What is Harvest Now, Decrypt Later?
Harvest Now, Decrypt Later (HNDL) is an attack strategy where nation-state adversaries and sophisticated threat actors collect and store encrypted data today with the intention of decrypting it in the future when quantum computers become capable of breaking current encryption.
Why This Matters Right Now
If your encrypted data needs to remain confidential for 10+ years, it is already at risk. Adversaries are collecting encrypted traffic today, knowing they can decrypt it when quantum computers arrive. The protection window has already closed for long-lived secrets.
How HNDL Attacks Work
1. Harvest
Adversaries intercept and store encrypted communications, database exports, and network traffic—often at massive scale
2. Store & Wait
The encrypted data is archived in long-term storage, waiting for quantum computing capabilities to mature
3. Decrypt Later
When quantum computers can break RSA/ECC encryption, all harvested data becomes readable—years of secrets exposed at once
What Data is at Risk?
Any encrypted data that must remain confidential beyond the expected arrival of cryptographically relevant quantum computers (estimated 2030-2040) is potentially at risk today. The key question is: How long does your data need to stay secret?
| Data Type | Typical Shelf Life | HNDL Risk Level |
|---|---|---|
| Financial Records | 7-10 years | High |
| Medical Records | Lifetime | Critical |
| Trade Secrets | 10-20 years | Critical |
| M&A Documents | 5-15 years | High |
| Government/Military | 25+ years | Critical |
| Personal Communications | Varies | Medium |
Who is Conducting HNDL Attacks?
HNDL attacks are primarily associated with nation-state actors who have the resources to collect and store massive amounts of encrypted data, and the strategic patience to wait years for quantum decryption capabilities. Intelligence agencies worldwide are believed to be engaged in HNDL operations.
How to Protect Against HNDL
- Assess Your Risk: Identify which data categories have long-term confidentiality requirements. Use a cryptographic inventory (CBOM) to catalog quantum-vulnerable systems.
- Prioritize Migration: Begin transitioning high-risk systems to post-quantum cryptography (PQC). Follow the NIST PQC Migration Roadmap for a phased 2025–2035 timeline.
- Implement Hybrid Encryption: Use both classical and PQC algorithms during the transition period
- Document for Governance: Create audit trails showing proactive quantum risk management that satisfy quantum compliance obligations under SOC 2, HIPAA, and DORA.
How QCI-QS1 Governs HNDL Risk
The QCI-QS1 standard treats HNDL not as a technical footnote but as a board-level accountability issue. HNDL exposure is mapped across three clauses:
- Clause 4 (QRAF): Assigns executive ownership of quantum risk, including HNDL exposure for long-lived data categories.
- Clause 5 (QASI): Requires a complete inventory of quantum-vulnerable cryptographic assets — the first step in quantifying what an adversary could harvest.
- Clause 6 (Q-Risk Score): Converts HNDL exposure into a 0–100 metric with hard ceilings, producing board-ready evidence of risk posture.
Organizations that complete QCI-QS1 alignment can demonstrate to regulators, insurers, and auditors that HNDL risk has been identified, measured, and assigned accountable ownership.
The MOSCA Equation
Cryptographer Michele Mosca developed a framework to determine when organizations must begin quantum preparation:
If X + Y > Z, you need to act now
- X = Time to migrate your cryptographic systems
- Y = How long your data must remain secret
- Z = Time until quantum computers can break encryption
For most organizations with long-lived secrets, this equation already indicates urgent action is needed.
Continue Learning
What is Post-Quantum Cryptography?
Learn about the encryption standards designed to resist quantum attacks
Cryptographic Inventory (CBOM)
Catalog quantum-vulnerable assets as the first step in HNDL defense
NIST PQC Migration Roadmap
Phased 2025–2035 roadmap for migrating to post-quantum cryptography
Quantum Compliance Mapping
Map HNDL risk to SOC 2, HIPAA, DORA, and NIS2 obligations
QCI-QS1 Standard
The free, auditable quantum risk management framework with HNDL governance clauses