Reading time
10 minutes
Category
Zero Trust
Author
Yann Lazar
Summary
Nation-state actors are harvesting encrypted data today. Financial records. Strategic communications. Identity credentials. They are storing all of it until quantum computers can break the encryption.
The attack already happened. The decryption is scheduled for later.
Forrester’s 2026 predictions show organizations beginning to respond. Over 5% of cybersecurity budgets is now going to quantum security initiatives. Cryptographic inventories. Migration planning. Testing of quantum-resistant algorithms.
The migration to post-quantum cryptography is not a software update. It takes years. The organizations that start later will be decrypted first.
The Theft Already Happened.
Your data is encrypted. You checked the box. The connection is secured. The certificate is valid. Everything your security tools tell you says the data is protected.
It is not. Not entirely. Not anymore.
Right now, state-level adversaries are intercepting encrypted traffic. Your organization’s traffic is in scope. They are archiving it. Not to read today. They cannot. The encryption holds for now. They are storing it until they have a quantum computer powerful enough to break it retroactively.
That moment has a name. Security researchers call it Q-Day. Estimates vary on when it arrives.
What does not vary: everything harvested before it arrives will be readable after it does.
The question is not whether your encryption will eventually fail against a quantum adversary. For the algorithms most organizations are running today, it will. The question is whether you will have replaced them before Q-Day makes the archive valuable.
What Post-Quantum Cryptography Actually Is
Post-quantum cryptography refers to cryptographic algorithms designed to resist attacks from quantum computers.
Today’s widely-used encryption standards rely on mathematical problems that classical computers cannot solve in practical time. RSA. Elliptic curve cryptography. Quantum computers can solve them.
Post-quantum algorithms use different mathematical foundations. Foundations that remain hard for quantum systems to break. NIST published the first standardized post-quantum algorithms in 2024.
Migrating to them requires identifying every place current cryptography is used. Replacing the underlying algorithms. Validating that nothing in the chain breaks in the process.
What a Quantum Computer Actually Does to Your Encryption
Most people understand quantum computing as “a very fast computer.” That framing misses the threat.
A classical computer tries to factor a large number by working through possibilities one at a time. It would take longer than the age of the universe to break standard encryption that way. That is why we trust it.
A quantum computer does not work sequentially. It uses quantum mechanical properties to evaluate vast numbers of possibilities at once. The mathematical problems that make RSA and elliptic curve cryptography secure (factoring large primes, solving discrete logarithms) become tractable. Not in centuries. In hours.
This does not mean every piece of encrypted data is at risk today. Quantum computers powerful enough to break production encryption do not yet exist at scale.
But the harvest-now-decrypt-later strategy does not need them to exist yet. It only needs them to exist eventually.
And the data being harvested today has a long shelf life. Strategic communications. Identity credentials. Financial records. Intellectual property. The value of that archive grows the moment Q-Day arrives.
“Later” Is Closer Than Most Roadmaps Assume
The standard response to quantum risk has been to treat it as a long-horizon concern. Important, but not urgent. Something for the next strategic planning cycle.
That response is no longer defensible.
Forrester’s 2026 predictions show organizations allocating real budget to quantum initiatives. That is not theoretical research. That is cryptographic inventories. Migration roadmaps. Quantum-resistant algorithms tested in live environments.
The reason the timeline has compressed is not that Q-Day has been precisely dated. It is that the migration itself takes longer than most organizations expect.
A full cryptographic inventory across a large enterprise takes months. Mapping every system, protocol, library, and integration that uses cryptography. Replacing algorithms without breaking dependent systems takes longer. Validating the migration takes longer still.
Organizations that start in 2026 will be mid-migration when Q-Day arrives. Organizations that start in 2029 may not finish in time.
The Migration Is Not a Software Update
This is the part that surprises most security teams when they actually begin.
Cryptography is not a layer that sits cleanly on top of everything else. It is woven through the stack. Embedded in protocols, libraries, hardware security modules, certificate chains, VPN configurations, code signing, and authentication flows. Also in third-party integrations your team did not build and may not fully see.
A quantum migration requires three things. None of them are fast:
- A complete cryptographic inventory. You cannot migrate what you have not mapped. Most organizations discover, mid-inventory, that cryptography is being used in places nobody documented.
- Algorithm replacement without breaking dependencies. Post-quantum algorithms have different performance characteristics and key sizes. Systems tuned for current algorithms may not handle the change without modification.
- Supply chain and vendor alignment. Your migration is not done if your vendors, cloud providers, and integration partners have not also migrated. The chain is only as strong as the weakest link.
Organizations taking quantum risk seriously are not waiting for a standardized framework to appear. They are starting the inventory now, because the inventory takes long enough that there is no time to waste.
What 20+ Years of Operating Zero Trust Shows About the Migration
ON2IT was founded in 2005 to operate Zero Trust at enterprise scale. We have run Zero Trust governance for organizations in regulated sectors. We have walked migration plans through real production environments. We have seen what the cryptographic inventory turns up, and what the migration breaks.
