“Harvest now, decrypt later” (HNDL) has dominated the post-quantum cybersecurity narrative for years. But on October 1, the NSA formally framed a second, equally critical threat and most modern cryptographic inventories aren’t equipped to catch it.
Here’s how the NSA breaks down the dual-front quantum risk:
Harvest Now, Decrypt Later (HNDL): Adversaries stockpile encrypted communication today to decrypt it when quantum hardware matures. This is a confidentiality problem.
Trust Now, Forge Later (TNFL): Adversaries forge quantum-broken digital signatures to compromise the live authentication chains you trust right now from code-signing keys and certificate authorities (CAs) to device identities and secure boot protocols. This is an integrity problem and it attacks live trust today, not stored data down the road.
Why your CBOM probably missed it: Most Cryptographic Bill of Materials (CBOM) sweeps were designed around confidentiality: identifying TLS endpoints, VPN tunnels, and databases at rest. Code-signing certs, firmware signing keys, and internal PKI chains rarely trigger those alerts because no one evaluated them through a confidentiality lens.
The Clock is Ticking: NSA directives mandate that new commercial National Security Systems support quantum-resistant algorithms starting in 2027, with non-compliant legacy systems phased out by 2030.
The Takeaway: If your PQC roadmap only covers data encryption, you’re missing half the equation. Algorithms like ML-DSA and SLH-DSA belong directly in your CI/CD pipelines, code-signing workflows, and PKI architecture, and discovery needs to start now.
Question for CISOs & Security Engineers: How is your organization mapping signature-based assets like code-signing keys and CA chains separately from your standard data-at-rest encryption inventories?
#PostQuantumCryptography #PQC
