Harvest Now, Decrypt Later: Most Organizations Still Aren't Ready for the Quantum Cryptography Shift
NIST published its first three post-quantum standards in 2024. A year later, only 5% of security teams have a defined strategy. The clock is running whether they know it or not.

Key points
- Adversaries can steal encrypted data today and wait for quantum hardware capable of breaking it, with no breach alarm firing
- A 2025 ISACA survey found only 5% of cyber professionals rate the threat a high priority, the same 5% with a defined quantum-readiness strategy
- NIST finalized three post-quantum cryptography standards in 2024; the EU's roadmap sets 2026, 2030, and 2035 as transition deadlines
- Crypto-agility, the ability to swap cryptographic algorithms without rebuilding systems, is the architecture approach drawing the most practical interest
- The realistic near-term threat is nation-state adversaries harvesting data now, not broad criminal exploitation of quantum hardware
What is harvest now, decrypt later?
An adversary exfiltrates encrypted data today, stores it, and waits for quantum hardware capable of breaking the underlying cryptography. No breach alarm fires. Incident response never triggers. The damage surfaces years later, and by then the window to protect that data has long closed. This is not a hypothetical. It is an active, if slow-burning, threat.
How big is the preparedness gap?
A 2025 ISACA survey puts it in stark terms: two-thirds of cyber professionals are concerned about quantum computing's eventual ability to break current encryption, yet only 5% classify it as a high priority. That same 5% represents organizations with a defined quantum-readiness strategy. Not a coincidence.
We first covered the quantum cryptography beat on 12 June 2026, and the preparedness picture hasn't improved since.
Should you worry about Q-Day?
The "Q-Day" framing, a single date when classical cryptography collapses, is probably counterproductive. CEPS, the European think tank, argues the transition will be gradual rather than sudden. Félix Barrio, director general of Spanish national cybersecurity institute INCIBE, told Computerworld Spain the timeline runs anywhere from a few months to a decade depending on which estimates you trust. He also notes that early quantum capability will likely concentrate in government hands given hardware costs. That matters for threat modeling: nation-state adversaries harvesting data now are the realistic near-term concern, not broad criminal use.
What standards exist?
NIST finalized its first three post-quantum cryptography standards in 2024, covering algorithms designed to resist quantum attacks. The EU's roadmap sets first-phase PQC deployments by end of 2026, high-risk use cases by 2030, and remaining systems by 2035.
PQC or QKD?
Post-quantum cryptography replaces algorithms at the software level and integrates into existing infrastructure at manageable cost. Quantum key distribution (QKD) uses quantum-physical properties to detect interception and invalidate compromised keys, but it's mostly appearing in high-sensitivity point-to-point links between large facilities. Alberto de Mercado, Fortinet's systems engineering manager for service providers, told Computerworld Spain the foundational requirement is crypto-agility: systems that can swap cryptographic algorithms without full architectural redesigns. Hard-coding a single algorithm is technical debt that compounds. CaixaBank is already acting on this, targeting a crypto-agility model by 2029 covering data in transit and data at rest, with NIST's PQC schemes folded in as they mature.
What should defenders do now?
No EU regulation explicitly mandates PQC timelines, but GDPR, NIS2, alongside DORA carry long-term data-protection obligations that read as implicit pressure. Start with inventory: identify data with long confidentiality requirements, map the cryptographic algorithms protecting it, and assess exposure under a harvest-now scenario. Organizations that wait are betting quantum capability won't arrive before their sensitive data loses relevance. For most, that's a bet worth examining before a nation-state examines it for them.



