A community for managing partners, GCs and compliance leads

Quantum-safe is a relationship question, not a technology question.

Post-quantum cryptography (PQC) — the next generation of encryption designed to resist quantum computers — is now a settled NIST standard. The work that follows is governance work. It belongs to leadership, not to the engineering team alone.

Assessing your firm's PQC exposure directly? Speak with the ASIMOV advisory team →

Aug 2024

NIST finalised FIPS 203, 204, 205 — the first post-quantum standards

2035

NSA CNSA 2.0 migration deadline for US national-security systems

30–100 yrs

Confidentiality horizon on a typical law firm matter file

The leadership briefing

What harvest-now-decrypt-later means for your client relationships

The firms that get caught by PQC risk will not see it coming. They will see it in a renewal audit — when the auditor asks about cryptographic asset inventory and the answer is silence. Or they will see it when a client asks what the firm did between 2024 and 2030 to protect their data. This community exists so that your firm is not the one reaching for its notes.

What is happening now is called harvest-now-decrypt-later. Adversaries are capturing encrypted traffic and stored ciphertext today, with the intention of decrypting it once a cryptographically relevant quantum computer arrives. Industry consensus puts that arrival somewhere between 2030 and 2040. The data being collected now is yours. The clock on its confidentiality has already started.

For a managing partner, the stake is the relationship. A client shared an M&A strategy, an estate plan, a tax structure, or an IP filing with your firm on the understanding that confidentiality survives the engagement. The encryption protecting that promise — RSA and elliptic-curve cryptography — is the same encryption that will fail when a sufficiently powerful quantum computer exists. The relationship does not break today. It breaks the day a client asks what you did about it.

NIST finalised the first post-quantum standards in August 2024: FIPS 203 (ML-KEM, key exchange), FIPS 204 (ML-DSA, digital signatures), FIPS 205 (SLH-DSA, hash-based signatures). The UK NCSC has published migration guidance. ISO 27001:2022 already requires cryptographic controls to be reviewed against emerging threats. The standards are settled. What remains is governance: who owns the inventory, who signs off the migration plan, who reports to the board.

The relationship does not break today. It breaks the day a client asks what you did between 2024 and 2030 to prepare, and you have no answer.

Watch

The quantum threat — explained for leadership

How this site works

Five editorial principles we apply to every piece we publish

01

Lead with the relationship

Every briefing on this site starts from the people at risk — clients, partners, staff — and works backward to the control. Technical detail earns its place only when it serves a decision a leader must make.

02

Anchor on recognised standards

We work from NIST, NCSC, ENISA, ISO 27001, ICAEW, SRA, FCA SYSC and GDPR — not from vendor marketing. Where standards diverge, we name the divergence and explain the trade-off.

03

Translate, do not dilute

Managing partners are not engineers, but they are not stupid. We define jargon on first use, keep the reasoning visible, and never reduce a serious decision to a checklist the reader cannot challenge.

04

Specific over generic

Replace vendor-neutral abstractions with named standards, named clauses, named regulators. ‘Appropriate technical measures’ means Article 32 GDPR; ‘effective governance’ means SRA Code 7.1. Specificity is respect for the reader's time.

05

No alarmism, no theatre

The risk is real and bounded. We avoid catastrophic framing, we avoid performative compliance gestures, and we focus on the controls that genuinely move the risk needle.

The standards we work with

Eight frameworks a managing partner should be able to name in a board meeting

Each entry follows the same structure: what the standard is, what it expects of your firm, and the practical action that follows. None require an engineering degree to act on. All require the partnership to take ownership.

NIST FIPS 203 / 204 / 205

US federal, de facto global reference

Post-Quantum Cryptography Standards

What it is

Finalised August 2024. ML-KEM replaces RSA/ECDH key exchange. ML-DSA replaces RSA-PSS/ECDSA signatures. SLH-DSA offers a conservative hash-based alternative.

Practical action

Ask your cloud and SaaS vendors which FIPS standard they are implementing, by when, and whether hybrid mode (classical + PQC) is supported during the transition.

NCSC PQC Migration Guidance

UK, all sectors

UK National Cyber Security Centre

What it is

Sets out the cryptographic lifecycle expectations NCSC will use when assessing UK organisations. Currently guidance rather than regulation, but anchors regulator and insurer expectations.

Practical action

Use the NCSC lifecycle phases (discover, prioritise, plan, migrate, retire) as your board reporting structure. Each phase has a named owner and a named deadline.

