Stay Up to Date
Subscribe to our newsletter
On September 3, 2026, the G7 Cybersecurity Working Group and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published a joint advisory naming harvest-now-decrypt-later (HNDL) a present-tense threat, not a future one. Seven governments and the agency responsible for U.S. federal civilian cybersecurity have never said this together before.
Nothing in "Preparing for the Post-Quantum Era: A Call to Action" is new information to anyone who has been paying attention. What changed is who signed it, and when. Canada, France, Germany, Italy, Japan, the United Kingdom, and the United States moving in the same week is a signal to procurement committees and board risk registers, not a technical disclosure. If your cryptographic exposure is still unmapped, the excuse that this is a speculative, future problem no longer holds up in a board meeting.

Many readers of a G7 and CISA advisory might assume it applies to defense contractors and government agencies, because the loudest quantum-security deadline, CNSA 2.0, is scoped specifically to U.S. National Security Systems. That assumption is wrong, and the advisory itself says so directly: it stresses that the threat needs addressing across all sectors, not just critical infrastructure operators.
The regulatory record outside defense confirms it.
Those are commercial enterprises, not defense contractors, and the gap between planning and deployed protection shows up with no CNSA 2.0 obligation in sight, which is the clearest evidence this was never a defense-only problem.
The regulatory calendar is no longer an abstraction. On September 21, 2026, FIPS 140-2 certificates move to Historical status, meaning only FIPS 140-3 validated cryptographic modules are eligible for new federal procurement. That date is two weeks from this advisory's publication. It sits ahead of a sequence of dates that were already on the calendar: the National Institute of Standards and Technology (NIST) finalized its post-quantum cryptography standards, FIPS 203, 204, and 205, in August 2024. The NSA's Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) requires all new acquisitions for National Security Systems to be compliant starting January 1, 2027. The EU's post-quantum cryptography roadmap mandates critical infrastructure migration by 2030. In financial services, DORA has required demonstrated crypto-agility since January 2025, and PCI DSS 4.0 activated future-dated cryptographic controls in March 2025.
None of these deadlines is coordinated with each other by design. They are coordinated by consequence: they all trace back to the same underlying constraint, which is that migrating cryptographic infrastructure inside a large organization takes years, not months, and the agencies setting these dates know it.
The instinct after reading an advisory like this is to reach for a solution. That instinct is premature. An organization cannot migrate what it has not inventoried, and in practitioner terms, the most consistent failure point in early cryptographic inventories is not the primary application. It is the middleware, the message queues, and the third-party integrations where TLS defaults were set once, years ago, and never revisited by anyone who understood what algorithm was running underneath.
A cryptographic exposure assessment answers three questions before any migration plan is credible:
That assessment does not require ripping out infrastructure or committing to a vendor. It requires a clear, board-ready picture of exposure, which is the actual gap the ISACA data points to.
The organizations that come out of 2027 in the strongest position will not be the ones with the most advanced cryptography. They will be the ones that treated cryptographic exposure as a standing board risk item in 2026, the same way they treat any other risk with a known deadline and an unknown cost of inaction.
The G7 and CISA advisory does not create that risk. It confirms that seven governments have stopped treating it as optional to disclose. Whether an individual organization continues to treat it as optional to act on is now a governance decision, not a technical one.

About Horizen Labs Quantum Security Team
Horizen Labs delivers expert-led quantum security consulting, helping organizations assess and address cryptographic exposure before regulatory and threat timelines force the issue.
Quantum Risk Check

A quantum risk score across three dimensions: cryptographic exposure, harvest risk, and signature Integrity, plus regulatory flags and recommended next steps.
Check NowYour board needs to understand quantum risk. Here's the briefing that gets it on the agenda.

Plain language. Current regulatory deadlines. Five actions they can approve today.
Download Now for FreeBLOG

Horizen Labs published Part 2 of its quantum-resistant migration series, turning the lens on the company itself. It's a candid look at what's already protected, what's being deliberately left alone for now, and where the real exposure still sits: signing keys and custody.

Quantum risk reaches insurers twice, through the long-lived claims data they store and the policyholders they cover. This is what harvest now, decrypt later means for a carrier, what FINMA Guidance 05/2026 requires, and which two workstreams to run before the next renewal cycle.

Horizen Labs is migrating the Horizen protocol to quantum-resistant cryptography. Part 1 maps where the real exposure sits: the public-key and signature surfaces, not the hash primitives. It lays out a pull-based roadmap pegged to Ethereum's and the Superchain's post-quantum milestones, targeting end-2029.