Insurers have an unusual relationship with time. A life policy written this year may pay out in the 2070s. Claims files, medical questionnaires and underwriting notes sit in archives for decades. That long horizon is exactly what makes quantum computing in insurance a present-day concern, even though the machines that matter are years away.
The other thing insurers do is carry everyone else’s risk. If a quantum computer ever breaks the public-key cryptography used across the economy, cyber books will feel it at the same moment as the insureds do. The security side and the modeling side run on different clocks:
| Now (2026 to 2030) | Later (once error-corrected machines exist) | |
|---|---|---|
| Policy and claims data | Inventory the cryptography, start with life and health archives | Legacy RSA and ECC disallowed under NIST’s draft plan by 2035 |
| Cyber underwriting | Add post-quantum questions to applications | Possible correlated losses if migrations lag |
| Pricing and capital models | Learn, keep models modular, test small optimization problems | Possible faster Monte Carlo through amplitude estimation |
Why is insurance data exposed to quantum attacks earlier than most?
Insurance data is exposed early because insurers keep sensitive records for decades, and most of it is protected by RSA or elliptic-curve cryptography that a large quantum computer could break. Encrypted policy, claims and medical data copied today can be stored and read later, while it is still sensitive.
Most of an insurer’s sensitive data is protected in transit and at rest by schemes that rest on RSA or elliptic curves: TLS to brokers and portals, VPNs to third-party administrators, signed documents, encrypted backups. A large enough quantum computer running Shor’s algorithm would break those schemes. Anyone who copies encrypted traffic today can store it and decrypt it once that machine exists.
For a bank, a stolen transaction record loses value within a few years. For a life or health insurer, a policyholder’s medical history is just as sensitive in 2040 as it is now. That is why insurers belong near the top of the post-quantum queue, next to health providers.
The standards are ready. NIST published ML-KEM, ML-DSA and SLH-DSA (FIPS 203, 204 and 205) on August 13, 2024, and its draft NIST IR 8547 proposes disallowing RSA and elliptic-curve cryptography at common strengths by 2035. The European Union’s coordinated roadmap from June 2025 asks member states to start the transition by the end of 2026 and to move critical infrastructure no later than the end of 2030. The work that takes time is finding where the old algorithms live in policy administration systems, claims platforms and the dozens of vendors behind them. Our post-quantum cryptography migration service is built around that inventory.
How should cyber underwriters treat quantum risk?
Cyber underwriters should treat quantum risk as a possible correlated loss: one shared weakness in public-key cryptography that could hit many insureds at once. Pricing it precisely is not possible yet, but asking applicants about their post-quantum plans is, and the answers also say a lot about security maturity today.
Cyber underwriters already worry about events that hit many policyholders through one shared weakness. A cryptographically relevant quantum computer would be that kind of event, and so would a poorly handled migration that leaves old algorithms running in widely used software.
You do not need to price this risk precisely yet. You can start asking about it. A few questions fit naturally into existing cyber questionnaires:
- Does the applicant have an inventory of where it uses public-key cryptography?
- Has it asked its main software and cloud vendors for their post-quantum plans?
- Does it know which of its data must stay confidential for more than ten years?
The answers tell you something about security maturity today, not only about quantum risk.
Supervisors are starting to name the issue. The G7 Cyber Expert Group issued a statement on quantum risk in September 2024 and, in January 2026, a non-binding roadmap for moving the financial sector to post-quantum cryptography. In Latin America, insurance supervisors such as Colombia’s Superintendencia Financiera, Mexico’s CNSF and Brazil’s SUSEP oversee cybersecurity through their general risk rules; we have not seen a quantum-specific requirement from them yet.
What can quantum computing do for insurance pricing today?
Quantum computing does very little for insurance pricing today. The algorithm actuaries hear about, quantum amplitude estimation, could speed up Monte Carlo simulation, but only on large error-corrected machines that do not exist yet. Current work is small research experiments, useful for learning and not for pricing a book.
Actuarial work is full of simulation: stochastic reserving, catastrophe models, economic scenario generators, capital calculations under Solvency II or local equivalents. Quantum amplitude estimation is the algorithm people point to here. In theory it needs quadratically fewer samples than classical Monte Carlo to reach the same accuracy.
The catch is the hardware. Amplitude estimation at useful scale needs deep circuits on error-corrected machines. The closest public estimate comes from finance: a 2021 study by Goldman Sachs and IBM researchers (Chakrabarti and colleagues, in the journal Quantum) found that a quantum advantage in pricing certain derivatives would need about 8,000 logical qubits and a T-depth of 54 million. Today’s largest chips have physical qubits in the hundreds and only small numbers of logical qubits in experiments.
Where does that leave an actuarial team? With two reasonable moves. First, keep an eye on optimization problems (reinsurance structure, asset allocation, claims routing) where hybrid solvers are improving and a small experiment costs little. Second, make sure your models are written in a way that could swap in a different sampling engine later. Neither requires buying quantum hardware or cloud time this year.
A realistic plan for an insurer in 2026
Start with the data that has the longest life. Life, health and disability portfolios come first, then commercial lines with sensitive documents. Map the cryptography that protects those records and the vendors that hold copies.
Add post-quantum clauses to new contracts with policy administration, claims and document management vendors. Ask for dates, not slogans.
Put two or three post-quantum questions into your cyber underwriting form, and track the answers across your book.
Train a small group: two or three security engineers who will run the migration, and a couple of actuaries who understand enough about quantum algorithms to judge a vendor pitch. Our training for teams is designed for that mix.
If a problem in pricing or reinsurance looks promising, test it against the best classical method you have before spending on quantum cloud time. Quantum use case discovery does exactly that screening.
Where AndesQubit fits
For most insurers the right first step is a quantum readiness assessment: a few weeks to rank cryptographic exposure by data lifetime and to separate the one or two modeling problems worth watching from the rest. We work in Spanish and English and are opening engagements in stages through our early-access list. If you are unsure whether you need any of this yet, write to us and we will tell you.
Sources
- NIST CSRC, Post-quantum cryptography FIPS approved (FIPS 203, 204 and 205), August 13, 2024
- NIST IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards, November 2024
- European Commission, EU reinforces its cybersecurity with post-quantum cryptography, June 23, 2025
- G7 Cyber Expert Group, Statement on advancing a coordinated roadmap for the transition to post-quantum cryptography in the financial sector, January 2026
- Chakrabarti et al., A threshold for quantum advantage in derivative pricing, Quantum 5, 463 (2021)