Encrypted records sent today are being saved for the day quantum machines can read them, and migrating the world's RSA and elliptic curve cryptography, the math that secures most internet traffic, takes years.
Encrypted records sent today are being saved for the day quantum machines can read them, and migrating the world's RSA and elliptic-curve cryptography — the math that secures most internet traffic — takes years. The window to act is closing.
Q-Day, shorthand for "Quantum Day," is the date when non-quantum-safe cryptographic techniques and algorithms can be broken by a quantum computer. That date is predicted to arrive around 2030, though it could come as early as 2028, according to the current research consensus. The threat is not future tense. It is present tense. Hackers and state actors are already using a strategy known as harvest now, decrypt later: capturing encrypted data today, storing it, and waiting for quantum computers powerful enough to crack it open.
Three primary architectural paths exist to defend against this threat and achieve quantum-safe readiness: post-quantum cryptography (PQC), quantum key distribution (QKD), and hybrid strategies that combine the two. Each offers distinct mechanisms for safeguarding sensitive data, and understanding their operational differences is vital for any organization beginning a migration.
PQC relies on software-coded mathematical algorithms designed to resist quantum attacks. The National Institute of Standards and Technology (NIST) has standardized three core algorithms: FIPS 203 and FIPS 204, which use lattice-based techniques to establish secure connections and prove message authenticity, and FIPS 205, a hash-based alternative that is slower but offers a different cryptographic approach. Being software-based, PQC is highly scalable. NIST [selected FALCON for FIPS 206](https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization) and HQC for standardization in March 2025, adding two further algorithms to the post-quantum portfolio. The White House has moved to accelerate federal adoption: Executive Order 14409 and OMB Memorandum M-26-15 set a government-wide migration milestone of 2035. The NSA's Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) specifies software-signing and key-establishment milestones from 2026 through 2033 for national security systems.
QKD, by contrast, uses the physics of quantum mechanics to secure key distribution — a fundamentally different approach than PQC's mathematical hardness. Hybrid strategies combine classical and post-quantum algorithms to provide defense-in-depth during the transition period.
The cryptographic threat feels abstract, but the hardware timeline is concrete. Quantum computers are already performing calculations that conventional supercomputers cannot match. Google's 105-qubit Willow quantum processor completed a benchmark computation in under five minutes that would take a conventional supercomputer working since the Big Bang to finish. The 1,000-qubit barrier was crossed nearly three years ago — and a 1,000-qubit machine is exponentially more powerful than Google's 105-qubit Willow, not just ten times more powerful. IBM's Kookaburra processor, per IBM's public roadmap disclosed in 2022 and reported by IEEE Spectrum, was targeted to exceed 4,000 qubits by 2025 — a roadmap milestone, not a confirmed achieved milestone.
This is the hardware reality against which the 2028–2030 Q-Day window must be read. Organizations cannot wait for Q-Day to arrive before acting. The data harvested today will be decrypted with tomorrow's quantum computers.
The scale of the migration problem cannot be overstated. RSA (Rivest–Shamir–Adleman) and elliptic-curve cryptography (ECC) are the two public-key systems that negotiate secure connections, authenticate users, and digitally sign software across the internet. Replacing them requires changes to every affected system, library, and protocol that relies on them — a process that runs in years, not weeks or months, for large organizations.
The harvest-now, decrypt-later strategy exploits exactly this migration gap. Records intercepted today — financial transactions, medical data, encrypted backups, government communications — are stored with the assumption that quantum decryption will become feasible within a plausible timeframe. For the most sensitive data categories, that window is measured in years, not decades.
Most organizations are still in the preparation phase. The question is no longer whether quantum computers will break current encryption, but how much sensitive data will be compromised before the migration is complete. The 2028–2030 window is not an optimistic projection; it is a risk horizon that defines how much time organizations have to finish a multi-year cryptographic infrastructure overhaul that has barely started.
Achieving quantum-safe readiness is not a single product or a single upgrade. It requires coordinated action across five dimensions: inventorying where RSA and ECC are in use, validating that PQC algorithms perform correctly in the organization's environment, optimizing performance overhead, testing interoperability, and certifying that the overall system is quantum-safe before the deadline arrives.
The deadline, moreover, is not uniform. CNSA 2.0 already requires certain national security systems to meet software-signing milestones by 2026. Federal civilian agencies face a 2035 whole-of-government target. The private sector has no equivalent mandate, though the interdependencies between government and commercial infrastructure mean that the federal timeline sets a de facto standard for any organization that touches federal data or systems.
Organizations that begin the inventory and assessment process now are building optionality. Those that wait until the hardware timeline clarifies will have less time to execute a migration that, for large institutions, already runs in years. Q-Day is not a problem to solve on its date. It is a deadline that started clocking the moment harvest-now, decrypt-later became a viable strategy — which, by most accounts, was years ago.