Post Quantum Cryptography for Insurance: NAIC Data Security and 30-Year Claim Windows

Why Insurance Has a PQC Problem Before Most Industries
Insurance claims windows routinely exceed 30 years. Workers' compensation, long-term disability, life insurance, annuities, and reinsurance contracts create multi-decade obligations. The underlying customer data (health records, financial history, policy terms, beneficiary information) must remain confidential throughout. Combined with Harvest Now Decrypt Later, insurers are already inside their PQC migration window.
NAIC Insurance Data Security Model Law #668
The National Association of Insurance Commissioners adopted Model Law #668 in 2017. It requires:
- An information security program proportionate to the insurer's size and complexity.
- A written risk assessment.
- 72-hour breach notification to the state commissioner.
- Board oversight of the program.
As of August 2025, 21 states have adopted the model law. It does not yet mandate Post Quantum Cryptography specifically, but regulators interpret "appropriate technical measures" to include addressing known future threats such as CRQC.
Applying Mosca's Theorem to Insurance
- Data confidentiality lifetime (X): 30-50 years for life, workers' comp, annuities.
- Migration timeline (Y): 3-5 years for most insurers.
- CRQC arrival (Z): 10-20 years per Global Risk Institute 2025.
X + Y consistently exceeds Z. Insurance is already past the Mosca threshold.
What Insurers Should Do
- Inventory classical cryptography (RSA-based key management, ECDSA-signed policies, TLS versions).
- Deploy hybrid ML-KEM for new systems.
- Encrypt long-term archives with ML-KEM hybrid before CRQC arrives.
- Update vendor contracts requiring PQC roadmaps from third-party administrators, reinsurers, and data processors.
Frequently Asked Questions
What is NAIC Model Law #668?
NAIC Insurance Data Security Model Law adopted 2017. Requires information security program, risk assessment, 72-hour breach notification. 21 states adopted as of August 2025.
Does NAIC mandate PQC?
Not explicitly as of April 2026. Regulators interpret 'appropriate technical measures' to include addressing CRQC threats. Expect explicit guidance by 2027-2028.
Why insurance before other industries?
Insurance claims windows (30-50 years for life, workers' comp, annuities) exceed expected CRQC horizon. X+Y>Z already holds under Mosca's theorem.
What PQC algorithms should insurers deploy?
ML-KEM-768 hybrid with X25519 for key exchange; ML-DSA-65 for signatures; AES-256-GCM for bulk. Per NIST FIPS 203/204/205.
Sources
Related Articles
Protect Your Data Before Q-Day Arrives
QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.
Try QNSQYOriginally published at quantumsequrity.com/blog/pqc-insurance-long-tail-claims.