Harvest Now, Decrypt Later: Most Organizations Still Aren't Ready for the Quantum Cryptography Shift

NIST published its first three post-quantum standards in 2024. A year later, only 5% of security teams have a defined strategy. The clock is running whether they know it or not.

ThreatVectr Newsdesk· 3 min read
Harvest Now, Decrypt Later: Most Organizations Still Aren't Ready for the Quantum Cryptography Shift
Share

The attack is simple in concept. An adversary exfiltrates encrypted data today, stores it, and waits for quantum hardware capable of breaking the underlying cryptography. No breach alarm fires. No incident response triggers. The damage surfaces years later — and by then, the window to protect that data has long closed.

This is "harvest now, decrypt later," and it is not a hypothetical. It is an active, if slow-burning, threat.

A 2025 ISACA survey puts the preparedness gap in stark terms: two-thirds of cyber professionals are concerned about quantum computing's eventual ability to break current encryption, yet only 5% classify it as a high priority. That same 5% represents the share of organizations with a defined quantum-readiness strategy. The numbers are not a coincidence — they are the same cohort.

The "Q-Day" framing — a single date when classical cryptography collapses — is probably counterproductive. The European think tank CEPS and others argue the transition will be gradual, not sudden. Félix Barrio, director general of Spanish national cybersecurity institute INCIBE, puts the timeline at anywhere from months to a decade, depending on which estimates you trust. He also notes that early quantum capability will likely concentrate in government hands, given hardware costs. That matters for threat modeling: nation-state adversaries harvesting data now are the realistic near-term concern, not broad criminal use.

NIST finalized its first three post-quantum cryptography standards in 2024, covering algorithms designed to resist attacks from quantum hardware. The EU has mapped a parallel transition roadmap — first-phase PQC deployments by end of 2026, high-risk use cases covered by 2030, remaining systems by 2035.

Two approaches dominate current planning. Post-quantum cryptography (PQC) — algorithm-level replacements compatible with existing infrastructure — is drawing the most immediate interest because integration costs are manageable. Quantum key distribution (QKD), which uses quantum-physical properties to detect interception and invalidate compromised keys, is showing up mostly in high-sensitivity point-to-point links between large facilities. The operational bar for QKD is higher; most organizations aren't there yet.

The concept pulling both threads together is crypto-agility: building systems that can swap or layer cryptographic algorithms without full architectural redesigns. Alberto de Mercado, Fortinet's systems engineering manager for service providers, frames it as the foundational requirement — organizations that hard-code a single algorithm are building technical debt that will be painful to unwind. CaixaBank is already running with this framing, targeting a crypto-agility model by 2029 that covers both data in transit and data at rest, with NIST's new PQC schemes folded in as they mature.

The regulatory angle is still soft. No EU regulation explicitly mandates PQC timelines, but GDPR, NIS2, and DORA all carry long-term data-protection obligations that organizations handling sensitive records should already be reading as implicit pressure.

The practical starting point for defenders is inventory: identify data with long confidentiality requirements, map the cryptographic algorithms protecting it, and assess exposure under a harvest-now scenario. Organizations that do nothing are making a bet that quantum capability won't arrive — or won't be used against them — before that data loses its sensitivity. For most, that bet isn't as safe as the 95% non-planning rate suggests they think.

© 2026 Threat Vectr