Harvest now, decrypt later (HNDL) is a data-confidentiality risk: an attacker can copy encrypted information today and keep it in the hope of decrypting it later, if a future quantum computer can break the public-key cryptography protecting it. The threat is not proof that quantum computers can break ordinary encryption today. It matters now when information must remain secret for years or decades, because the data can be collected before it can be decrypted.
How a harvest-now, decrypt-later attack works
An attacker does not have to read captured information immediately. They can retain encrypted network traffic or other data and wait for a future capability to defeat the public-key cryptography used to protect it. NIST explains: “Even if an adversary can’t crack the encryption that protects our secrets at the moment, it could still be beneficial to capture encrypted data and hold onto it, in the hopes that a quantum computer will break the encryption down the road.” NIST’s post-quantum cryptography explainer describes why migration matters before that capability exists.
The practical exposure depends on the data’s required secrecy lifetime, the cryptography protecting it, and how long it takes the organization to change affected systems. Information that will lose sensitivity soon is different from information that must remain confidential for decades. NIST cites health records, financial data, intellectual property and national-security information as examples that may need long-term protection.
Why plan the transition before quantum computers arrive?
No one knows when a cryptographically relevant quantum computer will be built. NIST notes that some predictions put it at less than 10 years, but that is a reported possibility, not a consensus date or forecast. Separately, NIST says the move from algorithm standardization to integration has historically taken 10 to 20 years; the explainer does not specify the year for that historical figure. That interval describes migration complexity, not a countdown to quantum capability.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
NIST’s advice is to start migration planning rather than wait for a quantum milestone. Its mathematician Dustin Moody, who leads NIST’s post-quantum cryptography standardization project, said: “We encourage organizations to begin their transition to these standards immediately to ensure their data remains secure in the quantum era.”
Which post-quantum standards are ready?
NIST finalized three post-quantum cryptography standards in 2024 and says they are ready to implement. Its current post-quantum cryptography page identifies ML-KEM and ML-DSA as finalized standards. These are distinct from algorithms still under consideration; organizations should confirm the status and implementation guidance for the specific standard and product they plan to use.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
NIST IR 8547, published as an initial public draft on November 12, 2024, describes the expected transition from quantum-vulnerable cryptographic standards to post-quantum digital-signature and key-establishment schemes. Its listed comment period closed January 10, 2025. It is a draft, not a final transition mandate. The U.S. government has separately set a 2035 goal to mitigate as much quantum risk as feasible; that is a government policy goal, not a prediction of when a capable quantum computer will exist.
What the 2026 HAWK case says about AI—and what it doesn’t
NIST reports that Anthropic announced on July 28, 2026, that an AI model helped discover a vulnerability in HAWK, a lattice-based signature algorithm then being considered for standardization. The HAWK team withdrew it from consideration, and NIST says it will not be standardized or deployed. NIST also says the finding does not affect finalized standards such as ML-KEM and ML-DSA, which rely on different mathematical foundations.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
This is a specific example of AI assisting security analysis of a candidate algorithm. It does not show that AI has broken finalized post-quantum standards, that AI makes quantum decryption possible today, or that HAWK changes the HNDL timeline. Candidate algorithms can be scrutinized and withdrawn without implying that finalized standards have failed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How organizations can start reducing HNDL exposure
- Identify long-lived secrets. Find data whose confidentiality must last for years, including sensitive information sent over networks and data retained in storage. Classify it by sensitivity and required secrecy lifetime rather than assuming every encrypted record has equal urgency.
- Build a cryptographic inventory. Locate where public-key algorithms are used across systems, applications, protocols, products and services. Record dependencies so that a change to one component does not overlook connected systems.
- Prioritize migration work. Consider the data’s sensitivity and secrecy lifetime, use of quantum-vulnerable public-key cryptography, system criticality and dependencies. These are planning factors, not a universal scoring formula.
- Set a migration roadmap and engage providers. Ask technology vendors when and how their products and services will support post-quantum cryptography. Include PQC support in procurement and IT modernization discussions.
- Evaluate interoperability and performance. Test how migrated systems work with existing protocols and services, and benchmark them in the relevant environment before broad deployment.
NIST NCCoE’s post-quantum cryptography FAQ frames migration work around cryptographic visibility, risk management, interoperability and benchmarking. NIST also recommends organizations discuss roadmaps with providers in its guidance on safeguarding computers with new standards.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

