📚 Educational Edition

⚖️ Mosca Hand Threshold Evaluator

The Learned Hand Formula in threshold form, with the probability variable read as the mass of the vulnerability window under the most recent Quantum Threat Timeline curve

R  <  P(W)
R = B/L (risk ratio)  |  W = [today, start+X+Y] — the range of Z that harms you
Evaluated as of: | Updates at ProteQC.com
Foundation
From Foreseeability to Duty
Before the arithmetic of breach: why the law asks anything of you at all.
1994 · Foreseeable
harm perceivable
Shor's proof makes the harm perceivable in principle — the article's epistemic boundary. Foreseeability has never required certainty: a risk is foreseeable when a reasonable person would recognize it and take it into account. Restatement (Third) of Torts § 3 (2010). Perceivable — but in 1994, recognized almost nowhere outside cryptography.
The record accrues · Chargeable
notice accumulates
Standards, statutes, surveys, and deployments pile up — the notice record charted above the awareness control in Step 2. Each institutional action tightens the foreseeability determination (the article's ratchet), until the question a court asks is no longer “could you have known?” but “how could you not have known?”
Your anchor · Duty
the clock starts
At some signal on that record, reasonable ignorance runs out for an organization of your kind. Duty crystallizes; from that date D accrues — and breach becomes measurable.
Foreseeability is central to establishing duty; constructive notice is how general foreseeability becomes chargeable to a particular defendant; duty is where the clock starts. Whether the law asks anything of you is answered on this chain — how much it asks is arithmetic, and the next panel does the arithmetic.
Foundation
From Carroll Towing to the Threshold Form
Two steps of algebra, one substitution — nothing added, nothing smuggled in.
1947 · The Hand Formula
B < P × L
Negligence when the burden of precaution is less than the probability of harm times the magnitude of loss. United States v. Carroll Towing Co., 159 F.2d 169 (2d Cir. 1947).
Divide by L · Threshold Form
B / L < P
The same inequality, rearranged. Now each side belongs to the party who knows it: your costs and your exposure on the left; the world's probability on the right.
Substitute · The Mosca Hand Threshold
R < P(W)
Name the ratio R = B/L and make P organization-specific: the mass of the expert-survey curve falling inside your vulnerability window W = [today, start + X + Y].
The rearrangement changes no law and no math — it changes who must prove what. R is endogenous: yours to compute, document, and defend. P(W) is exogenous: published, annually re-surveyed, and rising. When the second number overtakes the first, the Hand Formula's condition for negligence is satisfied on the defendant's own figures.
Step 1
Your Risk Ratio — R = B/L
Both variables are endogenous: your own migration cost and your own loss exposure. R is the fraction of your exposed loss it would cost to prevent that loss. Start from a sector archetype or set your own:
B = Burden of PQC Migration
Total cost of migration: cryptographic inventory, technology, labor, consulting, testing, business disruption.
L = Magnitude of Loss
Loss if harvested data is eventually decrypted: breach response, regulatory penalties, litigation, reputational damage.
R = 2.8%
Step 2
Your Vulnerability Window — W
The range of CRQC-arrival dates that harm you. Left edge: today. Right edge: migration start + X + Y, when the last datum harvested under breakable encryption expires. Until migration begins, the right edge slides forward daily.
X = Data Shelf Life
How long your data must remain confidential (retention obligations, trade secrets, personal data sensitivity).
1 yr25 yrs
Y = Migration Time
Time to complete PQC migration once begun, including inventory, remediation, and validation.
0.5 yr10 yrs
D = Cryptographic Procrastination
Elapsed time between awareness and commencement of migration. Slide along the public record — the thumb snaps to each notice event — or anchor precisely with the list and date field below. The later the claimed date, the more of this record precedes it:
2015today
🔖 Constructive-notice timeline — the public record, with citations

Foreseeability is central to establishing duty — and constructive notice is how foreseeability becomes chargeable to a particular organization. Each entry below is a dated public signal a fact-finder could point to; use as anchor sets your awareness date to it. Which signal starts your clock is a legal argument, not a computation — the record is what accumulates either way.

