Skip to content
Cyber Defense Technologies

Insights

Harvest Now, Decrypt Later: Why Post-Quantum Planning Starts Today

Encrypted data stolen today could be decrypted once cryptographically relevant quantum computers exist. What the threat is, what NIST and NSA have published, and the first steps every organization should take.

By Cyber Defense Technologies December 2, 2025 5 min read

Most of the internet's security rests on a small number of public-key algorithms, such as RSA and elliptic curve cryptography. They protect web traffic, VPNs, email, software updates and digital signatures. Their strength comes from mathematical problems that classical computers cannot solve in any practical amount of time.

A large, fault-tolerant quantum computer running Shor's algorithm could solve those problems efficiently. Such a machine, often called a cryptographically relevant quantum computer, does not exist publicly today, and estimates of when one might arrive vary widely. But waiting for certainty would be a mistake, for one reason.

The harvest-now, decrypt-later threat

Encrypted data does not need to be decrypted when it is stolen. An adversary can record encrypted traffic today, store it, and decrypt it once quantum capability is available. For information that loses value quickly, that delay may not matter. For information that must remain confidential for years or decades, such as national security information, weapons designs, health records, intellectual property and long-term financial data, the risk exists now.

That is why governments treat quantum readiness as a present-day priority rather than a future one.

What has been published

NIST's post-quantum standards

In August 2024, NIST published its first three post-quantum cryptography standards:

  • FIPS 203 (ML-KEM): a key-encapsulation mechanism for establishing shared secrets, based on CRYSTALS-Kyber
  • FIPS 204 (ML-DSA): a digital signature algorithm, based on CRYSTALS-Dilithium
  • FIPS 205 (SLH-DSA): a stateless hash-based digital signature algorithm, based on SPHINCS+

In March 2025, NIST selected HQC as an additional key-encapsulation algorithm, based on different mathematics, as a backup. A standard for FN-DSA, based on the FALCON signature scheme, has also been in development. Organizations should track NIST's announcements for final standards.

NSA's CNSA 2.0

For national security systems, NSA's Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) specifies quantum-resistant algorithms and a transition timeline. National Security Memorandum 10 set the goal of mitigating quantum risk to federal systems by 2035.

CNSA 2.0 milestones for national security systems

  1. 2025

    Support and prefer begins

    Software and firmware signing, web browsers, servers and cloud services should support and prefer CNSA 2.0 algorithms.

  2. 2026

    Networking equipment

    VPNs and routers should support and prefer CNSA 2.0.

  3. January 1, 2027

    New acquisitions

    New national security system acquisitions should support CNSA 2.0, unless noted otherwise.

  4. 2030 to 2033

    Exclusive use

    Signing and networking equipment move to exclusive use by 2030; browsers, servers, cloud, operating systems and most other categories by 2033.

  5. 2035

    Quantum-resistant

    The goal, in line with NSM-10, for national security systems to be quantum-resistant.

Summarized from NSA’s CNSA 2.0 guidance; check NSA for the authoritative, current dates.

Why migration takes so long

Replacing cryptography is not like applying a patch:

  • Cryptography is everywhere. In applications, libraries, operating systems, network devices, hardware security modules, smart cards, embedded systems and third-party services.
  • Much of it is hidden. Embedded in vendor products and legacy code, often undocumented.
  • Dependencies are deep. A change to certificates or protocols ripples through clients, servers and partners.
  • New algorithms behave differently. Post-quantum keys and signatures are larger, which can affect performance, bandwidth, storage and protocols with size limits.
  • Hardware has long lives. Devices fielded today may still be in use when quantum capability arrives.

Previous cryptographic transitions, such as moving away from older hash algorithms, took many years. This one is larger.

First steps

1. Build a cryptographic inventory

Find out where cryptography is used, which algorithms and key sizes, what data each protects, how long that data must stay secret, and who owns each system. Without an inventory, prioritization is guesswork.

2. Prioritize by data lifespan and exposure

Systems that protect long-lived secrets and whose traffic crosses networks an adversary could intercept come first. Systems protecting short-lived data can follow.

3. Engage your vendors

Ask suppliers of software, hardware, cloud services and network equipment for their post-quantum roadmaps. Much of your migration will arrive through vendor updates, and procurement is the easiest place to require readiness.

4. Build crypto agility

Design systems so algorithms can be changed through configuration rather than redesign. Crypto agility makes this transition, and future ones, far less painful.

5. Consider hybrid approaches

During the transition, many implementations combine a classical and a post-quantum algorithm, so security holds as long as either one remains unbroken. Follow applicable guidance: NSA's CNSA 2.0 guidance for national security systems differs from commercial practice in some respects.

6. Test before you deploy

Post-quantum algorithms change key and signature sizes and performance characteristics. Test interoperability, performance and failure modes in realistic environments.

A leadership issue, not only a technical one

Quantum readiness requires budget, vendor management, architecture decisions and multi-year planning. It belongs on the leadership agenda, with an accountable owner and a roadmap, rather than being left to individual engineering teams.

Frequently asked questions

When will quantum computers break today's encryption? No one knows precisely, and public estimates vary widely. Planning does not depend on the exact date: data that must stay secret beyond it is at risk now, and migration takes years.

Should we wait for the standards to settle? The core NIST standards, FIPS 203, 204 and 205, are final. Starting with the inventory, vendor engagement and crypto agility is useful regardless of future additions.

Do we need to replace AES? Symmetric encryption is far less affected by known quantum attacks. Using sufficiently large keys, such as AES-256, is generally recommended. The priority is public-key cryptography.

How CDT can help

CDT's quantum readiness and post-quantum security services include cryptographic discovery and inventory, quantum risk assessment and roadmaps aligned with NSM-10 and CNSA 2.0, and migration engineering to the NIST standards.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.