CISA, the NSA, the UK NCSC, ENISA and the ACSC have each formally confirmed harvest-now-decrypt-later collection as an active, ongoing operation by multiple nation-state actors. The premise is simple: capture encrypted traffic today, store it, and decrypt it when the capability exists.
This desk is careful with claims about future capability, and this one does not depend on any. The collection is happening now and is confirmed. Whether and when the decryption becomes feasible is a separate question that the collectors are evidently willing to bet on.
The Deadline Is Set By Your Data, Not By The Technology
The framing that matters is not when a quantum computer breaks RSA. It is how long a given piece of information needs to remain confidential.
A session cookie needs minutes. A price negotiation needs months. A patient record, an intelligence source’s identity, a state’s diplomatic traffic, a person’s biometric enrolment — these need decades. For anything in the last category, traffic captured today is already exposed if the capability arrives within its confidentiality lifetime.
Which Is Why The Argument About Timelines Is Beside The Point
Debate about whether a cryptographically relevant machine arrives in five years or twenty is genuinely unresolved, and it is the wrong axis for a defender.
An organisation only needs to ask a question it can answer from its own records: what do we transmit that must still be secret in fifteen years? If the answer is anything, the risk is present-tense regardless of who is right about the timeline.
What This Means For The Files In This Database
The categories this desk has covered with the longest confidentiality requirements are exactly the ones exposed here: biometric registers as in 26-0324 and 26-0217, national identity systems, lawful-intercept infrastructure as in 26-0715, and health records.
None of those can be re-issued when the encryption fails, which is the same structural problem in a different layer.
Compiled from published agency guidance and analysis, listed below. We make no claim about when quantum decryption capability will exist; the confirmed fact is the collection activity. Corrections: corrections@forensicpost.com.
- Harvest now, decrypt later: quantum security riskPalo Alto Networks
- Harvest now, decrypt later: a guide to post-quantum cryptographic migrationMedium — Adnan Masood
- Post-quantum cryptography: harvest-now readinessServnet UK