The most recent conversations about quantum computing’s threat to cybersecurity are generally talk about it as something in the future, like because by the time we actually had large-scale quantum computers, then that was worth discussing at least! This framing overlooks an important point, however: the risk to encrypted data does not remain idle until the quantum computer arrives. The danger now begins for any data kept secret for years or even decades, because adversaries are already gathering encrypted data with the plan to decrypt it once they have built a quantum computer powerful enough to run relevant algorithms. Knowing why this distinction matters and which data coinages are least secure is critical for any organization handling information with a long confidentiality horizon.
More specifically, once built at an appropriately large scale, a quantum computer will be able to break the public-key cryptographic algorithms that currently protect virtually all digital communications and data at rest in information systems. RSA and elliptic curve cryptography, as the foundation of everything from TLS connections to digital signatures and key exchange, is itself based upon mathematical problems that classical computers cannot solve in a reasonable time frame while quantum algorithms (in particular, Shor’s algorithm) can theoretically prove efficient at solving them.
Organizations evaluating how quantum computing risk applies to their long-term data protection strategy will find a useful starting point in the resource on quantum security for long-lived data, which outlines the foundational concepts behind quantum-resistant cryptography and how organizations can begin preparing for the transition.
Table of Contents
ToggleThe Harvest Now, Decrypt Later Threat Model
Quantum computing is able to exploit the nature of quantum mechanics – this means that your data is not as safe from future events, but how close are we to having that future? With quantum computers (QCs) across the globe still in their infancy, massive adversaries in the realm of nation-state actors with endless coffers and plenty of time for intelligence operations to bear fruit already possess tools capable of intercepting and stockpiling data encrypted today solely with the thought that once a cryptographically relevant QC sits before them in reality, they will be able to decrypt such information. This now-decrypted-later approach shifts the target market for legal compliance away from service providers and towards enterprise-sized end-users with long-arc R&D projects.
An organization that is working with a classical threat model might reasonably consider data encrypted to standards in place today as safe for the foreseeable future simply because breaking that encryption with classical computing resources would be impractical. This standard assumption is broken by the method: Harvest now, decrypt later. Data encrypted and intercepted today does not need to be decrypted and broken by the enemy in order to be compromised; it simply needs its value for that adversary to outlive any reasonable expectation that decryption would remain out of reach. This risk might be acceptable for data that has a short useful life. Certainly not for data which must remain confidential for ten, twenty or more years.
When a cryptographically relevant quantum computer will be available is, in the opinion of experts, still really anyone’s guess with timescales from years to decades. What is not uncertain, however, is that adversaries are moving under the assumption that the capability will be here shortly and organizations that postpone migration planning are committing risk on a timeline they cannot manage. The quantum risk assessment urgency that industry analysts now describe centers on exactly this gap: inventorying cryptographic assets, evaluating harvest-now-decrypt-later exposure, and prioritizing systems for migration before regulatory deadlines force the issue.
Most Quantum Risky Data Categories
No data encrypted will experience the harvest now, decrypt later threats equally. Whether the period of sensitivity is a long one compared with plausible estimates on when quantum breaking will be possible. Data that is not particularly appreciable in terms of quantum risk because it loses sensitivity quickly to a quarterly earnings report, any marketing email will be either no longer interesting by the time it can be decrypted, or (if period applicable) simply other routine corporate communications.
Data requiring long-term protection is a new risk profile altogether asyncio. At the very top end of this spectrum sits government and military classified information, where confidentiality requirements can linger for 30 years or more. Similarly, healthcare records often need to stay dormant for the lifetime of an individual but sometimes longer. This includes financial records kept for longer periods based on retention requirements, intellectual property and business secrets whose competitive advantage can last many years, and even legal and contractual documentation with long-term confidentiality obligations all too sensitive to have their time-to-decrypt by quantum computing be shorter than the timeline we can project to when that capability will arrive.
Organizations in any of these categories need to view quantum risk assessment not as a future challenge but as a right-now planning concern, because the data being generated and encrypted today will be the data that is vulnerable when the ability to decrypt matures without quantum-resistant algorithm migration. Survey data backs up how wide this gap remains: quantum readiness poll findings from more than 2,600 digital trust professionals show most enterprises still lack a defined quantum computing roadmap, even as a majority express concern about encryption breaking before migration is complete.
The Cryptographic Foundations at Risk
To understand why quantum computing poses a threat to current encryption standards, you first need to understand what those algorithms really depend on in order to stay secure. The security of RSA encryption is grounded in the fact that, using established classical computing techniques, it would be practically infeasible to factor large numbers, particularly such extraordinarily large numbers into their prime components. Elliptic curve cryptography is based on the hardness of the discrete logarithm problem in the corresponding elliptic curve groups. This raises security issues as both problems are unsolvable on classical computers in polynomial time, at least for the key sizes currently being used, which is why these algorithms have resisted years if not decades of attempts to break them.
Enter quantum computers running Shor’s algorithm; they turn this whole equation on its head. Instead of needing time that increases exponentially with key size, as classical factoring methods do, Shor’s algorithm can theoretically solve those problems in polynomial time on a sufficiently capable quantum computer. This is not just a slow improvement to computational power; this is an entirely different kind of approach that makes the mathematical assumptions underlying RSA and elliptic curve cryptography moot once the necessary hardware eventually becomes available for widespread use.