Three things show up consistently:
1. Protect surfaces make the migration manageable.
Zero Trust is built around protect surfaces: the smallest defensible unit of data, asset, application, or service that matters. Cryptographic controls attach to each protect surface individually. That means you can migrate one surface at a time, without touching the entire security model at once.
Architectures without that granularity treat cryptography as a property of the network boundary. Replacing it means touching the trust model itself. A quantum migration in that environment is not a phased project. It is a rebuild. Those migrations stretch into years that quantum risk does not have.
2. The inventory takes longer than the migration plan.
In every engagement we have run, the cryptographic inventory finds more than the customer expected. Legacy systems with hardcoded algorithms. Vendor integrations using deprecated certificates. Code-signing flows nobody had documented. The map is harder than the move.
3. Zero Trust does not eliminate quantum risk. It changes what decryption costs the adversary.
Harvested data has two different threat profiles. In the first, decrypted data is a stepping stone: the adversary uses credentials, keys, or session data to gain access and move laterally. Zero Trust directly limits that path. Continuous identity verification, least-privilege access, and micro-segmentation raise the cost of each pivot to something most adversaries cannot pay.
In the second profile, decrypted data is the goal. Strategic communications, financial records, intellectual property. Zero Trust cannot recover data that was already in transit. But it limits the blast radius: protect surface segmentation restricts how much of the archive is exposed per session, per system, per integration. The adversary who decrypts one surface does not automatically reach the rest.
What ON2IT does in this space, and what we do not, is explicit:
- We do not sell post-quantum encryption algorithms.
- We do not replace your cryptographic libraries.
- We do not predict Q-Day.
- We do help you build the cryptographic inventory that the migration cannot start without.
- We do operate the Zero Trust architecture that makes migration possible without rebuilding the security model.
- We do design the migration roadmap that fits your supply chain and your timelines.
Key Takeaways
- Harvest-now-decrypt-later attacks are happening today. State-level adversaries are archiving encrypted data to decrypt retroactively when quantum computers become capable.
- The encryption protecting most enterprise data today (RSA, elliptic curve) will not survive a capable quantum computer. Migration to post-quantum algorithms is not optional. It is scheduled.
- The migration takes years. Cryptographic inventory, algorithm replacement, and supply chain alignment cannot be rushed. Starting late means finishing after Q-Day.
- Zero Trust built around protect surfaces makes migration manageable: one surface at a time, without rebuilding the security model. It also limits blast radius for both threat profiles: decrypted data used as a weapon, and decrypted data as the target itself.
- ON2IT operates Zero Trust governance for regulated-sector organizations. We do not sell algorithms. We do help you build the inventory and the architecture that the migration cannot start without.
Conclusion
Quantum risk feels distant because the threat is patient. It does not need to act now. It is content to wait. Collecting data. Until the capability exists to use it.
That patience is the trap. By the time Q-Day is imminent, the harvest window has already closed. The archive is full. The organizations that waited to start their migration will be decrypting in the wrong direction. Watching their own historical data become readable to an adversary who collected it years earlier.
The work that needs to happen is not exciting. Cryptographic inventories are slow. Migration planning is detailed. Algorithm testing is unglamorous. It is the work that determines whether your organization’s data is protected when Q-Day arrives. Or just protected until then.
Call to Action
You cannot migrate what you have not mapped. ON2IT can help you start. With a cryptographic inventory. With a Zero Trust architecture assessment. With a realistic quantum migration roadmap that fits your environment and your supply chain. We do not sell algorithms. We help you build the architecture that makes the migration possible.
For a deeper discussion of what quantum security means in practice, including where to start and what the migration exposes about your architecture, watch the Threat Talks episode “Blockchain in a Post-Quantum World” with Rob Maas and Jeroen Scheerder.
Adversaries with the resources to store large volumes of data are intercepting and archiving encrypted traffic today. They plan to decrypt it once quantum computers become capable of breaking current encryption standards. The attack is already happening. The decryption is scheduled for later. It matters now because the data being harvested today, credentials, financial records, strategic communications, will still be valuable when Q-Day arrives.
For a large enterprise, a complete migration typically takes several years. The cryptographic inventory alone can take months. Mapping every system, protocol, library, and third-party integration that uses cryptography. Algorithm replacement requires testing for compatibility and performance impacts across dependent systems. Supply chain alignment requires that vendors and integration partners complete their own migrations. Organizations that have begun this process report that the scope is consistently larger than initial estimates assumed.
Crypto-agility refers to an architecture’s ability to swap cryptographic algorithms without restructuring the systems that depend on them. It matters for quantum migration because the replacement cannot happen all at once. It has to be done component by component, without breaking the things that depend on each element. Architectures built with modularity in mind, including those designed around Zero Trust principles, tend to be crypto-agile. Architectures where cryptography is deeply embedded and load-bearing are harder and riskier to migrate.
Yes. For the same reason any long-horizon, high-impact risk belongs at the board level. The migration timeline intersects with strategic planning cycles. Infrastructure decisions made today set the conditions for how difficult the migration will be in three to five years. Board-level visibility ensures quantum risk is factored in. Before the architecture is locked in. Not after.

