Quantum Computing Is a Present-Tense Governance Issue: A General Counsel’s Roadmap for Privacy, Security and Compliance
A cryptographically relevant quantum computer may still be years away. The legal and risk-management work should begin now.
Quantum computing poses an unusual problem for general counsel: the deadline is uncertain, but waiting for certainty may itself create material risk.
No publicly known quantum computer can presently defeat the public-key cryptography on which modern commerce depends. The timing of a "cryptographically relevant" quantum computer remains contested. Yet adversaries do not need to wait. They can collect encrypted information today and attempt to decrypt it later—a strategy commonly called "harvest now, decrypt later." At the same time, large organizations may need years to locate cryptography embedded across applications, cloud services, connected products, operational technology, certificates, digital signatures and third-party platforms.
That combination changes the legal question. The issue is not whether counsel can predict the arrival date of a sufficiently capable quantum computer. It is whether the organization is taking proportionate steps now to identify long-lived information, understand cryptographic dependencies, preserve flexibility and avoid an expensive last-minute migration.
For most companies, the right response is neither panic nor a wholesale technology replacement. It is a governed, risk-based transition program.
What Quantum Computing Will—and Will Not—Change
Quantum computers use quantum phenomena to solve certain classes of problems in ways that differ fundamentally from conventional computers. Their most promising applications include materials science, drug discovery, optimization, finance and energy. In the near term, progress is likely to remain uneven: specialized quantum systems will work alongside classical computing, while researchers continue to improve error correction, hardware reliability and scale.
The cybersecurity concern is narrower than the phrase "quantum breaks encryption" suggests. A sufficiently powerful quantum computer could use Shor's algorithm to undermine widely used public-key systems, including RSA and elliptic-curve cryptography. Those systems support key exchange, authentication, certificates, software signing, virtual private networks, secure web traffic and digital signatures.
Symmetric encryption and hashing are affected differently. Grover's algorithm can reduce their effective security margin, but does not render them useless in the same way. Properly implemented stronger symmetric algorithms—commonly including AES-256—are generally expected to remain viable. The migration challenge is therefore not "replace all encryption." It is to find where quantum-vulnerable public-key cryptography is used and determine what must be upgraded, retired, re-platformed or managed through a vendor.
The principal mitigation is post-quantum cryptography, or PQC: algorithms designed to run on conventional computers while resisting attacks by both conventional and quantum computers. PQC is not the same as quantum key distribution, and "quantum-resistant" is a more accurate description than "quantum-proof." Cryptographic standards can evolve, implementations can fail and agility will remain important after the first migration.
The Standards Phase Has Already Begun
In August 2024, the National Institute of Standards and Technology finalized its first three principal PQC standards and stated that they were ready for immediate use:
- FIPS 203, based on ML-KEM, for establishing shared secret keys;
- FIPS 204, based on ML-DSA, for digital signatures; and
- FIPS 205, based on SLH-DSA, as a hash-based digital-signature alternative.
NIST has encouraged organizations to begin integration because full adoption will take time. Its initial public draft transition plan, NIST IR 8547, proposes deprecating quantum-vulnerable public-key algorithms after 2030 and disallowing them after 2035, subject to the scope and exceptions in the final guidance. Those dates should be treated as a planning signal, not as a universal private-sector legal deadline.
The federal government has nonetheless made the direction clear. National Security Memorandum 10 established a goal of mitigating as much quantum risk as feasible by 2035 and emphasized cryptographic agility across government, critical infrastructure, commercial services and cloud providers. OMB Memorandum M-23-02 required federal agencies to inventory quantum-vulnerable cryptographic systems and prioritize migration.
International guidance is converging on a similar arc. The European Commission and EU Member States have issued a coordinated PQC implementation roadmap. The United Kingdom's National Cyber Security Centre recommends that larger and more complex organizations complete discovery and initial planning by 2028, conduct highest-priority migrations by 2031 and aim to complete migration by 2035.
These government timelines do not automatically bind every private company. They do, however, influence customer expectations, procurement requirements, technical standards, critical-infrastructure oversight and the developing meaning of reasonable security.