First minuted board or executive engagement with quantum risk — board discussion recorded, cryptographic inventory commissioned, executive lead designated. If none is documented, leave unset: the tool assumes none.
Commencement freezes the window's right edge; W stops sliding and starts shrinking. If a governance date applies, set it above first — governance precedes commencement.
D = 0.00 years
Accruing since awareness date — and counting.
Step 3
P(W) and the Exposure Area
The Quantum Threat Timeline Report (QTTR) band with your window and risk ratio overlaid. The shaded exposure area is where expert consensus exceeds your ratio inside your window — darker where both interpretations agree, lighter where only the optimistic read does.
Cumulative probability of a CRQC (RSA-2048 in <24h) by calendar date, monotone-interpolated between the report's five survey anchors. Each surveyed expert answers in qualitative likelihood bins; the optimistic curve converts every answer to the top of its bin's cumulative probability range, the pessimistic curve to the bottom — the band between them is the survey's own interpretation range, not disagreement among experts. The time axis is fixed at 2015–2045 across all reports, so each survey's curve plots at its true calendar position; survey years beyond 2045 lie off-frame, and values beyond the 30-year survey horizon are clamped. The cumulative public notice record is charted in Step 2, directly above the awareness slider it feeds.
Pc(W) — capability mass
R = B/L threshold
Your risk ratio
Procrastination premium
Mass added since the window began sliding at awareness
Crossing date t*
🎯 Advanced: Target Profile — the harvest-and-prioritization factor Ph×Pd

The survey band above is the capability probability: the chance a CRQC exists inside your window. The Hand probability is the chance of harm to you, which the accompanying article's §III.E decomposes as P = Pc × Ph × Pd — capability, harvest, decryption prioritization. This panel supplies the latter two as a single factor Ph×Pd; the survey band above is Pc(W), and the headline threshold R < P(W) reads the composed Hand probability, P(W) = Pc(W) × Ph×Pd. The two are collapsed deliberately: harvest and prioritization are not independent — no adversary warehouses ciphertext it never expects to read, so data worth harvesting is data worth decrypting. Ph×Pd = 1.00 is the documented upper bound and the default; the anchor positions below are illustrative pedagogy, not threat-intelligence estimates.

Ph×Pd = Harvest-and-Prioritization Factor Ph×Pd = 1.00 — Upper bound
0.101.00

This factor cuts both ways. Defense counsel will argue your Ph×Pd is low; plaintiffs will answer that harvesting is cheap and indiscriminate, that no adversary warehouses ciphertext it never expects to read, and that prioritization climbs over your data's whole confidentiality horizon as decryption capability spreads and cheapens. Lowering Ph×Pd is an affirmative judgment — document it. (Scenario links carry the factor but not your rationale; the documentation block is the record.)

Fast and slow variables. Pc is the fast variable — resurveyed annually, it swings with each QTTR edition. Ph×Pd is the slow variable — a target-profile judgment, stable quarter to quarter — but it ratchets upward: harvest is an absorbing state (collected ciphertext never becomes uncollected; migration protects future traffic, not the warehouse), decryption capacity compounds (Gidney 2019–2025: a ~20× resource reduction), reaching progressively less attractive targets, and data accumulation grows the target itself. Re-estimate annually on the QTTR cadence; downward revisions demand extraordinary justification — a documented 0.60 that becomes 0.40 two years later reads as motivated reasoning. The documentation block timestamps your estimate against the survey edition in force.

Timestamped summary of inputs, sources, and result — governance in action. Copy into board minutes, a risk register entry, or counsel's file. The date matters: contemporaneous documentation is the record that the analysis was run.
Enterprise Feature

Live legal & regulatory monitoring — the Enterprise edition of this evaluator links each input to the current state of applicable law for your jurisdiction and sector: NYDFS Part 500, HIPAA Security Rule, GLBA Safeguards, SEC cyber disclosure, DORA, and state UDAP enforcement — plus new case law bearing on unmanifested-harm standing and the evolving standard of care. Your X (retention obligations) and L (penalty exposure) update as the law does — and calibrated target-profile advisory replaces the educational edition's illustrative T anchors with sector- and adversary-specific analysis, paired with per-organization feasibility dating in place of the single global standards-finalization boundary.

Inquire: advisory@proteqc.com · ProteQC.com

Methodology & data provenance

Anchors. Averaged cumulative probabilities computed from the raw expert response counts published in each report's Appendix A.4, using the report's own optimistic/pessimistic bin assignments. QTTR 2024 (n=32, published Dec 6, 2024); the March 2026 QTTR (n=26, published Mar 9, 2026), referred to in the accompanying article as the March 2026 Quantum Threat Timeline Report. Cross-checked against values stated in each report's body (e.g., Mar 2026: ~15% optimistic at 5 years; 28–49% at 10 years; 51–70% at 15 years). Read in sequence, the selectable curves trace the foreseeability ratchet the article describes: each survey cycle has moved the consensus probability upward, tightening the duty inside the window since long before most organizations knew the window existed.

