The quantum transition is approaching fast, while the legal and regulatory landscape is only beginning to take shape. For businesses, the question is not whether quantum technologies will reshape opportunities and risks, but how soon and how prepared they will be when it happens. In this alert, our technology lawyers explain why the time to act is now, what practical steps businesses should be taking and why there is no time to wait for the regulatory framework to catch up.

The quantum transition is closer than we think

Quantum technology is no longer a distant research concept. The technology is evolving at speed, and we are nearing a “tipping point” where the fruits of research will mature into commercial applications. Organizations that understand the operational and legal implications of quantum transition now will be far better placed and secured than those that wait.

On 1 September 2026, Dittmar & Indrenius hosted an Innovation & Law breakfast event on this topic, featuring a panel discussion moderated and prepared by Partner Anna Haapanen as well as Senior Attorneys Eila El Asry and Johanna Tuohino. The panel was joined by guest speakers Jere Kiviharju (Director of Cryptographic Operations, Finnish Defence Command), Milja Kalliosaari (Government Relations Manager, IQM Quantum Computers) and Teppo Seesto (Quantum Ambassador, IBM), discussing the quantum transition from technological, security and regulatory perspectives, in addition to innovation and intellectual property perspectives.

This alert builds on the themes discussed at that event and sets out some key developments relevant to legal and compliance functions. In a nutshell, we shed light on three aspects of the quantum transition: (1) why it matters; (2) how the regulatory framework is developing; and (3) how organizations can prepare.

1) Which businesses are concerned and why it matters?

Quantum technology comprises three main strands: quantum computing, quantum communications and quantum sensing. Together, these underpin the broader shift known as the quantum transition, spanning next-generation processing power, secure communications infrastructure and highly sensitive measurement and detection capabilities.

Quantum computing is set to transform especially sectors that rely on large-scale computation or complex optimization, including financial services, healthcare, logistics, defence, and infrastructure. Quantum computing is also increasingly seen as a complement to artificial intelligence, with hybrid quantum-AI models expected to unlock capabilities that neither technology achieves alone.

Alongside the potential for competitive disruption, the most pressing quantum-related concern in the near term is the growing exposure to cybersecurity risks. Quantum computers are expected, within the coming years, to be capable of breaking the encryption standards that currently protect much of our data, including sensitive business and personal data. This means that businesses and organisations across all sectors need to critically assess their encryption standards and cybersecurity practices.

Organizations holding long-lived data (think of IP portfolios, personal health records, or financial archives) face a specific risk: encrypted data could already be harvested today, intended to be decrypted once quantum capabilities arrive. This “harvest now, decrypt later” threat is real and requires action before quantum-enabled decryption is achievable. This also means that some historic data breaches that were previously contained due to encryption of the leaked data could later give rise to fresh exposures.

2) The developing regulatory and policy framework

There is currently no national or EU-level regulation that specifically addresses quantum technologies. The European Commission’s planned EU Quantum Act is intended to boost research and innovation, scale up industrial capacity, and reinforce supply chain resilience and governance, but the concrete measures it will introduce remain to be seen. In the meantime, several existing legal instruments are already relevant in the preparation for the quantum transition:

Cybersecurity Legislation: A number of EU instruments already impose cybersecurity obligations that will be directly affected by quantum developments. The NIS2 Directive requires operators of essential services and digital providers to implement “state-of-the-art” security measures and report incidents, while the Cyber Resilience Act mandates security-by-design for products with digital elements, including preparedness for known and foreseeable threats. As quantum threats mature, both standards will increasingly demand the adoption of post-quantum cryptography (PQC), and this will be an ongoing process rather than a single remediation project. Sector-specific cybersecurity frameworks such as DORA for the financial sector layer further requirements along with these horizontal instruments.

Dual-Use Export Controls: Quantum technologies likely fall within the scope of dual-use export control regulations, meaning that the export of such technology outside the EU will in most cases require an export licence. As a result, export control rules have wide-ranging implications for quantum technology companies, affecting product development, business planning, international collaboration, and strategic decision-making.

EU and National Strategies: EU-level and national strategic initiatives are also shaping the quantum technology landscape. The need both to support the development of quantum technologies and ecosystems and to prepare for the risks they pose has been recognised at the policy level. Notable examples include the Commission’s Quantum Europe strategy, a Commission Recommendation on the transition to post-quantum cryptography, and Finland’s national quantum technology and cybersecurity strategies. Until the legislative framework catches up, much of the practical preparedness work is being led by public bodies and industry organisations.

3) How can we prepare?

The window to prepare is open, but it is narrowing. Transitioning to post-quantum cryptography is a multi-year programme requiring coordinated effort across IT, security, legal, and business functions. Legal and compliance functions are generally well positioned to actively assist with at least the following steps:

  • Mapping cryptographic exposure: Understand where your organisation relies on encryption and assess how long that data needs to remain confidential. A practical first step is to prepare a Cryptography Bill of Materials (CBOM), an inventory of cryptographic methods in use, and from there build a roadmap, prioritising the systems and data sets that carry the greatest risk.
  • Reassessing historic breach exposure: Data lost in past security incidents may currently be protected only by encryption that quantum computing could soon render ineffective. Revisit the residual exposure from any historic breaches, particularly where trade secrets, personal data, or privileged communications were involved, and factor quantum risk into cyber due diligence on M&A targets.
  • Review contracts and supply chain: Regulatory cybersecurity obligations flow through supply chains. Review your vendor contracts for security warranties, incident notification obligations, technical cybersecurity requirements (such as encryption requirements) and liability provisions that may need updating to reflect quantum risk.

The quantum transition is not just a future problem. Businesses need to begin building their quantum roadmaps now at the latest. The legal and compliance functions have a clear role to play along with the cybersecurity and other functions, and the time to step into it is now.

Contact