Summary: Harvest now decrypt later is a real and active threat in which adversaries stockpile today's encrypted data to decrypt it with future quantum computers. Protecting long-lived data with post-quantum encryption is no longer optional for organisations handling sensitive information.

Harvest now decrypt later (also written as HNDL) is a cyberattack strategy in which an adversary intercepts and stores encrypted data today, without being able to read it, and then waits until a sufficiently powerful quantum computer is available to break the encryption retroactively. The attack requires no immediate decryption capability. The investment is in patience and storage.

For IT managers, CISOs and Data Protection Officers, this reframes the threat model entirely. The question is no longer only whether your encryption is strong today. It is whether the data you transmit and store now will still be protected ten or twenty years from now.

Why the Quantum Threat Makes Past Interceptions Dangerous

Current asymmetric encryption, including RSA and elliptic curve cryptography, relies on mathematical problems that classical computers cannot solve in practical time. Quantum computers running Shor’s algorithm can, in principle, break these schemes. The uncertainty is timing, not feasibility.

“Adversaries are already harvesting encrypted data today with the intent to decrypt it once cryptographically relevant quantum computers become available.”

NSA Cybersecurity Directorate, US National Security Agency

ENISA estimated in its 2021 threat landscape report that a cryptographically relevant quantum computer is likely between 10 and 20 years away. That range sits squarely within the retention period of many categories of enterprise data.

Key implication: Encrypted network traffic captured today by a well-resourced adversary, such as a nation-state intelligence service, does not need to be readable now. It only needs to be stored until quantum hardware matures.

Which Long-Lived Data Is Most at Risk

Not all data carries the same exposure. The severity depends on how long the information must remain confidential and how attractive it is to a sophisticated threat actor.

Data category Typical confidentiality horizon Example risk scenario
Intellectual property and R&D documents 10 to 30 years Patent filings, product roadmaps, formulas intercepted now and decoded after quantum breakthrough
Personnel and medical records 10 to 75 years (depending on jurisdiction) Health data or HR files that remain sensitive for an individual’s lifetime
Legal contracts and M&A communications 10 to 20 years Confidential deal terms usable for competitive intelligence or litigation
Government and defence communications Classified: 25 to 50+ years Diplomatic cables and operational plans that retain strategic value for decades
Authentication credentials and private keys Active until rotated TLS session keys captured in transit, used to retroactively decrypt entire communication streams

Long-lived data stored in cloud environments under foreign legal jurisdiction carries a compounded risk: both future quantum decryption and present-day legal compulsion orders, such as those possible under the US CLOUD Act, create separate but overlapping exposure vectors.

See how Qsentinel solves this in practice.Start a 10-user pilot →

How to Protect Long-Lived Data Today

The response to harvest now decrypt later consists of two complementary tracks: cryptographic migration and architectural sovereignty.

Adopt post-quantum encryption now, not at maturity

In August 2024, NIST finalised the first set of post-quantum cryptographic standards. The primary algorithms are ML-KEM (Module-Lattice Key Encapsulation Mechanism, formerly CRYSTALS-Kyber) for key exchange and ML-DSA (Module-Lattice Digital Signature Algorithm, formerly CRYSTALS-Dilithium) for authentication. These are based on lattice problems that are considered resistant to both classical and quantum attacks.

“The migration to post-quantum cryptography is urgent. Organisations that delay risk exposing data whose confidentiality must be preserved for decades.”

Dustin Moody, Mathematician and project lead, NIST Post-Quantum Cryptography Standardisation

The US Office of Management and Budget issued memorandum M-23-02 in 2022, requiring federal agencies to complete a full inventory of cryptographic systems and begin migration planning within 180 days. While this applies to US federal agencies, it signals the regulatory direction European organisations should anticipate under frameworks such as NIS2 (Directive EU 2022/2555) and evolving ENISA guidance.

Combine post-quantum encryption with sovereign hosting

Post-quantum algorithms protect the cryptographic layer. Sovereign hosting addresses where data physically resides and under which legal system it falls. For European organisations, Swiss jurisdiction or on-premise deployment eliminates exposure to the US CLOUD Act and equivalent foreign surveillance legislation.

