
Security teams still treat encryption as a present-tense control. If a session is encrypted on the wire, the working assumption is that the secret is safe. Harvest now, decrypt later (HNDL) is the strategy that treats that assumption as the opening. Adversaries copy ciphertext they cannot read, warehouse it while storage is cheap, and wait for a machine that can finish the job. The pressure is no longer abstract calendar-watching. In April 2026, The Quantum Insider argued that 2026 is when this store-and-wait model becomes an operational planning issue for government communications, healthcare records, and intellectual property that must remain confidential long after the original transfer. Waiting for a public quantum break is waiting until the archive is already in someone else’s hands.
HNDL Is a Store-and-Wait Attack on Public-Key Crypto
The decision over the next year is not whether quantum computers exist. It is which datasets still need to be secret after the public-key algorithms that protect them are retired, and whether those datasets are still wrapped in RSA or ECC when they move or when they sit in backup. If the answer is “most of the regulated archive,” hybrid PQC on the wire and on new backups is a present control. If the answer is “session tokens that die in an hour,” HNDL is a lower queue item than the rest of the crypto debt.
The mechanism is simple once the handshake is separated from the bulk cipher. In a typical TLS session the two sides use public-key cryptography to agree on a symmetric session key, then encrypt the payload with that key. An attacker who records the full session gets two things: the public-key messages that established the key, and the ciphertext that followed. Today those public-key messages are unreadable as keys. They are still worth keeping.
It Is Not a Quantum Computer Sitting on Your Network
It is also not quantum key distribution, which uses physical properties of photons to establish keys and lives in a different architecture conversation. Buying a quantum link does not, by itself, stop someone from copying classical Transport Layer Security (TLS) sessions elsewhere on the path. And HNDL is not fixed by stretching RSA key lengths. Longer keys raise classical cost. They do not change the qualitative break Shor’s algorithm is expected to deliver.
This week, pull one list the organization already has: data-retention schedules, or the last records-of-processing inventory. Mark every class whose confidentiality obligation runs past 2035. Then ask whoever owns TLS, VPN, and backup encryption which of those classes still negotiate keys with RSA or ECC. That conversation fits in an hour and tells you whether HNDL is a paper risk or an archive you are still handing to collectors.
That is why post-quantum work focuses first on key encapsulation and signatures, not on throwing away AES. ML-KEM is designed so that even a quantum attacker should not recover the encapsulated key from the public transcript. Hybrid designs combine a classical exchange with a post-quantum one so both must fail. The Cloud Security Alliance’s research on HNDL against AI infrastructure walks the same cause-and-effect for model weights, prompts, and training sets that move between clouds: intercept now, decrypt when the public-key wrapper dies. The output of HNDL is not a new exploit kit. It is a delayed plaintext archive.
Capture the Handshake, Keep the Ciphertext, Wait
Timing is the contested part. Serious people disagree on when a cryptographically relevant quantum computer arrives, and treating a single “Q-Day” year as settled science is a mistake. Palo Alto Networks’ explainer on HNDL puts the practical test in the right place: if the data will still matter when quantum decryption becomes feasible, it is already in scope. The disagreement is about the clock, not about whether recorded ciphertext is an asset.
Cloud backup and SaaS archives concentrate the same risk in fewer places. One stolen object store can hold years of mail, file shares, and database dumps wrapped in keys that were negotiated under today’s public-key schemes. Organizations that already struggle to say which backups still contain regulated personal data will find HNDL unforgiving, because the attacker does not need to decrypt on the day of the theft.
The National Institute of Standards and Technology (NIST) Post-Quantum Cryptography project exists because that future break would expose past traffic. In 2024 NIST finalized three Federal Information Processing Standards (FIPS) meant to replace the public-key pieces at risk: FIPS 203 for the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM), FIPS 204 for ML-DSA signatures, and FIPS 205 for SLH-DSA. NIST has said those algorithms can and should be put into use now. HNDL is why “now” is the relevant word. Data intercepted under today’s RSA or ECC handshakes does not become safer with time.
Hospitals, Archives, and Anything That Must Stay Quiet for Decades
National-security and civilian government traffic has the same shape with classified and controlled-unclassified holdings that must stay closed well past a single hardware generation. In 2026, The Quantum Insider treated confidentiality into the 2030s as the planning horizon that makes HNDL a present collection problem rather than a lab concern. Financial institutions sit next to that pile. Payment credentials rotate. Core banking extracts, identity attributes, and deal rooms do not. A 2025 Federal Reserve staff paper on HNDL and post-quantum migration is itself a signal that long-lived financial confidentiality is now a policy subject, not only a vendor slide.
