost always arrives through a certification, a contract clause, or a customer’s security requirements at renewal, years before any regulator writes to it.
- Two threats run on 2 different clocks. Confidentiality fails backward, because data copied today is read later. Trust fails forward, because certificates and signing keys become forgeable the day the machine exists. Those produce different priority lists.
- The first question anyone asks is where your cryptography lives, and most organizations can’t answer it. Every published mandate names that inventory as the first deliverable.
- Most of your estate belongs to your vendors. A large share of the cryptography in a typical enterprise sits inside purchased products on release schedules you don’t control.
- Waiting behaves differently here than in other technology decisions. Deferring usually preserves optionality. Here, information collected while you wait is exposed retroactively, so the delay itself is the decision.
Source: NIST IR 8547 initial public draft, csrc.nist.gov; CISA, NSA, and NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography,” August 21, 2023, cisa.gov.
The short version:
- The replacement standards were finalized in August 2024, so “we’ll act once the standards are ready” has stopped being an accurate description of where things stand.
- The U.S. schedule retires today’s public-key encryption: the weaker key sizes deprecated after 2030, and everything classical disallowed after 2035 regardless of size.
- The first question any regulator or auditor asks is where your cryptography lives, and most organizations can’t answer it.
- A large share of what you’d need to change sits inside products you bought, so your timeline depends on vendors who may have no dated commitment.
- Data you hold now is exposed retroactively, which means waiting doesn’t preserve optionality the way it usually does.
- Liability when this eventually fails has never been settled between organizations, vendors, insurers, and the people whose data it was.
What lives here
No idea where to begin? Where do we actually start is the first 90 days: 5 moves, none of them requiring budget or headcount.
- What of our company’s data is at risk? The 9 families, sorted by how long each stays valuable, and the retention laws that set the clock.
- What does this actually cost? What drives the number, why inventory comes first, and why the range is so wide.
- Who’s liable when this fails? The unsettled question between you, your vendors, your insurer, and your customers.
- What can’t I fix myself? The cryptography inside purchased products, and what to demand from those vendors.
- What should I ask my own security team? Five questions that reveal whether this has actually started.
- What do regulators expect of us? What’s binding today, what’s coming, and what sector rules add.
- Does our cyber insurance cover this? How this class of loss interacts with policies written for break-ins.
- How do I explain this to my board? The version that survives a board meeting, without technical language.
- What is technically happening to our systems? The mechanism at the level an estate operates on: the 2 threats on 2 clocks, every layer the vulnerable cryptography sits in, and which layers are configuration changes versus capital purchases.
- What if we’re a law firm? Privilege has no expiry, litigation holds preserve the highest-value material, and the duty of technological competence already reaches this.
- What if we’re a small business? No security team, a handful of vendors, no migration budget. The 5 things worth checking, the shorter list you can ignore, and the email to send your vendors.
- Why not wait until AI is under control? The most common reason organizations defer, taken seriously, and the one property that makes deferring this different from deferring anything else.
- What if we run a clinic or hospital? Lifetime-sensitive records, retention rules that forbid deletion, and equipment that can’t be updated, all at once.
- What if we’re investing or acquiring? Cryptographic exposure as a diligence item, the 6 questions, and why standard diligence structurally misses it.
- What if we run a school or university? Records about children that outlive their childhood, research data with no expiry, and a lever most institutions already have through consortium purchasing.
Why “wait and see” behaves differently here
Most technology risks reward patience. You wait, the market matures, prices fall, and the standards settle. Deferring costs you little.
This one inverts that, for a specific reason. Information collected while you wait is exposed retroactively the day a capable machine exists, so the delay itself is a decision to leave everything sent during that period permanently readable. Combined with migrations of this size historically taking a decade, an organization can be behind without ever having made a visible mistake.
The practical consequence for a leadership team is that the decision doesn’t depend on predicting when the machine arrives. It depends on how long your data has to stay confidential and how long your own migration will take, both of which you can find out.
Where to go next
- Start here if you want the underlying mechanism first, with no background assumed.
- For policymakers covers the regulatory picture in more depth.
- The question template works just as well for your own vendors as for a bank.
Go deeper into the technical detail
Brief Your Board and Own Your Quantum Risk are the technical versions, written for security leaders, and they’re what to forward to your CISO. The arguments are the case rather than the explanation. Why Post-Quantum Migrations Stall is the one most business readers find useful, and Is the Quantum Threat Overhyped takes the skeptical view seriously instead of waving it off.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-08-02 · Maintained by Addie LaMarr, LaMarr Labs.