Data encrypted today can be stolen today and read a decade from now, once the machine that breaks the encryption exists. That is the entire threat model behind harvest now, decrypt later, and it does not depend on any breakthrough that has happened yet. It depends on an adversary's patience and a captured copy of your traffic, sitting on a drive, waiting.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
Why this stopped being speculative
For years, quantum decryption was easy for boards to file under someday. That filing is no longer defensible, because the standards bodies stopped waiting for someday and started publishing deadlines.
In August 2024, NIST finalized its first three post-quantum cryptography standards. FIPS 203 defines ML-KEM, the general-purpose encryption standard, built on the algorithm formerly known as CRYSTALS-Kyber, chosen for small keys and fast operation. FIPS 204 defines ML-DSA, the primary digital signature standard, built on CRYSTALS-Dilithium. FIPS 205 defines SLH-DSA, a backup signature standard using different underlying mathematics than ML-DSA, in case a future weakness is found in the lattice-based approach the other two share. NIST's own language on release was not cautious. The agency told administrators to start integrating these standards into their systems immediately, stating plainly that full integration will take time and that waiting for something better is not a reason to delay.
Then NIST followed with a timeline. Its draft report, NIST IR 8547, sets 2030 as the year traditional public key cryptography, meaning RSA and ECDSA, begins to be deprecated, and 2035 as the year those algorithms are disallowed outright. That builds on National Security Memorandum 10 from May 2022, which set 2035 as the broader federal migration target. NIST said openly that cryptographic migrations have historically taken more than a decade to complete. The math on that alone should concern any board that has not started.
The National Security Agency moved on a parallel and, in places, more aggressive track. Its Commercial National Security Algorithm Suite 2.0 requires new National Security Systems deployments to comply starting January 1, 2027. Equipment and services that cannot support CNSA 2.0 must be phased out by December 31, 2030, and use of the compliant algorithms becomes mandatory by December 31, 2031. That is a five-year runway from a standing start, for systems that, by definition, protect information the government has decided matters most.
None of this is a projection of what regulators might eventually ask for. These are published dates, from NIST and NSA, already on the calendar.
What the adversary is actually doing right now
The mechanism that makes today's encrypted traffic tomorrow's readable file does not require a quantum computer to exist yet. It requires only that someone with the resources and patience to wait is collecting encrypted data now, storing it, and holding it until decryption becomes possible.
Nobody can prove exactly how much of this collection is happening, because by design it produces no incident to detect. What can be measured is expert confidence in the timeline that would make it pay off. The Global Risk Institute's Quantum Threat Timeline Report puts the probability of a cryptographically relevant quantum computer, one actually capable of breaking current public key cryptography, at somewhere between 28 and 49 percent within the next ten years, based on its ongoing survey of experts in the field. That is a wide range, and it is meant to be. Nobody credible claims certainty about the date. What the range does establish is that a nontrivial, expert-weighted probability exists inside a decade, which is exactly the window that matters for any data with a confidentiality shelf life longer than ten years.
That shelf life question is where this stops being an abstract cryptography problem and becomes a governance problem. Most organizations have never inventoried which of their data actually needs to stay confidential for a decade or more. Health records, genomic data, long-term intellectual property, national security information, and multi-decade financial or legal agreements all qualify. A password reset token does not. The risk is not evenly distributed across an organization's data, and treating it as if it were leads to either paralysis or a migration effort that protects the wrong things first.
The confidentiality clock
Every category of sensitive data an organization holds has two numbers attached to it, whether anyone has written them down or not. How long that data needs to stay confidential from today, and how long it will take to migrate the systems that protect it to post-quantum algorithms. Call this the confidentiality clock. When the second number is smaller than the first, the data is exposed to harvest now, decrypt later regardless of what the current encryption strength looks like today, because the encryption strength today is not the variable that matters. The variable that matters is whether a readable copy will still be sitting on an adversary's disk when the key finally breaks.
Running this exercise forces a different kind of prioritization than a typical vulnerability scan. A system protecting data with a five-year confidentiality requirement, migrated within two years, is not urgent. A system protecting genomic research data with a thirty-year confidentiality requirement, on a legacy platform with no announced post-quantum roadmap from its vendor, is the most urgent thing in the portfolio, even if it has never triggered a single security alert. Most CISOs can name their highest-risk systems by exploit exposure. Far fewer can name them by confidentiality clock, because almost nobody has built the inventory.
Picture a healthcare system holding twenty years of patient genomic data, encrypted with RSA-2048 in a vendor platform the organization does not control the roadmap for. The data's required confidentiality period, driven by both regulation and the fact that a person's genome does not change, easily exceeds thirty years. Under NIST IR 8547's own timeline, RSA starts being deprecated in 2030, six years out at the time this is written. The confidentiality clock on that genomic data was already negative before this article was drafted. The organization does not get to decide this is not urgent. The math already decided it.
The honest counterargument
The strongest objection to urgency here is not paranoid, it is economic. Migrating cryptographic infrastructure is expensive, disruptive, and, critics correctly note, aimed at a threat that by NIST's own admission may be a decade or more away, with real uncertainty in that estimate. Spending heavily now on a threat with a probability in the 30 to 50 percent range over ten years, when that budget could address ransomware, credential theft, or phishing losses that are certain and happening today, is a defensible allocation argument. Boards that have limited security budgets and a queue of active, provable threats are not wrong to ask why quantum jumps the line.
The answer is that harvest now, decrypt later does not behave like other risks on that list, because it is the only one where the exposure event already happened and cannot be undone. A ransomware attack prevented next year is a ransomware attack that never occurred. Data harvested and stored today is compromised the moment it is copied, whether or not the key ever breaks, because the outcome no longer depends on any control the organization can still apply. Every other item in the risk register can still be prevented. This one, for data already in transit under classical encryption, already cannot be. That asymmetry, not the raw probability of a quantum computer arriving on any particular date, is why this deserves budget now rather than in the year the timeline finally becomes certain. The counterargument wins on cost discipline for short-lived data. It loses on anything the confidentiality clock says needs to survive the decade.
Monday questions for leadership and the board
Ask which categories of the organization's data have a confidentiality requirement of ten years or longer, and whether that inventory has ever actually been built, rather than assumed to not exist.
Ask which of those long-lived data categories are protected today by RSA or ECC-based encryption with no vendor-published post-quantum migration date.
Ask what the organization's internal target date is for beginning FIPS 203, 204, and 205 integration, and compare it honestly against NIST's 2030 deprecation date and NIST's own statement that these migrations take over a decade.
Ask whether any national security, defense, or government-adjacent contracts require CNSA 2.0 compliance, and if so, whether the organization is on pace for the January 2027 new-deployment deadline.
The line that matters
The quantum computer that breaks today's encryption does not need to exist yet to do damage. It only needs to exist before your data stops mattering, and for the data your organization is protecting right now, that clock is already running.