Harvest Now, Decrypt Later is a cyberattack strategy where adversaries collect data today and store it for future decryption by cryptographically relevant quantum computers. Also called store now, decrypt later, the HNDL threat exploits a simple reality: data that is safe today will not remain safe once quantum computing advances far enough to break the cryptographic algorithms protecting it.
This guide explains how Harvest Now, Decrypt Later works, which industries face the greatest risk, and how post-quantum cryptography provides the path forward for organizations protecting long-lived sensitive data.
How Harvest Now, Decrypt Later Attacks Work
HNDL attacks follow a three-phase pattern. First, adversaries intercept encrypted data in transit across networks, capturing encrypted network traffic, VPN sessions, and communications between systems. The harvesting phase is passive and often undetectable because the attacker does not need to break encryption at this stage.
Second, attackers store the harvested data indefinitely. Storage costs are low, making it feasible for nation-states to archive massive volumes of sensitive encrypted data for years.
Third, once cryptographically relevant quantum computers become operational, the attacker uses quantum decryption to break the public key cryptography protecting the harvested data.
Why Harvest Now, Decrypt Later Changes Breach Dynamics
Traditional cyberattacks require real-time decryption or credential theft. Harvest Now, Decrypt Later changes traditional breach dynamics because the initial theft is the damaging event, even though the data remains unreadable at the time of capture.2
Organizations may not gain visibility into the compromise until years later, when the harvested data is finally decrypted. This delay fundamentally alters incident response and risk modeling. By the time the breach becomes visible, the stolen data may have been used for years.
HNDL exploits the time gap before quantum decryption becomes feasible.3 This makes HNDL uniquely dangerous: the attack is already underway, even though the damage has not yet materialized.
Encrypted Data at Risk from Harvest Now, Decrypt Later
Not all data faces the same HNDL risk. The primary targets are data with long confidentiality requirements: information that must remain confidential for years or decades after capture.
Data collected today may remain sensitive for decades.4 Data remains vulnerable to HNDL whenever its confidentiality lifespan exceeds the expected timeline for quantum decryption capability.
High-value data at greatest risk includes government and military communications, intellectual property and trade secrets, financial data subject to long retention requirements, medical records with decades-long privacy obligations, and classified national security systems data.
How Cryptographically Relevant Quantum Computers Enable Decrypt Later
The Decrypt Later phase depends entirely on the arrival of cryptographically relevant quantum computers. These are quantum systems powerful enough to run algorithms like Shor's algorithm at sufficient scale to break the encryption methods protecting harvested data.
Quantum computers could break current public-key encryption algorithms like RSA.5 Current asymmetric encryption algorithms, including RSA and elliptic curve cryptography, will become vulnerable once quantum systems reach sufficient qubit counts with adequate error correction.6
Cryptographically relevant quantum computers would be able to derive private keys from public keys, breaking public key cryptography that protects encrypted data across the internet. This includes the encryption protecting data encrypted in transit and digital signatures used for authentication, code signing, and secure transactions.
Q-Day is expected to occur in the 2030s or later.7 Three papers published between May 2025 and March 2026 reduced the estimated quantum resources needed to break RSA-2048 from 20 million qubits to fewer than one million, accelerating the timeline for cryptographically relevant quantum computers.
Encrypted Communications and Encrypted Network Traffic Under Threat
Harvest Now, Decrypt Later targets encrypted communications flowing across networks. Adversaries collect encrypted data from TLS-protected sessions, VPN tunnels, email encryption, messaging platforms, and any channel where encrypted traffic carries sensitive information.
Encrypted network traffic is especially vulnerable because it passes through shared infrastructure. Multiple national cybersecurity agencies have confirmed that adversaries are systematically intercepting and archiving encrypted communications today.9
Intercept Encrypted Data: The Harvesting Phase
To intercept encrypted data, adversaries use passive network monitoring, compromised infrastructure, and supply chain compromises. Because the attacker only needs to capture and store data without breaking it, the operation can remain undetected.
Attacks using HNDL can occur without the need for immediate decryption.10 This is what makes HNDL fundamentally different from conventional data breaches. The attacker has no need to crack credentials or exploit vulnerabilities in real time. They simply capture the traffic and wait.
Organizations must assess data sensitivity to mitigate HNDL risks.11 Understanding which data flows carry the most sensitive information is the first step toward reducing exposure.
Long-Lived Sensitive Data and Data Retention Risk
Organizations need to prioritize the protection of long-lived sensitive data.12 Data with long confidentiality requirements faces the highest Harvest Now, Decrypt Later exposure because its value persists beyond the timeline for quantum decryption.
