95% of Enterprises Have No Post-Quantum Migration Plan — And Attackers Are Already Harvesting Your Data
TL;DR
A new industry report puts a number on the crisis security teams have warned about for years: 95% of organizations have no Post-Quantum Cryptography migration roadmap. Meanwhile, state-sponsored actors are already executing "Harvest Now, Decrypt Later" — stealing your encrypted data today to crack it the moment a cryptographically relevant quantum computer exists. The clock did not wait for you to be ready.**
Harvest Now, Decrypt Later isn't a hypothetical attack model — it's already standard operating procedure for well-resourced state actors. The mechanics are simple and brutal: intercept and store encrypted traffic and data exfiltration today, secured under RSA, ECDSA, or Diffie-Hellman, and sit on it. Once a quantum computer capable of running Shor's algorithm at sufficient scale exists — the moment the industry calls Q-Day — every byte of that harvested data gets decrypted retroactively. Data with a shelf life longer than the time-to-Q-Day (medical records, state secrets, intellectual property, long-lived credentials) is exposed the instant that threshold is crossed, no matter how strong the encryption looked the day it was captured.
That's what makes the new report's headline number so alarming: 95% of organizations surveyed have zero formal roadmap to migrate toward NIST's standardized PQC algorithms — ML-KEM (FIPS 203) for key encapsulation, ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for digital signatures. These standards have been finalized and available for integration for a while now. The algorithms aren't the bottleneck. Organizational inertia is.
The uncomfortable math here is timeline math, not technology math. PQC migration isn't a weekend patch — it requires a full cryptographic inventory (knowing every place RSA, ECDSA, and DH are baked into your systems, often buried in third-party libraries and legacy hardware), followed by staged rollout, interoperability testing, and hybrid classical-PQC deployment to avoid breaking existing systems during transition. Security leaders widely estimate multi-year timelines for enterprise-scale migration. If your data needs to stay confidential for 10+ years and you haven't started, the harvesting has almost certainly already begun against you.
Regulators are done waiting for voluntary action — NIST, NSA, and equivalent bodies across the EU and Asia-Pacific have all issued hard PQC migration deadlines for critical infrastructure and government contractors. Being in the 95% isn't just a security gap anymore — it's rapidly becoming a compliance failure with a clock attached.
The move is not complicated: inventory your cryptography now, prioritize systems protecting long-lived sensitive data, and start hybrid PQC deployment before Q-Day turns "sensitive" into "public."