Why Privacy Risk Begins Before the Quantum Computer Arrives
The most immediate exposure involves data whose useful or harmful life may exceed the remaining life of its encryption.
Trade secrets, source code, product roadmaps, genomic information, health records, biometric identifiers, government-sensitive data, privileged communications, M&A materials and long-term identity records may retain value for a decade or longer. If such information is intercepted or exfiltrated now, an adversary may preserve it for later decryption. Conventional incident analysis focused only on present readability can therefore understate the long-tail harm.
This does not mean every encrypted archive is in immediate jeopardy. Exploitation depends on how information was transmitted or protected, what an attacker captured, the algorithms and key-management architecture involved, the later availability of a capable quantum computer and the continuing value of the data. But it does mean that data classification and retention decisions should account for confidentiality lifetime, not merely today's access controls.
That has practical privacy consequences. Data minimization and defensible deletion reduce the volume of information available for both conventional and future attacks. Retention schedules should distinguish information that loses sensitivity quickly from information—such as biometrics or genetic data—that cannot meaningfully be "reset." Vendor reviews should examine whether long-lived sensitive data crosses public networks, which party controls the cryptographic layer and whether the service can migrate without replacing the entire platform.
What This Means for Compliance and Disclosure
Most privacy and cybersecurity laws are technology-neutral. They do not yet require every organization to deploy a named PQC algorithm. They commonly require reasonable or appropriate safeguards, risk assessment, vendor oversight, security governance and periodic adjustment as threats and available protections change.
That structure matters. The HIPAA Security Rule, for example, requires regulated entities to assess risks to electronic protected health information and review and modify safeguards to maintain reasonable and appropriate protection. The FTC Safeguards Rule requires covered financial institutions to maintain an information-security program using administrative, technical and physical safeguards. Article 32 of the GDPR directs controllers and processors to consider risk, cost and the state of the art when selecting security measures.
PQC may not be a standalone compliance box under those regimes. A documented evaluation of quantum exposure can nevertheless become part of demonstrating a reasonable, current risk-management process—especially for organizations holding long-lived sensitive information or operating infrastructure that cannot be upgraded quickly.
For public companies, the issue also intersects with disclosure controls. The SEC's cybersecurity rules require registrants to describe their processes for assessing, identifying and managing material cybersecurity risks, board oversight and management's role, and to disclose material cybersecurity incidents within the applicable framework. Quantum risk should not be inserted into filings simply because it is topical. But companies with unusual exposure—such as providers of cryptographic products, long-life connected devices, critical infrastructure, financial platforms or data-rich services—should determine whether the risk is addressed through existing enterprise-risk, disclosure-committee and board-reporting processes. Boilerplate speculation is not a substitute for that analysis.
The GC's Role: Turn a Technical Migration Into a Governed Risk Program
The chief information security officer and technology teams should lead cryptographic discovery and engineering. General counsel should ensure that the program answers the questions that create legal, contractual and governance consequences.
1. Establish Ownership and Reporting
Name an accountable executive and a cross-functional working group that includes security, architecture, privacy, procurement, product, compliance, records management, internal audit, finance and legal. Define what reaches the risk committee or board and what evidence will be retained. Quantum readiness should fit within existing cyber governance, not become an isolated science project.
2. Build a Risk-Ranked Cryptographic Inventory
A conventional asset inventory is not enough. The organization needs visibility into cryptographic algorithms, protocols, certificates, keys, libraries, hardware roots of trust, code-signing processes, identity systems, APIs, VPNs, backups, connected products and vendor-controlled services. Some organizations call the resulting artifact a cryptographic bill of materials.
Prioritize by combining:
- the sensitivity and useful life of the data;
- the likelihood that encrypted traffic or data could be captured;
- the business criticality and external exposure of the system;
- the difficulty and lead time of migration;
- the system's expected end-of-life date; and
- the availability of vendor-supported PQC or hybrid options.
