Encrypted data copied today could be readable within the life of the deal. That makes cryptography a diligence question now, not a 2030 problem. 'Harvest now, decrypt later' means adversaries copy encrypted data today and store it until a quantum computer can break the encryption. Anything that must stay secret for years is exposed now. The fix is standardised. NIST finalised ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) in August 2024, and its guidance deprecates RSA and ECC by 2030 and disallows them by 2035. For a buyer, the question is simple: will the target's most sensitive data still need protecting after those dates, and is there a credible migration plan? Most hold periods run past 2030.

Research · Cybersecurity

Harvest Now, Decrypt Later: Adding Post-Quantum Readiness to M&A Due Diligence

Encrypted data copied today could be readable within the life of the deal. That makes cryptography a diligence question now, not a 2030 problem.

Joash BoytonFounder & Managing Director

Independent analysis and opinion. How we research

Published
Reading time
7 min read
NIST finalised FIPS 203, 204 and 205
Aug 2024
RSA and ECC deprecated under NIST guidance
2030
RSA and ECC disallowed under NIST guidance
2035
CNSA 2.0 quantum-resistant-only window for national security systems
2030-33
Cold data archive corridor of tape storage racks with blue status lights and a sealed archive box on a cart

Summary

Summary

  • 'Harvest now, decrypt later' means adversaries copy encrypted data today and store it until a quantum computer can break the encryption. Anything that must stay secret for years is exposed now.
  • The fix is standardised. NIST finalised ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) in August 2024, and its guidance deprecates RSA and ECC by 2030 and disallows them by 2035.
  • For a buyer, the question is simple: will the target's most sensitive data still need protecting after those dates, and is there a credible migration plan? Most hold periods run past 2030.
  • For a seller, a documented cryptographic inventory and migration roadmap is a clean, low-cost way to remove a diligence question and support the price.

01 · Research

The threat runs on a delay

Data taken today, read tomorrow.

Most cyber risks show up when they happen. Harvest now, decrypt later is different. An adversary copies encrypted traffic or files today, stores them cheaply, and waits for a quantum computer able to break today's public-key encryption. The breach happens now; the damage arrives later.

That is why the timeline matters to deal-makers. The question is not when a quantum computer arrives, but how long the target's sensitive data needs to stay secret.

02 · Research

The standards and the dates

The replacement algorithms are ready.

The good news is that the fix is no longer theoretical. In August 2024 NIST finalised three post-quantum standards, and the deadlines for leaving the old algorithms are now published.

ItemWhat it isDate
FIPS 203 (ML-KEM)Key establishment, replacing RSA/ECDH key exchangeFinal, August 2024
FIPS 204 (ML-DSA)Digital signaturesFinal, August 2024
FIPS 205 (SLH-DSA)Hash-based digital signaturesFinal, August 2024
NIST transition guidanceRSA and ECC deprecated, then disallowed2030, then 2035
CNSA 2.0Quantum-resistant algorithms only, national security systems2030-2033 by system type
Key post-quantum standards and timelines

Our earlier research on the 2029 encryption deadline maps the vendors and the consolidation already under way. This piece focuses on what to ask inside a deal.

03 · Research

A post-quantum diligence checklist

Six questions that scope the issue quickly.

  1. 01Cryptographic inventoryWhere is public-key cryptography used: TLS, VPNs, code signing, databases, backups, device firmware, partner integrations?
  2. 02Data lifetimeWhich datasets must stay confidential beyond 2030? Health, financial, legal, IP and government data usually do.
  3. 03Migration roadmapIs there a plan to adopt ML-KEM and ML-DSA, with owners, sequencing and budget?
  4. 04Crypto-agilityCan algorithms be swapped through configuration and libraries, or are they hard-coded into products and hardware?
  5. 05Supply chainWhich vendors, HSMs, chips or cloud services must move first, and what have they committed to?
  6. 06CommitmentsDo customer contracts, certifications or regulators already reference encryption standards the target must meet?

The answers usually land in one of three places: already migrating, planned and costed, or not yet scoped. Only the last needs real negotiation, and even then it is a plannable integration item rather than a deal-breaker.

04 · Research

Turning readiness into value

Sellers can close the question before it is asked.

Target positionBuyer readTypical deal outcome
Inventory done, migration under wayModern, well-run security functionSupports price; quick diligence
Roadmap costed, not startedKnown, bounded integration itemCovered in the 100-day plan
Not yet scopedOpen question on data exposureSpecific warranties or price discussion
How post-quantum readiness reads to a buyer

For sellers, preparing a cryptographic inventory is a small piece of work with an outsized effect on how a security-literate buyer reads the business. For buyers, adding these six questions to the technical diligence scope costs little and protects data the business will still hold in 2035.

Our technical due diligence work covers this alongside the wider security review.

Reference

Frequently asked questions

What does 'harvest now, decrypt later' mean?

It describes attackers intercepting and storing encrypted data today, expecting to decrypt it once quantum computers can break current public-key encryption such as RSA and elliptic-curve cryptography. Data with a long confidentiality life, like health records, intellectual property, financial records or government data, is at risk even though no such computer exists yet.

Why does post-quantum readiness matter in an acquisition?

A buyer typically owns a business for five years or more. Under NIST guidance, RSA and ECC are deprecated by 2030 and disallowed by 2035, and national security systems face the faster CNSA 2.0 timeline. A target that has not started migrating carries a known future cost and a data-exposure risk that should be priced and planned for.

What should be on a post-quantum due diligence checklist?

Ask for a cryptographic inventory, the confidentiality lifetime of the most sensitive data, a migration roadmap to ML-KEM and ML-DSA, evidence of crypto-agility in the architecture, vendor and hardware dependencies, and any contractual or regulatory commitments on encryption standards.

How can a seller turn post-quantum readiness into value?

By preparing the inventory and roadmap before marketing the business. It turns an open-ended technical question into a scoped, costed plan, which shortens diligence and removes a reason for the buyer to hold back price or ask for specific indemnities.

About the analyst

Joash Boyton

Joash Boyton

Founder and Managing Director, Acquiry · Melbourne, Australia · Global coverage

Joash Boyton is the Founder and Managing Director of Acquiry, a specialist M&A advisory firm focused on the acquisition and sale of businesses. He executes buy-side and sell-side mandates from USD $1M to $500M across technology, SaaS, fintech, payments, gaming, blockchain and emerging verticals, and is not limited to them. Any sector, any market.