Post-Quantum Readiness for Law, CPA and Investment Firms in DFW

Post-quantum readiness is usually filed under problems for later. For a law firm it is not, because attorney-client privilege has no expiry date and encrypted traffic can be copied today and opened in a decade.
Most technology risks have a shape professional firms recognize. Something happens, you respond, you notify, you recover. This one is different. The damage would be done years before anyone knows, and the decision that determines whether it happens to you is being made now, quietly, by whoever controls how your firm encrypts data in transit.
This is not a prediction about when a cryptographically relevant quantum computer arrives. Nobody credible will give you that date. It is about a much narrower question: how long does your firm’s confidential material need to stay confidential, and is that longer than the time remaining before today’s encryption stops holding?
For a great many law, CPA and investment firms in Dallas-Fort Worth, the honest answer is yes.

What Is Harvest Now, Decrypt Later?
Harvest now, decrypt later is an attack in which encrypted data is captured today and stored until quantum computing makes it decryptable. The attacker gains nothing at the moment of capture, so there is no breach to detect and nothing to notify. The exposure is realized years afterwards, which makes the risk a function of how long your data must stay secret rather than of how strong your encryption is today.
That reframing is the entire point. A firm asking “is our encryption strong enough?” is asking the wrong question. The right one is “how long does this need to hold, and will it?”

