Post-quantum security became operationally urgent in 2026, when the White House signed Executive Order 14412 on June 22. The order mandates a national migration to NIST-approved post-quantum cryptography (PQC), while NIST prepares to finalize its fourth standard, FN-DSA, later this year. For enterprises and critical infrastructure operators, “harvest now, decrypt later” is no longer a future risk: adversaries are already stockpiling encrypted data. Yet most organizations have not completed even a cryptographic inventory.
What Is Harvest Now, Decrypt Later?
Harvest now, decrypt later (HNDL) is a cyberattack strategy in which adversaries collect encrypted data today and store it until future quantum computers can break current public-key cryptography. Unlike traditional attacks, HNDL lets state-sponsored groups sit on stolen ciphertext for years. The Cloud Security Alliance notes that CISA, the NSA, NIST, and allied agencies warn adversaries may already be storing encrypted data, with China's Salt Typhoon campaign reaching 600-plus organizations across 80-plus countries. Long-lived data — government records, financial information, healthcare files, intellectual property — is most exposed, because risk begins the moment encrypted data is stolen, not when Q-Day arrives. This is the core of quantum decryption risk.
Executive Order 14412: A Mandated Migration Timeline
Signed June 22, 2026, and published in the Federal Register June 25, Executive Order 14412 shifts U.S. policy from voluntary guidance to enforceable deadlines. The order warns that large-scale quantum computers “particularly in the hands of adversaries” will pose a significant threat. Key provisions: agencies must designate PQC migration leads within 30 days; high-value assets and high-impact systems must adopt PQC for key establishment by December 31, 2030, and digital signatures by December 31, 2031; NIST must launch a PQC pilot by 2027; and CISA and NIST must issue cryptographic bills of materials guidance within 270 days. The directive also pushes agencies to assist critical infrastructure owners and pursue cost-saving procurement. This timeline makes 2026 the planning year that determines whether the 2030-2031 deadlines are achievable, underscoring that critical infrastructure cybersecurity cannot wait.
NIST Standards and the Fourth PQC Standard (FN-DSA)
NIST finalized its first three post-quantum standards on August 13, 2024: FIPS 203 (ML-KEM) for key encapsulation, FIPS 204 (ML-DSA) for signatures, and FIPS 205 (SLH-DSA) as a hash-based backup. In March 2025, NIST selected HQC as a second key-encapsulation mechanism. The fourth signature standard, FIPS 206 (FN-DSA, based on Falcon), is in final review and expected later this year or early 2027. Falcon offers the most compact signatures — roughly 666 bytes for Falcon-512 versus about 2,420 bytes for Dilithium — valuable for bandwidth-constrained applications, though its floating-point Gaussian sampler adds complexity. Comparison: ML-KEM for encryption (fast, larger ciphertext); ML-DSA for signatures (widely deployed, larger); SLH-DSA for hash-based signatures (conservative, slower); FN-DSA for compact signatures (bandwidth-efficient, complex). This diversity is central to post-quantum cryptography standards and crypto-agility.
The Asymmetric Risk: Who Loses If We Delay
The migration math is unforgiving. Organizations need 12 to 15 years to migrate cryptographic systems, yet only about 5% have formal quantum transition plans despite 62% expressing concern — a three-to-five-year vulnerability window. The quantum threat window is compressing: estimates to break RSA-2048 dropped from around 20 million qubits to potentially under 100,000 in 2025-2026 research, and IonQ projects cryptographically relevant quantum computers by 2028-2029. For critical infrastructure operators, delaying a cryptographic inventory means adversaries may already hold their encrypted traffic. Attackers only need to succeed once, while defenders must migrate every system, including 64% of 2022-era secrets still valid in 2026. This is why the enterprise PQC migration gap is systemic risk, not niche concern.
Expert Perspectives
The executive order frames the stakes plainly: “The advent of large-scale quantum computers, particularly in the hands of adversaries, will pose a significant threat to widely used cryptographic systems.” Security researchers add that HNDL is a present risk, not a future one, because risk begins the moment encrypted data is stolen. NIST's Dustin Moody has urged organizations to begin migration now. The consensus among quantum security experts: 2026 is the last year to start without avoidable exposure.
FAQ
What is post-quantum cryptography?
Algorithms designed to resist both classical and quantum computers, replacing RSA and elliptic-curve cryptography.
Why is 2026 a pivotal year for PQC migration?
Executive Order 14412 set 2030-2031 federal deadlines, and NIST is finalizing FN-DSA, making 2026 the decisive planning window.
What are the NIST-approved PQC standards?
FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) finalized in 2024; HQC selected in 2025; FIPS 206 (FN-DSA) in final review.
What is harvest now, decrypt later?
Adversaries collect encrypted data now and store it until quantum computers can break current encryption.
How long does PQC migration take?
Typically 12-15 years, but only about 5% have formal plans, creating a 3-5 year vulnerability window.
Conclusion: The Window to Act Is Closing
The quantum decryption countdown is here. With Executive Order 14412 in force, NIST's fourth standard nearing finalization, and adversaries actively harvesting encrypted data, 2026 is the year post-quantum security went urgent. Organizations that begin cryptographic inventories and adopt crypto-agile architectures now will be ready for 2030-2035; those that wait risk their most sensitive data being already compromised.
Follow Discussion