The mechanic of HNDL

"Harvest now, decrypt later" — HNDL — is the dominant practical threat model in post-quantum risk planning. The argument runs as follows: a cryptographically relevant quantum computer (CRQC) capable of breaking RSA-2048 and ECC-P-256 does not yet exist. Most credible estimates put its arrival between 2030 and 2040, with some outliers earlier or later. But an adversary capable of capturing encrypted traffic today does exist — and an adversary capable of warehousing that traffic for a decade exists in unlimited supply.

The implication: any data encrypted today with pre-quantum algorithms is at risk of decryption at the moment a CRQC arrives. The risk window starts now, not at CRQC arrival.

Why the timeline is shorter than it sounds

The naive timeline is "data encrypted today, CRQC in 2035 → 9 years of risk." That timeline is wrong because it misses two factors:

  • Data lifetime. Most regulated data has a useful or sensitive life measured in decades. PHI under HIPAA is sensitive for the patient's lifetime. Legal records under privilege are sensitive indefinitely. Defence and intelligence records are sensitive across regime changes.
  • The "decrypt later" lag. Once a CRQC exists, breaking individual captured ciphertexts is not instantaneous. Bulk decryption proceeds at the rate the adversary chooses to apply compute. The first to be decrypted are the highest-priority targets.

The practical horizon: data encrypted today with pre-quantum-only algorithms should be assumed reachable by an adversary willing to invest a decade of patience. For sensitive data, that is the same as saying "reachable now."

Which industries are most exposed

HNDL exposure is highest where:

  • Data lifetime is multi-decade (healthcare, legal, intellectual property)
  • Adversaries are state-level (defence, government, critical infrastructure)
  • Strategic value compounds over time (research, trade-secret holdings)

For these industries, "we'll migrate to PQ when standards are stable" was a defensible position until August 2024. After NIST finalised FIPS 203 and FIPS 204, the position became: "we will migrate to PQ before our next data-retention cycle." For most regulated industries, the next data-retention cycle is now.

The CCCS and CNSA 2.0 inflection point

Both Canada's Cyber Centre PQC migration guidance (updated 2025) and the NSA's Commercial National Security Algorithm Suite (CNSA 2.0) profile call for active migration to PQ algorithms beginning immediately, with full transition targets for sensitive workloads between 2027 and 2035.

Procurement teams responsible for sensitive data should now ask vendors not "will you support PQ?" but "are you shipping FIPS 203 and FIPS 204 in production today, on customer data?"

The hybrid argument

Pure-PQ encryption is risky for a different reason: the security of lattice-based algorithms (ML-KEM, ML-DSA) is grounded in a mathematical hardness assumption that, while well-studied, has shorter cryptographic mileage than RSA or AES. A new attack on lattices could emerge.

The pragmatic answer is hybrid encryption: compose a PQ algorithm with a classical algorithm such that an adversary must break both to read data. For key encapsulation, this means wrapping the data-encryption key with AES Key Wrap (classical, well-understood) AND ML-KEM-1024 (post-quantum). A quantum break against ML-KEM leaves AES standing. A classical break against AES (vanishingly unlikely) leaves ML-KEM standing. The system is at least as secure as the strongest of the two.

What SkyeConnex ships

On the Sovereign tier, every data-encryption key (DEK) is wrapped with this hybrid construction: AES Key Wrap (SP 800-38F) composed with ML-KEM-1024 (FIPS 203). The wrap process is a single operation; the unwrap requires both halves to succeed. An adversary harvesting SkyeConnex ciphertext today and waiting for a CRQC in 2035 still has to defeat AES-256 — which CRQC does not enable.

On the signature side, every audit log entry, compliance report, and per-file integrity certificate is dual-signed with HMAC-SHA-256 (online verify) and ML-DSA-87 (offline post-quantum non-repudiation). The dual envelope is the migration story for procurement teams that demand a clean path from today to the post-quantum world.

What to do this quarter

  • Inventory the data you hold. For anything with a sensitive-life exceeding 5 years, treat HNDL as an active threat.
  • Audit your encryption stack. Where is RSA or ECC in the key-encapsulation path? Where is RSA, DSA, or ECDSA in the signature path?
  • For any sensitive workload, prioritise migration to hybrid PQ algorithms before your next data-retention cycle ends.
  • Ask vendors specifically about FIPS 203 and FIPS 204 production use — not roadmap. Our posture is public →

If your CISO wants to walk through a sovereignty-and-PQ architecture together, book a briefing. 45 minutes, live, on your data-retention model.


Published March 18, 2026 · Written by SkyeConnex Inc. · More from the SkyeConnex blog

See SkyeConnex live.