Is Q-Day Really Nigh? Perceptions Of The Quantum Risk
The quantum threat to encryption has moved from the theoretical to the strategic.
In our latest Computing research we look at developments in quantum computing and cryptography, whether UK IT leaders believe the risk is real and what actions they are taking.
Q-day is the day when a sufficiently powerful quantum computer can break public-key cryptography.
Given that public-key cryptography is what secures our email, our online accounts, our VPNs, our cloud workloads, our software updates, our identity systems, our banking transactions – effectively everything we do online – this is not a day that most will be looking forward to. The big question is when (or even if) it will arrive.
Q-day ≠ Y2K
Quantum risk is sometimes compared to the Y2K bug, which is comforting as, despite fears of imminent catastrophe, no planes fell out of the sky when the clocks struck midnight and we entered the new millennium.
But the comparison is also misleading. With Y2K we knew exactly what might break, we knew exactly how to fix it and the fix was easy. And, of course, with Y2K the clue was in the name – we knew exactly when it would happen.
Q-day has none of those comforts. We don't know the date, we don't know which systems will be hit first, and the fix is complex.
Most importantly, in 1999 there were no hostile nation states patiently hoovering up encrypted data in the hope that one day they will be able to crack it. Today, that is explicitly the strategy.
If anyone does know more than the rest of us about when Q-day will arrive, it's governments with classified research programs, intelligence budgets measured in tens of billions, and a strong incentive not to share their workings. The most advanced quantum work is almost certainly happening quietly behind closed doors.
More positively, the world has had 30 years to prepare for Q-Day, and we know what to do.
A Very Brief History Of The Quantum Threat
1976: Public-key cryptography solves a problem humanity has wrestled with for centuries: how do two people communicate securely without first meeting to exchange a secret key? RSA, and later elliptic curve cryptography (ECC), solve this problem. They rely on mathematical calculations that are quick and easy to perform one way, but brutally hard to reverse.
1994: Peter Shor shows that if you had a large enough quantum computer, you could break those hard problems very quickly. At the time, though, quantum computers are very rudimentary, essentially lab toys. The threat is academic - interesting but distant.
Meanwhile, the rest of the world gets busy with its new toy, the World Wide Web.
Late 1990s: There’s an explosion in ecommerce. A little later online banking becomes a trusted part of everyday life, thanks to protection from public key cryptography which has become embedded pretty much everywhere.
2001: Shor's algorithm is actually run for the first time. On tiny numbers - but it works.
In the years that follow, quantum computing progresses quietly, solving niche physics and chemistry problems. At the same time cryptographers are busy designing alternatives to RSA and ECC.
Then the momentum shifts.
2019: IBM releases its first commercial quantum computer, the System 1. The next few years see claim and counterclaim over quantum advantage as competition heats up.
2024: U.S. National Institute of Science and Technology (NIST) finalizes its first set of post-quantum cryptography standards.
At the end of the year Google announces a breakthrough in quantum error correction - one of the main barriers to scale – with its Willow chip.
2025: Google AI scientist Craig Gidney lowers the estimated resources needed to break RSA-2048 encryption by a factor of 20.
Perception Of The Quantum Risk
The 2020s are when the threat moved from the theoretical to the strategic.
The digital economy was built on maths that cryptographers have known for three decades has an expiry date. Q-day represents that date.
We asked 100 UK IT leaders about their perception of quantum risk.
Two per cent think it’s mostly hype, which is a perfectly valid position. It’s certainly not inevitable that quantum computers and software will be able to scale up as envisaged, and there are plenty of experts in the field who are skeptical that the formidable technical barriers will be overcome soon - if ever.
For example, Tim Palmer, a physicist at the University of Oxford, estimates that quantum computers will reach peak usefulness for factoring large numbers at around 1,000 qubits and will never scale to the million or so required to break RSA-2048.
Meanwhile, the Swiss Quantum Commission notes that “neither quantum hardware capable of large-scale fault-tolerant quantum computation, nor any end-to-end commercially successful application thereof, has been demonstrated.”
Most Computing respondents believe that quantum is a threat to encryption, but they're split almost exactly down the middle on whether the threat is urgent.
This is a classic risk-management pattern. If something is high impact but uncertain in timing, our instinct is to stick it on the back burner and get back to more urgent priorities.
Recommended Migration Timelines
The National Cyber Security Centre (NCSC) has a timeline for all organisations to move to post-quantum cryptography (PQC).
By 2028: discovery and assessment complete
By 2031: highest-risk systems migrated
By 2035: vulnerable cryptography removed
This broadly matches advice from other authorities.
In the U.S., the NSA says that sensitive government systems must implement quantum-resistant algorithms by 1st January 2027, with PQC required across the board by 2031, and with a full transition by 2035. “In practice, this means all new code should be signed with PQC schemes now, and existing signed code must be updated,” the agency says.
The EU’s roadmap pinpoints the end of 2026 member as the time by which states should have a national PQC strategy in place, with pilots launched to cover high- and medium-risk use cases. High-risk systems must be fully migrated to PQC by the end of 2030, with as many as possible medium and low risk systems protected by 2035.
Global Risk Institute Estimates
Every year, the Global Risk Institute asks quantum computing experts a simple question: “When do you think RSA-2048 will be broken?”