Long-tail secret information includes sensitive data like classified communications and medical records.13 Financial services often retain data for over 7 years due to regulatory requirements.14 Healthcare data must be retained for at least 6 years under HIPAA.15
Organizations with long data retention face high HNDL exposure.16 Data retention policies should be reviewed to reduce unnecessary archives, minimizing the volume of encrypted data that could be harvested and later decrypted.
Stolen encrypted data can potentially remain protected for decades under current encryption methods, but that protection evaporates once cryptographically relevant quantum computers arrive.18
Quantum Decryption and Quantum Computing Threats
Quantum decryption means using quantum computing to break classical cryptographic algorithms. Quantum attacks will affect the confidentiality of long-term sensitive information.19
Quantum computers could break RSA and ECC encryption by 2030. The quantum decryption threat is not limited to a single algorithm. Every system relying on quantum-vulnerable cryptography for key exchange, digital signatures, or data protection faces exposure.
Quantum computing advances are accelerating. A sufficiently powerful quantum computer running Shor's algorithm could factor the large prime numbers that RSA depends on, and solve the discrete logarithm problem that underpins elliptic curve cryptography, rendering both useless for protecting encrypted data.
Critical Infrastructure and National Security Systems
Critical infrastructure faces outsized Harvest Now, Decrypt Later risk. Power grids, water systems, industrial control systems, and transportation networks rely on encryption methods that will eventually break. National security systems protect state secrets and intelligence data with confidentiality requirements spanning decades. The NSA's CNSA 2.0 already requires quantum-resistant algorithms for new national security systems acquisitions beginning January 1, 2027.
Critical systems in the defense industrial base, energy sector, and telecommunications face compounded risk. Telecommunications data has long-term strategic value and exposure.22 Encrypted data from these sectors carries both immediate operational value and long-term strategic value, making it a prime HNDL target.
AI Infrastructure and the Same HNDL Risk
AI infrastructure is particularly vulnerable to HNDL attacks. In the Thales 2026 report, 61% of respondents named Harvest Now, Decrypt Later their top quantum-related concern.24 AI systems process sensitive data at scale, and the intellectual property embedded in trained models has long-term strategic value that makes it ideal for Harvest Now, Decrypt Later.
The same HNDL risk applies to any system where data carries lasting value. Whether the target is AI model weights, financial data, medical records, or classified communications, the fundamental dynamic is identical: adversaries collect encrypted data now and wait for quantum capability to arrive.
Post-Quantum Cryptography and Post-Quantum Cryptography Standards
Post-quantum cryptography protects data against future quantum attacks. PQC uses cryptographic algorithms that resist attacks from both classical and quantum computers, ensuring that encrypted data remains protected even after cryptographically relevant quantum computers arrive.
NIST finalized post-quantum cryptography standards in August 2024, releasing FIPS 203, 204, and 205. These post-quantum cryptography standards specify ML-KEM for quantum-resistant key encapsulation and ML-DSA for digital signatures.
RSA and ECC will be deprecated by 2030 according to NIST. Organizations face a migration timeline of 5 to 15 years for PQC. Organizations must transition to PQC before quantum systems become operational, or the encrypted data they are protecting today will be exposed to HNDL decryption.
Post-Quantum Migration Planning and Post-Quantum Migration
Organizations must start post-quantum migration before Q-Day. Post-quantum migration planning begins with understanding your cryptographic exposure: where vulnerable encryption exists and which systems protect data with the longest confidentiality requirements.
Post-quantum migration involves four phases: conduct cryptographic discovery to inventory all cryptographic algorithms, key lengths, and cryptographic libraries; assess risk by mapping cryptographic dependencies to data sensitivity; prioritize systems protecting long-lived sensitive data; and implement post-quantum algorithms using a phased approach.
Organizations must prioritize long-lived sensitive data for protection.30 Systems handling medical records, financial data, intellectual property, and national security information should migrate first.
Encryption Methods and Quantum Vulnerable Cryptography
Current encryption methods that rely on public key cryptography face the greatest risk. RSA, elliptic curve cryptography, and Diffie-Hellman key exchange all depend on mathematical problems that classical computers cannot solve but quantum computers can solve efficiently.
This encompasses most asymmetric encryption and digital signature schemes in widespread use today whose security assumptions are broken by quantum attacks.
