The Hidden PQC Cost in Quantum M&A

M&A activity is rife in quantum computing. That is fact. What fewer boards are pricing in is the cost of post-quantum cryptography inside those deals.
The quantum sector is moving from research-led development towards commercialisation, strategic investment and consolidation. IonQ, for example, reported agreements involving major acquisitions and held $3.3 billion in cash, cash equivalents and investments at the end of 2025. It also completed acquisitions including Oxford Ionics and Vector Atomic.
This activity is creating a new M&A consideration: the cryptographic debt inherited with every target.
Every acquisition inherits cryptographic debt
Quantum hardware companies, photonics businesses and quantum software platforms may rely on:
TLS 1.2, RSA 2048 and ECC P-256
Proprietary key-management systems
Vendor-specific hardware security modules
Embedded cryptographic libraries in firmware and APIs
Long-lived keys protecting intellectual property and calibration data
Cloud, software and supply-chain dependencies without clear PQC roadmaps
Some systems cannot be upgraded simply by changing a library. They may require hardware replacement, firmware changes, certificate re-issuance, new validation activity or a complete redesign of integration layers.
That is why post-quantum cryptography should be treated as an M&A diligence issue, not merely a post-close security project.
What PQC adds to the deal
In an M&A context, PQC costs appear across several workstreams:
Discovery and inventory
The acquirer needs to identify cryptographic modules, certificates, keys, protocols, algorithms and dependencies across the target’s IT, cloud, OT, laboratory and production environments.
Risk assessment
Sensitive data with long retention periods must be prioritised, particularly where it could be exposed to harvest-now, decrypt-later attacks.
Remediation
The target may need to re-issue certificates, upgrade protocols, replace cryptographic libraries and migrate towards approved post-quantum algorithms.
NIST finalised its first three PQC standards in August 2024:
FIPS 203, ML-KEM, for key establishment
FIPS 204, ML-DSA, for digital signatures
FIPS 205, SLH-DSA, for digital signatures
NIST has encouraged system administrators to begin transitioning to these standards
Validation and compliance
Cryptographic changes may require testing, independent assessment, vendor validation and consideration of FIPS 140-3, contractual obligations and sector-specific requirements.
Integration
The acquired company’s cryptographic architecture must be aligned with the buyer’s key-management systems, HSM strategy, identity infrastructure and governance model.
Ongoing crypto-agility
The combined organisation needs a sustainable way to track cryptographic dependencies. Cryptographic bills of materials, or CBOMs, can help establish that visibility. In quantum technology environments, QBOMs may also become relevant for tracking quantum-specific components and dependencies.
The cost cannot be treated as a footnote
For a mid-market transaction, PQC-related discovery, remediation, validation and programme management can become a high-six or low-seven-figure cost once the full integration effort is understood.
For a multi-billion-pound consolidation, it is likely to be a multi-year transformation programme.
The precise figure will depend on the target’s architecture, data sensitivity, regulatory environment, hardware lifecycle, supplier dependencies and the maturity of its cryptographic inventory. The important point is that the cost should be identified before completion, not discovered after the deal has closed.
If PQC is ignored during diligence, the acquirer may be buying:
Undocumented cryptographic dependencies
Expiring certificates and long-lived keys
Non-agile legacy systems
Unfunded hardware and software replacement
Integration delays
Additional compliance and contractual exposure
That is technical debt purchased at a premium.
PQC belongs in the M&A model
Smart acquirers will treat PQC as a priced risk in the term sheet, diligence process and post-merger integration plan.
They should:
Include cryptographic diligence in the technology and security workstreams
Require disclosure of cryptographic inventories, certificate lifetimes and vendor roadmaps
Identify systems vulnerable to harvest-now, decrypt-later exposure
Model PQC migration costs alongside other integration costs
Assess whether suppliers can support crypto-agility
Establish ownership, funding and milestones before completion
The quantum market is entering its credibility era. The next signal of maturity will be boards that refuse to approve a transaction until the PQC cost is explicit, owned and funded.
SITG-Consulting is developing a sector-based model for assessing PQC costs in M&A transactions.
Watch this space.




Comments