ISO/IEC 27001:2022 — Annex A.8.24

International, certifiable

Information Security Management — Cryptography

What it is

Requires organisations to define and implement cryptographic policies, key management, and lifecycle review. The 2022 revision explicitly expects emerging-threat review — PQC qualifies.

Practical action

If your firm is ISO 27001 certified, your next surveillance audit will be asked about PQC readiness. Update the cryptographic policy now; the auditor will follow.

SRA Code of Conduct — Principle 7

UK law firms and solicitors

Solicitors Regulation Authority

What it is

Requires effective governance arrangements and confidentiality of client information. PQC readiness is now within scope of ‘effective governance’ for any firm with long-lived matter data.

Practical action

Add a cryptographic risk line to your annual SRA Compliance Officer (COLP/COFA) report. The SRA has not issued specific PQC guidance yet, but the principle already applies.

ICAEW Code of Ethics & ISQM 1

UK accountancy and audit

Institute of Chartered Accountants in England and Wales

What it is

ISQM 1 (International Standard on Quality Management) requires firms to address risks to quality, including confidentiality of engagement data. PQC migration is a quality-management question.

Practical action

Add cryptographic risk to your ISQM 1 risk register. Document the firm's transition plan as a quality response, not just an IT project.

FCA SYSC 13.7

UK FCA-regulated firms

Financial Conduct Authority — Operational Resilience

What it is

Expects regulated firms to have appropriate cyber resilience, including protection of client data against foreseeable threats. PQC is now foreseeable.

Practical action

Include cryptographic transition in your FCA operational resilience self-assessment. Document the board-level owner and the milestones.

UK GDPR — Article 32

UK, all data controllers and processors

Data Protection — Security of Processing

What it is

Requires ‘appropriate technical and organisational measures’ — a standard that rises with the threat environment. Reliance on RSA/ECDH for data with a 10-year+ confidentiality horizon is now difficult to defend.

Practical action

Review your Article 30 Record of Processing. For each processing activity with a long confidentiality horizon, document the cryptographic control and the migration plan.

CNSA 2.0

US national-security systems (de facto market clock)

Commercial National Security Algorithm Suite 2.0

What it is

NSA mandate requiring ML-KEM, ML-DSA and SLH-DSA for new national-security systems by 2025, full migration by 2035. Functions as the regulatory clock for the broader market.

Practical action

Treat 2035 as your external deadline, but expect client contract clauses, insurer questions, and regulator guidance to push internal deadlines earlier — 2030 is the practical target for PSFs.

What we cover

Three content tiers, mapped to how leaders actually consume guidance

The community is structured around the cadence at which a managing partner, GC, or compliance lead can absorb PQC guidance. Articles fit a commute. White papers fit a board pack. Discussion groups fit a monthly peer conversation.

Articles

Free

Weekly · 800–1500 words · free

A single decision or question, framed for a managing partner reading on a phone.

Audience

Managing partners, GCs

Access

Open access

Examples
  • What your board needs to ask about cryptographic asset inventory
  • Harvest-now-decrypt-later, explained without the quantum mechanics
  • NIST FIPS 203/204/205 finalised — what changes for your firm this quarter
  • Your document management system is where PQC risk actually lives
  • Signal, iMessage, WhatsApp — which secure messaging is quantum-safe today

White papers

Members

Monthly · 8–20 pages · members

Sector-specific migration roadmaps, suitable for tabling at a partnership meeting.

Audience

Partners, IT directors, compliance leads

Access

Member tier (from £250/year)

Examples
  • Post-quantum migration roadmap for UK law firms
  • Post-quantum migration roadmap for UK accountancy & audit
  • Cryptographic asset discovery — a guide for partnership boards
  • PQC and legal professional privilege — a risk assessment
  • Vendor PQC readiness — a due diligence framework
  • Pilot to production — running a 90-day PQC pilot

Discussion groups

Members

Monthly · 60–90 minutes · members

Facilitated peer groups of 8–25 specialists, organised by topic not by technology.

Audience

Specialist leads (risk, procurement, IT, compliance)

Access

Member+ tier (from £500/year)

Examples
  • M&A confidentiality — sharing deal-by-deal approaches
  • Blockchain and DLT exposure — for firms with digital-assets clients
  • PKI and certificate migration — for IT directors running internal CAs
  • Vendor risk — for procurement leads assessing cloud and SaaS
  • Cyber insurance renewal — for risk managers preparing for 2028 questions
  • Regulatory horizon — for compliance officers tracking NCSC/FCA/SRA

Practical first steps

Five things a managing partner can do this quarter

None of these require a budget approval. None require an engineer. All of them create the paper trail a regulator or insurer will later want to see. The point is not to complete the list — it is to change the firm's posture toward the question.

