All posts

PQC Basics · Part 6 of 10

Harvest Now, Decrypt Later: The Quantum Data Risk Explained

August 21, 2026 ·  PQCClear  ·  6 minute read

This is the idea that turns everything in this series from worth planning for into worth acting on now. It has a slightly dramatic name for something that's actually simple to explain: harvest now, decrypt later.

The Idea in Two Steps

An attacker doesn’t need to break your encryption today to benefit from breaking it years from now. They just need to have a copy of the data waiting when they can.

Back in part 4, we established something important: no quantum computer capable of breaking today’s common encryption exists yet, and serious estimates put that possibility years away. It’s tempting to conclude that means there’s time to wait. Harvest now, decrypt later is the reason that conclusion is wrong.

Happening now

Copy the encrypted data

An attacker intercepts or exfiltrates encrypted data today. They cannot read it. That's fine. Reading it isn't the step they're on yet. Storage is cheap, and the data isn't going anywhere.

Happening later

Decrypt it once possible

Years from now, once a sufficiently powerful quantum computer exists, the attacker goes back to their stored copy and decrypts it then. The theft already happened. Only the reading was delayed.

Why This Collapses the Wait-and-See Strategy

If you only think about the moment of decryption, waiting seems reasonable. Nothing readable happens until a quantum computer exists, so why not deal with it when one does? Harvest now, decrypt later breaks that logic by moving the moment that actually matters. The theft, the part you could have prevented, already happened, potentially years before the decryption itself.

By the time a capable quantum computer exists, data encrypted with today’s vulnerable methods, and already sitting in an attacker’s storage, becomes exposed all at once, going back potentially years. Waiting doesn’t avoid the exposure. It just delays discovering it happened.

Not All Data Is an Equally Attractive Target

This is the detail that makes the risk practical to reason about rather than just alarming. Stealing and storing data for years only makes sense to an attacker if the data is still worth something years later. A great deal of data isn’t.

Low harvest value

Short-lived by nature

  • A one-time login code, valid for two minutes
  • A session token that expires when you log out
  • A live video call, watched once and gone

High harvest value

Sensitive for years or decades

  • Financial account and transaction records
  • Health records
  • Long-term loan and mortgage documents
  • Government and national security records

This is exactly why data retention matters as much as the encryption method itself when evaluating this risk, and it’s part of why a real inventory, the whole subject of part 1, needs to capture not just what encryption protects something, but how long that something stays sensitive.

The theft isn’t in the future. Only the reading is.

Put parts 5 and 6 together and the shape of the problem becomes clear: banks depend on vendors they don’t fully see into, and some of what those vendors are protecting right now is exactly the kind of long-lived data worth harvesting today. Which raises a very practical question for anyone doing this assessment: what actually counts as a good answer when you ask a vendor about their encryption? “Industry-standard encryption” clearly isn’t one. The next post is about what is.

Find out which vendors are still harvestable

PQCClear assesses the quantum readiness of every fintech vendor in your portfolio: a PQC Readiness Score, a full CBOM, and an examination-ready report for each one.

Request access
harvest now decrypt laterquantum data riskdata retentioncryptographic inventory

PQC Basics is an ongoing series from PQCClear explaining post-quantum cryptography readiness in plain language, one idea at a time. This post represents PQCClear’s own editorial explanation and should not be construed as technical, legal, or regulatory advice.

Key sources: Quantum-Readiness: Migration to Post-Quantum Cryptography (CISA, NSA, and NIST joint factsheet, August 2023); NIST IR 8547, Transition to Post-Quantum Cryptography Standards (initial public draft, November 2024).