PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Explainer3 min readReviewed September 20267 sources

Harvest now, decrypt later explained

Data encrypted today with quantum-vulnerable key exchange could be recorded now and decrypted later. That is why post-quantum planning cannot wait for a quantum computer to exist.

Key takeaways
  • CISA, NSA and NIST describe threat actors who may target data today that needs long-term protection, in a 'catch now, break later' or 'harvest now, decrypt later' operation.
  • The risk falls on key establishment and public-key encryption protecting data with a long secrecy lifetime.
  • Traffic crossing public networks is exposed earliest.
  • Hybrid post-quantum key exchange, now a default in OpenSSL 3.5, addresses the risk for new sessions.
  • A QBOM identifies which systems combine quantum-vulnerable key exchange with long-lived data.

What government agencies say

The joint CISA, NSA and NIST factsheet on quantum readiness, published in August 2023, puts it plainly: "Cyber threat actors could be targeting data today that would still require protection in the future (or in other words, has a long secrecy lifetime), using a catch now, break later or harvest now, decrypt later operation" [1].

The UK NCSC makes the same point in its guidance on preparing for post-quantum cryptography: "For key establishment and encryption, there is a risk from an attacker collecting and storing data today and decrypting it at some point in the future" [2]. It adds that for organisations needing long-term protection of very high-value data, the possibility of a future cryptographically relevant quantum computer "is a relevant threat now" [2].

Canada's federal migration roadmap notes that systems protecting confidentiality across public networks face earlier risk because of harvest-now, decrypt-later threats, making them candidates for accelerated migration [3].

How the attack works

  1. An adversary records encrypted traffic or copies encrypted data at rest, including the key-exchange messages.
  2. The data is stored. Storage is cheap, and the adversary does not need to decrypt anything yet.
  3. If a sufficiently capable quantum computer becomes available, the adversary uses it to recover keys from the recorded public-key exchange, then decrypts the data.

Nothing in this sequence requires a quantum computer today. That is why agencies treat it as a present-day planning issue, without needing to predict when step 3 becomes possible. This article makes no such prediction.

What is exposed

CryptographyHarvest-now exposure
Key establishment with RSA, finite-field Diffie-Hellman or elliptic-curve Diffie-Hellman (for example in TLS, VPNs, SSH)Exposed: recorded handshakes could later yield session keys
Public-key encryption of data or keys (for example RSA-wrapped keys)Exposed
Digital signatures (RSA, ECDSA)Not exposed in the same way; forgery requires the capability at the time of attack, though long-lived roots of trust still need early migration
Symmetric encryption (AES) with keys not derived from quantum-vulnerable exchangeMuch less affected; the NCSC says AES with at least 128-bit keys can continue to be used [2]

Which data matters

The deciding factor is secrecy lifetime. Examples include health and genetic records, long-term financial and identity data, legal and state secrets, intellectual property and design data, and credentials or keys that remain valid for years. Mosca's inequality captures the logic: if the time data must stay secure plus the time needed to migrate exceeds the time until current public-key cryptography is broken, the problem already exists [4].

Mitigations

  • Post-quantum key establishment. ML-KEM, standardised in FIPS 203, is NIST's key-encapsulation mechanism designed to resist quantum attack [5].
  • Hybrid key exchange during transition. A PQ/T hybrid scheme combines at least one post-quantum and one traditional algorithm [6]. OpenSSL 3.5 changed its default TLS key shares to offer X25519MLKEM768 alongside X25519 [7]. Hybrid key exchange protects new sessions; it does not protect data already recorded.
  • Reduce what can be harvested. Shorter retention, fewer copies and minimising sensitive data in transit across public networks all reduce exposure.
  • Prioritise with an inventory. The CISA, NSA and NIST factsheet recommends a cryptographic inventory that documents protection lengths for sensitive data sets [1].

Where the QBOM fits

A QBOM links each quantum-vulnerable key-establishment asset to the data it protects and that data's lifetime. Filtering for key establishment, public-network exposure and long lifetime gives you the harvest-now priority list. See Quantum risk assessment and What is a QBOM?

How IntelliXBOM helps

IntelliXBOM correlates cryptographic assets such as TLS and VPN key-exchange configurations with the software, hardware and business services that use them. With version history and diffs, teams can show when a service moved from classical to hybrid or post-quantum key exchange, and produce timestamped evidence for that change.

Frequently asked questions

What does harvest now, decrypt later mean?

It describes adversaries collecting encrypted data today and storing it so they can decrypt it later if quantum computers become able to break the public-key cryptography used to protect it. CISA, NSA and NIST also call it catch now, break later.

Does hybrid key exchange protect data already captured?

No. Hybrid or post-quantum key exchange protects sessions established after it is deployed. Data recorded earlier under classical key exchange remains exposed, which is why early migration matters for long-lived data.

Is harvest now, decrypt later a threat to digital signatures?

Not in the same way. Forging a signature requires the capability at the time of the attack, so recorded signatures are not the main concern. Long-lived signing keys embedded in devices still need early migration because they are hard to replace.

Sources

  1. Quantum-Readiness: Migration to Post-Quantum Cryptography (August 2023)CISA, NSA and NISTwww.nccoe.nist.gov/sites/default/files/2023-08/quantum-readiness-fact-sheet.pdf
  2. Next steps in preparing for post-quantum cryptographyUK National Cyber Security Centrewww.ncsc.gov.uk/paper/next-steps-in-preparing-for-post-quantum-cryptography
  3. Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)Canadian Centre for Cyber Securitywww.cyber.gc.ca/en/guidance/roadmap-migration-post-quantum-cryptography-government-canada-itsm40001
  4. Cybersecurity in an era with quantum computers: will we be ready? (Mosca, 2015)IACR Cryptology ePrint Archiveeprint.iacr.org/2015/1075.pdf
  5. FIPS 203, Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM)NISTcsrc.nist.gov/pubs/fips/203/final
  6. RFC 9794, Terminology for Post-Quantum Traditional Hybrid Schemes (June 2025)IETFwww.rfc-editor.org/rfc/rfc9794.html
  7. OpenSSL 3.5 release notesOpenSSL Libraryopenssl-library.org/news/openssl-3.5-notes/

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related QBOM guides

Across the BOM Suite

Put your QBOM under governance.Quantum readiness with continuous correlation and timestamped evidence.