  1. Name a cryptographic risk owner at the partnership table

    The owner does not need to be technical. They need authority to ask IT, procurement, and compliance for answers and to document those answers. ISO 27001 calls this ‘leadership commitment’ (Clause 5). SRA Code 7 expects it. Record the appointment in a partnership minute. If no one owns the question, no one answers it.

  2. Ask IT one question and write down the answer

    ‘Where do we use RSA or elliptic-curve cryptography, and which of those uses protect data with a confidentiality horizon over 10 years?’ You will not get a complete answer. That is the point. The gap between what IT knows and what the firm needs to know is your first inventory request — and your first governance finding.

  3. Add a PQC line to your next board or partnership report

    Three lines: (a) what the firm has inventoried, (b) what the firm has not, (c) the next action and its owner. This is the reporting structure NCSC recommends. It also creates the audit trail a regulator or insurer will later ask for.

  4. Review your three largest vendor contracts for PQC clauses

    Document management, e-signature, and case management vendors are where the greatest impact is concentrated. Ask each: (a) which NIST PQC standard are you implementing, (b) by when, (c) will hybrid mode be available during transition. The answers inform your renewal negotiation.

  5. Raise PQC at your next cyber insurance renewal meeting

    Insurers are still calibrating their PQC underwriting questions. Being ahead of the question — bringing a one-page summary of the firm's inventory and plan — positions the firm favourably and may anchor your premium. It also forces internal progress.

About the author

Sushila Nair — security and audit specialist

Twenty years at the boundary where security meets governance — audit work, ISACA-aligned practice, expert witness instructions in cybersecurity disputes. The thread through all of it: the people who bear the consequences of security decisions are rarely the people who make them. That gap is where this community lives.

The PQC conversation in the market is split. Technical papers written for cryptographers — correct, unreadable at leadership level. Vendor briefings — readable, tilted toward a product. What is missing is the sector-specific, leadership-tier, vendor-neutral view written by someone who has sat in the audit room. I know what regulators ask. I know what the silence looks like when an organisation runs out of answers. That space is what this community fills.

I am not an algorithm designer. I will not tell you which cryptographic primitive to implement. What I will do is translate what NIST, NCSC, ISO and the UK regulators expect of your firm, frame the decisions your partnership needs to make, and give you the peer community where managing partners, GCs and compliance leads can compare approaches without a vendor in the room.

Join the community

Membership is structured around how you actually use it

The community is intentionally small and sector-specific. Three tiers, no upsell theatre, no marketing automation. If you are a managing partner, GC, or compliance lead at a regional professional services firm, you are the audience.

Open

Free

Always

  • ·Weekly articles
  • ·Newsletter (bi-weekly digest)
  • ·Resources page — curated links to NIST, IETF, ETSI, NCSC
  • ·Open webinars (quarterly)

Member

£250 / year / person

Annual

  • ·Everything in Open
  • ·Full white paper library (8–20pp each, monthly)
  • ·Member-only webinars (bi-monthly)
  • ·Discussion group access (one group)
  • ·Vendor comparison tools and templates
Apply for membership

Member+

£500 / year / person

Annual

  • ·Everything in Member
  • ·Additional discussion groups (up to three)
  • ·Annual benchmarking report
  • ·Priority booking for advisory engagements
  • ·Annual community summit invitation
Apply for membership+

Advisory engagement

Ready to assess your firm's exposure directly?

Community membership gives you the knowledge to ask the right questions. If you want an independent, signed assessment of your firm's cryptographic risk position — with a named professional accountable for every finding — that is the ASIMOV AI Audit.

Learn about the ASIMOV AI Risk Audit →

Subscribe to the newsletter

Bi-weekly digest of articles, regulatory updates, and community announcements. Work emails only — we read every subscription and we do not share lists.

We respect your inbox. One welcome email, then bi-weekly. Unsubscribe in one click.

The elsewhere layer

Where the deep technical material lives

This site deliberately does not publish original algorithmic or mathematical content. We curate, we annotate, we translate — but the technical depth lives at the standards bodies, in the academic literature, and in the implementation libraries. The list below is the curated set we recommend to members who want to go deeper than the leadership tier.