Europol’s HNDL Report Is Useful, but It Is Not a Migration Plan

Europol’s Harvest now, decrypt later report addresses a serious problem. Sensitive information encrypted today could become readable in the future if sufficiently capable quantum computers can break the public-key cryptography protecting it. Published on 7 October 2026, the report examines that exposure through a criminal and law-enforcement lens.
The subject deserves attention. The report deserves scrutiny.
It is a useful briefing for readers encountering the threat for the first time. It connects technical exposure with criminal motivations and the enduring value of sensitive information.
But usefulness is not novelty. A warning is not a programme. And another instruction to “prepare now” is not the leadership this subject requires.
For organisations already working on post-quantum cryptography, the relevant question is not whether they should begin thinking about quantum risk. It is whether they can prove that their exposure is being identified, prioritised and reduced.
The warning should already have triggered action
Harvest now, decrypt later, usually shortened to HNDL, describes collecting encrypted information today with the intention of decrypting it when the necessary capability becomes available.
The attacker does not need to break the cryptography at the point of collection. They need access to useful ciphertext, the ability to retain it and a future route to decryption.
The research underpinning Europol’s briefing examines this problem across TLS, QUIC and SSH, including the practical and economic constraints on future attacks.
This is not a newly discovered threat.
On 21 August 2023, CISA, the NSA and NIST published joint quantum-readiness guidance. They urged organisations to establish a roadmap, develop cryptographic inventories, assess risk and engage suppliers.
On 13 August 2024, NIST released its first three final post-quantum cryptography standards: FIPS 203 for ML-KEM, FIPS 204 for ML-DSA and FIPS 205 for SLH-DSA.
By October 2026, “prepare now” should be a reminder to organisations that have failed to act, not the principal destination of the discussion.
The warning has had years to become a programme.
Hybrid protection already ships
The availability of protection matters because it changes the nature of the leadership challenge.
OpenSSH has offered post-quantum hybrid key agreement by default since version 9.0, released in April 2022. OpenSSH 10.0, released in April 2025, made the ML-KEM-based hybrid mlkem768x25519-sha256 its default key-agreement algorithm.[openssh]
OpenSSL 3.5, released on 8 April 2025, introduced native support for the NIST-standardised PQC algorithms and hybrid post-quantum TLS key establishment.[postquantum][openssl-library]
These developments do not mean that every organisation is protected.
A capable library is not a migrated application. An upgraded client is not an upgraded server. An available algorithm is not proof that a connection negotiated it.
Versions, configurations, endpoint compatibility and supplier dependencies still matter.
But the conversation has moved. Relevant protection is no longer confined to research papers or future product announcements. Organisations can examine deployment paths now.
That makes the absence of an inventory, an owner or a supplier commitment harder to defend.
Standards are not the same as deployment
OpenPGP illustrates why reporting must distinguish standards status from implementation readiness.
RFC 9980, Post-Quantum Cryptography in OpenPGP, was published in June 2026. It defines post-quantum public-key extensions to OpenPGP for encryption and signatures.
Its publication does not mean every OpenPGP product supports those extensions. It does not guarantee interoperability across every deployed client. It does not remove the need to plan key transitions.
Nevertheless, “the standard is being developed” and “the standard exists but deployment remains uneven” are materially different positions.
Readers need to understand which problem they face:
A missing standard.
A missing implementation.
An unsupported deployed version.
An incompatible endpoint.
A supplier-controlled dependency.
An unfunded migration decision.
Those are different obstacles. They require different owners and different remedies.
Collapsing them into a general instruction to wait, monitor or prepare is not enough.
The scale remains uncertain
The report’s treatment of evidence deserves a careful distinction.
Europol says there is no clear evidence that HNDL is being systematically exploited at scale. That is an important limitation, not a reason to dismiss the underlying exposure.
Nor does the possibility that previously stolen encrypted information could provide future raw material establish the prevalence of deliberate HNDL activity.
Possibility, technical feasibility, observed behaviour and measured scale are separate categories.
Organisations should not claim that every business is demonstrably subject to large-scale HNDL collection. Equally, they should not conclude that incomplete evidence makes long-lived sensitive data safe.
The defensible response is to examine their own exposure:
What information must remain confidential for many years?
Which cryptographic mechanisms protect it?
Where could an adversary obtain encrypted copies?
Which systems and suppliers control remediation?
How long will migration take?
What would disclosure cost the organisation and the people affected?
That is a basis for prioritisation. A generic threat statement is not.
