Question 01
What is “harvest now, decrypt later”?
It describes an adversary who collects encrypted traffic or archives today, intending to decrypt them once a sufficiently capable quantum computer exists. Nothing about the data has to change for this to work, and nothing on the victim’s side registers it as a breach at the moment of collection.
The exposure therefore depends less on when such a machine arrives than on how long the data has to stay confidential. A payment instruction that is worthless within a week is a different proposition from identity records, contracts or health data that must remain private for decades.
Question 02
What are FIPS 203, 204 and 205?
In August 2024 NIST published its first three post-quantum standards. FIPS 203 specifies ML-KEM, a key-encapsulation mechanism for establishing shared keys, the job that RSA and elliptic-curve key exchange do today. FIPS 204 specifies ML-DSA and FIPS 205 specifies SLH-DSA, both digital-signature schemes, the second built on hash functions as a deliberately conservative alternative.
In March 2025 NIST also selected HQC as a backup key-encapsulation algorithm, with its standard to follow. Together these are now the reference point that procurement teams, auditors and regulators use.
Source: NIST, FIPS 203, 204 and 205, 13 August 2024; NIST, selection of HQC, March 2025.
Question 03
When do the deadlines fall?
The dates below are the ones most often cited. They come from different authorities and bind different parties, but they point in the same direction.
- 2026
- EU: member states begin the transition by the end of the year.
- 2028
- UK: organisations complete discovery and set their migration plans.
- 2030
- US: federal systems use post-quantum key establishment by 31 December, and a contracting rule is to hold federal suppliers to the same standards. NIST: quantum-vulnerable algorithms proposed for deprecation. EU: high-risk use cases migrated.
- 2031
- US: post-quantum digital signatures by 31 December. UK: highest-priority migration complete.
- 2035
- NIST: quantum-vulnerable algorithms proposed to be disallowed. UK: migration complete. EU: as many systems as feasible migrated.
Source: US Executive Order 14412, 22 June 2026; NIST IR 8547, initial public draft, November 2024; UK NCSC, Timelines for migration to post-quantum cryptography, March 2025; EU NIS Cooperation Group, Coordinated Implementation Roadmap, June 2025.
Question 04
Why does a US order matter to a South African institution?
Executive Order 14412 binds US federal agencies and, through procurement, their suppliers. Its reach is wider than that, because the systems a South African bank depends on (cloud platforms, hardware security modules, card schemes, correspondent banks and core software) are largely sold into that market and will be re-engineered to meet it.
Regulators and auditors also tend to adopt the most specific published timetable as the benchmark for what reasonable preparation looks like. The practical effect is that a South African institution inherits the deadline through its supply chain and its counterparties, whether or not a local rule names it.
Question 05
What does South Africa’s incident-reporting regime require?
Joint Standard 2 of 2024, issued by the Prudential Authority and the FSCA, has applied to financial institutions since 1 June 2025. Since 1 September 2026, material IT and cyber incidents are reported on a prescribed template: an initial notification within 24 hours of the incident being classified as material, an update within 14 calendar days, and a final investigation report within a period agreed with the relevant authority.
The clock starts at classification. The regime does not measure how long an intruder was present before anyone looked, which is the interval our current series examines.
Source: FSCA and Prudential Authority, Joint Notice 2 of 2026 and Joint Communication 5 of 2026; Joint Standard 2 of 2024.
Question 06
What is crypto-agility?
Crypto-agility is the ability to replace a cryptographic algorithm, key size or protocol without re-engineering the applications that depend on it. It matters because the post-quantum transition will not be a single substitution: standards are still being added, and implementations will be revised as weaknesses are found.
An estate in which the algorithm is written into business logic faces the migration once for every algorithm it adopts. An agile estate faces it once.
Question 07
Does post-quantum cryptography stop the misuse of a stolen credential?
No. Post-quantum cryptography ensures that the mathematics behind a signature or an encrypted session cannot be broken by a quantum computer. It does not establish who is using a valid key. An instruction signed with a stolen credential is correctly signed under any algorithm, classical or post-quantum, and every control that checks the signature will approve it.
Migration closes one exposure and leaves the other exactly where it was, which is why we treat the two as a single problem.
Read the thesis →
Last reviewed 28 September 2026