Harvest Now, Decrypt Later as a Cross-sector Threat: A Scoping Review of Data-confidentiality Lifetimes Against Post-quantum Migration Readiness

Simon Baradziej · International Journal of Computational Intelligence Systems · 2026

Abstract A cryptographically relevant quantum computer (CRQC) would break the public-key algorithms that protect most digital communication, but the risk does not begin when such a machine is switched on. Under the harvest-now-decrypt-later (HNDL) threat model, an adversary records encrypted traffic now and decrypts it once a CRQC exists, so any data whose confidentiality must outlast the machine’s arrival is exposed from the moment it is transmitted. This scoping review maps documented data-confidentiality lifetimes, charted by data category, against post-quantum migration readiness, documented by custodian sector, and applies Mosca’s inequality to reason about which data categories are most exposed. Following the Arksey and O’Malley framework, Joanna Briggs Institute guidance, and the PRISMA Extension for Scoping Reviews, 42 sources spanning peer-reviewed literature, standards bodies, government documents, and labeled grey literature were charted. Documented confidentiality lifetimes reach decades or are effectively perpetual for national-security records, health and genomic data, biometric identifiers, and privileged legal communications, and span years to decades for financial records. Migration-readiness evidence is uneven: most developed for government and defense and for cross-industry surveys, partial for finance and telecommunications, and largely absent for health care, genomics, and the legal sector. Reasoning through Mosca’s inequality, data categories with multi-decade or indefinite confidentiality requirements are, by that logic, already exposed to HNDL, because credible expert estimates place a meaningful probability of a CRQC within the same horizon; these exposure assessments are reasoned inferences rather than measurements. The central finding is a structural mismatch between long confidentiality obligations and immature migration, compounded by a readiness evidence gap that is itself a risk.

Read the paper · More papers on PaperTik