Summary
Summary
- 'Harvest now, decrypt later' means adversaries copy encrypted data today and store it until a quantum computer can break the encryption. Anything that must stay secret for years is exposed now.
- The fix is standardised. NIST finalised ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) in August 2024, and its guidance deprecates RSA and ECC by 2030 and disallows them by 2035.
- For a buyer, the question is simple: will the target's most sensitive data still need protecting after those dates, and is there a credible migration plan? Most hold periods run past 2030.
- For a seller, a documented cryptographic inventory and migration roadmap is a clean, low-cost way to remove a diligence question and support the price.
01 · Research
The threat runs on a delay
Data taken today, read tomorrow.
Most cyber risks show up when they happen. Harvest now, decrypt later is different. An adversary copies encrypted traffic or files today, stores them cheaply, and waits for a quantum computer able to break today's public-key encryption. The breach happens now; the damage arrives later.
That is why the timeline matters to deal-makers. The question is not when a quantum computer arrives, but how long the target's sensitive data needs to stay secret.
02 · Research
The standards and the dates
The replacement algorithms are ready.
The good news is that the fix is no longer theoretical. In August 2024 NIST finalised three post-quantum standards, and the deadlines for leaving the old algorithms are now published.
| Item | What it is | Date |
|---|---|---|
| FIPS 203 (ML-KEM) | Key establishment, replacing RSA/ECDH key exchange | Final, August 2024 |
| FIPS 204 (ML-DSA) | Digital signatures | Final, August 2024 |
| FIPS 205 (SLH-DSA) | Hash-based digital signatures | Final, August 2024 |
| NIST transition guidance | RSA and ECC deprecated, then disallowed | 2030, then 2035 |
| CNSA 2.0 | Quantum-resistant algorithms only, national security systems | 2030-2033 by system type |
Our earlier research on the 2029 encryption deadline maps the vendors and the consolidation already under way. This piece focuses on what to ask inside a deal.
03 · Research
A post-quantum diligence checklist
Six questions that scope the issue quickly.
- 01Cryptographic inventoryWhere is public-key cryptography used: TLS, VPNs, code signing, databases, backups, device firmware, partner integrations?
- 02Data lifetimeWhich datasets must stay confidential beyond 2030? Health, financial, legal, IP and government data usually do.
- 03Migration roadmapIs there a plan to adopt ML-KEM and ML-DSA, with owners, sequencing and budget?
- 04Crypto-agilityCan algorithms be swapped through configuration and libraries, or are they hard-coded into products and hardware?
- 05Supply chainWhich vendors, HSMs, chips or cloud services must move first, and what have they committed to?
- 06CommitmentsDo customer contracts, certifications or regulators already reference encryption standards the target must meet?
The answers usually land in one of three places: already migrating, planned and costed, or not yet scoped. Only the last needs real negotiation, and even then it is a plannable integration item rather than a deal-breaker.
04 · Research
Turning readiness into value
Sellers can close the question before it is asked.
| Target position | Buyer read | Typical deal outcome |
|---|---|---|
| Inventory done, migration under way | Modern, well-run security function | Supports price; quick diligence |
| Roadmap costed, not started | Known, bounded integration item | Covered in the 100-day plan |
| Not yet scoped | Open question on data exposure | Specific warranties or price discussion |
For sellers, preparing a cryptographic inventory is a small piece of work with an outsized effect on how a security-literate buyer reads the business. For buyers, adding these six questions to the technical diligence scope costs little and protects data the business will still hold in 2035.
Our technical due diligence work covers this alongside the wider security review.
Reference
Frequently asked questions
What does 'harvest now, decrypt later' mean?
It describes attackers intercepting and storing encrypted data today, expecting to decrypt it once quantum computers can break current public-key encryption such as RSA and elliptic-curve cryptography. Data with a long confidentiality life, like health records, intellectual property, financial records or government data, is at risk even though no such computer exists yet.
Why does post-quantum readiness matter in an acquisition?
A buyer typically owns a business for five years or more. Under NIST guidance, RSA and ECC are deprecated by 2030 and disallowed by 2035, and national security systems face the faster CNSA 2.0 timeline. A target that has not started migrating carries a known future cost and a data-exposure risk that should be priced and planned for.
What should be on a post-quantum due diligence checklist?
Ask for a cryptographic inventory, the confidentiality lifetime of the most sensitive data, a migration roadmap to ML-KEM and ML-DSA, evidence of crypto-agility in the architecture, vendor and hardware dependencies, and any contractual or regulatory commitments on encryption standards.
How can a seller turn post-quantum readiness into value?
By preparing the inventory and roadmap before marketing the business. It turns an open-ended technical question into a scoped, costed plan, which shortens diligence and removes a reason for the buyer to hold back price or ask for specific indemnities.




