Harvest now, decrypt later
Start with the order, because it reads like a response to an emergency that has not happened yet.
On June 22, 2026, the United States signed Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks," alongside a companion order on quantum innovation. It tells federal agencies to migrate their high-value systems to post-quantum cryptography — key establishment by the end of 2030, digital signatures by the end of 2031 — directs contractors to follow on the same timeline, and orders every agency to name a lead post-quantum transition officer within thirty days. In the dry language of federal mandates, it is an instruction to replace the locks on the entire government before a date certain.
The thing it defends against does not exist. A cryptographically relevant quantum computer — one that can run Shor's algorithm at the scale needed to break the RSA and elliptic-curve encryption securing essentially all of today's internet — has not been built, and the honest expert consensus is that no one knows when it will be. A December 2024 survey of some thirty quantum experts put the odds of such a machine within ten years at roughly one in five to one in three. A respectable minority doubts it arrives at useful scale for a very long time, if ever. So why the deadline, and why now?
Because the order is not defending against the machine. It says so itself. Its stated rationale is "the risk of adversaries collecting United States information now, and decrypting it later once large-scale quantum computers are operational." Harvest now, decrypt later: an adversary does not need to break your encryption today to win. It needs only to record it today — capture the ciphertext as it crosses a cable, a satellite uplink, an internet exchange — and store it, cheaply, indefinitely, against the day the machine exists. When that day comes, the archive is decrypted in bulk, retroactively. Every secret it held that is still a secret is exposed at once.
This collapses the entire quantum question into a single, timeline-independent fact. You can argue about when Q-Day arrives. What you cannot argue away is that the recording is already possible and the incentive already obvious — bulk interception of network traffic is documented, from the Snowden-era programs to this year's Salt Typhoon intrusions, and the storage is cheap. That any specific archive is being hoarded to wait out the cryptography is an inference rather than a confirmed cache, but it is a well-founded one, and the order itself takes exactly that careful posture: it warns of "the risk of adversaries collecting United States information now, and decrypting it later," hedging the intent while conceding the exposure. Because the decryption is retroactive, the date of Q-Day does not protect you; the only thing that protects a given message is whether it was already wrapped in quantum-safe encryption at the instant it was intercepted. If it was not, it is already in the archive. The break is merely scheduled.
That is the inversion at the heart of this edition. We are used to thinking of a broken cipher as a future event exposing future messages. Harvest-now-decrypt-later makes it a past event exposing present ones. The data you send today is the data being harvested today. The clock started without a starting gun, and — as a former CISA official put it of the years between now and the 2030 deadline — "we still have all that data that's still moving out, that's still at risk of being harvested."
Encryption was never a state. It was a bet.
To feel why this is unsettling rather than merely technical, give up a comfortable assumption: that "encrypted" is a property a message has, the way a locked door is locked.
It is not. Encryption is a bet — a wager that the cost of breaking the cipher will exceed any attacker's resources for as long as the protected information matters. For the algorithms running the modern internet, that wager has been astronomically safe, because brute force would take longer than the age of the universe. But the bet was never "this is unbreakable." It was "this is unbreakable in time." And the second clause is doing all the work.
A quantum computer running Shor's algorithm does not brute-force the wager; it changes the math underneath it, turning a problem that would take eons into one that takes days. The moment that machine exists, the bet that secured a given message is revealed, retroactively, to have been lost — not at the moment of the break, but at the moment the message was sent, if anyone was recording. This is why "harvest now, decrypt later" is not a metaphor. It is a precise description of how a time-bound bet fails when the horizon collapses.
And it reframes the previous edition's good news. Confidentiality won, we wrote — the EU could not force the scanning of encrypted messages, the architecture held, the math did not negotiate. All true, and all of it about classical encryption, which is exactly the bet harvest-now-decrypt-later is built to call. The encryption that resisted a continent of regulators is the same encryption an adversary is recording to break on a longer schedule. Winning the fight to keep your messages encrypted, and losing the fight to keep that encryption ahead of the machine, are not contradictory. They are this year's two halves of one story: the lock held — and someone is patiently photographing it from every angle to cut a key later.
