Harvest now decrypt later (also written as HNDL) is a cyberattack strategy in which an adversary intercepts and stores encrypted data today, without being able to read it, and then waits until a sufficiently powerful quantum computer is available to break the encryption retroactively. The attack requires no immediate decryption capability. The investment is in patience and storage.
For IT managers, CISOs and Data Protection Officers, this reframes the threat model entirely. The question is no longer only whether your encryption is strong today. It is whether the data you transmit and store now will still be protected ten or twenty years from now.
Why the Quantum Threat Makes Past Interceptions Dangerous
Current asymmetric encryption, including RSA and elliptic curve cryptography, relies on mathematical problems that classical computers cannot solve in practical time. Quantum computers running Shor’s algorithm can, in principle, break these schemes. The uncertainty is timing, not feasibility.
“Adversaries are already harvesting encrypted data today with the intent to decrypt it once cryptographically relevant quantum computers become available.”
NSA Cybersecurity Directorate, US National Security Agency
ENISA estimated in its 2021 threat landscape report that a cryptographically relevant quantum computer is likely between 10 and 20 years away. That range sits squarely within the retention period of many categories of enterprise data.
Which Long-Lived Data Is Most at Risk
Not all data carries the same exposure. The severity depends on how long the information must remain confidential and how attractive it is to a sophisticated threat actor.
| Data category | Typical confidentiality horizon | Example risk scenario |
|---|---|---|
| Intellectual property and R&D documents | 10 to 30 years | Patent filings, product roadmaps, formulas intercepted now and decoded after quantum breakthrough |
| Personnel and medical records | 10 to 75 years (depending on jurisdiction) | Health data or HR files that remain sensitive for an individual’s lifetime |
| Legal contracts and M&A communications | 10 to 20 years | Confidential deal terms usable for competitive intelligence or litigation |
| Government and defence communications | Classified: 25 to 50+ years | Diplomatic cables and operational plans that retain strategic value for decades |
| Authentication credentials and private keys | Active until rotated | TLS session keys captured in transit, used to retroactively decrypt entire communication streams |
Long-lived data stored in cloud environments under foreign legal jurisdiction carries a compounded risk: both future quantum decryption and present-day legal compulsion orders, such as those possible under the US CLOUD Act, create separate but overlapping exposure vectors.
How to Protect Long-Lived Data Today
The response to harvest now decrypt later consists of two complementary tracks: cryptographic migration and architectural sovereignty.
Adopt post-quantum encryption now, not at maturity
In August 2024, NIST finalised the first set of post-quantum cryptographic standards. The primary algorithms are ML-KEM (Module-Lattice Key Encapsulation Mechanism, formerly CRYSTALS-Kyber) for key exchange and ML-DSA (Module-Lattice Digital Signature Algorithm, formerly CRYSTALS-Dilithium) for authentication. These are based on lattice problems that are considered resistant to both classical and quantum attacks.
“The migration to post-quantum cryptography is urgent. Organisations that delay risk exposing data whose confidentiality must be preserved for decades.”
Dustin Moody, Mathematician and project lead, NIST Post-Quantum Cryptography Standardisation
The US Office of Management and Budget issued memorandum M-23-02 in 2022, requiring federal agencies to complete a full inventory of cryptographic systems and begin migration planning within 180 days. While this applies to US federal agencies, it signals the regulatory direction European organisations should anticipate under frameworks such as NIS2 (Directive EU 2022/2555) and evolving ENISA guidance.
Combine post-quantum encryption with sovereign hosting
Post-quantum algorithms protect the cryptographic layer. Sovereign hosting addresses where data physically resides and under which legal system it falls. For European organisations, Swiss jurisdiction or on-premise deployment eliminates exposure to the US CLOUD Act and equivalent foreign surveillance legislation.
Managed Nextcloud Enterprise deployments, such as those offered through Qsentinel with integrated post-quantum encryption and Swiss or on-premise hosting, address both dimensions simultaneously. This matters because implementing post-quantum algorithms on infrastructure still subject to foreign legal orders solves only half the problem.
Audit your current cryptographic posture
Most enterprises do not have a complete picture of which systems still rely on RSA-2048 or ECDH for key exchange. A cryptographic inventory, covering email gateways, VPNs, file sync platforms, internal APIs and certificate authorities, is the necessary first step before any migration can be sequenced. GDPR Article 32 already requires organisations to implement appropriate technical measures; regulators are increasingly likely to interpret this in light of foreseeable quantum risk when reviewing incidents involving long-lived personal data.
FAQ
Is harvest now decrypt later a theoretical risk or an active threat?
It is an active threat. Intelligence agencies including the NSA have publicly stated that nation-state actors are already collecting encrypted communications and files today, with the intention of decrypting them once quantum computing power is available.
How long does data need to remain confidential before harvest now decrypt later becomes a concern?
Any data that must remain confidential for ten years or more is already in scope. This includes medical records, legal contracts, intellectual property, personnel files and government communications. If a quantum computer capable of breaking current encryption arrives within that window, intercepted data becomes readable.
What is post-quantum encryption and which algorithms should organisations adopt?
Post-quantum encryption uses mathematical problems that quantum computers cannot solve efficiently. NIST standardised ML-KEM for key encapsulation and ML-DSA for digital signatures in August 2024. These are the recommended starting point for enterprise migration.
Does GDPR or NIS2 require organisations to address quantum threats?
Neither Regulation (EU) 2016/679 (GDPR) nor Directive (EU) 2022/2555 (NIS2) explicitly mentions quantum computing. However, both require appropriate technical measures to protect personal data and critical infrastructure. Regulators and the EDPB have indicated that “appropriate” must be interpreted in light of foreseeable future threats, which increasingly includes the quantum threat.
Can switching to a sovereign cloud eliminate the harvest now decrypt later risk?
Sovereign hosting reduces interception risk by limiting the legal and physical exposure of data to foreign jurisdictions and their intelligence services. However, it does not eliminate the cryptographic risk. Full protection requires combining sovereign hosting with post-quantum encryption so that any data already intercepted in transit cannot be decrypted later.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
