The number that changed everything: in 2019, experts estimated breaking RSA encryption would require 20 million quantum bits. By 2025, that dropped to under 1 million. By early 2026, three research papers published within months of each other pushed that estimate to fewer than 100,000 under certain conditions. That's not a gradual reduction. It's an order-of-magnitude collapse in the technical barrier between today and the day quantum computers crack the encryption protecting global banking, healthcare, government communications, and the internet.
That day has a name in security circles: Q-Day. Nobody knows exactly when it will arrive. The timeline is compressing faster than most organizations are moving to prepare for it.
This article covers:
How quantum computing breaks encryption in plain terms
Why the threat timeline moved up dramatically in 2025 and 2026
What "harvest now, decrypt later" means and why it's already happening
What organizations need to do before Q-Day arrives
How Quantum Computing Breaks Encryption Without a CS Degree
Current encryption, RSA, and elliptic curve cryptography (ECC) are built on a mathematical problem classical computers can't solve in any practical timeframe. Cracking RSA-2048 on today's hardware would take longer than the age of the universe.
Quantum computers evaluate enormous numbers of possibilities simultaneously using qubits. In 1994, mathematician Peter Shor published an algorithm showing a sufficiently powerful quantum computer could factor large numbers, the problem RSA relies on, exponentially faster than any classical machine. The hardware to run it didn't exist then. It's the hardware gap that's been closing ever since.
The three papers published between May 2025 and March 2026 showed newer quantum architectures could run cryptographic attacks with dramatically fewer qubits than any prior estimate assumed. One paper was considered sensitive enough that the authors published proof their attack circuits work without revealing how they work.

Why 2026 Is the Year the Threat Got Real
2026 has been formally designated the Year of Quantum Security, a global initiative backed by the FBI, NIST, and international cybersecurity agencies. That's not a label. It reflects a genuine inflection point.
Milestone | Date | What It Means |
NIST finalizes 3 post-quantum cryptographic standards | August 2024 | First official replacements for RSA and ECC |
NIST selects HQC as backup key encapsulation mechanism | March 2025 | Redundancy if primary standards show weaknesses |
Three papers compress qubit requirements by order of magnitude | May 2025 – March 2026 | Q-Day estimate moves dramatically closer |
NSA CNSA 2.0 deadline: all new national security systems quantum-safe | January 2027 | Hard U.S. government mandate |
NIST guidance: phase out vulnerable algorithms | After 2030 | Federal migration begins |
NIST guidance: disallow vulnerable algorithms entirely | After 2035 | Hard deadline no exceptions |
EU Coordinated PQC Transition Roadmap | 2030–2035 | 18-nation migration mandate |
Google announced in March 2025 it is targeting 2029 to complete post-quantum cryptography migration across its systems, stating explicitly the goal is to provide "the clarity and urgency needed to accelerate digital transitions across the industry." When Google sets a four-year public deadline, the industry reads the room.
The Global Risk Institute's Quantum Threat Timeline Report 2025, drawing on 26 internationally recognized experts, assessed the probability of a cryptographically relevant quantum computer at 28–49% within 10 years and 51–70% within 15. Those are the most aggressive predictions in the report's seven-year history.
Harvest Now, Decrypt Later: The Threat Already Running
This is what most cybersecurity conversations miss, and it's the reason urgency matters now, not when Q-Day actually lands.
Nation-state actors are already collecting encrypted data they can't currently read, storing it until quantum computers powerful enough to decrypt it become available. The FBI has confirmed this is an active strategy. Healthcare records with 50-year retention requirements, government communications, classified intelligence, and financial contracts, all of it is a target.
If that data is encrypted today using RSA or ECC and gets harvested now, it doesn't matter how strong today's encryption is. When Q-Day arrives, the data opens. The standard response of "we'll migrate when quantum computers actually arrive" misses the problem completely. The collection is happening right now.
What Organizations Should Actually Do
Post-quantum cryptography (PQC) refers to encryption algorithms designed to resist attacks from both classical and quantum computers. NIST's August 2024 standards ML-KEM, ML-DSA, and SLH-DSA are the first finalized replacements for RSA and ECC. The quantum cryptography market was valued at $820 million in 2026 and is projected to reach $3.73 billion by 2035 at an 18.3% CAGR, per Roots Analysis 2025.
Action | Why It Can't Wait |
Conduct a cryptographic inventory | Can't migrate what you can't find map every RSA and ECC-dependent system |
Prioritize data by sensitivity and retention period | Long-lived data faces harvest-now-decrypt-later risk today |
Test NIST-approved PQC algorithms | Migration takes 3–5 years; starting in 2026 means finishing around 2030–31 |
Build crypto-agility into new systems | Design to swap algorithms without full rebuilds; standards may evolve |
Brief boards and executives | This is a strategic budget decision, not just a technical one |
The Trump administration's June 2025 executive order explicitly referenced Biden's NSM-10 as the foundational PQC transition document, rare bipartisan continuity that signals how non-political this threat assessment has become. Canada requires all federal departments to have a PQC migration plan drafted by April 2026 and high-priority systems transitioned by end of 2031.
For most organizations, systems being designed or purchased today should be evaluated for quantum vulnerability now. Systems containing long-lived sensitive data need early migration. Everything else follows NIST phaseout guidance after 2030, a hard stop after 2035.
FAQs:
What is Q-Day, and when will it happen?
Q-Day is when a quantum computer becomes powerful enough to break RSA and ECC encryption in a practical timeframe. Experts assess the probability at 28–49% within 10 years and 51–70% within 15, per the Global Risk Institute's 2025 report. Three papers in early 2026 pushed the estimated hardware requirement down from 20 million qubits to potentially fewer than 100,000, accelerating those timelines significantly.
Does quantum computing break all encryption?
No. It specifically threatens asymmetric encryption, RSA and ECC, which underpin most of the internet's secure communications, digital signatures, and key exchanges. Symmetric encryption like AES-256 is considered sufficiently resistant to quantum attacks. The systems at highest risk are those used to establish secure connections and verify identities.
What is post-quantum cryptography?
Encryption algorithms mathematically resistant to quantum computer attacks. NIST finalized three PQC standards in August 2024: ML-KEM, ML-DSA, and SLH-DSA, designed to replace RSA and ECC. Migrating to these standards before Q-Day is the primary technical response to the quantum threat.
What is "harvest now, decrypt later" and is it actually happening?
Yes, the FBI has confirmed nation-state actors are collecting encrypted data today to decrypt once quantum computers mature. Healthcare records, government communications, financial data, and classified intelligence are all targets. Organizations with long-retention sensitive data need to treat this as a present threat, not a future one.
How long does migrating to post-quantum cryptography take?
Three to five years for most large organizations. NIST's guidance sets 2030 as the phaseout date for vulnerable algorithms and 2035 as the hard deadline. Organizations starting migration in 2026 are on a tight but achievable schedule. Those waiting until 2028 or later risk missing the window, especially in regulated industries.