This produces a defensible sequence. A product designed to remain in the field for fifteen years presents a different risk from a commodity SaaS tool scheduled for retirement next year.
3. Require Cryptographic Agility in Procurement and Development
The durable objective is not merely adopting today's chosen algorithm. It is the ability to change algorithms, keys, certificates and protocols without redesigning the product or renegotiating every critical contract.
New procurement language should address supported standards, migration roadmaps, interoperability, testing, software and firmware updates, backward compatibility, key ownership, incident cooperation, end-of-life support and responsibility for migration costs. Product-development requirements should discourage hard-coded algorithms and undocumented cryptographic dependencies. Legal should resist absolute promises such as "quantum-proof," which may overstate both present capability and future assurance.
4. Revisit Data Governance and Incident Response
Identify information with a long confidentiality life and reduce unnecessary retention. Update incident playbooks so an investigation asks whether an attacker obtained quantum-vulnerable ciphertext, certificates, signed artifacts or key material whose significance may persist even if the data cannot presently be decrypted. Preserve enough technical evidence to reassess the incident as capabilities evolve.
5. Integrate Quantum Readiness Into Transactions and Contracts
For acquisitions involving security products, connected devices, infrastructure, valuable datasets or long-lived technology, diligence should examine cryptographic architecture, unsupported dependencies, product lifecycles, vendor commitments and migration cost. Representations and covenants should remain proportionate to what can actually be verified.
The same analysis belongs in major outsourcing, cloud, licensing and supply-chain relationships. A company cannot migrate a dependency that its provider cannot identify or update.
6. Test Before Broad Deployment
PQC implementations can create larger keys, signatures, certificates or messages; performance and interoperability effects vary by application. Hybrid deployments may reduce transition risk but add complexity. Organizations should pilot in controlled environments, use validated implementations where required, monitor NIST errata and implementation guidance and avoid inventing bespoke cryptography.
7. Document the Decisions
A reasonable program will evolve. Record the assumptions, risk ranking, scope, deferrals, vendor dependencies, testing results, budget decisions and review cadence. The goal is not to prove that counsel predicted the future. It is to show that management recognized a developing risk, used credible standards, made proportionate decisions and revisited them as facts changed.
Five Questions GCs Should Ask Now
- Which information must remain confidential for ten years or more, and how is it protected in transit and at rest?
- Do we know where RSA, elliptic-curve and other quantum-vulnerable public-key cryptography appears in our products, infrastructure and vendor stack?
- Can our critical systems change cryptographic algorithms without a major redesign or prolonged outage?
- Do our strategic vendors have credible PQC roadmaps, testing plans and contractual duties to support migration?
- Who owns the risk, what milestones are funded, and how will material issues reach management, the board and—where appropriate—the disclosure committee?
The Practical Conclusion
Quantum computing may ultimately deliver substantial commercial and scientific value. It may also redraw the assumptions underlying digital confidentiality and authenticity. The date of that transition is uncertain; the direction of travel is not.
For general counsel, the immediate task is not to select algorithms or declare an emergency. It is to ensure that long-lived data is identified, cryptographic dependencies are discoverable, contracts preserve migration options, technical teams can test safely and governance bodies receive decision-useful information. Organizations that begin that work now can fold PQC into ordinary refresh cycles and vendor negotiations. Those that wait for a dramatic breakthrough may find that their real constraint is not computing power, but time.
About Whiteford
Jeff Schell is a registered patent attorney and Managing Partner of the Mountain West practice at Whiteford, where he counsels technology companies on intellectual property strategy, AI governance and venture growth. A former multi-exit software founder and trained machine learning engineer, he advises companies from startup through exit on building defensible IP positions. That combination of engineering and transactional experience maps directly onto the questions raised here: where quantum-vulnerable cryptography lives inside a product, whether vendor agreements preserve the ability to change it and how those decisions hold up under diligence.
The information contained here is not intended to provide legal advice or opinion and should not be acted upon without consulting an attorney. Counsel should not be selected based on advertising materials, and we recommend that you conduct further investigation when seeking legal representation.