The firms that get caught by PQC risk will not see it coming. They will see it in a renewal audit — when the auditor asks about cryptographic asset inventory and the answer is silence. Or they will see it when a client asks what the firm did between 2024 and 2030 to protect their data. This community exists so that your firm is not the one reaching for its notes.
What is happening now is called harvest-now-decrypt-later. Adversaries are capturing encrypted traffic and stored ciphertext today, with the intention of decrypting it once a cryptographically relevant quantum computer arrives. Industry consensus puts that arrival somewhere between 2030 and 2040. The data being collected now is yours. The clock on its confidentiality has already started.
For a managing partner, the stake is the relationship. A client shared an M&A strategy, an estate plan, a tax structure, or an IP filing with your firm on the understanding that confidentiality survives the engagement. The encryption protecting that promise — RSA and elliptic-curve cryptography — is the same encryption that will fail when a sufficiently powerful quantum computer exists. The relationship does not break today. It breaks the day a client asks what you did about it.
NIST finalised the first post-quantum standards in August 2024: FIPS 203 (ML-KEM, key exchange), FIPS 204 (ML-DSA, digital signatures), FIPS 205 (SLH-DSA, hash-based signatures). The UK NCSC has published migration guidance. ISO 27001:2022 already requires cryptographic controls to be reviewed against emerging threats. The standards are settled. What remains is governance: who owns the inventory, who signs off the migration plan, who reports to the board.