Skip to main content
Skip to content
Home/Knowledge Center/What Is Harvest-Now-Decrypt-Later?
Threats7 min read

What Is Harvest-Now-Decrypt-Later?

The quantum threat that is active today, not in the future.

What Is It?

Harvest-now-decrypt-later (HNDL) is a threat model in which an adversary records and stores encrypted network traffic or data today, with the intent to decrypt it once a cryptographically relevant quantum computer is available. The adversary does not need to break the encryption now they simply wait until the technology catches up.

The HNDL threat reframes the quantum risk from a future problem to a present one. Any encrypted data captured today that must remain confidential for years or decades is potentially exposed right now, before a single quantum computer capable of breaking encryption has been built.

Governments, intelligence agencies, and sophisticated threat actors are known to operate large-scale passive collection programs. The addition of long-term storage to a program that already captures encrypted traffic converts a future quantum capability into a present harvest-now-decrypt-later operation.

Why Does It Matter?

Most cryptographic threats require the adversary to act at the time of the attack. HNDL breaks this assumption. An adversary operating today with entirely classical infrastructure can execute a successful HNDL campaign if they have the ability to capture network traffic and the storage capacity to retain it.

The severity of HNDL risk depends on data lifetime, not on the current timeline for quantum computers. A system protecting communications that must remain confidential for 30 years health records, classified government communications, long-term financial archives faces immediate HNDL exposure even if quantum computers are two decades away. The question to ask is not 'when will quantum computers arrive?' but 'how long does this data need to remain secret?'

NSA, CISA, and NIST all cite HNDL as the primary driver for beginning PQC migration now. The window to protect data in transit closes the moment it is transmitted. Post-quantum key exchange that has not been deployed cannot retroactively protect traffic that has already been harvested.

How It Works

The HNDL attack has two distinct phases, separated by potentially years or decades.

Phase 1: Harvest

The adversary records encrypted network traffic. This requires network access passive interception on shared infrastructure, compromised network nodes, tapped fiber, or insider access. No decryption occurs at this stage. The effort is largely storage and collection logistics, which are well within the capability of sophisticated nation-state actors today.

Phase 2: Decrypt later

Once a cryptographically relevant quantum computer is available, the adversary runs Shor's algorithm against the recorded session key exchange (ECDH or RSA key transport) to recover the session key, then uses that key to decrypt the stored session data. This does not require continued access to either original party only the stored ciphertext.

Enterprise Impact

HNDL risk is concentrated in specific data categories. Organizations should assess their exposure by data type and confidentiality lifetime.

Government and classified communications

Long retention requirements and high adversary interest make this the highest-priority category. NSA CNSA 2.0 addresses this directly.

Health records

Protected for decades under HIPAA and equivalent regulations. Patient data collected today may require confidentiality protection for 30+ years.

Financial records and transaction archives

Regulatory audit and compliance retention can extend 7-20 years for certain record types.

Intellectual property and trade secrets

Competitive value extends for years. Early-stage product plans, formulations, and technical data harvested today remain valuable after quantum decryption.

Root CA and code-signing keys

Compromise enables retroactive authentication fraud: previously signed code or certificates could be forged in a way that is indistinguishable from original signatures.

NIST Guidance

Mitigating HNDL requires transitioning key exchange mechanisms to post-quantum algorithms before the data is in transit. NIST provides clear guidance on this.

FIPS 203: ML-KEM

The designated standard for post-quantum key encapsulation. Deploying ML-KEM (or hybrid ECDH + ML-KEM) is the primary technical mitigation for HNDL risk on data in transit.

Hybrid key exchange

NIST and NSA recommend deploying hybrid key exchange (combining ECDH with ML-KEM) as an immediate interim step. This provides post-quantum protection while maintaining compatibility with systems that do not yet support ML-KEM.

NIST IR 8547 (draft)

Identifies HNDL as a key driver for migration urgency and provides guidance on prioritizing key exchange mechanisms for early migration.

References

Apply This to Your Organization

Schedule a Consultation

A post-quantum readiness specialist will walk through how these concepts apply to your specific systems, data, and timeline.