Symmetric encryption algorithms, such as AES, are specifically affected in a different way. They do, however, suffer a penalty in effective security due to Grover’s algorithm (though it’s more moderate and typically can be mitigated by simply increasing key length rather than having to replace the entire algorithm). The quantum threat is largely focused on public-key cryptographic systems we use for key exchange and digital signatures, the systems that most directly secure data in transit and authenticate identity across networks.
Post-Quantum Cryptography and Beyond
Cryptographers have been working on post-quantum cryptography for years to counter this threat, which refers to algorithms believed secure against a quantum computing adversary (and will also be secure against classical computers). These algorithms use other mathematical problems than RSA and elliptic curve cryptography ones, believed to be hard even by quantum computers such as some lattice-based & hash-based cryptographic constructions.
This effort has now reached the standardization stage. The work led by the National Institute of Standards and Technology through the post-quantum cryptography standards project culminated in the publication of three finalized federal standards in 2024, covering key-encapsulation mechanisms and digital signature schemes derived from a multi-year international evaluation process involving cryptographers from industry, academia, and government worldwide. These standards represent the foundation that most organizations will build their post-quantum migration around.
The transition to these new standards is not a simple software update. This requires organizations to take stock of the places cryptography is in use across their infrastructure—and this simply is not as easy an endeavor as it sounds, given that encryption lives within certificates and VPN configurations and application code, firmware and third-party software in ways that are often undocumented. Identify, assess for quantum exposure, and prioritize these touchpoints according to the sensitivity and lifespan of the data it retains.
The Real (Not Theoretical)-Case For Timeline Pressure
At the same time, NIST’s own published guidance for when to begin that transition provides a roadmap timeline recommending current public-key algorithms be phased out by 2030 and entirely retired from federal standards by 2035 has been labeled “too conservative” by industry analysts in light of state-level adversaries reaching quantum capability at a commercially relevant scale far earlier than that date.
Independent reporting on this dynamic, including quantum migration timeline analysis from CSO Online, captures the gap between the federal compliance timeline and the actual threat timeline: analysts cited in the coverage estimate that state actors could achieve quantum computing at scale by 2028, several years ahead of NIST’s full deprecation deadline, while emphasizing that sensitive data often retains its value for many years, making the urgency of migration considerably higher than the regulatory timeline alone would suggest.
This disparity between regulatory mandates and threat timelines is one of the key reasons organizations cannot afford to view post-quantum migration as an exercise in compliance reserved only for the future when they must comply. As data encrypted in the present, using current standards, if intercepted and then stored by an adversary today, is potentially exposed regardless of how long it takes the organization to actually migrate the exposure window opened when the data was first encrypted, not at some later point when such an organization eventually gets around to upgrading.
Long-term Planning: When You Have to Build for Cryptographic Agility
With so much uncertainty about when exactly quantum decryption capability will arrive and how post-quantum standards might continue to evolve as more research continues, organizations are increasingly looking at cryptographic agility the ability to change out cryptographic algorithms across systems without re-architecting everything every time something changes.
This implies designing systems such that cryptographic algorithms are not hard-coded in a way that makes it very difficult to update them when necessary, maintaining complete and up-to-date inventories of how and where cryptography is implemented, and establishing governance processes that can adapt as standards evolve over time as the post-quantum cryptography field continues to mature. Hybrid approaches provide a reasonable halfway state for data with the confidentiality requirement that lasts longer than the transition period, combining existing classical algorithms with post-quantum algorithms in a way that provides immediate quantum security as standards and tooling continue to mature.
Organizations already starting this work, thinking of it as an infrastructure-building, long-term investment instead of a deadline-driven compliance project, will be in vastly better shape than those that wait for either regulation to make mandates or quantum computing capacity simply to come along and force the issue.
Frequently Asked Questions
What features make data vulnerable to the harvest now, decrypt later attack?
All data protected today by quantum-vulnerable public-key encryption, such as RSA or elliptic curve encryption, is likely to become exposed if stored by an adversary from now on. The vulnerability is not tied to when the data was created, but when it will expire. Data with short-term sensitivity becomes moot long before quantum decryption capability arrives and data that has long-term confidentiality needs remains exposed for as long as it holds value, regardless of when the underlying key is compromised.
But what, one might ask, is post-quantum cryptography and how can it be different from just sticking to longer encryption keys?
For symmetric algorithms like AES, increasing key length mitigates some quantum vulnerability, since metrics for quantum attacks using Grover’s algorithm show only a modest computational advantage that can be countered with larger keys. Symmetric-key algorithms such as AES are subject to a different kind of threat from Shor’s algorithm: they can literally be “broken” regardless of key length, and Shor provides an efficient means to solve the underlying mathematical problem that keeps them secure. This can be done with post-quantum cryptography, where the mathematical foundation is completely changed, with problems that will theoretically never be solved by classical computers or by scalable quantum computers (such as lattice-based constructions).
Should Organizations Wait for Fully Mature Post-Quantum Cryptography Standards Before Starting Migration?
No, because as we said above the harvest now decrypts the later threat, which means that data encrypted today is already effectively exposed no matter when an eventual migration happens. Although there are some specific algorithms that need evaluation within the general post-quantum standardization effort, the main standards finalized in 2024 are stable and can be implemented today. Enterprises with sensitive data that will remain valid for several years face a substantially higher risk from delaying migration than from moving to best-practice solutions today.