HNDL is an attack strategy, not a product and not a new protocol. An attacker records encrypted sessions or stored files today, then decrypts them later if a cryptographically relevant quantum computer can recover the keys that wrapped the data. The vulnerable piece is public-key cryptography used for key establishment and many signatures, especially Rivest–Shamir–Adleman (RSA) and elliptic-curve cryptography (ECC). Shor’s algorithm is the quantum method expected to solve the math those schemes rely on. Symmetric ciphers with adequate key lengths are a different problem and are generally treated as more durable.
Federal direction is the other current trend. The same Fed paper notes that NIST has urged organizations to implement the new algorithms as soon as possible and that the U.S. government has directed federal agencies to migrate. Vendors of firewalls, clouds, and backup platforms are adding ML-KEM and related algorithms because buyers in those agencies will soon fail a checklist, and because private firms that sell into government copy the checklist.
Hybrid Handshakes Are Moving Out of the Lab
The pain is not “encryption will someday fail.” It is secrets whose legal or commercial life is longer than the remaining life of RSA and ECC. Healthcare feels this first because clinical histories, genomic data, and claims files are still damaging a decade after the visit. A captured transfer of those records is a future breach with a long fuse, and disclosure duties do not expire just because the original cipher did.
Take a hospital sending a longitudinal record to a specialist over TLS that still negotiates an ECC key exchange. A collector on a backbone, a compromised middlebox, or a stolen packet capture keeps the bytes. Disk is inexpensive, so the file can sit for years with a case name and a date. If a later quantum computer recovers the ECC material from the handshake, the session key falls out, and the stored payload opens with ordinary symmetric decryption. The patient did not have to be interesting in 2026. The record only had to remain sensitive when the math caught up.
HNDL is easy to confuse with three other stories, and the mix-ups change what people fund. It is not evidence that quantum computers are decrypting production traffic today. The harvest step uses ordinary collection: packet capture, compromised links, backup theft, or lawful intercept stored beyond its original purpose. The decrypt step is the part that still depends on machines that do not yet break RSA at scale.
Platform Suites, Crypto Specialists, and Backup Vendors
The market is splitting by where the cipher is changed, not by a single HNDL category. CISA’s catalog of product categories that use PQC standards is the cleanest public map of that split, and it is explicit that a product can support PQC while still speaking classical algorithms for interoperability. Cloud platforms such as Google Cloud are folding PQC into existing transport and key-management services so customers inherit hybrid handshakes without standing up a new security stack. Network security vendors such as Palo Alto Networks treat HNDL as a reason to upgrade VPNs and TLS inspection rather than as a standalone appliance. Data-protection vendors such as Commvault are adding PQC, including support for Hamming Quasi-Cyclic (HQC), around backups and archives whose ciphertext may outlive the original application. Specialist firms such as PQShield sell software and hardware implementations meant to drop into protocols and chips without waiting for a full platform refresh. Encryption incumbents such as Thales pitch crypto-agility inside existing key-management and hardware-security modules so algorithm swaps are an operations task. Newer commercial stacks such as SuperQ’s SuperPQC suite are trying to sell an end-to-end PQC path through managed-security partners rather than through a hyperscaler console.
Inventory the Secrets That Outlive Your Current Ciphers
What is in production is early replacement of the public-key wrapper, often as a hybrid so old clients still interoperate. NIST has been explicit that ML-KEM, ML-DSA, and SLH-DSA are ready to deploy, and its NCCoE migration work is the public map for that work. In October 2024 NIST advanced 14 additional digital-signature candidates into a second round, which is an emerging hedge against depending on a single signature family. In November 2024 it released draft IR 8547 on transitioning to the new standards. Those are procurement and engineering facts, not conference demos.
Still speculative, and labeled so, is any claim that a cryptographically relevant quantum computer arrives on a fixed date inside two years. The basis for talking about it at all is the harvest already underway plus the public PQC standards. Anything beyond a 24-month adoption window for hybrid TLS, VPN, and code-signing is a scenario, not a schedule. The sound emerging move is crypto-agility: the ability to swap algorithms without rebuilding the application, because the first PQC suite will not be the last.