The order, and the fire it lights
EO 14412 is not the first word on this; it is the loudest. A 2022 national security memorandum had already set a government-wide migration target of 2035. The new order compresses that to 2030 and 2031 for the systems that matter most, lays down a cascade of nearer deadlines — agency transition leads in thirty days, inventory guidance in ninety, a NIST migration pilot in one hundred eighty — and, crucially, reaches past the government into its supply chain, directing that federal contractors comply with post-quantum standards by the end of 2030. An earlier federal estimate put the cost of migrating just the prioritized civilian systems, excluding the classified and military ones, at roughly seven billion dollars across a decade.
The deadlines look distant. They are not, and that is the point of the fire. Cryptographic migrations are the slowest infrastructure projects there are, because cryptography is everywhere and labeled nowhere — baked into firmware, hard-coded in devices, buried in protocols and certificates and chips that no one has inventoried. The honest reading of a 2030 deadline set in 2026 is not "we have four years to relax." It is "this is so hard that four years is tight," which is itself the argument that the harvest is winning: if it takes the best-resourced government on earth until 2030 to re-encrypt its own high-value systems, everything not yet migrated is exposed for the duration, and the adversary's recorder runs the whole time.
The tools to do it exist, which is the genuinely hopeful part. In August 2024, after an eight-year open competition, NIST finalized the first post-quantum standards: ML-KEM for key exchange, ML-DSA and SLH-DSA for signatures, with a code-based backup, HQC, selected in 2025 as a hedge in case the lattice math underlying the others is itself broken. The algorithms are real, vetted, and shipping. The question the rest of this piece asks is not whether we can migrate. It is what, exactly, we are migrating — and whether we are moving fast on the part that matters or the part that is easy.
What has a long shelf life
Harvest-now-decrypt-later is not a uniform threat. It is a sorting problem, and sorting it is the antidote to both the panic and the denial.
Most data has a short shelf life. A one-time login code, a lunch order, a session token, a "running late" text — decrypt it in 2034 and you have learned nothing worth the electricity. For the overwhelming majority of the traffic crossing the internet right now, the harvest is real and the loss is nil, because the secret expired long before the machine arrived.
But some data has a shelf life measured in decades, or in a lifetime, and for that data the harvest is catastrophic. State secrets and diplomatic cables stay sensitive for thirty years. Health and genomic records stay sensitive for as long as you and your relatives are alive. Source code and engineering designs stay sensitive until the product is obsolete. Financial and legal records, the identities of intelligence sources, the locations of dissidents — all of it has the property that matters here: it is still dangerous when decrypted late.
And then there is the category this series has spent the year documenting, which is the worst case in every dimension at once. The biometric and identity registries that governments compelled into existence across 2026 — the national biometric IDs, the age-verification ID stores, the SIM registries linking every line to a legal name — are maximally sensitive, maximally permanent, maximally retained, and held by exactly the slow-moving custodians least likely to have migrated. A password leaked in a harvest can be changed. A credit card can be reissued. You cannot reset your iris. A fingerprint-and-iris database harvested today and decrypted in 2032 is not a breach you recover from; it is a biometric that is compromised for the rest of the enrolled person's life, for every system that will ever trust that biometric. Mexico's biometric national identity became official in October 2025. The harvester does not need it decrypted today. It needs only to be recording when the country puts it on a wire.
This is the triage the moment demands. Not "encrypt everything against quantum tomorrow," which is neither possible nor necessary, but "find the data that is still lethal in a decade and get it behind quantum-safe encryption before it is intercepted, not after." The shelf life is the sort key. The registries are at the top of the list, and they are nowhere near the front of the queue.
Mosca's inequality
There is a piece of arithmetic that turns all of this from a vibe into a deadline, and it belongs to the cryptographer Michele Mosca. It is almost embarrassingly simple, which is why it is hard to escape.