Why This Lands Differently on Professional Firms
General business data has a short secrecy half-life. A price list stolen today and decrypted in 2034 is worthless. Professional firms hold the opposite kind of material.
Law firms: privilege does not expire
Attorney-client privilege survives the matter, the relationship and in most circumstances the client’s death. A privileged communication intercepted in encrypted form this year and opened in 2033 is still privileged, and its disclosure is still a harm. ABA Formal Opinion 477R already requires lawyers to make judgments about securing client communications based on sensitivity, and Model Rule 1.1’s technology comment requires keeping current with the risks of relevant technology. Neither of those obligations has a carve-out for risks that mature slowly.
Investment firms: retention outlasts the encryption
SEC recordkeeping obligations keep advisory records for years, and the customer information covered by Regulation S-P does not become harmless with age. Account numbers, tax identifiers and financial histories retain their value to an attacker far longer than a normal breach window. We cover the current obligations in our piece on what Reg S-P now requires firms to evidence.
CPA firms: the data is permanent by nature
A Social Security number does not get reissued because it was disclosed late. Tax records, beneficial ownership details and multi-year financial histories are among the longest-lived sensitive data any small firm holds, and the WISP obligations under IRS Publication 4557 apply to protecting it for as long as you hold it.
When Do Firms Need to Be Post-Quantum Ready?
Firms need to be post-quantum ready before the sum of their data’s required secrecy lifetime and their migration time exceeds the time remaining until quantum decryption is feasible. NIST has published the schedule that anchors this: quantum-vulnerable algorithms are deprecated after 2030 and disallowed after 2035, and the NSA’s CNSA 2.0 requires national security systems to migrate by 2030. A firm holding data that must stay confidential for ten years is already inside the window.
That arithmetic is worth doing explicitly, because it produces a different answer for different firms.
| Firm type | Typical secrecy lifetime | Inside the window? |
|---|---|---|
| Litigation or corporate law firm | Indefinite; privilege does not lapse | Yes, clearly |
| RIA or wealth manager | Client lifetime plus estate administration | Yes |
| CPA or tax practice | Decades; identifiers never change | Yes |
| General commercial business | Months to a few years | Usually not yet |
This is why the generic advice aimed at small business, which amounts to wait and see, is wrong for professional firms specifically. The waiting is the exposure.
Want to know where your firm’s long-lived data actually sits? We run a cryptographic inventory as part of our security assessment for professional firms. Call (888) 352-4832 or request one.
What Is Crypto-Agility, and Why Is It the Actual Deliverable?
Crypto-agility is the ability to change the cryptographic algorithms a system uses without rebuilding the system. It matters more than any individual algorithm choice, because the practical failure mode is not picking the wrong cipher. It is having encryption hard-coded into applications, appliances and integrations so deeply that changing it requires a project nobody has budgeted.
NIST published the first three post-quantum standards in 2024, including ML-KEM for key establishment and ML-DSA for digital signatures. Most firms will never touch those names. What they will experience is whether their vendors can turn the new algorithms on, and whether anyone at the firm knows which systems are waiting on which vendor.
What a Firm Should Actually Do This Year
None of this requires buying quantum anything. The useful work in 2026 is inventory and leverage.
- Build a cryptographic inventory. Which systems hold or transmit data with a long secrecy lifetime, what protects it, and who supplies that protection. Most firms have never written this down, and it is the prerequisite for every later decision.
- Classify by secrecy lifetime, not by sensitivity. These are different axes. A document can be moderately sensitive and need to stay secret for thirty years. That is the one that matters here.
- Put the question to your vendors now. Ask your document management, practice management, portfolio accounting, email and VPN providers for their post-quantum roadmap in writing. You are not expecting a migration date. You are establishing that you asked, and finding out which vendors have no answer at all.
- Prioritize data in transit. Harvest now, decrypt later is primarily an interception problem. Traffic crossing untrusted networks is the first thing to care about, ahead of data sitting on an encrypted disk in your office.
- Fold it into what you already do. Add a post-quantum roadmap question to your vendor review cycle, and add long-lived data to your client security questionnaire evidence pack. This should cost you a meeting, not a project.
- Write down the decision. Whatever you conclude, record that the firm considered it and why it chose the timeline it chose. For lawyers this is the technology-competence duty discharged in the only way that is provable later.
The NIST post-quantum cryptography project is the authoritative reference if someone at your firm wants the primary source, and the NIST Cybersecurity Framework gives you a structure to hang the inventory on.
What Not to Do
Three failure modes are already visible in how this topic gets sold.
- Buying a product to solve it. There is no post-quantum appliance that makes a firm ready. Readiness is an inventory and a vendor posture, and anyone selling otherwise is ahead of the evidence.
- Treating it as urgent. It is not urgent. It is early, which is a different thing and calls for a different budget. A firm that panics now will overspend on the wrong layer.
- Ignoring it because the date is uncertain. The uncertainty cuts the other way. Because nobody can tell you when, a firm holding thirty-year secrets cannot argue it had time.
Frisco, Plano and Irving
Plano firms tend to hold the deepest archives, because the region’s established practices have twenty to forty years of accumulated matter files and client records. Long-lived data is exactly the exposure this creates, and it is usually spread across systems nobody has catalogued. Our Managed IT Plano team handles these inventories, and our Managed IT Plano security practice covers the financial-firm side.
Irving and Las Colinas firms will meet this first through someone else’s questionnaire. The corridor’s corporate and institutional clients run mature vendor diligence, and post-quantum roadmap questions have started appearing in enterprise assessments. Our Managed IT Irving practice works from an office at 7301 State Hwy 161, and our Managed IT Irving team tracks what is showing up in those reviews.
Frisco firms have the easiest version of this problem and the shortest path through it. Cloud-native practices inherit their cryptography from a small number of major platforms, which means readiness is largely a matter of knowing which platforms and keeping current. DKBinnovative is headquartered in Frisco; our Managed IT Frisco and Managed IT Frisco teams cover this work.
Frequently Asked Questions
What is harvest now, decrypt later?
Harvest now, decrypt later is an attack in which encrypted data is captured today and stored until quantum computing makes it decryptable. There is no breach to detect at the time of capture, so the risk is a function of how long your data must stay secret rather than of how strong your encryption is today.
When do firms need to be post-quantum ready?
Before the sum of their data’s required secrecy lifetime and their migration time exceeds the time remaining until quantum decryption is feasible. NIST deprecates quantum-vulnerable algorithms after 2030 and disallows them after 2035, and NSA CNSA 2.0 requires national security systems to migrate by 2030. A firm holding data that must stay confidential for ten years is already inside the window.
What is crypto-agility?
Crypto-agility is the ability to change the cryptographic algorithms a system uses without rebuilding the system. It matters more than any individual algorithm choice, because the common failure is encryption hard-coded into applications and appliances so deeply that changing it becomes an unbudgeted project.
Is this urgent for a small law or accounting firm?
It is early rather than urgent, and the distinction matters for budgeting. But it applies earlier to professional firms than to general businesses, because privilege does not expire and tax identifiers are never reissued. The work due this year is inventory and vendor questions, not spending.
Do we need to buy anything to become post-quantum ready?
No. There is no product that confers readiness. What a firm needs is a cryptographic inventory, a classification of data by secrecy lifetime, and written post-quantum roadmaps from the vendors that supply its encryption.
Does this affect our compliance obligations today?
Not directly. No current rule requires post-quantum migration for private firms. Indirectly it reaches lawyers through the technology-competence duty and reaches every firm through client security questionnaires, where post-quantum roadmap questions have begun to appear in enterprise vendor assessments.
Working With DKBinnovative
We have supported professional firms across Dallas-Fort Worth since 2004, which is 22 years, currently covering 2,632+ end users across 55+ companies with a 78% first-call resolution rate and 98.14% client satisfaction. Our infrastructure standardizes on Microsoft Azure and Microsoft 365, both of which are moving on post-quantum work at platform level, which is a large part of why cloud-native firms have a shorter path here.
If you want to know where your firm’s long-lived data sits and which vendors have an answer, that is a cryptographic inventory and it takes us a few weeks. It is the only part of this that is worth doing right now.
Call (888) 352-4832 or book an assessment.
Related reading: Investment & Professional Firms · IT Support for Law & Accounting Firms · Managed IT for Law Firms · Managed IT for RIA Firms · Client Security Questionnaires
External references: NIST Post-Quantum Cryptography Project, NIST Cybersecurity Framework, 17 CFR Part 248, IRS Publication 4557.
Serving the DFW Metroplex
