Harvest now, decrypt later: sizing the risk honestly
2 May 2026 · 5 min read · Post-quantum
The threat is real but it is not universal. The deciding factor is how long your data must stay confidential.
One question decides your urgency
How long does this data need to remain secret? If the answer is measured in days, quantum decryption is not your problem. If it is measured in decades, health records, state secrets, long-lived contracts, biometric templates, source code for long-lived products, then traffic captured today may be readable within its confidentiality window.
That single question sorts most estates into priority tiers faster than any generic maturity model.
Inventory before algorithms
Most organisations cannot yet answer where their cryptography lives. Certificates, embedded libraries, hardware modules, third-party SaaS, and hardcoded algorithm choices in old code all count. A cryptographic bill of materials is the prerequisite for any credible migration plan.
Discovery is unglamorous and it is where the schedule actually goes.
Crypto-agility outlasts any single algorithm
The goal is not to swap one fixed algorithm for another fixed algorithm. It is to reach a state where changing algorithms is a configuration decision rather than a re-architecture. Organisations that build agility now will absorb the next transition without another multi-year programme.
Working through this yourself?
We run ISO 27001 and ISO 42001 readiness programmes and quantum training for teams facing exactly these decisions.
Book a discovery call