Call X the number of years your data must stay secret. Call Y the number of years it will take you to migrate your systems to quantum-safe cryptography. Call Z the number of years until a cryptographically relevant quantum computer exists. If X plus Y is greater than Z — if your data's required secrecy lifetime, plus your migration time, exceeds the time until the machine — then you are already too late. Data you are protecting today will still be valuable when the machine arrives, and you will not have finished moving it in time.
The power of the inequality is that it does not require you to know Z. It only requires you to notice that Y is large and X, for the data that matters, is enormous. If your migration will take six years and your secrets must hold for twenty-five, then you are exposed for any Z under thirty-one — which covers essentially every serious estimate on the table, including the optimistic ones. "Wait and see" is a coherent strategy only if you believe Z is larger than X plus Y, and for long-shelf-life data, X alone eats most of the plausible range. This is the answer to the most reasonable objection in the whole debate — we don't know when Q-Day is, so why rush? — without having to claim a date. You rush because the lead time is long and the shelf life is longer, and those two numbers you do know.
What shipped, and what didn't
Here is the part that should be reassuring and instead is the sharpest twist in the story: the migration is already well underway, and it is going fast — on exactly the data that needs it least.
The open, user-side encryption stack moved first and moved hard. Signal added post-quantum protection to its key agreement in 2023 and, in October 2025, extended it into the continuous ratchet itself — so that even an attacker who one day breaks a session cannot unwind the whole conversation — with the new design formally verified before it shipped. Apple rebuilt iMessage's protocol for post-quantum security in 2024. The browsers followed: Chrome and Firefox now negotiate a hybrid post-quantum key exchange by default, pairing the classical algorithm with ML-KEM so that breaking the session requires breaking both. By Cloudflare's measurement, the share of human web traffic negotiating post-quantum protection crossed from under three percent at the start of 2024 to a majority by the end of 2025. For the encrypted conversation in your pocket, the harvest is already getting harder.
But look closely at what that majority covers. It is the transport leg — the ephemeral session key between your device and a content network — and it is precisely the short-shelf-life data the harvest cares least about. The parts harvest-now-decrypt-later cares most about have barely begun to move. Server-to-server and origin encryption is post-quantum on the order of one connection in ten. Digital signatures — the authentication layer, the thing that proves a software update or a certificate is genuine — are slower still, and the standard for the most efficient of them is not even final. And the deep tail is a different problem in kind: the embedded systems, industrial controllers, satellites, vehicles, medical devices, and power-grid hardware with service lives of ten to thirty years, much of it impossible to update in the field, all of it humming along on classical cryptography that will still be running when the machine arrives.
So the uncomfortable synthesis is this. The migration is winning the cheap race and losing the timeline-proof one. We moved fast on ephemeral session keys, where a late decryption is worthless, and we have hardly moved on long-lived, irreplaceable data — the secrets, the health records, the biometric registries — held by the custodians slowest to act. The headline number is real and it is genuinely good news for your messages. It is also measuring the wrong thing if you read it as "we're halfway done." We are halfway done with the easy half.
The case for calm
The honest version of this story has to take its strongest critics seriously, because they are not cranks; some of them are the same cryptographers who built the tools this series champions, and their objection is the best argument in the field.
It runs like this. Q-Day may be a very long way off, or may never arrive at useful scale. The largest quantum computers today command on the order of a thousand error-prone physical qubits; a credible 2025 estimate put the requirement for breaking RSA-2048 at under a million of them — a striking reduction from earlier figures of twenty million, but still three to four orders of magnitude beyond anything that exists, and contingent on error-correction breakthroughs that have not happened. One prominent cryptographer has publicly offered to bet "huge amounts of money" against a relevant quantum computer arriving by 2035; another likes to point out that quantum machines "have yet to factor the number 35." Around this genuine uncertainty has grown a quantum-industrial complex — vendors, consultancies, and startups with sky-high valuations and minuscule revenues, whose business model is selling migration urgency, and whose threat assessments should be read with that in mind. And the rush itself carries a real risk: post-quantum implementations are young, and young cryptographic code has bugs, sometimes worse ones than the battle-tested classical code it replaces. A serious flaw was already found in one popular post-quantum library in 2023.
