Quantum Risk Disclosure: What Investors and Regulators Are Asking

The disclosure frameworks that govern cybersecurity risk management are not waiting for quantum computers to arrive. In the United States, the SEC's Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure rule (Release No. 33-11216) has been in force since September 2023. In the EU, NIS2 and DORA impose active cryptography and ICT risk obligations on tens of thousands of organisations. In New York, the NYDFS Part 500 second amendment took effect in November 2023. These are current obligations, not draft proposals.

The question for CISOs, General Counsel, CFOs, and Chief Risk Officers is not whether disclosure obligations exist. They do. The question is whether quantum risk is material under those frameworks. For organisations holding long-lived sensitive data, operating critical infrastructure, or carrying multi-year system replacement cycles, the answer is increasingly yes. The harvest now, decrypt later (HNDL) threat model means the risk exists in the present tense: data collected today under RSA or ECC encryption may be decrypted once a cryptographically relevant quantum computer (CRQC) becomes operational, which the Global Risk Institute's 2024 survey places at a 14 to 34 per cent probability within ten years.

This article equips security teams to understand which disclosure frameworks are already active, what “material” means in the quantum risk context, and what internal preparation is required to support accurate and defensible disclosures. The CISO who cannot answer three basic questions about quantum exposure is not in a position to advise the board. The board that cannot answer those questions when challenged is not fulfilling its oversight obligations under SEC Item 1C.

The Disclosure Frameworks That Are Already Active

US SEC Cybersecurity Disclosure Rule (17 CFR § 229.106)

The SEC's final rule, effective for large accelerated and accelerated filers from fiscal years ending on or after 15 December 2023, requires annual disclosure under Form 10-K Item 1C of four specific elements: the registrant's processes for assessing, identifying, and managing material risks from cybersecurity threats; whether those processes are integrated into the organisation's overall risk management systems; board oversight of cybersecurity risk; and management's role in assessing and managing those risks. These are process disclosures, not outcome disclosures. The SEC is asking how you manage cybersecurity risk, not just whether you have had an incident.

Form 8-K Item 1.05 adds an incident disclosure obligation: material cybersecurity incidents must be reported within four business days of a materiality determination. Materiality follows the reasonable investor standard established in TSC Industries v. Northway: whether there is a substantial likelihood that a reasonable investor would consider the information important in making an investment decision.

Quantum risk fits within Item 1C through two routes. First, HNDL attacks targeting an organisation's data satisfy the SEC's definition of a cybersecurity threat. The rule defines a cybersecurity threat as “any potential unauthorised occurrence on or conducted through a registrant's information systems that may result in adverse effects on the confidentiality, integrity, or availability” of information. HNDL attacks satisfy that definition because data collected now may lose confidentiality in the future. Second, where quantum risk constitutes a material risk to the business, it must appear within the risk management process disclosure regardless of whether a specific incident has occurred.

UK FCA and TCFD-Aligned Disclosure

The UK Financial Conduct Authority extended TCFD-aligned disclosure requirements to standard listed companies under FCA Policy Statement PS21/23, covering accounting periods beginning on or after 1 January 2022. The earlier requirement for premium-listed companies was introduced via PS20/17 under Listing Rule 9.8.6R(8), in force from 1 January 2021. Both sets of requirements apply on a comply-or-explain basis. TCFD's Risk Management recommendations require companies to describe their processes for identifying and assessing risks, managing those risks, and integrating those processes into overall risk management. This structural pattern maps directly onto how quantum risk should be framed in UK disclosures: identify the cryptographic assets and HNDL exposure, assess the risk against a quantum timeline, integrate the management process into the ICT and operational risk framework.

The NCSC's guidance on post-quantum cryptography, updated in 2023, provides the technical basis for characterising quantum risk as a known and manageable risk. The NCSC's position is that organisations should begin migration planning now, particularly where data longevity exceeds ten years. A UK-listed company in sectors with long-lived sensitive data cannot credibly claim that quantum risk is too speculative to disclose when the national cyber authority has published guidance recommending active planning.

NYDFS Part 500 and EU Sustainability Reporting

The NYDFS Cybersecurity Regulation (23 NYCRR Part 500), amended November 2023, requires covered entities to designate a CISO responsible for reporting to the board at least annually on the cybersecurity programme and material cybersecurity risks. For Class A companies (those with 2,000 or more employees or over $1 billion in gross annual revenue, and subject to the $20 million gross annual revenue floor that gates Class A designation), the second amendment also introduced 72-hour notification for extortion payments and expanded incident notification requirements. The CISO's annual board report must address the entity's cybersecurity programme, compliance status, and exceptions or improvement areas. A known and unmanaged quantum risk exposure falls squarely within that reporting scope.