In 2024 - the latest figures available - they estimated that there's a 5% - 14% chance that this could happen within five years - or by 2029.
RSA-2048 is one of the industry-standard algorithms for data encryption. Its effective key strength is about 112 bits, and brute-forcing it, even with a supercomputer, would take around 150 million years.
But a quantum computer would make short work of RSA-2048 (and elliptic curve alternatives) - provided such a device can be scaled up to meet the challenge.
A metaphor for the classical approach is sending a person into an enormous maze and waiting for them to emerge with the answer – 150 million years later. The quantum approach is like sending an entire search party into the maze. Every time they hit a fork in the road they split and try both. That way they can emerge with a result mere hours or days later.
Interpreting that output is the tricky bit, though. That’s what Shor’s algorithm does.
Post-Quantum Cryptography
Quantum computers are only good at solving certain types of problems, where there are discernible patterns that can be exploited.
PQC algorithms using lattice‑based schemes rely for security on noisy, high‑dimensional geometric space, while hash‑based schemes offer quantum computers only limited speed advantage, if any, in brute-forcing the answer.
As far as we know, these are mathematical problems for which there is no known magical quantum shortcut – you can’t go from 150 million years to 24 hours. While the new algorithms may still be vulnerable, the threat is unlikely to come from a quantum computer.
Post-Quantum Strategy
The Mosca Inequality
The big problem for CIOs and CISOs is not just the uncertain timeline. It’s how to assign what will likely be a substantial budget to mitigate a risk that may be a long way off - or never arrive, and which will take several years to prepare for.
Michele Mosca, a professor at the Institute for Quantum Computing at the University of Waterloo, Canada, argues that whenever Q-day might arrive, the lengthy timeline for mitigation and the need to store sensitive data for extended periods means organisations should treat the risk as a near-term planning problem. The Mosca Inequality encapsulates this thinking.
X + Y > Z
Where:
X is how long your data needs to remain secure
Y is how long it will take you to migrate to post-quantum cryptography
Z is how long until quantum breaks existing systems
If X plus Y is greater than Z, you lose.
If data must be retained for seven years - which is a common requirement for compliance - and if migration takes three years (which could be optimistic depending on the organization), then X + Y is 10 years. If a quantum computer capable of running Shor’s algorithm arrives before that then all your data is at risk. Being on the right side of this inequality does not guarantee security, however, as data protected by vulnerable systems that’s harvested now could still be decrypted later (HNDL attack).
(According to the GRI forecast from 2024, there’s a 22% - 40% chance that Q-day will arrive by 2036.)
Looking at the Global Risk Institute chart and starting from 2026 rather than 2024, we can see that in 10 years, or 2036, according to the quantum computing experts polled there’s a 22% - 40% chance that Q-day will arrive. This estimate was made before the latest improvements in quantum error correction.
Given what’s at stake, these are not the kind of odds we want to be facing. But how does this prediction compare with others?
As we’ve seen, some skeptics believe Q-day to be decades away. On the other hand, IBM and Google both suggest commercially viable, fault-tolerant quantum systems could arrive around 2029. Granted, there are several reasons why both might want to exaggerate progress, but their roadmaps have been pretty solid so far.
The arrival of such a device wouldn’t mean instant cryptographic collapse, but it would trigger massive investment and presumably enhanced progress thereafter.
Breaking RSA-2048 using Shor's algorithm is estimated to require around 1,730 logical qubits, according to one group of researchers, far beyond the capacity of today's machines (around 50 logical qubits), but no longer science fiction.
What Organizations Say They'll Do
On paper, intentions look encouraging. Thirteen percent expect to move to post-quantum cryptography by 2028, 30 percent by 2031 and 19 percent by 2035.
But, in addition to the large number of “Don’t knows”, there is some cause for doubt.
Only a small minority are in the discovery or implementation phases, each of which could take a couple of years, realistically.
Most are aware of the issue but not yet taking action, or are at the planning stage. Several respondents said they are waiting to be led by their vendors.
The biggest barrier cited? Cost and budgeting. Second was competing priorities. Most IT leaders have more security issues than they can effectively handle, so an additional problem with a nebulous timeline will not gain their full attention.
Thirty-nine percent mentioned unclear standards and timelines. The timeline may be uncertain - although the NCSC and others are been clear about where organisations should be. But there are now approved standards to follow, so waiting for clarity may not be a defensible strategy.
The U.S. National Institute for Standards and Technology (NIST) has already approved replacement systems for both data encryption and digital signatures, and is working on others, so while implementation is not trivial, the standards are there now.
Are We At Risk?
Any cyber-risk calculation should include an assessment of whether the organization is likely to be a target. Early quantum-enabled adversaries are likely to be state-backed actors. They will not go after random SMEs but they will target governments, banks, cloud providers, defense and energy, and other critical infrastructure. But every business is connected in some way as partners, customers or elements of the supply chain, so everyone would be affected.
The good news is that the technology ecosystem has been moving on this for more time. Cloud providers are rolling out quantum-safe options, as are networking and communications vendors, and providers of browsers, operating systems, banking systems and so on.
The bad news is that vendors cannot fix the cryptographic sprawl within organizations. That’s something they must do for themselves.
So - is Q-day nigh? No-one knows but given the timelines it would certainly seem wise to start taking it seriously.
This article originally appeared on MES Computing’s sister site Computing.