Explainer
Harvest now, decrypt later: why the quantum threat is already here
"Harvest now, decrypt later" means an adversary records encrypted data today and keeps it until a quantum computer can break the encryption.[1] NIST calls it one of the main reasons the move to post-quantum cryptography is urgent, and it is cited in the June 2026 US executive order on post-quantum migration.[2][3]
The idea
Imagine someone tapes every phone call you make, even though they cannot understand the language. They do it because they expect to learn it later. That is “harvest now, decrypt later”. An attacker who cannot break encryption today can still copy the encrypted data and store it, hoping a future quantum computer will unlock it.[1]
This is why the quantum threat matters before quantum computers exist. Some secrets stay valuable for many years, and once they have been copied, it is too late to protect them.[1][2]
The threat model has three parts: an adversary able to intercept and store ciphertext at scale, data whose confidentiality must outlast the arrival of a cryptographically relevant quantum computer, and key establishment that relies on RSA or (EC)DH. Once Shor’s algorithm can recover the session key from a recorded handshake, all the traffic protected by that key can be read.[4] NIST’s draft transition plan names this threat model as a main reason for urgency.[2]
What is at risk, and what is not
The data most at risk is data that stays sensitive for a long time. NIST gives government secrets and medical records as examples.[5] Signatures, the digital equivalent of a handwritten signature, are different. A signature only needs to be unbreakable at the moment someone checks it. Recording signatures today gives an attacker nothing to decrypt later.[6]
The asymmetry shapes migration order. Confidentiality needs post-quantum key establishment, typically ml-kem in a hybrid construction, deployed well before a CRQC exists. Authentication needs post-quantum signatures before a CRQC exists, but not years ahead.[6] Many early deployments therefore protected key exchange first, as in hybrid-post-quantum-tls and the signal-post-quantum-protocol.[7][8] In 2026, Google and Cloudflare shifted priority toward authentication, citing new attack estimates.[9][10]
Why it sets the deadlines
A simple way to see the urgency: if data must stay secret for ten years and migration takes ten years, migration has to begin a decade before a quantum computer appears. Historically, getting a new algorithm from standard to full deployment has taken 10 to 20 years.[11] Expert estimates for a capable quantum computer range from a few years to a few decades.[12]
Policymakers use this reasoning directly. The June 2026 US executive order on post-quantum migration cites the risk of adversaries collecting US information now and decrypting it later.[3] The G7 cybersecurity working group’s September 2026 call to action urges organizations to start their transition now.[13]
What defends against it
The main defence is to switch key establishment to post-quantum algorithms, usually combined with a classical algorithm for safety.[14] On the web this is already widespread. Cloudflare said in April 2026 that over 65% of human traffic to its network was post-quantum encrypted, and that it had enabled post-quantum encryption for all websites and APIs in 2022.[15][16] Messaging apps such as Signal and iMessage have added post-quantum protection too.[17][18] None of this protects data that was recorded before the switch. For the debate about how fast to move, see migration timeline debate.
Questions readers ask
What does "harvest now, decrypt later" mean?
An attacker captures and stores encrypted data now, hoping a future quantum computer will be able to decrypt it.[1]
Does the threat apply to digital signatures too?
Not in the same way. NIST notes that authentication stays secure as long as the algorithms and keys are secure at the moment authentication happens, so signatures are only at risk once a capable quantum computer exists.[6]
Which data is most at risk?
Data that keeps its value for many years. NIST gives government secrets and medical records as examples.[5]
How is the internet defending against it?
By switching key exchange to hybrid post-quantum algorithms. Cloudflare said in April 2026 that over 65% of human traffic to its network was already post-quantum encrypted.[15]
Sources
Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.
- [1]
In a "harvest now, decrypt later" attack, an adversary captures encrypted data today and stores it, hoping a future quantum computer will break the encryption. confirmedas of 2026-10-10
- What Is Post-Quantum Cryptography? · NIST (retrieved 2026-10-10)
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- [2]
NIST describes the harvest-now-decrypt-later threat as one of the main reasons the transition to post-quantum cryptography is urgent, because sensitive data often keeps its value for many years. confirmedas of 2026-10-10
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- [3]
Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks", published in the Federal Register on 25 June 2026, makes it US policy to move federal systems to NIST's post-quantum standards and cites the risk of adversaries collecting data now to decrypt later. confirmedas of 2026-06-25
- Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks (Federal Register 2026-12909) · Federal Register (Executive Office of the President) · 2026-06-25 (retrieved 2026-10-10)
- The White House's post-quantum executive order is an important milestone. It's time to get to work · Cloudflare · 2026-06-23 (retrieved 2026-10-10)
- [4]
A large-scale quantum computer would make insecure the public-key systems based on integer factorization, such as RSA, and those based on the discrete logarithm problem, which includes elliptic-curve cryptography. confirmedas of 2026-10-10
- NIST IR 8105: Report on Post-Quantum Cryptography · NIST · 2016-04-01 (retrieved 2026-10-10)