Every clause of that is true, and the conclusion that follows from it is not "do nothing" but "do the right thing, carefully." Concede the timeline fully — we do not know Z, and the brochure-sellers are real. The thesis survives the concession intact, because the load-bearing claim was never about the date. It was about the harvest, which is timeline-independent: whatever Z turns out to be, the long-shelf-life data harvested under classical encryption before you migrate is lost whenever the machine arrives. The answer to "young PQC has bugs" is the hybrid deployment the serious projects already use — classical and post-quantum together, so the new code can only ever add security, never subtract it, and a bug in the lattice math still leaves the proven classical algorithm standing. The answer to the quantum-industrial complex is not to ignore the threat it oversells but to do the unglamorous triage the brochures skip: inventory your cryptography, sort by shelf life, migrate the long-lived data first with hybrids, and stay skeptical of anyone selling a panic button. Both things are true at once. The grift is real, and so is the harvest.
The global clock
The migration is a race, and the racers are running at wildly different speeds, which is its own kind of risk.
The most-cited harvester is China, which has poured a reported ten to fifteen billion dollars into quantum research and has both the interception reach and the patience that harvest-now-decrypt-later rewards; the asymmetry of the strategy is that the country which records the most today wins the most whenever Q-Day comes, regardless of who builds the machine first. The defenders are moving on their own clocks: the US intelligence community's roadmap pushes national-security systems to post-quantum exclusivity between 2030 and 2033; the United Kingdom's cyber authority sets milestones to 2035; Germany's security office wants critical infrastructure migrated by 2030 — and yet, by recent surveys, fewer than one organization in twenty has so much as a migration plan. The standards are global and the urgency is not. The result is a world that has agreed on the algorithms and disagreed on the schedule, with the slowest-moving custodians holding the longest-lived data, and an adversary indifferent to all of it as long as the recorder is running.
The discipline between denial and panic
Two postures fail here, and they fail symmetrically.
Denial — "Q-Day is hype, the machine isn't close, relax" — is wrong not because the timeline is short but because the harvest does not wait for the timeline. It is happening now, against data with a shelf life longer than any plausible Z, and the migration that would stop it takes years to run. By the time denial is proven wrong, the long-lived secrets are already in the archive, and there is no patch for a decryption that already happened.
Panic — "drop everything and quantum-proof the world by Tuesday" — is wrong because it is impossible, because it funds the grift, and because rushing young cryptography into critical systems can subtract security instead of adding it. Between the two sits the only posture that survives contact with the facts: triage. Find the data that is still lethal in a decade. Move it behind quantum-safe encryption first, in hybrid with the classical algorithms so the floor never drops. Demand crypto-agility — the ability to change algorithms again, fast, when the next break comes, because there will be a next break — from every vendor and every system you buy, because the deepest lesson of this moment is not "switch to ML-KEM" but "never again hard-wire a cipher you cannot replace." And as individuals, do the one thing fully in reach: use the tools that already migrated. The encrypted messenger with a post-quantum ratchet protects today's conversation against tomorrow's machine, which is the rarest thing in this whole landscape — a defense you can deploy before the threat instead of after.
This is the sequel to the previous edition, and it complicates that edition's victory without erasing it. Confidentiality won, against the regulators who wanted to scan it. That win is real, and it is borrowed against a clock. The encryption we celebrated is being recorded to be broken later, and the data we are least prepared to protect is the data we can least afford to lose — the identities, the biometrics, the irreversible facts of a body, which a decade of policy is busy compelling onto wires that someone, somewhere, is patiently recording.
You cannot re-key your iris. The only move is to make sure it was never sent in the clear.
URnetwork is a peer-to-peer overlay for censorship-resistant transport, designed to resist network-layer Deep Packet Inspection; its February 19, 2026 MCP server release lets agentic clients establish VPN sessions over the peer-to-peer overlay. URnetwork's code is open and auditable, and its transport security tracks the post-quantum migration this edition describes — the discipline of staying crypto-agile, in public, where the change can be verified rather than promised.
https://ur.io