Post-quantum pressure reaches identity's cryptographic core
New post-quantum HSMs arrive as harvest-now-decrypt-later attacks target identity records. Why crypto-agility is now a verification infrastructure question.


The cryptography underneath digital identity just got its clearest upgrade notice yet. Thales this week launched its Luna 8 hardware security module, a network appliance supporting both current and post-quantum algorithms, and the launch framing matters more than the box: 61 percent of organizations now cite harvest-now-decrypt-later attacks as their top quantum concern, and 59 percent are already prototyping post-quantum cryptography, per Thales's 2026 Data Threat Report.
Harvest now, decrypt later is the threat model that makes quantum a present-tense identity problem. Adversaries collect encrypted data today, biometric templates, identity records, signed credentials, verification archives, and wait for quantum capability to unlock it. Data with a short shelf life can shrug; identity data cannot, because a person's biometrics and life records stay sensitive for decades. Every verification provider, wallet scheme, and credential issuer is in the long-lived data business, whether they have noticed or not.
The competitive HSM field, Entrust, Utimaco, and Crypto4A alongside Thales, is converging on the same answer: crypto-agility, the ability to swap algorithms without rebuilding applications. That answer applies well beyond the hardware.
Why identity infrastructure feels this first
Three properties put verification systems at the front of the migration queue. Longevity: verification evidence and signed credentials must remain provable for retention periods measured in years, spanning the expected arrival of cryptographically relevant quantum machines. Signature centrality: the entire credential era, mobile driver's licenses, EUDI wallet attestations, hardware-signed capture, chain-anchored records, rests on digital signatures, exactly the primitive quantum attacks break first. And harvest appeal: identity stores are the highest-value long-shelf-life target an attacker can bank, the AI-era version of stealing the filing cabinet and picking the lock later.
The AI pressure runs in parallel: the same report finds only 34 percent of organizations know where their data lives and 47 percent of sensitive cloud data unencrypted, while 61 percent have seen AI applications targeted with sensitive data as the objective. Automated systems with broad data access widen the harvest surface while quantum shortens the decryption horizon.
Crypto-agility as a verification design principle
The HSM vendors' consensus, migration without replacing applications, is the standard every verification architecture should be held to. In practice that means algorithm choices isolated behind interfaces rather than welded into record formats; hybrid signing paths that can layer post-quantum schemes alongside current curves as standards mature; key ceremonies and hardware roots that upgrade in place; and re-anchoring strategies for archives, so evidence signed under today's algorithms can be countersigned under tomorrow's before the originals weaken.
deepidv builds on that principle: verification evidence is anchored cryptographically with the signing machinery isolated from the records it protects, so algorithm migration is an infrastructure event rather than an evidence-invalidating one. For buyers, the question to put to any provider holding your identity data is direct: what is your post-quantum migration plan, and does it preserve the provability of everything you have already signed?
What to do this quarter
The migration to-do list is unglamorous and overdue. Inventory where identity data and signatures live, the step the 34 percent statistic says most organizations have skipped. Classify by shelf life: anything sensitive past 2035 is already harvest-exposed. Demand crypto-agility statements from every identity vendor and credential scheme in the stack. And watch the certification tracks, FIPS 140-3 and EU Common Criteria evaluations of post-quantum modules, because regulated industries will inherit those baselines as procurement requirements soon after they land.
Quantum timelines remain debated; the harvest logic does not depend on them. Data stolen this year is decrypted whenever the capability arrives, and the only defense that works is the one deployed before the theft.
Post-Quantum Identity FAQ
- What is harvest now, decrypt later?
- An attack strategy where adversaries steal encrypted data today and store it until quantum computers can break the encryption. It makes quantum risk a present-tense problem for long-lived sensitive data, identity records and biometrics above all, since their value survives until decryption day.
- Why does post-quantum cryptography matter for identity verification?
- Because verification runs on digital signatures, credentials, attestations, signed capture, anchored evidence, and signatures are the primitive quantum attacks break first. Identity data also stays sensitive for decades, so records signed and encrypted today must survive the algorithm transition.
- What is crypto-agility?
- The ability to change cryptographic algorithms without rebuilding the applications and records that depend on them: isolated signing interfaces, hybrid schemes during transition, upgradeable hardware roots, and re-anchoring for archives. It is the design property that makes post-quantum migration an upgrade rather than a crisis.
- When will quantum computers break current encryption?
- Estimates vary from years to decades, and the uncertainty is the point: harvest-now-decrypt-later attacks bank stolen data against whenever capability arrives. Organizations protecting data that stays sensitive past the early 2030s are already inside the risk window regardless of the exact date.
- What should businesses ask identity vendors about quantum readiness?
- Three things: the post-quantum migration plan and its timeline, whether already-signed evidence and credentials remain provable through the transition, and which certifications, FIPS 140-3 and Common Criteria evaluations of PQC modules, the vendor's cryptographic infrastructure is tracking.
Relevant Articles
Sub-150ms attestation at the client edge
The signature-heavy architecture now in scope.
Sep 4, 2026
EUDI wallet deadline: Europe's identity clock hits 90 days
A continent of new credentials to future-proof.
Sep 11, 2026
Verifiable digital credentials just became CIP-grade ID
Signature trust entering bank regulation.
Sep 11, 2026
What is deepidv?
Not everyone loves compliance — but we do. deepidv is the AI-native verification engine and agentic compliance suite built from scratch. No third-party APIs, no legacy stack. We verify users across 211+ countries in under 150 milliseconds, catch deepfakes that liveness checks miss, and let honest users through while keeping bad actors out.
Learn More