Quantum computers capable of breaking today’s public-key encryption don’t exist yet. The data an attacker steals and stores today, to decrypt once they do, is already being collected — which is why post-quantum planning is a today problem, not a someday one.
By VVnT SeQuor Team··3 min read
In this article
01
The attack that’s already happening
“Harvest now, decrypt later” describes a strategy, not a prediction: an adversary…
02
What NIST’s post-quantum standards actually change
NIST finalized its first set of post-quantum cryptography standards in August 2024 — ML-KEM…
03
Where to start: a crypto inventory most organizations don’t have
Most organizations cannot currently answer “where do we use RSA or ECC, and for what”…
The attack that’s already happening
“Harvest now, decrypt later” describes a strategy, not a prediction: an adversary intercepts and stores encrypted traffic or exfiltrated data today, betting that a sufficiently capable quantum computer will eventually be able to break the RSA or elliptic-curve encryption protecting it. For data with a long confidentiality shelf life — health records, government communications, trade secrets, anything that still matters in ten or fifteen years — that bet doesn’t need quantum computing to arrive soon to be worth making now.
What NIST’s post-quantum standards actually change
NIST finalized its first set of post-quantum cryptography standards in August 2024 — ML-KEM (key encapsulation, derived from CRYSTALS-Kyber) for encryption and ML-DSA (digital signatures, derived from CRYSTALS-Dilithium) chief among them. That finalization matters because it moves post-quantum cryptography from “candidate algorithms being evaluated” to “standards vendors can actually build against” — browsers, cloud providers, and security libraries are rolling in support on a real, if staggered, timeline.
Most organizations skip straight to step three without ever completing step one — the inventory is slow, unglamorous work, but it’s what makes every later step possible to prioritize correctly.
Where to start: a crypto inventory most organizations don’t have
Most organizations cannot currently answer “where do we use RSA or ECC, and for what” without a dedicated inventory effort — cryptography is embedded in TLS configurations, VPNs, code-signing processes, and third-party libraries, rarely centrally tracked.
Prioritize by data sensitivity and confidentiality lifespan, not by system criticality alone — a system protecting data that’s worthless in five years is a lower migration priority than one protecting data that needs to stay confidential for decades, even if the former is otherwise more business-critical.
Flag vendor and third-party dependencies explicitly — your own migration plan is incomplete if a critical vendor’s cryptography roadmap isn’t part of the picture.
A realistic migration sequence
Most guidance converges on hybrid approaches first: running classical and post-quantum algorithms together during a transition period, so a flaw discovered in the newer post-quantum algorithms doesn’t leave systems with no proven fallback. Full migration to post-quantum-only cryptography follows once hybrid approaches have matured in production and vendor support is broad enough that it’s not a bespoke engineering effort for every system.
This isn’t a 2026 deadline problem. No regulator has set a hard post-quantum migration deadline for most industries yet. The reason to start the inventory now is that it’s slow, cross-cutting work with a long tail — starting it two years before you need results is a very different position than starting it once a deadline or incident forces the pace.
Frequently asked questions
Do we need to migrate everything to post-quantum cryptography right now?
No — the realistic first step is a cryptographic inventory and a prioritized plan based on data sensitivity and confidentiality lifespan, not an immediate wholesale migration. Systems protecting long-lived sensitive data deserve earlier attention than systems protecting short-lived or already-public data.
Is post-quantum cryptography the same as quantum encryption?
No — post-quantum cryptography refers to classical algorithms (like ML-KEM and ML-DSA) designed to resist attacks from quantum computers, run on today’s ordinary hardware. Quantum encryption (quantum key distribution) is a different, much less widely deployed approach that requires specialized hardware.
How urgent is this really, given quantum computers that can break RSA don’t exist yet?
The urgency is specific to data with a long confidentiality shelf life being harvested today, not to an imminent quantum breakthrough. For data that only needs to stay confidential for a year or two, the urgency is genuinely low; for data that needs to stay confidential for a decade or more, the harvesting risk is active today regardless of when a capable quantum computer actually arrives.
This is general guidance, not a scoped engagement plan. If you want one for your specific environment, talk to our Cybersecurity & Cyber Assurance practice.