◎ THE MACHINE THRESHOLD.
Quantum / EXPLAINER / 2 MIN READ + OPTIONAL DEEP DIVE

Tomorrow’s computers. Today’s secrets.

A future computer could expose a copy collected today. Follow the two clocks that make this a present-day problem.

AI-assisted synthesis · Published 2026-09-11 · Updated & sources checked 2026-09-11
How we research and correct our work

Some information matters for a day. Other information must stay private for years. That difference is the heart of this story.

One file. Two clocks.

A confidential design travels across a network. Its owner needs it to remain secret for twelve years. An observer copies the encrypted traffic today and keeps it. In this hypothetical, a machine capable of attacking that cryptography becomes available eight years later. The important gap is four years: the copy could become readable while the design still needs protection. Neither number is a forecast. They simply make the timing problem visible.

Conceptual locked archive and optical cable
AI-generated conceptual illustration · not a photograph or scientific measurement

Why the conversation started early

NIST describes a “harvest now, decrypt later” concern: adversaries could collect encrypted information and retain it for a future quantum capability. The timing of a cryptographically relevant quantum computer remains uncertain. The concern is a planning rationale, not evidence that such a machine is already available. [1]

TRY IT / ABOUT 30 SECONDS

Could stolen data become readable years later?

Imagine someone steals an encrypted copy of a confidential file today. They cannot read it yet—but they keep it.

For this example only, imagine they can read that copy eight years from now. That is an invented date, not a prediction.

Choose an example to see what happens.

Choose “A message” or “A design” above.

See whether the stolen copy would become readable while the information still needs to be private.

Explore other dates
Years after the copy was stolen
0102030
How long it must stay private
When the copy becomes readable in this example
Years it becomes readable too soon

This example assumes the copy was stolen and that its encryption can later be broken. It illustrates timing, not the security of a real file. Original explanation from NIST →

Three standards, two different functions

In August 2024, NIST finalized ML-KEM for establishing shared secret material, and ML-DSA and SLH-DSA for digital signatures. Signatures help authenticate information; they are a different job from keeping a message confidential. These standards supply components for systems to adopt, rather than automatically upgrading every website or device. [2]

A copy can outlive the connection

In a hypothetical example, a design is sent through an encrypted connection today. An attacker saves the encrypted traffic. Replacing the organization’s software later can protect subsequent connections, but it does not retrieve that saved copy. The future risk depends on the cryptography used, the information captured and the capability of a future attacker. This is why the lifetime of a secret matters as well as the date of a software upgrade.

A different kind of upgrade

Post-quantum cryptography uses mathematical approaches intended to resist attacks by conventional and quantum computers. It runs on conventional systems; adopting it does not require owning a quantum computer. Quantum computing itself also has possible scientific applications, including molecular simulation. The research opportunity and the security migration are connected, but they are different projects. [1]

What migration looks like in practice

NIST’s migration project separates discovery from interoperability testing. First, organizations need to locate where cryptography is used. Then implementations need to work together across products and protocols. A published algorithm is therefore a starting point for engineering, not evidence that a fleet of applications has already changed. [3]

Go a little deeper

Optional reading · about 2 more minutes

Why encryption and signatures are separate

NIST’s 2024 standards address key establishment and digital signatures. ML-KEM supports establishing secret material that a system can use for confidential communication. ML-DSA and SLH-DSA address signatures. [2] As an analogy, keeping an envelope unreadable and checking who signed a letter answer different questions. A system may need both, and changing one component does not establish that every other dependency has changed.

What an inventory is trying to find

NIST’s discovery work examines where and how cryptography protects data and systems, so inventories can inform migration priorities. Its interoperability work tests compatibility in controlled settings. [3] In an illustrative organization, one connection might depend on an application, a device and a vendor service. Updating just the application would leave unanswered whether its partners can communicate using the replacement.

Three things the timeline cannot tell you

The interactive example below assumes a copy was captured today and that a future attacker can defeat its particular cryptography. It does not model how likely capture is, which protocol was used, whether the necessary information was retained, or the date such a machine will exist. A scenario outside the selected confidentiality period is not a verdict that a real system is safe. It only changes the timing relationship in this example.

A more useful question than “when?”

Our interpretation: ask what needs protection, for how long, and what dependencies have to change. A short-lived notice and a long-lived design need not have the same priorities. The diagram makes one relationship visible; an actual migration plan needs the technical inventory and evidence that the simplified model leaves out.

Original sources

Attributed synthesis, not original reporting. Examples labeled hypothetical or illustrative are explanatory. Reviewing a source does not independently validate its findings.

  1. NIST: What is post-quantum cryptography? ↗

    Ongoing explainer; no breakthrough date established.

  2. NIST: First three finalized standards ↗

    Published August 13, 2024.

  3. NIST NCCoE: Migration to post-quantum cryptography ↗

    Ongoing migration project; checked September 11, 2026.

Suggest a correction

Where this question leads next

Follow new explainers and updates →