up:: For Business Leaders MOC

What if we’re a small business?

Almost everything written about this transition assumes you have a security team, a vendor-management function, and a board. If you have 12 people and a bookkeeper, most of that advice is written for somebody else.

The good news is structural: your cryptography lives almost entirely inside software you bought. For a big company that’s the hardest problem, because they have to chase 200 vendors. For you it’s the easiest, because your whole exposure is a list you could write on one page.

You’re not going to run a migration program. You’re going to check a short list and ask a few questions.

The short version:

  • You can’t fix this yourself, and you’re not supposed to. Your vendors do the work. Your job is knowing which ones matter and asking.
  • Your inventory is your vendor list. The thing large companies spend months building, you already have in your billing records.
  • Most of your data doesn’t matter here. What matters is anything still sensitive in 10 years.
  • Your real deadline probably arrives in a customer questionnaire, not from a regulator.
  • Software costs nothing. The new encryption ships in normal updates you’re already paying for.
  • Old hardware is the one place you might actually spend money, and it’s usually a payment terminal, a door system, or a machine on a shop floor.

Do we actually have to do anything?

Less than you’d fear, and it isn’t nothing.

No U.S. law requires a private company to inventory or replace its encryption. What reaches a small business comes through 3 doors instead:

  1. Customers. If you sell to a bank, a hospital, a defense supplier, or any government body, their obligations flow into your contract at renewal. This is the most common way a small company first hears about it, and it usually arrives as a security questionnaire with a question about cryptography on it.
  2. Payment and compliance rules. Card payment standards define acceptable encryption by pointing at federal key-strength guidance, so when that guidance changes, the definition changes underneath you.
  3. Your own software vendors. Whatever they ship, you run. When they migrate, you migrate, usually without noticing.

Source: PCI SSC glossary entry for Strong Cryptography, pcisecuritystandards.org.

If you sell only to consumers, hold nothing that stays sensitive for a decade, and run no old hardware, the honest answer is that you can read the rest of this page in 5 minutes and then get back to work.

What are the 5 things worth checking?

This is the whole exercise. Each one is a question you can answer today, without help.

#What to checkWhy it mattersHow to check it
1Your website and anything customers log intoThis is the encryption most likely to be recorded off a networkAsk whoever hosts it whether it supports post-quantum key exchange, or whether they’re on a current platform that does
2Your main software vendorsAccounting, CRM, email, file storage, payroll. Your data lives here and so does its encryptionSend the email below to your top 5 by importance
3Your payment processorCard data carries defined obligations, and they’re the ones who carry themAsk what their post-quantum timeline is; a serious processor has an answer
4Your backupsBackups are copies that sit still for years, which is exactly the exposure profile that mattersAsk where they’re stored and whether the encryption is current
5Anything with a chip that’s over 5 years oldPayment terminals, door and alarm systems, cameras, machines on a floor. Cryptography here is often fixed and can’t be updatedList them, and find out whether the maker still issues updates

Rows 1 through 4 are almost certainly free and already in progress at your vendors. Row 5 is the one that can cost real money, because equipment whose cryptography is fixed in the chip gets replaced rather than updated.

What can we safely ignore?

More than you’d expect, and saying so is the honest half of this.

  • Buying anything sold as quantum-safe for small business. No consumer or small-business product fixes this. Anything marketed that way is charging you for a problem it doesn’t address. See Is anyone selling me something I dont need.
  • Your day-to-day operational data. Invoices, schedules, routine email, order traffic. Almost none of it matters to somebody opening it in 12 years.
  • Hiring anyone. There’s nothing here that needs a security hire at your size.
  • A formal cryptographic inventory. The mandates that require one apply to federal agencies. Your vendor list does the same job at your scale.
  • Predicting when quantum computers arrive. Nobody credible has that date, and your decisions don’t depend on it.

What does it actually cost us?

For most small businesses, close to nothing in software and some hours of attention.

