top of page

The Hidden PQC Cost in Quantum M&A

Writer: Brian Couzens
Brian Couzens
35 minutes ago
3 min read
Business executives reviewing and signing an M&A term sheet beside a cybersecurity diagram showing certificates, keys and post-quantum cryptography risks.


M&A activity is rife in quantum computing. That is fact. What fewer boards are pricing in is the cost of post-quantum cryptography inside those deals.

The quantum sector is moving from research-led development towards commercialisation, strategic investment and consolidation. IonQ, for example, reported agreements involving major acquisitions and held $3.3 billion in cash, cash equivalents and investments at the end of 2025. It also completed acquisitions including Oxford Ionics and Vector Atomic.

This activity is creating a new M&A consideration: the cryptographic debt inherited with every target.

Every acquisition inherits cryptographic debt

Quantum hardware companies, photonics businesses and quantum software platforms may rely on:

  • TLS 1.2, RSA 2048 and ECC P-256

  • Proprietary key-management systems

  • Vendor-specific hardware security modules

  • Embedded cryptographic libraries in firmware and APIs

  • Long-lived keys protecting intellectual property and calibration data

  • Cloud, software and supply-chain dependencies without clear PQC roadmaps

Some systems cannot be upgraded simply by changing a library. They may require hardware replacement, firmware changes, certificate re-issuance, new validation activity or a complete redesign of integration layers.

That is why post-quantum cryptography should be treated as an M&A diligence issue, not merely a post-close security project.

What PQC adds to the deal

In an M&A context, PQC costs appear across several workstreams:

Discovery and inventory

The acquirer needs to identify cryptographic modules, certificates, keys, protocols, algorithms and dependencies across the target’s IT, cloud, OT, laboratory and production environments.

Risk assessment

Sensitive data with long retention periods must be prioritised, particularly where it could be exposed to harvest-now, decrypt-later attacks.

Remediation

The target may need to re-issue certificates, upgrade protocols, replace cryptographic libraries and migrate towards approved post-quantum algorithms.

NIST finalised its first three PQC standards in August 2024:

  • FIPS 203, ML-KEM, for key establishment

  • FIPS 204, ML-DSA, for digital signatures

  • FIPS 205, SLH-DSA, for digital signatures

NIST has encouraged system administrators to begin transitioning to these standards


Validation and compliance

Cryptographic changes may require testing, independent assessment, vendor validation and consideration of FIPS 140-3, contractual obligations and sector-specific requirements.

Integration

The acquired company’s cryptographic architecture must be aligned with the buyer’s key-management systems, HSM strategy, identity infrastructure and governance model.

Ongoing crypto-agility

The combined organisation needs a sustainable way to track cryptographic dependencies. Cryptographic bills of materials, or CBOMs, can help establish that visibility. In quantum technology environments, QBOMs may also become relevant for tracking quantum-specific components and dependencies.

The cost cannot be treated as a footnote

For a mid-market transaction, PQC-related discovery, remediation, validation and programme management can become a high-six or low-seven-figure cost once the full integration effort is understood.

For a multi-billion-pound consolidation, it is likely to be a multi-year transformation programme.

The precise figure will depend on the target’s architecture, data sensitivity, regulatory environment, hardware lifecycle, supplier dependencies and the maturity of its cryptographic inventory. The important point is that the cost should be identified before completion, not discovered after the deal has closed.

If PQC is ignored during diligence, the acquirer may be buying:

  • Undocumented cryptographic dependencies

  • Expiring certificates and long-lived keys

  • Non-agile legacy systems

  • Unfunded hardware and software replacement

  • Integration delays

  • Additional compliance and contractual exposure

That is technical debt purchased at a premium.

PQC belongs in the M&A model

Smart acquirers will treat PQC as a priced risk in the term sheet, diligence process and post-merger integration plan.

They should:

  • Include cryptographic diligence in the technology and security workstreams

  • Require disclosure of cryptographic inventories, certificate lifetimes and vendor roadmaps

  • Identify systems vulnerable to harvest-now, decrypt-later exposure

  • Model PQC migration costs alongside other integration costs

  • Assess whether suppliers can support crypto-agility

  • Establish ownership, funding and milestones before completion

The quantum market is entering its credibility era. The next signal of maturity will be boards that refuse to approve a transaction until the PQC cost is explicit, owned and funded.

SITG-Consulting is developing a sector-based model for assessing PQC costs in M&A transactions.

Watch this space.


 
 
 

Comments


bottom of page