The encryption protecting your data today was designed to outlast classical computers. Quantum computers operate by different rules, and nobody can tell you when they will get there. What arrives ahead of the capability is the question — from a customer’s security review, from a regulator, from a line on a procurement form asking what you are doing about it. You will answer that question years before anyone can prove the threat has landed.
That answer is a brand signal. It gets read next to everything else you have said about how you handle what people trust you with, and it either agrees with the rest or it does not.
What You’ll Learn
- Why the questions about quantum risk carry hard dates even though the threat does not
- The two default answers — reassurance and alarm — and what each one costs
- Why a security claim behaves like every other signal a brand sends
- What you can state about your quantum posture today and still defend in five years
- Where that answer has to appear for it to hold together
Why the Question Arrives Before the Threat Does
Q-Day — the point at which quantum computers can break the RSA and elliptic curve cryptography protecting most stored data and digital communication — has no date. Estimates from the cybersecurity research community run from the early 2030s into the mid-2040s, and hardware milestones have repeatedly outpaced the projections that preceded them. No one has a defensible year.
The obligations have dates. In June 2026, Executive Order 14412 directed federal agencies to move high-impact systems and high-value assets to post-quantum key establishment by December 31, 2030, and to post-quantum digital signatures by December 31, 2031, with federal contractors required to meet post-quantum FIPS by the end of 2030. NIST’s transition roadmap, IR 8547, deprecates RSA-2048 and ECC P-256 in 2030 and disallows RSA and ECC entirely in 2035. In the EU, NIS2 and DORA push verification onto the buyer: regulated organizations are expected to assess a vendor’s cryptographic readiness rather than accept a self-certification. Australia’s Cyber Security Centre publishes a vendor-neutral set of post-quantum questions written to be attached to procurement and contract renewals.
So the sequence runs backwards from the intuition. The threat is undated and the disclosure is scheduled. Long before any of this is demonstrable, someone holding a checklist will ask what you have done, and they will write your answer down.
The date you are being held to is not Q-Day. It is the date on the questionnaire.
The Two Answers That Cost You Something
Two answers are available without doing any work, and both get used.
The first is reassurance. Security is a priority. The landscape is being monitored. The roadmap is under evaluation. The organization is quantum-ready. Nothing in that answer can be checked, which is the whole of its appeal and the reason it fails. Under NIS2 and DORA the buyer is now the one doing the verifying, so the unverifiable answer no longer clears procurement. What it still clears is the sales call — and it leaves behind a claim your engineers may not be able to stand behind in 18 months.
The second is alarm. Borrow the urgency from the vendors selling migration, describe the threat in the strongest terms available, and let the seriousness of the language stand in for the seriousness of the preparation. It works, briefly. Then the year passes, nothing breaks, and the alarm gets re-read as marketing by the exact audience it was meant to convince.
Both answers reach for trust directly. That is why they miss it. Trust is not something an audience decides to extend. It accumulates when signals agree with each other over time, and neither of these signals is agreeing with anything.
A Security Claim Is a Brand Signal
Subverse is a narrative branding and communication design studio, and the practice we work from treats language as structural material: a word either reinforces what a brand means or adds noise to a system that depends on coherence. Integrity, in that frame, is not a virtue. It is a structural requirement. When what an organization says and what it does contradict each other, meaning collapses no matter how well the saying was done.
A quantum-readiness claim sits under that rule the same as a positioning line or a pricing page. It carries one additional property: it is unusually easy to check, and checking it is now somebody’s job.
Security and trust language gets written by the people furthest from the brand system — legal, IT, a vendor template pasted into a page nobody owns — and it is the one part of a site that never gets read against anything else. We see it consistently. The claim on the security page, the claim in the RFP response, and the claim made on a sales call drift apart, and no single person is positioned to notice. When we audit a brand’s signals across its surfaces, that page is where we most often find statements no one in the room can source.
A claim that cannot be checked cannot compound. It can only be repeated.
What You Can Say Without a Date
The technical ground gives you far more defensible material than the reassurance script does.
Start with how long your data has to stay secret. “Harvest Now, Decrypt Later” describes adversaries intercepting encrypted traffic today and storing it against a future decryption capability. The consequence is that your deadline was never Q-Day — it is the confidentiality lifespan of what you hold. That is a fact about your own business, establishable this quarter, requiring no view on quantum hardware at all. If your records have to stay confidential for 10 years or more, data leaving your systems now is already inside the window, and you can say precisely that, with the number, and defend it later.
Then say what you have inventoried. A cryptographic audit — the mapping of every system, protocol, and stored dataset relying on RSA, ECC, or Diffie-Hellman key exchange — is either finished, underway, or not started. All three are answerable. Only one of them is embarrassing, and it is not the one you would expect: “not started, scheduled for Q3, and here is who owns it” reads as governance. “Quantum-ready” reads as a phrase.
Then name what you have moved, and to what. NIST finalized its first post-quantum standards in 2024 — ML-KEM for key encapsulation, ML-DSA and SLH-DSA for digital signatures. Naming the algorithm, the system it protects, and the date it went in produces a checkable sentence. Hybrid deployments, where a classical algorithm is layered with a post-quantum one so a failure in either does not compromise the whole, are worth saying out loud as well, because the layering is the reason the claim is a conservative one.
One rule sits under all three: replace the undated claim with the dated fact. You cannot say when the encryption breaks. You can say what you hold, how long it has to hold, what you have mapped, what you have migrated, and when. Each of those survives being checked, which is the only property that lets a claim accumulate into something.
Where the Answer Has to Live
The question comes through the security page, the RFP response, the vendor questionnaire, the sales conversation, the investor update, and eventually the incident note. Those surfaces get written by different people, at different times, under different pressure. Left alone they drift, and the drift is exactly what a buyer’s assessment is built to find.
What holds them together is not a policy document. It is a single governed set of facts about your cryptographic posture — what is deployed, what is scheduled, what the data lifespan is, who owns the migration — that every surface answers to instead of reinventing. Write it once, keep it current, and let the security page, the questionnaire, and the sales deck all resolve back to it. The work is unglamorous, and it is the whole mechanism. Coherence is the condition where a claim made in one place is still true in another.
That is also why this belongs to the brand and not to the security team alone. The security team can tell you what is true. Whether the organization says the same true thing in all six places is a communication design problem.
One good answer is worth less than six matching ones.
Conclusion
Quantum risk becomes a cryptography problem eventually, and cryptographers will solve that part. It is a communication problem now, and it stays one for as long as the honest answer to “when” is that nobody knows. That gap — years of being asked about something you cannot yet demonstrate — is where an organization builds a record of saying checkable things, or a record of saying comfortable ones.
The cryptography has deadlines: 2030, 2031, 2035. What you say in the meantime has none, and it is being written down anyway.


