Harvest Now, Decrypt Later: Why Post-Quantum Cryptography Is Already a Priority Today
- 5 days ago
- 1 min read
Imagine someone stealing your encrypted data today, not to read it now, but to decrypt it ten years from now.
That is the strategy behind "Harvest Now, Decrypt Later" (HNDL). Attackers are already collecting encrypted data, waiting for future quantum computers to become powerful enough to break the encryption algorithms that are considered secure today. According to the European Union, this type of data harvesting is likely already taking place.
For organizations that handle information requiring long-term confidentiality, such as patient records, financial data, intellectual property, or automotive platforms, this is a risk that needs to be addressed today. If your data still needs to remain confidential in ten or twenty years, it could already be at risk.
To prepare for this challenge, the EU has published a roadmap for the transition to Post-Quantum Cryptography (PQC). Member States are expected to develop national transition plans during 2026. Critical infrastructure should transition to quantum-resistant cryptography by 2030, with all other systems expected to follow by 2035.
The first step, however, is not to replace all existing encryption. Instead, organizations should begin by identifying where cryptography is used across their environment and which data requires long-term protection. A cryptographic inventory provides the foundation for prioritizing future migration efforts.
The quantum computer capable of breaking today's encryption may not exist yet, but the data it could decrypt in the future may already be collected today. That's why the time to start preparing is now.



