What if we’re investing or acquiring?
When you buy a company you buy its data, and you buy the condition that data is in.
Cryptographic exposure is close to invisible in a standard diligence process. It produces no incident to disclose, appears in no filing, and sits in systems nobody demos. A target can pass every question on a standard security questionnaire and still hand you a decade of records sent under encryption scheduled for retirement, plus a fleet of equipment nobody can update.
That’s technical debt with an unusual property: it accrued before you owned it, and it can’t be paid down retroactively.
Not legal advice
This is general education rather than transactional advice. What representations, warranties, or indemnities to seek are questions for your counsel.
The short version:
- You inherit the exposure, and it predates the deal. Data already sent can’t be re-protected after the fact.
- Standard diligence misses it structurally, because it produces nothing to disclose, file, or alert on.
- One question is the tell: can they produce an algorithm-level inventory of where their cryptography lives?
- Long-lived hardware is where the money is, converting a software story into a capital one.
- Their vendor contracts become your timeline, and those you can read during diligence.
- A dated obligation may already bind a regulated target, and it transfers with the entity.
What do you actually inherit?
Four things, and only 1 of them is fixable after close.
The data, in the condition it was sent. Everything the target transmitted under today’s key exchange, going back as far as somebody was collecting, is exposed retroactively. Buying the company buys that, and no post-close remediation reaches it.
The estate, including what can’t be updated. Equipment with cryptography fixed in firmware is a capital replacement rather than a software project. In industrial, medical, and infrastructure targets this is frequently the largest single number.
The vendor contracts, and their timelines. A target dependent on a supplier shipping post-quantum support in 2030 has a 2030 migration for those systems, and that becomes yours.
The obligations. A target holding certifications or contracts referencing validated cryptography, or selling into regulated or government markets, carries a dated obligation that transfers with the entity. That one is findable in diligence and it’s the most concrete.
What are the 6 questions?
Add these to the technical diligence request. Each has a factual answer, and an absent answer is itself informative.
| # | The question | What the answer tells you |
|---|---|---|
| 1 | Can you produce an algorithm-level inventory of where cryptography is used? | The single best predictor. A target with one has almost certainly done the rest |
| 2 | Which data categories must stay confidential beyond 10 years, and where do they live? | Whether the retroactive exposure is material or trivial |
| 3 | What proportion of cryptography sits in vendor products, and what dated commitments exist in writing? | Your post-close timeline, which you won’t control |
| 4 | Which systems or devices cannot receive cryptographic updates, and what are their service lives? | The capital number, and where the money is |
| 5 | What is your earliest binding date, and from which instrument? | Whether a deadline transfers with the deal |
| 6 | Has any customer or auditor asked about this, and what did you tell them? | Whether you’d be inheriting a representation already made |
Question 1 is the diagnostic. An organization holding a current algorithm-level inventory is in a small minority, and one that can produce it on request has almost certainly thought through everything downstream.
Question 6 is the one experienced diligence teams appreciate. An answer already given to a customer is a representation the target has made, and it comes with the entity.
Why does standard diligence miss this?
Because every mechanism diligence relies on requires an event, and this produces none.
There’s no breach to disclose, since copying encrypted traffic breaks nothing and triggers no alarm. There’s no regulatory action, since no U.S. instrument requires a private company to inventory or migrate. There’s no penetration-test finding, since the systems are working correctly. And there’s no line in the financials, since nothing has been spent.
A target can therefore answer a standard security questionnaire entirely truthfully and still carry the full exposure. The 6 questions above are built to surface what the standard ones structurally cannot.
How material is it, really?
It turns on one variable, and for many targets the honest answer is that it barely matters.
Low materiality: a business whose data stops mattering within 2 years, on modern cloud infrastructure, owning no long-lived hardware, selling to no regulated buyer. The exposure is small and remediation is ordinary vendor upgrades.
High materiality: intellectual-property-heavy businesses, healthcare, legal, financial services, defense suppliers, and anything with an installed base of long-lived equipment. Here the retroactive exposure reaches the core asset and the hardware number can be significant.
The distinguishing question is the one this whole Guide turns on: how long does this company’s data have to stay confidential? A target whose value rests on trade secrets has, by definition, data with no expiry date at all.
What does a credible answer look like?
Sophistication here says something useful about management generally, because it indicates a team tracking obligations without an incident forcing them to.
Strong. An inventory with a date on it, a named owner, a sorted view of which data carries long confidentiality lifetimes, dated commitments from the major vendors, and a known list of equipment that can’t be updated.
Reasonable. An honest account of where they are with the gaps named. Very few organizations are finished, and the standards were only finalized in August 2024.
A flag. “We use industry-standard encryption,” “we’re compliant,” or “our cloud provider handles it.” The first describes what’s being replaced, the second doesn’t answer the question, and the third holds for a fraction of the estate.
A serious flag. A target that has told a customer in writing it’s post-quantum ready and cannot support the claim. That’s a representation you’d be acquiring.
What can you do about it in a deal?
Four things, roughly in the order they arise.
- Price the hardware. Equipment that can’t be updated is a capital cost with a knowable range once counted, and it’s the number most likely to move a valuation.
- Read the vendor contracts for renewal dates. Renewals are where post-close leverage sits, and knowing them pre-close tells you when you can act.
- Treat the binding date as a schedule item. If a dated obligation transfers, it belongs alongside the other compliance obligations.
- Fund the inventory in the first 100 days. It’s cheap, it’s the prerequisite for everything else, and it’s far easier with post-close authority than as a pre-close negotiation. See Where do we actually start.
Questions people ask
Is this worth adding to every deal? The 6 questions cost a diligence team almost nothing and quickly screen out the deals where it doesn’t matter. For IP-heavy, regulated, or hardware-heavy targets it deserves real attention.
Can we get a representation covering it? A question for counsel. What’s worth knowing is that the exposure predates any representation, so a warranty about current state doesn’t reach data already sent.
Does this affect valuation? The capital cost of unfixable hardware does, straightforwardly. The retroactive data exposure is harder to price and behaves like a contingent liability nobody has allocated yet. See Who is liable when this fails.
What if the target is pre-revenue? Then it likely holds little long-lived data. The exception is deep tech and biotech, where the intellectual property is the entire asset and has no expiry.
Should we screen portfolio companies? The same 6 questions work portfolio-wide, and question 1 alone sorts them fast.
Is a target that has done nothing a bad target? No. Most organizations have done nothing. What distinguishes a good management team is an honest account of where they are.
Where to go next
- Where do we actually start is what a target should be doing, and what you’d fund post-close.
- What of our company data is at risk is the data-lifetime sort that decides materiality.
- Who is liable when this fails covers the unallocated liability question.
- What can I not fix myself covers the vendor timelines you inherit.
- For Business Leaders MOC is the full business route.
Go deeper into the technical detail
The technical version, on how most of an estate’s cryptography is inherited rather than chosen, is Cryptographic Supply-Chain Risk.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.