The European Sustainability Reporting Standards S4, mandatory for CSRD in-scope companies from financial year 2024 under Commission Delegated Regulation (EU) 2023/2772, includes disclosure requirements on product and service data security. Organisations subject to CSRD should confirm with legal counsel whether S4's cybersecurity provisions apply to their quantum risk exposure, and verify the specific Article reference before publication.

What “Material” Means in the Context of Quantum Risk

Materiality for SEC disclosure follows the facts-and-circumstances test from TSC Industries v. Northway: a risk is material if a reasonable investor would consider it important. There is no bright-line percentage threshold. The question is whether the information would alter the total mix of information available to a reasonable investor making a decision about the company's securities.

Quantum risk is material under this test in three specific categories. The first is data longevity: organisations holding data whose confidentiality must be maintained for more than five years carry HNDL exposure. If that data includes financial contracts, intellectual property, healthcare records, or national security information, the exposure is concrete. The second is system replacement cycles: organisations operating infrastructure with replacement cycles of five to ten years or longer, where cryptographic agility cannot be retrofitted, face a migration window that may not close before a CRQC becomes operational. The third is regulatory obligation: where organisations carry an existing mandate to migrate, such as CNSA 2.0 for US defence contractors, failure to demonstrate progress constitutes a material risk independently of whether a CRQC exists today.

NIST IR 8547 (Initial Public Draft, November 2024) sets out the migration timeline risk directly: organisations should complete migration from RSA and ECC to NIST-approved post-quantum algorithms by 2030 for most use cases. A company that cannot demonstrate progress against this timeline by the time of its next annual disclosure filing is carrying a documentable gap in its cybersecurity programme. That gap may be material to investors with positions extending beyond 2030.

The disclosure question is not whether quantum computers exist today. It is whether the risk of future quantum-enabled decryption of currently collected data is material to a reasonable investor. For sectors with long-lived sensitive data, including healthcare, financial services, defence, legal services, and intellectual property, that question is now being asked directly by sophisticated institutional investors and proxy advisory firms.

What Security Teams Need to Produce

Item 1C requires disclosure of processes for identifying, assessing, and managing cybersecurity risks. That means documented processes, not just outcomes. A cryptographic programme that exists informally but cannot be described in writing cannot be disclosed accurately. An inaccurate disclosure carries its own liability.

The minimum evidence base for a defensible quantum risk disclosure has three components. First, a cryptographic inventory identifying all deployed asymmetric cryptography, covering RSA, ECC, and Diffie-Hellman, with associated system classifications, data sensitivity ratings, and estimated data longevity. Second, a risk assessment scoring each system and data class against a quantum timeline, using the GRI 2024 consensus range of 2033 to 2035 as the planning horizon. Third, a migration roadmap with prioritised phases aligned to NIST IR 8547 guidance or equivalent sector-specific standards, showing current status and committed timelines.

The Cryptography Bill of Materials (CBOM), standardised under the CycloneDX 1.6 specification released in April 2024, provides the technical artefact that supports inventory-based disclosure. A CBOM records all cryptographic assets, including algorithms, key lengths, certificates, and their dependencies, in a machine-readable format that feeds directly into risk scoring and migration planning tools. The NIST NCCoE Migration to Post-Quantum Cryptography project (SP 1800-38) identifies CBOM generation as the target output of Phase 1 cryptographic discovery. For a detailed treatment of how to build that inventory, see our article on cryptographic inventory management.

The CISO should be able to answer three questions when briefing the board: what cryptographic assets does the organisation hold; what is the estimated exposure window for each asset class under the 2033 to 2035 Q-Day horizon; and what is the current migration status and projected completion date. If those three questions cannot be answered with documented evidence, the organisation is not in a position to make an accurate disclosure under Item 1C or its international equivalents. For the operational steps to build this evidence base, see How to Start a PQC Migration Programme.

The Investor Perspective

Institutional investors with long-dated positions, including pension funds, sovereign wealth funds, and insurance pools, are incorporating cyber risk longevity into ESG and governance assessments. Quantum risk is a growing component of this for portfolios holding technology companies, financial institutions, healthcare businesses, and defence contractors with long-duration positions. The World Economic Forum's Global Risks Report identified quantum risk within its technology risk taxonomy for both 2023 and 2024.

Proxy advisory firms, including ISS and Glass Lewis, have expanded their governance analysis to include cybersecurity risk management process disclosure. Board-level cybersecurity expertise and oversight structure are now assessed for sufficiently large public companies. An annual report that discusses material cybersecurity risks without addressing quantum risk may attract adverse commentary from proxy advisers where the company's sector makes quantum exposure plausible. Organisations should confirm with legal counsel whether ISS or Glass Lewis have published specific guidance on quantum cybersecurity risk as a board governance matter before their next disclosure cycle.