- NIST IR 8105: Report on Post-Quantum Cryptography · NIST · 2016-04-01 (retrieved 2026-10-10)
- [5]
NIST cites government secrets and medical records as examples of data with long-term sensitivity that make immediate action necessary. confirmedas of 2026-10-10
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- [6]
Unlike encryption, authentication is not exposed to harvest-now-decrypt-later attacks; it stays secure as long as the algorithms and keys are secure at the moment authentication is performed. confirmedas of 2026-10-10
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- [7]
Google announced that Chrome 131 would switch from Kyber to ML-KEM, changing the TLS codepoint for hybrid post-quantum key exchange from 0x6399 (Kyber768+X25519) to 0x11EC (ML-KEM768+X25519), because minor changes in the final ML-KEM standard made it incompatible with the Kyber version deployed earlier. confirmedas of 2024-09-13
- A new path for Kyber on the web · Google Security Blog · 2024-09-13 (retrieved 2026-10-10)
- A new path for Kyber on the web · Google Security Blog · 2024-09-13 (retrieved 2026-10-10)
- [8]
In September 2023 Signal introduced PQXDH, which derives a shared secret from both X25519 and CRYSTALS-Kyber so that an attacker must break both. confirmedas of 2023-09-19
- Quantum Resistance and the Signal Protocol · Signal · 2023-09-19 (retrieved 2026-10-10)
- [9]
Google said it had adjusted its threat model to prioritize post-quantum migration of authentication services and digital signatures, and recommended other engineering teams do the same. confirmedas of 2026-03-25
- Quantum frontiers may be closer than they appear · Google · 2026-03-25 (retrieved 2026-10-10)
- [10]
On 7 April 2026 Cloudflare said it was targeting full post-quantum security, including authentication, across its entire product suite by 2029. confirmedas of 2026-04-07
- Cloudflare targets 2029 for full post-quantum security · Cloudflare · 2026-04-07 (retrieved 2026-10-10)
- [11]
NIST says it has historically taken 10 to 20 years from the standardization of a new algorithm until it is fully integrated into information systems. confirmedas of 2026-10-10
- What Is Post-Quantum Cryptography? · NIST (retrieved 2026-10-10)
- [12]
NIST says no one knows when a quantum computer able to threaten current encryption will appear, with expert estimates ranging from a few years to a few decades. confirmedas of 2026-10-10
- What Is Post-Quantum Cryptography? · NIST (retrieved 2026-10-10)
- [13]
On 3 September 2026 CISA and the G7 Cyber Security Working Group published "Preparing for the Post-Quantum Era - A Call to Action", urging organizations and governments to begin the transition to PQC. confirmedas of 2026-09-03
- Preparing for the Post-Quantum Era: A Call to Action · CISA · 2026-09-03 (retrieved 2026-10-10)
- [14]
Hybrid schemes combine a quantum-resistant and a classical algorithm and are typically designed to stay secure if at least one of the two components is secure. confirmedas of 2024-11-12
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- [15]
As of April 2026, Cloudflare said over 65% of human traffic to its network was post-quantum encrypted. confirmedas of 2026-04-07
- Cloudflare targets 2029 for full post-quantum security · Cloudflare · 2026-04-07 (retrieved 2026-10-10)
- [16]
Cloudflare says it began preparing its post-quantum migration in 2019 and enabled post-quantum encryption for all websites and APIs in 2022. confirmedas of 2026-04-07
- Cloudflare targets 2029 for full post-quantum security · Cloudflare · 2026-04-07 (retrieved 2026-10-10)
- [17]
On 2 October 2025 Signal announced the Sparse Post Quantum Ratchet (SPQR), which runs alongside its Double Ratchet and mixes both keys in a "Triple Ratchet", rolling out without any user action. confirmedas of 2025-10-02
- Signal Protocol and Post-Quantum Ratchets · Signal · 2025-10-02 (retrieved 2026-10-10)
- Signal Protocol and Post-Quantum Ratchets · Signal · 2025-10-02 (retrieved 2026-10-10)
- [18]
In February 2024 Apple announced PQ3 for iMessage, which uses post-quantum cryptography for both initial key establishment and ongoing message exchange, rolling out with iOS 17.4. confirmedas of 2024-02-21
- iMessage with PQ3: The new state of the art in quantum-secure messaging at scale · Apple Security Research · 2024-02-21 (retrieved 2026-10-10)
- iMessage with PQ3: The new state of the art in quantum-secure messaging at scale · Apple Security Research · 2024-02-21 (retrieved 2026-10-10)
Revision history (1)
- Page created.
Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.
Cite this page
"Harvest now, decrypt later: why the quantum threat is already here." ContentLora, updated Oct 10, 2026. https://contentlora.com/explain/harvest-now-decrypt-later
Spotted an error? Suggest a correction or emailcorrections@contentlora.com.
Keep exploring
- ExplainerPost-quantum cryptography and security in 2026: a crash courseA sourced crash course on post-quantum cryptography: the quantum threat, NIST's new standards, deployment, migration deadlines and AI in security.
- ExplainerHow quantum computers break encryptionWhy Shor's algorithm threatens RSA and elliptic-curve cryptography, why AES survives, and how fast attack estimates fell in 2025-2026.
- AnalysisHow fast must we move to post-quantum cryptography?Q-Day timing, 2029 corporate targets versus 2030-2035 government deadlines, and whether to rush new algorithms: the post-quantum migration debate.
- WikiCrypto-agilityCrypto-agility is the ability to replace cryptographic algorithms without rebuilding systems. Why the post-quantum transition made it a priority.
- WikiDARPA AI Cyber Challenge (AIxCC)DARPA's two-year competition for AI systems that find and patch software vulnerabilities, won by Team Atlanta in August 2025. Results and significance.
- WikiNIST Post-Quantum Cryptography projectNIST's open, multi-year competition that produced the ML-KEM, ML-DSA and SLH-DSA standards, plus HQC, FN-DSA and the work still in progress.