up:: What To Do
How do I ask a company what their quantum plan is?
You send them a short message and ask. That sounds almost too simple, and it’s the single most useful thing an everyday person can do here.
Companies track what customers ask about. A handful of questions gets logged. A pattern of them reaches someone who sets budgets, and it’s often the thing that turns a security team’s ignored internal request into a funded project. Regulators watch the same patterns.
Everything below is yours to copy, edit, and send.
The short version:
- Ask any company that holds information about you that’ll still be sensitive in 10 or 20 years.
- Your bank, your hospital or doctor, your insurer, your employer, and any genetic testing company are the ones worth asking first.
- The short template below takes 30 seconds to send. The longer one is for when you want a real answer on the record.
- A good reply names a timeline and mentions an inventory. A brush-off talks about how seriously they take security without answering anything.
- You’re not being difficult. You’re asking a company what it’s doing about a risk that three U.S. federal agencies have published guidance on.
Who’s worth asking?
The test is whether they hold something about you that stays sensitive for years.
| Worth asking | Why |
|---|---|
| Your hospital, doctor, or health system | Medical records stay sensitive for life and can’t be reissued |
| Your bank, brokerage, and mortgage lender | A 30-year mortgage is a document set that stays live for three decades |
| Your insurer | Holds health, financial, and claims history together |
| A genetic testing company | Your genome is permanent and identifies your relatives too |
| Your employer’s HR or benefits team | Holds health, salary, immigration, and background information |
| Your lawyer, if you have ongoing matters | Privileged material stays privileged indefinitely |
| Your kids’ school or pediatrician | Records belonging to someone who’ll live 80 more years with them |
Less worth the effort: your streaming service, your food delivery app, and anything holding only information that’s worthless in 15 years.
The short version, for a contact form
Copy this straight into a support form or an email.
Hello,
I’d like to know what your plan is for post-quantum cryptography.
Encrypted data being collected today can be stored and decrypted later, once quantum computers are capable of breaking the encryption currently in use. That means information you hold about me is at risk from that point backwards, including anything already sent. My records with you stay sensitive for many years, so this affects me directly.
Three questions:
- Have you completed an inventory of where cryptography is used across your systems?
- What’s your timeline for migrating to the NIST post-quantum standards published in August 2024?
- Are you using post-quantum protection for my data in transit today?
I’d appreciate a written answer.
Thank you, [your name]
The longer version, when you want it on the record
Use this with a bank, an insurer, a health system, or anyone whose written answer you might want later. It names the sources, which makes it much harder to answer with nothing.
Hello,
I’m writing as a customer to ask about your organization’s preparation for post-quantum cryptography.
Why I’m asking. In August 2023, CISA, the NSA, and NIST published joint guidance warning that attackers “could be targeting data today that would still require protection in the future… using a catch now, break later or harvest now, decrypt later operation.” Encrypted information collected now can be stored and read once a sufficiently capable quantum computer exists, which means data you already hold about me is exposed retroactively from that day.
NIST published replacement standards in August 2024 (FIPS 203, 204, and 205), and has set a draft schedule retiring today’s public-key encryption: 112-bit RSA and elliptic-curve deprecated after 2030, all classical public-key disallowed after 2035. The records you hold about me will still be sensitive well past those dates.
What I’d like to know:
- Have you produced an inventory of everywhere cryptography is used across your systems, sometimes called a cryptographic bill of materials?
- Have you identified which categories of customer data have a secrecy lifetime long enough to be at risk from retroactive decryption?
- What is your timeline for migrating to the NIST post-quantum standards, and does it meet the 2030 and 2035 dates?
- Is my data currently protected in transit using post-quantum or hybrid key exchange?
- For systems you depend on from third-party vendors, do you have dated commitments from those vendors?
I’d appreciate a written response, and I’m happy to be directed to a published statement if one exists.
Thank you, [your name]
The urgency paragraph, if you’d rather write your own
Paste this into anything. Every figure is sourced below.
Encrypted data collected today can be stored and decrypted later, once a quantum computer capable of breaking current encryption exists. U.S. federal agencies have published guidance describing this as a present-day concern. NIST finalized replacement encryption standards in August 2024 and has set a schedule retiring today’s public-key encryption, deprecated after 2030 and disallowed after 2035. Information that has to stay private beyond those dates is already exposed to collection now.
Source: Quantum-Readiness: Migration to Post-Quantum Cryptography, CISA, NSA, and NIST joint factsheet, August 21, 2023; NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards,” August 13, 2024; NIST IR 8547 (Initial Public Draft), November 2024.
What does a real answer look like?
You’re looking for specifics. An organization that’s started this work can answer in concrete terms, because the work produces documents.
Signs they’ve genuinely started:
- They mention an inventory, a cryptographic bill of materials, or a discovery exercise.
- They give a date or a phase, even a rough one.
- They name the standards, or say ML-KEM, or mention hybrid key exchange.
- They distinguish between what they control and what sits inside vendor products.
- They say they’ve sorted data by how long it stays sensitive.
Signs of a brush-off:
- “We take the security of your data very seriously.” Every reply opens this way. Look at what follows it.
- “We use industry-standard encryption.” That’s a description of the encryption being replaced.
- “We use bank-level, military-grade, or 256-bit encryption.” None of those phrases address this, and the last one refers to the part that survives.
- “We’ll adopt new standards when they’re finalized.” They were finalized in August 2024.
- “This is a theoretical future risk.” The collection is present-tense, per the federal guidance above.
- No answer at all, which is itself information.
What do I do with the answer?
If it’s a good one, that’s genuinely reassuring, and it’s worth saying so, because internal teams doing this work rarely hear that a customer noticed.
If it’s a brush-off or silence, you have a few options that cost nothing. Ask again and reference your earlier message, since a second contact often routes differently. Ask on a public channel, because companies answer public questions faster than private ones. Send it to a reporter covering the sector, especially if you got the “we’ll adopt new standards when they’re finalized” answer, since that one’s checkably wrong. And for health and genetic data specifically, your state attorney general’s office may take consumer inquiries, as several did over 23andMe.
A note on tone. Polite and specific gets much further than angry and vague. You’re asking a reasonable question that the company should be able to answer, and the specificity is what makes it hard to deflect.
Questions people ask
Isn’t this a bit much for a regular customer? No. Customer questions are one of the few inputs that reliably move a security budget, and you’re asking about published federal guidance rather than something obscure.
What if I don’t understand their answer? Send it to the standard on this page and compare. If it names an inventory and a date, they’ve started. If it doesn’t, they haven’t.
Will they think I’m being difficult? Some will. The teams actually doing this work usually feel the opposite, because a customer asking is the evidence they’ve been trying to get in front of their own leadership.
Can I send this to a company in another country? Yes. The deadlines cited are American, and every major economy has its own equivalent. The technical situation is identical everywhere.
Where to go next
- What should my doctor and my bank be doing? is the standard you’re holding them to.
- What should I actually do? covers everything else on the personal list.
- What of mine is actually worth stealing? helps you decide who’s worth asking.
Go deeper into the technical detail
The technical version of what you’re asking them for is Cryptographic Bill of Materials (CBOM) and Start a Migration.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.