Somewhere in a data center you've never heard of, someone is saving your encrypted traffic. Not reading it, they can't, the encryption is solid. Just storing it. Waiting. Because within the next decade, a quantum computer may be able to crack it open like a walnut, and everything you thought was private becomes an archive.
This is the "harvest now, decrypt later" threat, and it's the reason the normally sleepy world of cryptography standards has become one of the most urgent stories in technology.
How we got here
Nearly all internet encryption relies on math problems that are hard for classical computers: factoring large numbers, computing discrete logarithms. A sufficiently powerful quantum computer running Shor's algorithm would solve both efficiently, breaking RSA, elliptic curve cryptography, and with them, the padlock on essentially all digital communication.
The timeline is debated, but the direction isn't. Estimates for a cryptographically relevant quantum computer range from the early 2030s to "longer than that," but the harvest-now threat doesn't wait for the timeline. Data with a long secrecy lifetime, state secrets, medical records, trade secrets, intellectual property, is being collected today against the day decryption becomes possible.
Everything you thought was private becomes an archive, waiting for the day decryption becomes possible.
The standards are ready. The migration isn't.
Enjoying this story?
Get the five most important stories in tech, every morning. Free.
The good news: the replacement cryptography exists. After a multi-year competition, NIST has finalized post-quantum standards, new algorithms based on lattice problems and other math that quantum computers can't easily crack. The algorithms are published, the specifications are done, and products are shipping.
The bad news: migrating the world's cryptography is a generational infrastructure project. Encryption is embedded everywhere: in protocols, in hardware, in firmware that can't be updated, in systems whose vendors no longer exist. The last big migration, from SHA-1 to SHA-2, took the better part of a decade for the easy parts. Post-quantum is harder, because the new algorithms have bigger keys, bigger signatures, and different performance characteristics that break assumptions baked into countless systems.
Who's moving first
The Quantum Threat Timeline
Why the migration to post-quantum encryption can't wait.
Note: For illustrative purposes only.
Browsers and messaging apps are furthest along, with several now negotiating post-quantum key exchange by default. Cloud providers are rolling out hybrid modes that combine classical and post-quantum algorithms, so a break in either one doesn't compromise security. Governments are setting deadlines: US federal systems face migration mandates, and regulated industries like finance and healthcare are building multi-year plans.
The laggards are predictable: embedded systems, industrial control, legacy enterprise software, and anything where "update the cryptography" means "replace the hardware." Those long-tail systems are also, inconveniently, often the ones guarding critical infrastructure.
What you should actually do

For most people, the advice is boring and correct: keep your software updated, because the migration is happening inside the updates. Use messaging apps that have deployed post-quantum protections. For organizations, the priority is crypto inventory: you can't migrate what you haven't mapped. Know where your encryption lives, which algorithms it uses, and what data has a secrecy lifetime longer than the quantum timeline.
The quantum apocalypse isn't coming tomorrow. But the harvest is happening today, and the only data that's safe is data encrypted with algorithms that survive what's coming. The window to migrate is open now. It won't stay open forever.
The geopolitics of encryption
Cryptography has always been geopolitical, and the post-quantum transition is no exception. Nations are treating quantum-safe encryption as strategic infrastructure, with export controls, standards battles, and intelligence implications. The country that migrates first protects its secrets longest; the country that migrates last remains exposed.
There's also a standards dimension with long-term consequences. The algorithms the world adopts now will guard communications for decades. Getting them right matters enormously, and the NIST process, with its public competitions and cryptanalysis, represents the best mechanism humanity has for building trustworthy cryptography. The alternative, opaque national standards, has a poor historical track record.
The deeper lesson
Step back and the post-quantum migration illustrates something profound about digital security: encryption is not a product you buy, it's a process you maintain. Every cryptographic assumption has a shelf life. RSA lasted decades; its successor must be deployed with the understanding that it too will one day fall.
The organizations handling this well are building crypto agility: the ability to swap algorithms without rebuilding systems. That's the real lesson of the quantum transition. Not that quantum computers break encryption (they will, eventually, for specific algorithms), but that the systems we build should assume their cryptography will need replacing.
Security is never done. It's just done for now, until the next transition. The post-quantum migration is the largest such transition in the history of the internet. How we handle it will define the security of the digital world for a generation.
The human element
For all the focus on algorithms, the weakest link in the quantum transition is organizational. Cryptography migrations require coordination across teams that rarely talk to each other: security, infrastructure, product, compliance. The technology exists. The project management is the hard part.
The companies succeeding treat this as a multi-year program with executive sponsorship, not a ticket in the security backlog. They've inventoried their cryptography, prioritized by data sensitivity and system criticality, and started with the highest-value targets. The ones failing are still in the "we should probably look into that" phase, which is another way of saying they'll be migrating under deadline pressure later.
Deadlines have a way of focusing the mind. The organizations that start now will migrate deliberately. The ones that wait will migrate frantically. The cryptography will be the same either way. The experience won't be.
243 Comments