Q-Shield

Harvest Now, Decrypt Later: Why Long-Lived Secrets Are Already Exposed

Harvest now, decrypt later is the threat model that makes post-quantum migration a today-problem — even though Q-Day is uncertain. What it is, who it affects, and the rational response.

The threat model in plain terms

Most attacks assume the attacker acts and profits in roughly the same moment: break in, read the data, leave. Harvest now, decrypt later breaks that assumption in two. The attacker does two things at two different times.

First, now: they record encrypted traffic as it passes — or copy encrypted archives — and simply store the ciphertext. They cannot read it. They do not try to. They keep it.

Second, later: once a quantum capability able to break today's public-key cryptography exists, they return to the stored ciphertext and decrypt it.

Nothing about step one looks like an attack. There is no breach to detect, no alarm to trip. The data was encrypted, and it stayed encrypted. The exposure is created quietly at capture time and only realized years later. That gap between capture and decryption is the entire point of the model.

Why an uncertain Q-Day still makes this a today-problem

It is tempting to file this under "future risk." The reasoning fails on one detail: exposure is fixed at the moment of capture, not at the moment of decryption.

The arrival of a cryptographically relevant quantum computer — one able to run Shor's algorithm against the RSA and elliptic-curve systems that protect most traffic today — is genuinely uncertain. Researchers disagree about the timeline, and there is no authoritative date. We treat Q-Day as an open question, and we will not sell it as a countdown.

But the honest version of the uncertainty cuts the other way from complacency. You do not need to know *when* Q-Day arrives to know whether a given secret is exposed. You only need to ask one question: must this data stay confidential past the point where the timeline becomes plausible? If yes, and it can be captured today, it is already at risk — regardless of the exact date. Waiting for certainty about the date is not caution; it is deferring a decision you already have enough information to make.

Confidentiality lifetime is the deciding variable

Not all data carries the same harvest-now exposure. The variable that separates the exposed from the safe is confidentiality lifetime — how long a secret must remain secret.

  • Long confidentiality lifetime — health records, legal and financial archives, government and defense communications, intellectual property and source code, long-term keys and credentials. These may need to stay confidential for a decade or more, well past any plausible Q-Day. If captured today, they are exposed today.
  • Short confidentiality lifetime — a session token that expires in minutes, a one-time code, ephemeral state. Even if captured, there may be nothing left to protect by the time decryption is feasible.

This is why "encrypt everything the same way" is not a risk strategy. Two secrets protected by the identical algorithm can carry completely different harvest-now exposure, purely because one must outlive the migration window and the other does not. Any rational response has to rank by confidentiality lifetime, not treat every record as equal.

The rational response: inventory, then rank

If exposure is set at capture time and driven by confidentiality lifetime, the response follows directly — and it is not panic.

1. Find what you have. You cannot rank secrets you cannot see. A cryptographic inventory catalogues where and how cryptography is used across your systems: the algorithms, key sizes, protocols, and certificate lifetimes, and the places each is relied upon. Unknown cryptography cannot be assessed for harvest-now exposure at all.

2. Rank by risk, lifetime included. With the inventory in hand, score each finding so the longest-lived, most exposed secrets surface first. Q-Shield's quantum risk scoring does this on five axes (five-axis QRS), with confidentiality lifetime as one of the axes — precisely because harvest now, decrypt later makes lifetime load-bearing, not incidental.

3. Sequence the migration. The ranking feeds a NIST-aligned migration roadmap toward ML-KEM (standardized as FIPS 203), so the data most exposed to harvest-now moves first and shorter-lived systems follow in order. This mirrors published guidance, which itself prioritizes harvest-exposed systems ahead of the rest.

The threat model does not demand that you migrate everything overnight, and it does not depend on a scary date. It demands that you know which of your secrets must outlive an uncertain deadline — and that you move those first. That ordering is the whole response, and it is available today, no countdown required.

Where Q-Shield fits

Q-Shield exists to turn this reasoning into a plan. It performs the cryptographic inventory, applies five-axis quantum risk scoring so the highest-risk, longest-lived secrets rise to the top, and produces a NIST-aligned migration roadmap toward ML-KEM, including a hybrid ECDH + ML-KEM key exchange where that fits. Harvest now, decrypt later is not a slogan in that workflow — it is the reason confidentiality lifetime is something Q-Shield measures and ranks, rather than something you hope you got right.

See how Q-Shield ranks your secrets by confidentiality lifetime so the most harvest-exposed data migrates first.

Get started