The attack that already happened — you just won’t know for years
Most cyberattacks announce themselves eventually: data leaks, systems lock, ransoms arrive. “Harvest now, decrypt later” (HNDL) is different. An attacker intercepts and stores your encrypted traffic and data today — health records, financial transactions, trade secrets, government communications — and simply waits. When a cryptographically relevant quantum computer arrives, they decrypt the whole archive retroactively.
The uncomfortable implication: any data with a long confidentiality shelf-life is already at risk, even though the decryption event is years away. If your data must stay secret for a decade, and quantum decryption may arrive within that window, the breach is effectively in progress.
Why the industry timeline points at 2026
The theoretical risk became an engineering deadline when NIST finalised its first post-quantum cryptography standards — the ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) algorithms — giving enterprises concrete, standardised, quantum-resistant primitives to adopt. That finalisation started the clock: 2026 has become the pivotal year for enterprises to begin NIST-aligned post-quantum migration and infrastructure readiness, with the broader roadmap pushing organisations to phase out legacy public-key cryptography (RSA, ECC) over the following years.
Two facts make this urgent rather than academic. First, HNDL means the harvesting is happening now, so waiting for quantum computers to be “ready” is already too late for long-lived secrets. Second, migration is genuinely slow — inventorying and replacing cryptography across an enterprise is a multi-year programme, not a patch.
The readiness gap most organisations are ignoring
Here is the sobering part. IBM’s 2026 Cost of a Data Breach report found that only 34% of organisations have visibility into their cryptographic assets — meaning two-thirds of companies cannot even answer the first question of a post-quantum migration: where is cryptography used across my systems? Just 37% reported encrypting data both at rest and in transit.
You cannot migrate what you cannot see. This visibility gap, not the algorithms themselves, is the real bottleneck.
How to start a post-quantum migration in 2026
You don’t need a quantum computer in your lab to begin. You need a disciplined, phased programme:
-
Build a cryptographic inventory (crypto-bill-of-materials).
Discover every place your systems use cryptography — TLS, VPNs, code signing, databases, APIs, embedded devices, third-party services. This is the single most valuable first step.
-
Classify data by confidentiality lifetime.
Rank data by how long it must stay secret. Anything with a 5–10+ year horizon is your highest HNDL priority.
-
Prioritise crypto-agility.
Architect systems so algorithms can be swapped without re-engineering the whole application. Crypto-agility is the goal even before full PQC rollout.
-
Pilot hybrid cryptography.
Deploy hybrid schemes that combine classical and post-quantum algorithms, so you gain quantum resistance without betting everything on brand-new primitives.
-
Engage your vendors.
Much of your cryptography lives in third-party products. Ask suppliers for their PQC roadmaps now — their timeline is your timeline.
-
Sequence the rollout.
Start with the highest-value, longest-lived, externally exposed data flows and work inward.
The strategic takeaway
Post-quantum migration is often mislabelled a “future problem.” Harvest-now-decrypt-later reframes it as a present one: the data being stolen today will be read tomorrow. The organisations that begin their cryptographic inventory in 2026 will migrate calmly over several years. The ones that wait for a quantum “big bang” will discover their most sensitive decade of data was compromised long before they started.