By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Ground LabsPublished July 15, 2026

TL;DR: Encrypted data theft is already a live threat because attackers can store it now and decrypt it later, while EY says 87% of UK business leaders expect quantum disruption by 2030 and ISACA found 56% of security and trust professionals are concerned, according to Ground Labs. The practical issue is not distant quantum capability but how long sensitive data, digital identities and certificates remain valuable and exposed.


At a glance

What this is: This is a Ground Labs analysis of harvest now, decrypt later risk and the need to pair data discovery with cryptographic inventory before quantum decryption becomes practical.

Why it matters: It matters because identity, certificate, authentication and long-lived personal data all sit inside the cryptographic trust chain that quantum risk can weaken, so IAM and security teams need to reduce exposure now.

By the numbers:

👉 Read Ground Labs' analysis of harvest now, decrypt later risk and PQC migration


Context

Quantum risk is often described as a future problem, but the security gap is already present: encrypted data can be stolen now and held until decryption becomes feasible. For identity programmes, the real issue is not just the algorithm in use, but the confidentiality lifespan of data, certificates and authentication material that may remain valuable for years.

Harvest now, decrypt later matters because identity systems depend on public-key cryptography for authentication, signing and trust. That means digital identities, certificates, software updates and long-lived personal data all become part of the exposure model, especially when copies spread across cloud, backups, email and third-party systems.


Key questions

Q: How should organisations reduce harvest now, decrypt later risk?

A: Start by identifying encrypted data that must remain confidential for years, not months. Then reduce duplication, tighten retention, map where keys and certificates live, and make replacement paths for cryptography part of normal architecture rather than an emergency project. The goal is to shrink the amount of valuable ciphertext available for future decryption.

Q: Why does quantum risk matter for non-human identities now?

A: Quantum risk matters now because organisations can already lose confidentiality through harvest-now, decrypt-later collection. Machine identities often protect traffic, tokens, and service-to-service data, so cryptographic agility and faster reissuance are part of NHI resilience before quantum systems mature.

Q: What usually breaks when cryptographic inventory is incomplete?

A: Incomplete inventory breaks prioritisation. Teams cannot tell which systems use which algorithms, which suppliers depend on them, or which assets are too critical to migrate without testing. That creates blind spots in PQC planning and pushes organisations into reactive, high-risk transitions instead of sequenced change.

Q: Who is accountable for post-quantum migration across partners and contractors?

A: Accountability sits with the organisation that owns the trust boundary, but the work spans vendors, contractors, and federated partners. Identity teams should define who approves changes, who validates compatibility, and who owns rollback if a cryptographic transition disrupts access. Cross-organisation trust is a governance issue, not just a technical one.


Technical breakdown

How harvest now, decrypt later works against cryptographic trust

Harvest now, decrypt later is a delay tactic. Attackers exfiltrate encrypted data today, then wait for quantum computing to make current public-key algorithms vulnerable. The threat is strongest where data has long confidentiality value, because intercepted material may still be sensitive when decryption becomes possible. This shifts the problem from immediate confidentiality loss to deferred compromise of records, identities and signed communications. It also means the attacker does not need a quantum computer to start the attack cycle. Practical implication: treat long-lived encrypted data as an active exposure, not a theoretical future asset.

Practical implication: Prioritise data with long confidentiality lifespans and reduce its exposure before migration windows extend further.

Why cryptographic inventory matters for identity and access systems

A cryptographic inventory maps the algorithms, keys, certificates, libraries and protocols protecting data and identity flows. In practice, that inventory is what tells you where RSA, Diffie-Hellman or elliptic-curve dependencies support authentication, signing and secure transport. Without it, teams cannot distinguish low-risk uses from critical trust paths that protect identity systems, software updates or cloud integrations. This is especially important because cryptography often sits inside third-party services and inherited application dependencies, not just obvious security tooling. Practical implication: build a system-level map that ties each cryptographic asset to the business data and identity process it protects.

Practical implication: Link every key, certificate and algorithm to the identity or data service it secures before planning migration.

What crypto-agility changes for certificates and digital identities

Crypto-agility is the ability to replace algorithms, keys and certificates without major disruption to applications or operations. It matters because post-quantum migration will not be a single switch flip. Organisations need standard libraries, centralised certificate and key management, and vendor visibility so they can change trust mechanisms as standards mature. For identity teams, that means the lifecycle of certificates, signing keys and authentication dependencies must be designed for replacement, not permanence. Practical implication: reduce hard-coded cryptographic dependencies and make key replacement a normal operating event, not a crisis response.

Practical implication: Design certificate and key replacement paths now so identity services can move to post-quantum methods without major rework.


Threat narrative

Attacker objective: The attacker wants to preserve encrypted identity and business data until quantum capabilities can turn captured ciphertext into readable, exploitable information.

  1. Entry occurs when attackers exfiltrate encrypted information from cloud, SaaS, backup or third-party environments without needing to break it immediately.
  2. Escalation happens over time as the same encrypted data retains value and becomes more vulnerable once quantum-capable decryption is feasible.
  3. Impact is deferred compromise of sensitive communications, identity material, signatures and long-lived records that were assumed safe at capture time.

NHI Mgmt Group analysis

Harvest now, decrypt later creates a confidentiality-lifespan problem, not a crypto problem alone. The article is right to frame quantum risk as current because the adversary objective is time-shifted theft. Data that stays sensitive for years is the real target, which means the governance question is how long information must remain confidential and where it exists. Identity, certificate and signing data matter here because they anchor trust over long periods. Practitioners should manage exposure by confidentiality horizon, not by cryptography in isolation.

