QNSI

PQC concepts

What is HNDL?

Also known as Harvest Now, Decrypt Later.

Adversary captures encrypted traffic today and stores it. When a CRQC arrives, every captured ciphertext is retroactively decryptable. Long-life records (medical, financial, classified, transcripts) are HNDL targets the moment they touch a wire.

Decision context

Why HNDL matters

Harvest-now-decrypt-later risk makes migration urgent for data that must remain confidential for years or decades even when a quantum computer does not yet exist. Captured ciphertext cannot be retroactively protected after the key-establishment primitive becomes breakable.

How to evaluate HNDL

Inventory data flows by confidentiality lifetime, capture attractiveness and exposure at every ingress, egress, backup and partner boundary. Prioritize records whose protection horizon exceeds the migration window. Verify the actual key-establishment path rather than treating AES key length alone as HNDL protection.

PQC concepts

PQC concepts evidence boundary

Post-quantum programmes combine cryptography, architecture, data lifetime, operational ownership, and migration governance. A concept is useful only when it changes a concrete inventory, policy, design, test, or evidence decision. Treat terminology as a decision aid rather than proof that a control exists.

FAQ

Common questions

What is HNDL?

Adversary captures encrypted traffic today and stores it. When a CRQC arrives, every captured ciphertext is retroactively decryptable. Long-life records (medical, financial, classified, transcripts) are HNDL targets the moment they touch a wire.

Why does HNDL matter?

Harvest-now-decrypt-later risk makes migration urgent for data that must remain confidential for years or decades even when a quantum computer does not yet exist. Captured ciphertext cannot be retroactively protected after the key-establishment primitive becomes breakable.

How should HNDL be evaluated?

Inventory data flows by confidentiality lifetime, capture attractiveness and exposure at every ingress, egress, backup and partner boundary. Prioritize records whose protection horizon exceeds the migration window. Verify the actual key-establishment path rather than treating AES key length alone as HNDL protection.

What is HNDL also known as?

HNDL is also known as Harvest Now, Decrypt Later. Adversary captures encrypted traffic today and stores it. When a CRQC arrives, every captured ciphertext is retroactively decryptable. Long-life records (medical, financial, classified, transcripts) are HNDL targets the moment they touch a wire.

More

Keep exploring