Managed Nextcloud Enterprise deployments, such as those offered through Qsentinel with integrated post-quantum encryption and Swiss or on-premise hosting, address both dimensions simultaneously. This matters because implementing post-quantum algorithms on infrastructure still subject to foreign legal orders solves only half the problem.

Practical priority: Begin by inventorying data with a confidentiality horizon exceeding ten years. Prioritise migrating the transport and storage encryption for those datasets first. Waiting for quantum computers to arrive before acting guarantees retroactive exposure of everything captured in the interim.

Audit your current cryptographic posture

Most enterprises do not have a complete picture of which systems still rely on RSA-2048 or ECDH for key exchange. A cryptographic inventory, covering email gateways, VPNs, file sync platforms, internal APIs and certificate authorities, is the necessary first step before any migration can be sequenced. GDPR Article 32 already requires organisations to implement appropriate technical measures; regulators are increasingly likely to interpret this in light of foreseeable quantum risk when reviewing incidents involving long-lived personal data.

FAQ

Is harvest now decrypt later a theoretical risk or an active threat?

It is an active threat. Intelligence agencies including the NSA have publicly stated that nation-state actors are already collecting encrypted communications and files today, with the intention of decrypting them once quantum computing power is available.

How long does data need to remain confidential before harvest now decrypt later becomes a concern?

Any data that must remain confidential for ten years or more is already in scope. This includes medical records, legal contracts, intellectual property, personnel files and government communications. If a quantum computer capable of breaking current encryption arrives within that window, intercepted data becomes readable.

What is post-quantum encryption and which algorithms should organisations adopt?

Post-quantum encryption uses mathematical problems that quantum computers cannot solve efficiently. NIST standardised ML-KEM for key encapsulation and ML-DSA for digital signatures in August 2024. These are the recommended starting point for enterprise migration.

Does GDPR or NIS2 require organisations to address quantum threats?

Neither Regulation (EU) 2016/679 (GDPR) nor Directive (EU) 2022/2555 (NIS2) explicitly mentions quantum computing. However, both require appropriate technical measures to protect personal data and critical infrastructure. Regulators and the EDPB have indicated that “appropriate” must be interpreted in light of foreseeable future threats, which increasingly includes the quantum threat.

Can switching to a sovereign cloud eliminate the harvest now decrypt later risk?

Sovereign hosting reduces interception risk by limiting the legal and physical exposure of data to foreign jurisdictions and their intelligence services. However, it does not eliminate the cryptographic risk. Full protection requires combining sovereign hosting with post-quantum encryption so that any data already intercepted in transit cannot be decrypted later.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

Is harvest now decrypt later a theoretical risk or an active threat?
It is an active threat. Intelligence agencies including the NSA have publicly stated that nation-state actors are already collecting encrypted communications and files today, with the intention of decrypting them once quantum computing power is available.
How long does data need to remain confidential before harvest now decrypt later becomes a concern?
Any data that must remain confidential for ten years or more is already in scope. This includes medical records, legal contracts, intellectual property, personnel files and government communications. If a quantum computer capable of breaking current encryption arrives within that window, intercepted data becomes readable.
What is post-quantum encryption and which algorithms should organisations adopt?
Post-quantum encryption uses mathematical problems that quantum computers cannot solve efficiently. NIST standardised ML-KEM (formerly CRYSTALS-Kyber) for key encapsulation and ML-DSA (formerly CRYSTALS-Dilithium) for digital signatures in August 2024. These are the recommended starting point for enterprise migration.
Does GDPR or NIS2 require organisations to address quantum threats?
Neither Regulation (EU) 2016/679 (GDPR) nor Directive (EU) 2022/2555 (NIS2) explicitly mentions quantum computing. However, both require appropriate technical measures to protect personal data and critical infrastructure. Regulators and the EDPB have indicated that 'appropriate' must be interpreted in light of foreseeable future threats, which increasingly includes the quantum threat.
Can switching to a sovereign cloud eliminate the harvest now decrypt later risk?
Sovereign hosting reduces interception risk by limiting the legal and physical exposure of data to foreign jurisdictions and their intelligence services. However, it does not eliminate the cryptographic risk. Full protection requires combining sovereign hosting with post-quantum encryption so that any data already intercepted in transit cannot be decrypted later.