Organizations must replace cryptographic algorithms that are quantum-vulnerable with post-quantum alternatives. Post-quantum encryption uses lattice-based, hash-based, and code-based approaches. Post-quantum algorithms like ML-KEM and ML-DSA provide quantum-resistant key encapsulation and digital signature capabilities.
Crypto Agility and Cryptographic Agility
Crypto agility is the ability to rapidly swap cryptographic algorithms without redesigning systems. Building cryptographic agility into your infrastructure now is essential to survive the transition to a post-quantum world.
A system built with algorithm-agile design can migrate to post-quantum encryption by updating configuration rather than rewriting code. Organizations should build crypto agility into every new system deployed today to prepare for the post-quantum world.
Hybrid Cryptography: Combining Classical and Post-Quantum Algorithms
Adopting hybrid cryptography can mitigate transition risks effectively.31 Hybrid cryptography combines classical and post-quantum algorithms in a single cryptographic operation, ensuring that data protected by hybrid approaches remains secure even if one algorithm is compromised.
This hedges against undiscovered vulnerabilities in newly standardized post-quantum cryptography standards while protecting against quantum threats to classical cryptography.
Pure quantum-resistant deployments will remain rare in 2026. Instead, hybrid approaches combining classical and post-quantum algorithms will dominate enterprise implementations through the transition period.
Cryptographic Discovery and Cryptographic Visibility
Organizations should inventory cryptographic assets for exposure assessment. Cryptographic discovery means identifying every cryptographic implementation across applications, infrastructure, and third-party dependencies.
Cryptographic visibility into your enterprise cryptography is essential for assessing HNDL exposure. Without knowing where vulnerable encryption exists, you cannot prioritize post-quantum migration or evaluate which encrypted data flows carry the greatest risk.
Automated continuous discovery is the only approach that scales. Building a Cryptographic Bill of Materials (CBOM) maps all cryptographic dependencies, key lengths, and encryption methods, providing the foundation for data protected against future quantum decryption.
Distributed Ledger Networks and Harvest Now, Decrypt Later
Distributed ledger networks face a unique Harvest Now, Decrypt Later challenge. Blockchain transactions are permanently recorded and publicly visible, meaning adversaries do not even need to intercept data because it is already stored on-chain.
If the cryptographic algorithms protecting distributed ledger networks are broken by cryptographically relevant quantum computers, every historical transaction becomes exposed. Digital signatures on past transactions could be forged, undermining the entire trust model.
Distributed ledger networks must transition to post-quantum cryptography before quantum capability arrives.
Network Architecture and Network Traffic Protection
Protecting network traffic against Harvest Now, Decrypt Later requires understanding your network architecture and identifying where encrypted data flows through vulnerable points.
Network architecture should minimize exposure to interception. Segment networks to isolate high-value encrypted communications and deploy encrypted tunnels with post-quantum encryption for critical data flows. Monitor network traffic patterns to detect anomalous exfiltration that could indicate harvesting activity.
Threat Model: Assessing Your HNDL Exposure
Every organization should incorporate HNDL into its threat model. The HNDL assessment requires answering three questions:
How long must your data remain confidential?
What encryption methods currently protect it?
How likely is it that adversaries are already harvesting your encrypted data?
If data must remain confidential for more than a decade and is protected by quantum-vulnerable cryptography, the Harvest Now, Decrypt Later risk is high. Security teams should map data classification to cryptographic protection and prioritize accordingly.
Not all data requires the same level of protection. Operational data with short confidentiality windows faces less HNDL risk than classified communications, intellectual property, or medical records with decades-long privacy requirements.
Key Exchange, Key Management, and Key Lengths
Key exchange protocols are the primary target for Harvest Now, Decrypt Later. RSA and ECC based key exchange enables adversaries to decrypt entire sessions once the private key is recovered through quantum decryption.
Key management systems must support post-quantum algorithms to protect key exchange from future quantum attacks. Transitioning key exchange to quantum-resistant key encapsulation mechanisms like ML-KEM is a top priority for post-quantum migration.
AES-256 remains quantum-resistant because quantum attacks only halve its effective security. Organizations should verify that key lengths meet post-quantum requirements across all systems.
Protecting Data in a Post-Quantum World
Data protected by post-quantum cryptography is safe from Harvest Now, Decrypt Later. The goal of post-quantum migration is to ensure that data captured today cannot be decrypted by cryptographically relevant quantum computers in the future.
Implement post-quantum encryption for data in transit, use hybrid cryptography for critical systems, strengthen symmetric encryption with appropriate key lengths, and conduct cryptographic discovery to identify and replace vulnerable algorithms.