Quantum migration will fail if organisations treat cryptographic inventory as an IT inventory exercise. The harder problem is mapping trust dependencies across applications, identity systems, cloud integrations and vendor services. A key or certificate is only meaningful when linked to the business process it protects, and that linkage is often missing. That gap becomes a governance failure when teams cannot prioritise which systems must move first. Practitioners should connect cryptographic assets to data criticality and identity workflows.

Crypto-agility is the named control capability that separates post-quantum readiness from wishful planning. Without the ability to replace algorithms and certificates without disruption, organisations will keep delaying migration until risk becomes operationally acute. The article correctly shows that standards alone do not solve replacement complexity across the digital supply chain. This is where identity teams should think beyond authentication technology and into lifecycle manageability. Practitioners should design for replacement, not permanence.

Long-lived personal data turns quantum risk into an identity governance issue as well as a data security issue. Biometric, health and legal records cannot simply be rotated the way a password can, so exposure decisions have to be made upfront. That creates an intersection between identity verification, privacy governance and cryptographic resilience. NIST CSF and NIST post-quantum guidance both point toward ownership, visibility and phased migration. Practitioners should align privacy, IAM and security planning around data that cannot be reissued.

What this signals

Confidentiality lifespan is becoming a practical governance metric for identity and data security teams. If a record or certificate must stay trustworthy for a decade, then ordinary retention and rotation assumptions no longer apply. That creates a planning need for joint visibility across IAM, privacy and data security, especially where identity data is duplicated into backups and third-party systems.

Post-quantum readiness will expose hidden dependency debt in certificate and key management. Teams that cannot replace cryptographic components without application downtime will delay migration and inherit avoidable risk. The strongest programmes will build replacement paths now, not after standards become operationally urgent.

NHI and machine identity governance will remain relevant because long-lived secrets and certificates are part of the same trust chain. Even when the article is about quantum risk, the control logic is familiar: know where the credential or certificate exists, who can use it, and how quickly it can be replaced. That is where the Ultimate Guide to NHIs , Why NHI Security Matters Now remains useful as a lifecycle reference.


For practitioners

  • Map long-lived data first Identify the records, identities and communications that must remain confidential beyond 2030, then rank them by exposure and business value. Focus first on biometric, legal, health and authentication-related data that cannot be reissued if exposed.
  • Build a cryptographic inventory tied to identity systems Create an inventory of algorithms, keys, certificates, libraries and protocols, then link each item to the identity, signing or transport service it protects. Use that map to expose hidden dependencies in cloud integrations, software signing and authentication flows.
  • Reduce duplicate exposure before migration Delete redundant copies, enforce retention policies and remove unnecessary access to sensitive archives across cloud, SaaS, backups and analytics environments. Lowering the number of places encrypted data exists reduces harvest-now risk while migration is still in progress.
  • Design crypto-agile replacement paths Separate cryptographic functions from business logic, standardise approved libraries and centralise certificate and key management so algorithms can be swapped without major rework. Test vendor readiness and update procurement requirements before renewal cycles lock in weak dependencies.

Key takeaways

  • Harvest now, decrypt later is already a present-tense risk because attackers can steal ciphertext long before they can decrypt it.
  • Identity systems are exposed because certificates, signatures and authentication flows depend on cryptography that may not survive the post-quantum transition.
  • The most effective response is to pair sensitive data discovery with cryptographic inventory and crypto-agile replacement planning.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.AM-1Asset management is central to discovering cryptographic dependencies and long-lived data exposure.
NIST SP 800-53 Rev 5SC-13Cryptographic protection directly relates to algorithm strength and transition planning.
NIST AI RMFMANAGEAI RMF is not central, so omitted.

Review SC-13 dependencies and plan replacement paths for cryptography that will not survive quantum attacks.


Key terms

  • Harvest now, decrypt later: An attacker strategy where encrypted traffic or stored data is collected today and decrypted later when better computing power becomes available. It matters to NHI governance because machine identities often protect the data paths and secrets most worth preserving over time.
  • Post-Quantum Cryptography: Cryptographic algorithms designed to remain secure against attacks from sufficiently powerful quantum computers. In practice, PQC is a migration problem as much as an algorithm problem because organisations must replace trust anchors, certificates, and secrets without breaking identity-dependent systems.
  • Crypto-Agility: Crypto-agility is the ability to change cryptographic algorithms, certificates, and trust dependencies without redesigning production systems. It matters because cryptographic standards evolve, and organisations need accurate inventories and automated lifecycle controls before they can migrate safely.
  • Cryptographic Inventory: A cryptographic inventory is a continuously updated record of keys, certificates, algorithms, libraries and trust anchors across an organisation. It is not a spreadsheet or one-time audit output. In practice, it links each asset to ownership, usage, lifecycle state and risk so teams can make remediation decisions.

What's in the full article

Ground Labs' full blog post covers the operational detail this post intentionally leaves for the source:

  • NIST post-quantum standards and the migration timeline details behind FIPS 203, 204 and 205
  • Stepwise guidance for building a cryptographic inventory across applications, keys, certificates and libraries
  • Practical methods for prioritising long-lived data by exposure, sensitivity and confidentiality lifespan
  • Vendor and supply-chain considerations for crypto-agility planning across dependent systems

👉 Ground Labs' full post covers the migration roadmap, data prioritisation logic and crypto-agility steps in more detail.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security and secrets management. It helps practitioners connect identity lifecycle controls to the broader security risks that shape access, trust and resilience.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org