The replacement encryption is a free public standard, and it ships inside normal updates from the companies you already pay. You aren’t buying it and you aren’t installing it.

Two things can cost money:

  1. Old equipment with fixed cryptography. A payment terminal or access-control system whose maker has stopped issuing updates gets replaced. That’s a capital purchase, and the honest planning move is to know which ones exist so the replacement lands on a normal refresh cycle rather than an emergency.
  2. A customer questionnaire you can’t answer. If a large customer asks and you have nothing, the cost is the deal, or the scramble to answer under time pressure. Answering it calmly is nearly free; answering it late is not.

Compare that against the U.S. federal government, which projected roughly $7.1 billion to migrate its own civilian systems between 2025 and 2035. The reason your number is so much smaller is that you own almost none of the cryptography you use.

Source: Office of Management and Budget, “Report on Post-Quantum Cryptography,” July 2024, OMB PQC Report.

What do we send our vendors?

Copy this. It takes 2 minutes per vendor and it’s the single highest-value thing on this page.

Subject: Post-quantum encryption timeline

Hi,

We're reviewing which of our suppliers are prepared for the move to
post-quantum encryption, following the standards NIST finalized in
August 2024.

Three questions:

1. Do you have a published timeline for supporting the post-quantum
   standards (ML-KEM for key exchange, ML-DSA for signatures)?
2. Is that support included in our current plan, or does it require
   a different tier or product?
3. Is there anything we need to switch on, or does it happen
   automatically on your side?

A short answer is fine. If the timeline isn't set yet, that's a useful
answer too, and I'd appreciate knowing when you expect to have one.

Thanks,
[name]

How to read what comes back:

The answerWhat it means
A named date and a product versionThe best answer available. Note it and move on
”It’s on our roadmap”A promise without a date. Ask when a date will exist
”We use bank-grade encryption”They didn’t understand the question. Ask again naming ML-KEM
”We’re already quantum-safe”Ask which algorithms and which product version. A real answer names them
Nothing at allThe most informative answer. Record it, and weigh it at renewal

Nobody expects a small business to audit a vendor. Asking is what matters, because a supplier who fields the question from 30 customers moves faster than one who fields it from none.

What if a customer sends us a questionnaire?

Answer it honestly and specifically, because a truthful “here’s where we are” outperforms a vague reassurance with almost every reviewer.

A good answer for a company your size has 4 parts: the fact that your cryptography is provided by named vendors, what those vendors have told you about their timelines, which equipment you’ve identified as old enough to need replacing, and when you’ll check again.

What sinks a response is claiming a program you don’t have. Enterprise security reviewers read these all day, and an unsupportable claim is worse than an honest gap, because it puts every other answer on the form in question.

Questions people ask

We’re 12 people. Is this really our problem? Directly, barely. It becomes your problem through customers and old equipment, which is why the list above is short and specific rather than a program.

Should we tell customers we’re post-quantum ready? Only if your vendors have told you so in writing and you can name the products. An unsupportable claim is a liability in a security review.

Our IT is one contractor. What do we ask them? The 5 checks above, in that order. Any competent IT provider can answer them, and the answers to 1, 4, and 5 are things they should already know.

Does this affect our website? Only in the sense that your host handles it. Modern hosting platforms and content delivery networks have largely deployed post-quantum key exchange already.

We keep customer records for years. Does that change things? Yes, and it’s the main reason a small business would care. Records that stay sensitive for a decade are exactly what this is about. See What of our company data is at risk.

What if we can’t afford to replace old equipment? Then the useful move is knowing which pieces they are and putting them at the front of the normal replacement cycle. A known 3-year plan is a defensible position; an unknown one isn’t.

When do we need to do this by? Your earliest real date is whenever your biggest customer’s next security review lands. For most small businesses that’s sooner than any regulatory deadline. See What do regulators expect.

Where to go next


Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.