The Quantum Threat Clock Is Already Ticking On Your Encrypted Data

Right now, there’s a cyberattack underway. It produces no alert, demands no ransom and requires no quantum computer. An adversary intercepts encrypted traffic — financial records, health data, government correspondence — and simply stores it. The files are unreadable today. 

The bet is that they will still matter on the day a sufficiently powerful quantum computer can read them. The technique has a name: harvest now, decrypt later. For any organisation holding data whose value survives the decade, it changes what "secure" means.

The mathematics behind the bet are settled. The public-key cryptography protecting almost all digital communication — RSA and elliptic-curve algorithms — is safe against every classical computer on Earth, and known to fall to a large-scale quantum machine running Shor's algorithm. What remains uncertain is the date. The institutions that set cryptographic policy have stopped treating that uncertainty as a reason to wait.

NIST finalised its first three post-quantum standards in August 2024 and has stated that RSA and elliptic-curve cryptography should be deprecated by 2030 and disallowed by 2035. In June 2026, the White House went further, ordering US federal agencies to move their most sensitive systems to post-quantum encryption by the end of 2030, with federal contractors required to follow. Infrastructure providers have responded by bringing their own migration targets forward — Cloudflare now aims to be fully post-quantum by 2029.

Your phone is already quantum-safe — but your servers aren’t

Signal added post-quantum protection in 2023. Apple followed with iMessage's PQ3 protocol in early 2024. Chrome and the other major browsers now negotiate hybrid post-quantum key exchange by default. The result: around two-thirds of the human-generated traffic reaching Cloudflare's network is already post-quantum encrypted. The consumer internet has largely completed the first phase of the transition.

Enterprise estates are a different picture. Core banking platforms, ERP systems, hardware security modules, VPNs, payment infrastructure, embedded and industrial devices — the systems carrying the most sensitive and longest-lived data — remain overwhelmingly based on classical cryptography. That gap between the consumer internet and the enterprise stack is where harvest-now-decrypt-later risk concentrates, because it pairs the most valuable data with the slowest migration path.

Why the Kingdom's timeline is tighter than most

Two features of the Saudi environment sharpen the deadline. The first is data longevity. Banking records carry retention obligations of a decade or more; health records must remain confidential for a lifetime; the control systems inside giga-project infrastructure are being commissioned with design lives measured in decades. Vision 2030 is generating exactly the category of data that harvest-now-decrypt-later targets: information whose confidentiality must outlast the arrival of quantum hardware.

The second is regulatory posture. The NCA's National Cryptographic Standards already define approved primitives at two levels — MODERATE and ADVANCED — and address post-quantum cryptography directly, with the NCA mandated to review and update the standards periodically. The Kingdom also ranks first globally for security, privacy and cryptography in the Stanford AI Index. The direction of travel is unambiguous; the question for CIOs is whether their estates will be ready when guidance hardens into mandate. Here is the playbook.

1. Build the cryptographic inventory

Most organisations cannot currently say where cryptography lives in their estate: which systems use which algorithms, at what key lengths, issued by whom, expiring when. A cryptographic bill of materials — covering TLS endpoints, certificates, HSMs, code libraries, embedded devices and vendor products — is the foundation for everything that follows. You cannot retire an algorithm you cannot find.

2. Triage by data shelf life

Apply the rule quantum-security planners call Mosca's inequality: if the years your data must stay confidential, plus the years your migration will take, exceed the years until a cryptographically relevant quantum computer arrives, you are already exposed. Classify data by required confidentiality lifetime and sequence the migration accordingly — long-lived data crossing external networks first.

3. Put five questions to every vendor

Which of your products rely on RSA or elliptic-curve cryptography? What is your post-quantum roadmap, with dates? Do you support hybrid schemes today? What is the upgrade path for firmware and HSMs? Will you commit to it contractually? Cryptography is now a procurement criterion, and vendors that cannot answer are telling you something important.

4. Pilot hybrid schemes now

Hybrid key exchange — classical and post-quantum combined, so security holds even if one component fails — is the mechanism the browser vendors used, and it is available in mainstream TLS stacks today. Pilot it on externally facing, non-critical systems first. Post-quantum algorithms bring larger keys and heavier handshakes — findings you want to surface in a pilot, well before they reach core banking.

5. Make crypto-agility the destination

The end state is an architecture in which algorithms can be swapped through configuration and policy, without re-engineering applications. Standards will keep evolving — NIST is already standardising additional algorithms — and this will be the first cryptographic migration of the quantum era rather than the last. Design so that the next one is routine.

Where to get started

For a large enterprise this is a three-to-five-year programme spanning inventory, procurement, piloting and phased rollout — which is precisely why the 2030 deadlines are closer than they appear. The organisations that begin the inventory in 2026 will meet them in an orderly way; those that begin in 2028 will meet them expensively. SBM can help. Get in touch to find out more.