Interpolation. Monotone cubic (Fritsch–Carlson) through anchors at 0, 5, 10, 15, 20, 30 years from report publication, with P(0) = 0. Values beyond 30 years are clamped at the 30-year anchor and flagged.

The window. W = [today, start + X + Y]. Left edge: a CRQC arriving today decrypts harvested data still within shelf life — and the left edge stays at today even after migration commences or completes, because migration stops future harvesting while the already-harvested archive remains decryptable until it ages out; arrival dates already in the past are spent risk, not exposure. Right edge: the last datum harvested before migration completes remains sensitive for X further years. Pc(W) = Pc(right) − Pc(left) — the unconditional capability mass of Z inside W; the composed Hand probability is P(W) = Pc(W) × Ph×Pd. (A conditional variant renormalizing on no-CRQC-today, Pc(W)/(1 − Pc(today)), is more aggressive; the unconditional form is used here as the conservative default.) In the accompanying article's terms, W is the organization's own remaining slice of the Shor–Q-Day window: the global interval, open since Shor's 1994 proof and closing at Q-Day, within which harm is foreseeable but not yet manifest.

Sliding vs. frozen. Until migration commences, the right edge is today + X + Y and W slides up the rising curve daily. Commencement freezes the right edge at start + X + Y; W then shrinks as the left edge (today) advances. The procrastination premium is P(W today) − P(W at awareness), both read on the current report's curve.

Awareness anchors & the notice gradient. The awareness date sets where D begins. The selector offers dated public signals — statutes and regulations in force, standards publications, intergovernmental statements, threat surveys, and industry deployments — each carried with its citation in the tool's data files. Which signal starts a particular organization's clock is a legal argument, not a computation: the tool takes the date you select (or your own documented date) and reports the consequences. The documentation block includes the full ladder — D measured from every listed signal — because the reasonableness of a claimed awareness date is naturally tested against the public record that preceded it. Step 2's notice strip — drawn directly above the awareness slider, sharing its 2015–today track, so the thumb climbs the record it selects from — plots that record as a cumulative step line: counts, not weights — each signal adds one step regardless of tier, because assigning relative evidentiary weight to a regulation versus a product deployment is an argument for counsel (and the accompanying article), not a datum this tool asserts. The strip notes the epistemic tier separately, in a caption on its baseline — Shor's algorithm (1994) and the founding of post-quantum cryptography as a field (2006): the issue's coming-into-existence, which per the accompanying article's two-boundary framework precedes any duty and is deliberately not selectable as an anchor. Existence made the harm foreseeable; it did not start anyone's clock. One boundary within the record carries structural weight: NIST announced the finalized FIPS 203, 204, and 205 on August 13, 2024, and migration to the finalized standards could not have commenced before they existed (announced August 13; published in the Federal Register August 14 — 89 Fed. Reg. 66,052 (Aug. 14, 2024)). D measured from an earlier anchor therefore decomposes into two clocks: notice delay — the aggregate name for the anchor-to-finalization stretch, time on notice while the finalized standards did not yet exist — and feasibility delay — finalization to commencement, time the standards existed and migration to them had not begun. When a governance date is documented, the notice-delay stretch resolves further into governance delay (anchor to first minuted engagement — notice accruing with no recorded response) and preparation runway (governance to finalization — documented diligence, excluded from D by definition: a number labeled procrastination must not include diligence, or it impeaches itself). Notice delay and governance delay are never interchangeable — the first is the undifferentiated aggregate, the second the culpable component a governance record isolates. Without a documented governance date the tool credits no runway: undocumented governance earns zero credit, the same conservative-default pattern as the harvest-and-prioritization factor. The strip marks the boundary with a dashed rule, the D counter reports the split, and the documentation block flags pre-standards anchors. See Post-Quantum Negligence §III.A (two-clock decomposition of the procrastination variable). The boundary is an argument marker, not an absolution: cryptographic inventory, crypto-agility, and vendor engagement were feasible throughout the notice period, and pre-standard deployments on draft-stable algorithms — Chrome's X25519Kyber768 hybrid (Chromium Blog, Aug. 10, 2023), Signal's PQXDH (Sept. 19, 2023), and Apple's iMessage PQ3 (Feb. 21, 2024, expressly framed against harvest-now-decrypt-later) — show migration-adjacent action was possible before finalization; evidence each side will read its own way. Feasibility was also organization-relative: this boundary marks the earliest theoretical date — the standards' existence — while organizations dependent on vendor libraries, HSM firmware, or certified implementations faced feasibility dates trailing into 2025–2026 (HQC selection and vendor availability; FN-DSA still pending). The educational edition keeps the single global boundary as the conservative, simple reading; per-organization feasibility dating is enterprise advisory territory. The full record, with citations and per-event anchor selection, is in the constructive-notice timeline beneath the D control; the duty-side logic — foreseeability → notice → duty → breach — is laid out in the “From Foreseeability to Duty” panel at the top of the page.