Organizations must also address stored data at rest in databases, backups, and archives, re-encrypting with post-quantum algorithms where feasible.
Enterprise Cryptography and Operational Security
Enterprise cryptography spans applications, infrastructure, cloud services, and identity providers. Securing it against HNDL requires systematic cryptographic discovery followed by prioritized migration.
Operational security depends on cryptography protecting communications and authentication. When those algorithms become vulnerable, every process built on them is at risk.
The 12 to 24 months required for large enterprises to complete cryptographic discovery reflects the sprawling, deeply embedded nature of modern encryption. Organizations that have not begun discovery are already behind the migration timeline.
Quantum Readiness and the Migration Timeline
Quantum readiness means your organization can transition to PQC before cryptographically relevant quantum computers arrive. CNSA 2.0 requires post-quantum cryptography by January 1, 2027, for new national security systems acquisitions.35
The global average quantum-safe readiness score is only 25 out of 100. DigiCert's July 2026 survey found 87% of organizations planning or piloting PQC, but only 7% have deployed quantum-safe cryptography across most of their certificate estate.37 Organizations that wait until Q-Day arrives will find migration timelines measured in years, not months.
How Aviatrix Supports Post-Quantum Migration and HNDL Defense
Understanding the Harvest Now, Decrypt Later threat tells you why you need to act. Aviatrix protects your encrypted data across your cloud network.
Aviatrix delivers centralized visibility into multicloud network traffic, encryption status, and security events from a single platform. With end-to-end encryption, distributed cloud firewall capabilities, and crypto agility built into the platform, Aviatrix helps organizations protect data in transit while maintaining the cryptographic agility needed for post-quantum migration.
By pairing cryptographic visibility with Aviatrix, security teams gain both the network architecture insights to identify where encrypted data is exposed and the operational tools to implement post-quantum encryption across their cloud infrastructure.
Explore cloud network security best practices or visit the Aviatrix Learn Center for zero trust cloud security and cloud security governance.
Sources
2 HashiCorp, "Harvest now, decrypt later: Why today's encrypted data isn't safe forever," hashicorp.com
3 The Quantum Insider, "What Is Harvest Now, Decrypt Later and Why Should You Care?," 2026. thequantuminsider.com
4 DestCert, "Harvest Now, Decrypt Later: The Quiet Threat Already Targeting Your Long-Lived Data," destcert.com
5 NIST, "Post-Quantum Cryptography FAQ," nist.gov
6 SecurityScorecard, "Quantum Computing and Cryptographic Risk," securityscorecard.com
7 PostQuantum.com, "What Is Q-Day?," postquantum.com
9 FedTech Magazine, "Harvest Now, Decrypt Later: A Federal Quantum Threat," 2026. fedtechmagazine.com
10 Encryption Consulting, "What Is Harvest Now, Decrypt Later?," encryptionconsulting.com
11 Keyfactor, "What Is Harvest Now, Decrypt Later (HNDL)?," keyfactor.com
12 Cloud Security Alliance, "Harvest Now, Decrypt Later: Quantum Risk to AI Infrastructure," cloudsecurityalliance.org
13 Recorded Future, "Quantum Risk Explained," recordedfuture.com
14 QuantumXC, "Harvest Now, Decrypt Later: HNDL Threat Model and Defense," quantumxc.com
15 Quantum Zeitgeist, "Harvest Now, Decrypt Later: The Complete 2026 Guide to HNDL," quantumzeitgeist.com
16 Unsung, "Harvest Now, Decrypt Later: CISO Guide," unsungltd.com
18 RAD, "Quantum Safe Encryption: PQC, QKD and Post Quantum," rad.com
19 The Quantum Insider, "Quantum Security: Threats, Solutions, and the Race to Protect Data," 2026. thequantuminsider.com
22 QuSecure, "Store Now, Decrypt Later," qusecure.com
24 Thales, "Harvest Now, Decrypt Later: Quantum and AI Threat," 2026. thalesgroup.com
30 CSIAC, "Planning for the Migration to Post-Quantum Cryptography," csiac.dtic.mil
31 QuantumXC, "Post-Quantum Cryptography in 2026: 5 Predictions," quantumxc.com
35 AxelSpire, "CNSA 2.0 and NIST PQC Deadlines 2026-2035," axelspire.com
37 ITECS, "Post-Quantum Cryptography: 2026 Migration Guide," itecsonline.com