The argument for proactive disclosure is not regulatory compliance alone. Companies that can demonstrate a mature, documented quantum risk programme differentiate themselves from peers who have not started. A CISO who can present a CBOM, a risk-scored migration roadmap, and a board briefing pack is providing institutional investors with what they increasingly look for: evidence that management has identified the risk and is managing it with discipline. That is a risk management maturity signal with commercial value as well as compliance value.

The EU and UK Regulatory Horizon

The EU NIS2 Directive (Directive (EU) 2022/2555) Article 21(2)(h) requires essential and important entities to adopt policies and procedures for cryptography and, where appropriate, encryption. Article 21(2)(d) covers supply chain security. NIS2 does not name post-quantum cryptography specifically, but ENISA guidance explicitly frames PQC as a component of the cryptography policies required under Article 21(2)(h). An organisation in scope for NIS2 that has no cryptography policy and no PQC migration plan has a documentable gap in its NIS2 compliance posture.

The EU Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) Articles 6 and 9 require financial entities to implement ICT risk management frameworks with specific controls for cryptographic key management and data protection in transit and at rest. Article 28 requires management of ICT third-party risks. DORA's supervisory authority disclosure framework creates reporting obligations where ICT risks, including cryptographic risks, are not managed to the required standard. Financial entities subject to DORA should integrate quantum risk into their ICT risk management documentation ahead of their next supervisory review.

The UK NIS Regulations 2018 (SI 2018/506) impose equivalent obligations on operators of essential services and relevant digital service providers. The ICO and sector regulators enforce these obligations. The UK National Quantum Strategy (DSIT, March 2023) reinforces the regulatory expectation that critical national infrastructure operators manage quantum risk as part of their CNI protection programmes. Taken together, these frameworks mean that for any regulated entity operating in the UK or EU, quantum risk is already within the scope of active regulatory obligations, not a future concern to be addressed once a CRQC appears.

The Internal Preparation Checklist

Before the next reporting cycle, security teams should work through six specific steps. First: complete or commission a cryptographic inventory covering all systems that process, transmit, or store data subject to long-term confidentiality requirements. Document the tool stack used, with CBOM output as the target artefact. Second: score each system and data class against NIST IR 8547 migration priority categories. Category 1 (discontinue as soon as practicable) has different urgency from Category 2 (plan migration) or Category 3 (monitor). Third: prepare a board-level quantum risk briefing using the three-question framework covering assets, exposure window, and migration status. A board that has received and approved that briefing has documented its oversight function under Item 1C.

Fourth: review existing Item 1C disclosures, or equivalent risk management sections in UK and EU filings, with legal counsel. Confirm that quantum risk is characterised accurately, and that the current state of not-yet-migrated is assessed against the materiality standard for the company's specific sector and data profile. Fifth: engage internal audit to assess whether the cryptographic inventory and migration roadmap are sufficient to support disclosure. Internal audit should be able to opine on process completeness, not just control outcomes. Sixth: agree on disclosure language. Quantum risk should be framed as a risk management process: the organisation has assessed the risk, has a documented programme, and is progressing against a defined roadmap. Absolute language is not useful and is not accurate.

For the crypto-agility architecture that makes a defensible migration programme possible, see our article on Crypto Agility: The Architecture Principle, which explains how to design systems that can swap cryptographic primitives without full platform replacement.

What Not to Do

Three disclosure mistakes appear frequently enough to be worth naming explicitly.

The first is waiting for a quantum-specific disclosure regulation before acting. Item 1C and its international equivalents apply now. If quantum risk is material under the reasonable investor test, it must appear in disclosures under existing frameworks. Waiting for a dedicated quantum risk regulation means waiting for a legal obligation that will arrive after the first CRQC is operational, which is not a defensible position.

The second is conflating Q-Day uncertainty with an absence of risk. The GRI 2024 expert survey identifies a 14 to 34 per cent probability of a CRQC within ten years. That range is wide and that probability is not certainty. But it is not zero, and it is not negligible for a company holding sensitive data with a 10-year longevity profile. Uncertainty about timing does not remove the obligation to manage the risk.

The third is delegating the disclosure question to IT without board-level engagement. SEC Item 1C explicitly requires disclosure of board oversight of cybersecurity risk, including the board's role in reviewing and approving cybersecurity risk management processes. Board members who cannot answer questions about the organisation's quantum risk programme are not in compliance with the intent of that requirement. The quantum risk briefing is not a technical exercise to be handled below board level. It is a governance requirement with director liability attached. For a structured guide to putting quantum risk on the board agenda, including a CISO briefing template, see our dedicated resource for CISOs preparing for board-level disclosure discussions.

About the Author

Steven Vaile is a quantum security and post-quantum cryptography consultant and the founder of Quantum Security Defence. He advises enterprises and government bodies on PQC migration strategy, cryptographic governance, and quantum risk assessment. He has spoken at international security conferences on the intersection of quantum computing and critical infrastructure protection.