Cheap retention does not mean cheap decryption
The economics deserve sharper attention.
The UC3M preprint cited by the report, On the Practical Feasibility of Harvest-Now, Decrypt-Later Attacks, was submitted on 1 March 2026. Its analysis treats traffic retention as economically trivial relative to the quantum workload required for subsequent decryption.
The distinction is consequential.
An adversary may be able to retain large quantities of encrypted information without being able to decrypt all of it economically. Collection can be broad while future decryption remains selective.
There is no inherent contradiction between cheap storage and expensive decryption. The weakness arises when those separate costs are not connected clearly to the resulting risk assessment.
A useful model should explain:
How the attacker acquires the information.
What it costs to retain.
Whether it will remain valuable.
What future decryption could require.
How protocol choices affect the workload.
Why particular targets deserve higher priority.
Cheap storage alone does not establish an economically viable attack. Expensive decryption does not make collection irrelevant.
Leadership needs those distinctions, especially when deciding which data and systems should move first.
A briefing cannot become your migration programme
Europol cannot build an enterprise’s cryptographic inventory, assign its executive owner or approve its budget.
It should not be criticised simply for failing to do work that belongs to the organisation.
But its report should not be mistaken for a delivery playbook either.
The difference between awareness and execution is visible in the questions an organisation can answer.
Does it know where vulnerable public-key cryptography is used? Does it know which data has the longest confidentiality requirement? Can it identify the suppliers controlling change? Has it tested a migration path? Can it demonstrate deployment rather than merely report intention?
If not, another warning has not solved the problem.
As SITG-Consulting explains in PQC Is Not About the Quantum Computer, the enterprise challenge extends beyond the arrival of a quantum machine. It includes the operational ability to discover dependencies, govern change and execute a transition.[sitg-consulting]
What accountable action looks like
The practical response should begin with evidence, not a product purchase.
Establish the baseline
Identify the cryptographic algorithms, protocols, libraries, keys, certificates, applications, infrastructure and supplier dependencies in use.
Connect that technical information to business ownership and the confidentiality lifetime of the data being protected.
The inventory must support decisions. A list of algorithms without application context or accountable owners does not do that.
Prioritise exposure and delivery difficulty together
Long-lived sensitive information deserves attention, but so do the systems that will take longest to change.
A supplier-controlled appliance, an embedded platform or a tightly coupled application may create a longer migration path than a service whose endpoints are both under the organisation’s control.
The priority is not simply “most sensitive first”. It is understanding sensitivity, exposure and the time required to deliver protection.
Test available protection
Where compatible implementations exist, test hybrid key establishment rather than treating it as a future possibility. OpenSSH and OpenSSL already provide relevant implementation paths.
Confirm what is negotiated. Check interoperability and performance. Identify exceptions. Document the deployed state.
An upgrade record is not the same thing as evidence of protection.
Require dated supplier answers
“PQC ready” is not a sufficient supplier response.
Ask what the product uses, what will change, which versions will support it, what the customer must do and when the capability will be available.
Then connect those answers to procurement, renewal and replacement decisions.
SITG-Consulting’s Post-Quantum Migration Mistakes: The PQC Baker’s Dozen examines why buying a product before understanding the transition is the wrong starting point.[sitg-consulting]
Put responsibility and funding in writing
Name the executive accountable for the programme.
Set funded milestones. Record exceptions and risk acceptance. Report progress against evidence, not activity.
Useful measures include inventory coverage, supplier response rates, tested migration paths, deployment coverage and unresolved dependencies.
For organisations needing an independent starting point, SITG-Consulting’s PQC Strategy and Readiness Assessment addresses the enterprise transformation challenge rather than treating PQC as an isolated technology upgrade.[sitg-consulting]
The SITG-Consulting verdict
Europol’s report provides a useful law-enforcement perspective on a legitimate long-term confidentiality risk. That contribution should be recognised.
It should also be kept in proportion.
The warning is established. Relevant hybrid protection is available. Standards publication and product deployment must be distinguished. Evidence of current scale remains incomplete. Collection and decryption have different economics.
None of those issues is resolved by telling organisations to prepare.
The report can prompt action. It cannot substitute for it.
The organisations that make progress will be those that know what cryptography they run, understand which data must remain confidential, obtain dated commitments from suppliers and can prove that protection is being deployed.
This subject is crying out for leadership.
Not another warning. Responsibility, funding, deadlines and measurable progress.
Brian Couzens and Clauden Higgsbottom




Comments