What is “Harvest Now, Decrypt Later”?
Attackers collect encrypted data today to decrypt it once a powerful quantum computer is available. Long-lived financial data carries the highest risk.
Why banks must define a quantum-safe migration plan by end-2026 — a guide to ML-KEM, ML-DSA, crypto-agility, and DORA compliance.
Quantum computers have not yet broken today's cryptography, but attackers are already storing encrypted data to decrypt later — the threat known as Harvest Now, Decrypt Later. For banks that retain decades of financial data, that risk is real today.
Financial regulators, the G7 Cyber Expert Group, and NIST have set a clear schedule:
| Deadline | Requirement |
|---|---|
| End of 2026 | Define a PQC migration roadmap and begin transition activities |
| End of 2030 | Complete PQC transition for high-risk systems and critical financial infrastructure |
The transition is built on NIST-standardized algorithms that must replace RSA and ECC:
More important than picking one algorithm is building crypto-agility — the ability to swap algorithms quickly without rewriting the whole system. The first step is a Cryptographic Bill of Materials (CBOM): a complete inventory of where, which algorithm, and which keys are used. Without it, migration is blind and risky.
Attackers collect encrypted data today to decrypt it once a powerful quantum computer is available. Long-lived financial data carries the highest risk.
NIST-standardized algorithms for the post-quantum era: ML-KEM for key exchange and ML-DSA for digital signatures, replacing RSA and ECC.
DORA mandates formal encryption and key-management policies and is the primary driver of the EU's coordinated push toward PQC.
Follow the related articles in this category and round out your organization's security strategy.
How banks apply “never trust, always verify”, phishing-resistant MFA, and behavioral biometrics to curb real-time fraud.
How banks in 2026 counter deepfake fraud, synthetic identity, and agentic AI — from Graph AI to continuous biometric verification.
A comprehensive guide to AI agents in 2026: building blocks, ReAct and multi-agent design patterns, MCP and A2A standards, governance, and real use cases in banking and security.