<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/getting-ahead-of-harvest-now-decrypt-later-post-quantum-cryptography-planning-rvmbo59g2" -->

---
title: Getting ahead of ‘harvest-now-decrypt-later’:...
description: Post-quantum cryptography migration is framed as an urgent present-day task rather than a distant future concern, driven by the &#x27;harvest-now-decrypt-later&#x27;...
canonical: https://daily.dev/posts/getting-ahead-of-harvest-now-decrypt-later-post-quantum-cryptography-planning-rvmbo59g2
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Getting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planning | daily.dev
og:description: Post-quantum cryptography migration is framed as an urgent present-day task rather than a distant future concern, driven by the &#x27;harvest-now-decrypt-later&#x27;...
og:url: https://daily.dev/posts/getting-ahead-of-harvest-now-decrypt-later-post-quantum-cryptography-planning-rvmbo59g2
og:image: https://api.daily.dev/og/posts/RvmBO59g2.png
og:image:alt: Getting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planning
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planning

**[CSO Online](https://daily.dev/sources/csoonline)** · 6 min read · 0 upvotes · 0 comments

## Summary

Post-quantum cryptography migration is framed as an urgent present-day task rather than a distant future concern, driven by the 'harvest-now-decrypt-later' threat where adversaries capture and store encrypted data today to decrypt once quantum computers become viable. NIST IR 8547 sets deprecation of RSA-2048 and ECC P-256 by 2030 and full removal by 2035, following the August 2024 finalization of three FIPS standards (ML-KEM, ML-DSA, SLH-DSA), with a fourth (FN-DSA/FIPS 206) expected later. The NSA mandates quantum-resistant cryptography for new national security acquisitions starting 2027, and the UK NCSC has laid out a phased roadmap through 2035. Guidance covers using Mosca's theorem to assess exposure, prioritizing cryptographic discovery, building crypto-agility, and coordinating with vendors, following the CISA/NSA/NIST six-step migration playbook.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4220259/getting-ahead-of-harvest-now-decrypt-later-post-quantum-cryptography-planning.html>

## Questions this post answers

### When will RSA-2048 and ECC P-256 be deprecated according to NIST's post-quantum transition plan?

NIST IR 8547 sets RSA-2048 and ECC P-256 for deprecation by 2030 and complete removal from NIST standards by 2035. This timeline was published following eight years of standardization work that concluded with three finalized FIPS standards in August 2024: ML-KEM for key encapsulation, and ML-DSA and SLH-DSA for digital signatures using different mathematical approaches.

_daily.dev helps security teams track cryptography standard deadlines while planning a post-quantum migration._

### What is harvest-now-decrypt-later and why does it matter before quantum computers exist?

Harvest-now-decrypt-later is a threat model where adversaries capture and store encrypted data today, then decrypt it retroactively once a cryptographically relevant quantum computer exists. It matters now for data with long confidentiality windows - healthcare records, financial data, classified material, trade secrets - which can require protection for decades, meaning exposure risk exists well before quantum computers are functional.

_Developers protecting long-lived sensitive data can follow harvest-now-decrypt-later risk discussions on daily.dev._

### When does the NSA require quantum-resistant cryptography for national security systems?

The NSA requires quantum-resistant cryptography for new acquisitions in national security systems starting in 2027. The UK's NCSC has set a comparable phased structure: identifying cryptographic services and building migration plans through 2028, executing high-priority upgrades from 2028 to 2031, and completing migration across all systems by 2035.

_Teams in defense-adjacent environments can track evolving quantum-resistant cryptography mandates on daily.dev._

## Similar posts on daily.dev

- [‘Harvest now, decipher later’: The quantum threat few are preparing for](https://daily.dev/posts/harvest-now-decipher-later-the-quantum-threat-few-are-preparing-for-lzhdrjp4j) · CSO Online · 0 upvotes · 0 comments
- [Post-Quantum Cryptography for Authentication: The Enterprise Migration Guide 2026](https://daily.dev/posts/post-quantum-cryptography-for-authentication-the-enterprise-migration-guide-2026-i5hayeibm) · Security Boulevard · 0 upvotes · 0 comments
- [Post-Quantum Cryptography Timelines: When Will Organizations Migrate?](https://daily.dev/posts/post-quantum-cryptography-timelines-when-will-organizations-migrate--igj5999db) · The Quantum Insider · 0 upvotes · 0 comments
- [Your Encryption Has an Expiration Date: France Turns Quantum Risk Into Procurement Law](https://daily.dev/posts/your-encryption-has-an-expiration-date-france-turns-quantum-risk-into-procurement-law-22hbagzog) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#quantum-computing](https://daily.dev/tags/quantum-computing), [#cryptography](https://daily.dev/tags/cryptography)

[View this post on daily.dev](https://daily.dev/posts/getting-ahead-of-harvest-now-decrypt-later-post-quantum-cryptography-planning-rvmbo59g2)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Getting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planning","url":"https://daily.dev/posts/getting-ahead-of-harvest-now-decrypt-later-post-quantum-cryptography-planning-rvmbo59g2","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/getting-ahead-of-harvest-now-decrypt-later-post-quantum-cryptography-planning-rvmbo59g2"},"datePublished":"2026-09-10T09:05:02.071Z","dateModified":"2026-09-10T09:25:48.302Z","description":"Post-quantum cryptography migration is framed as an urgent present-day task rather than a distant future concern, driven by the 'harvest-now-decrypt-later'...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/31d8611aceda9640287ef22c56af0bea?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/31d8611aceda9640287ef22c56af0bea?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/getting-ahead-of-harvest-now-decrypt-later-post-quantum-cryptography-planning-rvmbo59g2","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,quantum-computing,cryptography","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"Getting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planning"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/getting-ahead-of-harvest-now-decrypt-later-post-quantum-cryptography-planning-rvmbo59g2#faq","mainEntity":[{"@type":"Question","name":"When will RSA-2048 and ECC P-256 be deprecated according to NIST's post-quantum transition plan?","acceptedAnswer":{"@type":"Answer","text":"NIST IR 8547 sets RSA-2048 and ECC P-256 for deprecation by 2030 and complete removal from NIST standards by 2035. This timeline was published following eight years of standardization work that concluded with three finalized FIPS standards in August 2024: ML-KEM for key encapsulation, and ML-DSA and SLH-DSA for digital signatures using different mathematical approaches. daily.dev helps security teams track cryptography standard deadlines while planning a post-quantum migration."}},{"@type":"Question","name":"What is harvest-now-decrypt-later and why does it matter before quantum computers exist?","acceptedAnswer":{"@type":"Answer","text":"Harvest-now-decrypt-later is a threat model where adversaries capture and store encrypted data today, then decrypt it retroactively once a cryptographically relevant quantum computer exists. It matters now for data with long confidentiality windows - healthcare records, financial data, classified material, trade secrets - which can require protection for decades, meaning exposure risk exists well before quantum computers are functional. Developers protecting long-lived sensitive data can follow harvest-now-decrypt-later risk discussions on daily.dev."}},{"@type":"Question","name":"When does the NSA require quantum-resistant cryptography for national security systems?","acceptedAnswer":{"@type":"Answer","text":"The NSA requires quantum-resistant cryptography for new acquisitions in national security systems starting in 2027. The UK's NCSC has set a comparable phased structure: identifying cryptographic services and building migration plans through 2028, executing high-priority upgrades from 2028 to 2031, and completing migration across all systems by 2035. Teams in defense-adjacent environments can track evolving quantum-resistant cryptography mandates on daily.dev."}}]}
```