Crossing date t*. The first calendar date at which the sliding window's mass reaches R, found by forward scan with bisection refinement on each interpretation curve. If the mass already exceeded R at the report's publication, the crossing is reported as "at or before publication" rather than extrapolated to dates predating the survey.

Theoretical lineage. The window construction restates Mosca's Theorem — exposure when x + y > z — in probabilistic form. Michele Mosca, Cybersecurity in an Era with Quantum Computers: Will We Be Ready?, 16 IEEE Security & Privacy 38 (2018). The procrastination variable D adopts the augmentation introduced by Jaime Gómez García, Chair of the Europol Quantum Safe Financial Forum, within the FS-ISAC PQC Working Group's collaborative work — the Mosca-Gómez formulation, x + y + D > z (D is the formulation's delay term, elsewhere rendered pdelay). Under the article's own definition — delay from when migration could have begun — the formulation's delay term corresponds to Df, the feasibility delay; governance delay Dg enters the inequality only through spillover (preparation unfinished at finalization lengthens Df) and enters the law through the fiduciary lens (companion article in progress). See FS-ISAC PQC Working Grp., The Timeline for Post-Quantum Cryptographic Migration (Nov. 2025); Jaime Gómez García, Perspectives on the Transition to PQC in the Financial Sector, PKI Consortium PQC Conference (Jan. 16, 2025).

Benchmark sources for B and L presets. Burden: OMB/ONCD, Report on Post-Quantum Cryptography (July 2024) (~$7.1B for federal civilian systems, 2025–2035); sector program models of $50–300M+ for a single large operator. Loss: IBM, Cost of a Data Breach Report 2025 (U.S. average $10.22M; healthcare and financial costliest); Anthem 2015 breach aggregate ≈$171M ($115M class settlement + $16M OCR + $39.5M multistate AGs); UnitedHealth/Change Healthcare attack cost estimate $3.09B; Citi Institute (Feb. 2026) (systemic damage of a quantum-enabled attack on a major U.S. bank: $2.0–3.3T). Preset values are deliberately conservative within these ranges and are illustrative, not firm-specific.

Threshold logic. Liability exposure indicated when R < P(W), where R = B/L — algebraically the Learned Hand condition B < P×L for L > 0 (United States v. Carroll Towing Co., 159 F.2d 169 (2d Cir. 1947)), with P made organization-specific as the composed window probability Pc(W) × Ph×Pd.

Severity taper (future refinement). Arrival early in W (before migration completes) is catastrophic; arrival late in W harms only not-yet-expired harvested data, decaying to zero at the right edge. This refines L, not P, and is reserved for the enterprise analysis.

⚠️ Limitations — what this tool does not assess

This is an educational framework for one negligence-analysis lens. It does not model: regulatory compliance mandates (NIST, NSA CNSA 2.0, sector-specific rules); industry standards and peer behavior; insurance coverage and requirements; vendor and ecosystem readiness; technical feasibility of migration for specific systems; data classification nuances (different data types carry different X); operational impacts during migration; or the severity taper within the window (early CRQC arrival is catastrophic, late arrival harms only unexpired harvested data — an expected-loss refinement reserved for enterprise analysis). Relatedly, a scalar Ph×Pd applied across the whole window underweights late-window arrivals: Pd ramps up across W just as the severity taper ramps L down across it — both within-window gradients are scalar-simplified here, conservative in opposite directions, and both are enterprise refinements.

Recommended next steps: consult qualified legal counsel on your risk profile; engage cybersecurity experts on feasibility; review applicable regulatory requirements; conduct data classification to identify HNDL-sensitive holdings; and document your decision-making process regardless of the timeline you choose — the documentation itself is the governance.

Resources: NIST Post-Quantum Cryptography Project · NSA CNSA 2.0 Advisory · GRI / evolutionQ Quantum Threat Timeline Reports · Mosca, Cybersecurity in an Era with Quantum Computers, 16 IEEE Sec. & Priv. 38 (2018) · United States v. Carroll Towing Co., 159 F.2d 169 (2d Cir. 1947) · FS-ISAC PQC Working Group publications.

Was this tool helpful for your risk assessment?