Cookie Preferences

    We use cookies to ensure our website functions properly and to improve your experience. Essential cookies are always active. You can choose to enable other categories below. Learn more

    Active Threat

    What is Harvest Now, Decrypt Later?

    Harvest Now, Decrypt Later (HNDL) is an attack strategy where nation-state adversaries and sophisticated threat actors collect and store encrypted data today with the intention of decrypting it in the future when quantum computers become capable of breaking current encryption.

    Why This Matters Right Now

    If your encrypted data needs to remain confidential for 10+ years, it is already at risk. Adversaries are collecting encrypted traffic today, knowing they can decrypt it when quantum computers arrive. The protection window has already closed for long-lived secrets.

    How HNDL Attacks Work

    1. Harvest

    Adversaries intercept and store encrypted communications, database exports, and network traffic—often at massive scale

    2. Store & Wait

    The encrypted data is archived in long-term storage, waiting for quantum computing capabilities to mature

    3. Decrypt Later

    When quantum computers can break RSA/ECC encryption, all harvested data becomes readable—years of secrets exposed at once

    What Data is at Risk?

    Any encrypted data that must remain confidential beyond the expected arrival of cryptographically relevant quantum computers (estimated 2030-2040) is potentially at risk today. The key question is: How long does your data need to stay secret?

    Data TypeTypical Shelf LifeHNDL Risk Level
    Financial Records7-10 years
    High
    Medical RecordsLifetime
    Critical
    Trade Secrets10-20 years
    Critical
    M&A Documents5-15 years
    High
    Government/Military25+ years
    Critical
    Personal CommunicationsVaries
    Medium

    Who is Conducting HNDL Attacks?

    HNDL attacks are primarily associated with nation-state actors who have the resources to collect and store massive amounts of encrypted data, and the strategic patience to wait years for quantum decryption capabilities. Intelligence agencies worldwide are believed to be engaged in HNDL operations.

    How to Protect Against HNDL

    1. Assess Your Risk: Identify which data categories have long-term confidentiality requirements. Use a cryptographic inventory (CBOM) to catalog quantum-vulnerable systems.
    2. Prioritize Migration: Begin transitioning high-risk systems to post-quantum cryptography (PQC). Follow the NIST PQC Migration Roadmap for a phased 2025–2035 timeline.
    3. Implement Hybrid Encryption: Use both classical and PQC algorithms during the transition period
    4. Document for Governance: Create audit trails showing proactive quantum risk management that satisfy quantum compliance obligations under SOC 2, HIPAA, and DORA.

    How QCI-QS1 Governs HNDL Risk

    The QCI-QS1 standard treats HNDL not as a technical footnote but as a board-level accountability issue. HNDL exposure is mapped across three clauses:

    • Clause 4 (QRAF): Assigns executive ownership of quantum risk, including HNDL exposure for long-lived data categories.
    • Clause 5 (QASI): Requires a complete inventory of quantum-vulnerable cryptographic assets — the first step in quantifying what an adversary could harvest.
    • Clause 6 (Q-Risk Score): Converts HNDL exposure into a 0–100 metric with hard ceilings, producing board-ready evidence of risk posture.

    Organizations that complete QCI-QS1 alignment can demonstrate to regulators, insurers, and auditors that HNDL risk has been identified, measured, and assigned accountable ownership.

    The MOSCA Equation

    Cryptographer Michele Mosca developed a framework to determine when organizations must begin quantum preparation:

    If X + Y > Z, you need to act now
    • X = Time to migrate your cryptographic systems
    • Y = How long your data must remain secret
    • Z = Time until quantum computers can break encryption

    For most organizations with long-lived secrets, this equation already indicates urgent action is needed.

    Assess Your HNDL Exposure

    Understand which of your systems and data are vulnerable to Harvest Now, Decrypt Later attacks with a comprehensive Q-Risk assessment.