Join our Newsletter — 33% off our NHI Course
Home› FAQ› Foundations & NHI Taxonomy› Why does Harvest Now, Decrypt Later change the…
Foundations & NHI Taxonomy

Why does Harvest Now, Decrypt Later change the PQC timeline?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Foundations & NHI Taxonomy

Because the risk begins when encrypted data is collected, not when quantum decryption becomes practical. If sensitive information has a long retention life, it may still be valuable when future capabilities arrive, so delay increases exposure even if today’s encryption remains strong.

Why the timeline shifts once “harvest” starts

Harvest Now, Decrypt Later changes the PQC timeline because the threat is front-loaded. Adversaries do not need quantum computers today to create future exposure; they only need to capture ciphertext, archives, or backups that are likely to remain valuable long enough for later decryption attempts.

The practical implication is that waiting for quantum capability to become visible in the market is too late for data with a long shelf life. The timeline becomes a question of data retention, confidentiality horizon, and migration lead time, not just a question of when quantum decryption becomes technically feasible.

That is why post-quantum planning starts with the lifespan of the information itself. If the data must stay confidential for years, the cryptographic transition has to begin well before the quantum threat is operational.

What makes retained data the real exposure window

Encrypted data that is short-lived may never overlap with future quantum capabilities, but long-retention data often will. The risk is highest where records are stored for compliance, intellectual property, health, financial, government, or strategic reasons, because those datasets are attractive to stockpile now and decrypt later.

Encryption strength today is only part of the decision. What matters is whether the protected asset will still matter at the point when attacker capability catches up. That is why teams need to think in terms of confidentiality duration, not just current algorithm strength.

Transition planning also has to account for the hidden backlog of archived material, backups, transcripts, logs, and replicated copies. Those stores often outlive the systems that created them, so the migration problem is larger than replacing a single live channel.

What the PQC timeline should be tied to

The right timeline is usually driven by inventory, migration complexity, and data sensitivity rather than a single public quantum milestone. Organisations need to know where strong public-key cryptography is used, which data flows depend on it, and how long each protected class must remain secret.

That is why crypto-agility and cryptographic inventory matter so much. If you cannot quickly identify which systems use vulnerable algorithms, you cannot shorten the window between discovery and protection. NHIMG’s Post-Quantum Readiness for Identity and PKI is useful here because it connects PQC migration timelines to inventory, certificates, signing, and crypto-agility.

For machine and certificate-heavy environments, the transition also intersects with lifecycle management. NHIMG’s Machine Identity, PKI and Certificate Lifecycle Guide is relevant because certificate renewal, automation, and key protection affect how quickly organisations can change cryptographic trust at scale.

Risk and Threat Considerations

Harvest-now collection creates a delayed compromise model: the protected data may be safe today, but it becomes retrospectively readable if the same ciphertext is still available when decryption capability improves. That makes long-lived archives and replicated backups especially exposed.

Failure mechanism: The protection fails when the retention period outlasts the safe life of the encryption scheme, allowing previously captured ciphertext to become intelligible after future cryptanalytic or quantum advances.

Impact: Confidentiality loss can arrive years after collection, with no fresh intrusion required, which can expose sensitive records, weaken legal and commercial secrecy, and force expensive emergency migration.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-57, NIST CSF 2.0 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-57key management lifecycle — Key lifecycle, cryptoperiods and algorithm selectionPQC timing depends on key lifetimes and algorithm transition planning.
Recommendation — Set cryptoperiods and rotation plans to retire vulnerable algorithms before long-retention data outlives them.
NIST CSF 2.0ID.RA-01 — Asset vulnerabilities are identified and recordedPQC planning starts by identifying where vulnerable cryptography protects long-lived data.
Recommendation — Inventory cryptographic dependencies so you can prioritise the longest-retained data first.
ISO/IEC 27001:2022A.8.24 — Use of cryptographyThe topic is about cryptographic protection and migration risk for long-lived data.
Recommendation — Review cryptographic use across retention-heavy systems and plan transition controls for sensitive records.
CIS Controls v8CIS-3 — Data ProtectionHarvest-now exposure is fundamentally about protecting retained sensitive data over time.
Recommendation — Classify and protect long-lived sensitive data with stronger migration and retention controls.
OWASP Non-Human Identity Top 10NHI-07 — Long-Lived SecretsLong-lived secrets and stored credentials face delayed exposure as cryptographic protection ages.
Recommendation — Shorten secret lifetimes and rotate stored credentials before their protection window becomes stale.

Practitioner Guidance

What to prioritise: Classify data by confidentiality horizon, not only by sensitivity. The assets that need the fastest PQC attention are the ones that must stay secret the longest, especially where copies persist in backups, archives, or third-party retention systems.

What to verify: Confirm where public-key cryptography is used in storage, transport, signing, and key exchange, then check whether those dependencies exist in systems with long-lived records. If you cannot map the exposure path, you cannot justify the migration sequence.

Decision rule: If the data is likely to remain valuable when future decryption becomes practical, treat PQC as a current programme, not a future watch item. If the data expires quickly, the urgency is lower and migration can be staged accordingly.

Practitioner takeaway: The timeline should be set by the lifetime of the secret, not by the date quantum computing becomes headline news.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org