Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

CRQC Timelines: When Will Quantum Computers Break Encryption?

PQC

A Cryptographically Relevant Quantum Computer (CRQC) is a quantum computer powerful enough to break today’s public-key cryptography (RSA, ECC) using Shor’s algorithm. No CRQC exists in 2026, and expert estimates for when one might arrive vary widely, commonly placing meaningful probability in the 2030 to 2035 window. Because of ‘harvest now, decrypt later’, organizations must act well before that date.

A Cryptographically Relevant Quantum Computer (CRQC) is a quantum computer large and stable enough to break the public-key cryptography that secures the internet. None exists today, and predictions for its arrival differ, but many experts place significant probability in the 2030 to 2035 range. Crucially, the ‘harvest now, decrypt later‘ threat means the deadline to migrate is effectively already here.

Key Takeaways

  • A CRQC is a quantum computer that can run Shor’s algorithm at the scale needed to break RSA and ECC. No such machine exists as of 2026.
  • Expert timelines vary, but recent surveys place a meaningful probability of a CRQC within 10 years, and agency planning centers on the 2030 to 2035 window.
  • Resource estimates for breaking RSA-2048 dropped sharply: from about 20 million qubits (2019) to under 1 million noisy qubits (2025 estimate), showing the bar is falling.
  • The real deadline is set by ‘harvest now, decrypt later’ plus your data’s shelf life and migration time (Mosca’s Theorem), not by Q-Day itself.
  • NIST, the NSA (CNSA 2.0), and other bodies target migration to post-quantum cryptography by 2030 to 2035, so organizations should be migrating now.

What Is a CRQC (and What Is Q-Day)?

A CRQC is not just any quantum computer; it is one specifically capable of breaking real-world cryptography. Today’s quantum computers, while advancing quickly, are many generations short of that capability. The moment a CRQC can actually break widely used encryption is sometimes called Q-Day. Breaking cryptography this way relies on Shor’s algorithm, which efficiently solves the factoring and discrete-logarithm problems underlying RSA, Diffie-Hellman, and Elliptic Curve Cryptography (ECC). A CRQC running Shor’s algorithm could derive an RSA-2048 private key from its public key in a matter of hours to days.

Symmetric cryptography is in a very different position. Against AES and hash functions like SHA-256, the relevant quantum algorithm is Grover’s, which only provides a quadratic speedup, effectively halving security. Doubling key sizes (using AES-256 and SHA-384 or higher) is enough to stay safe. So the quantum threat, and the whole CRQC timeline question, is really about public-key cryptography.

PQC Advisory Services

Gain post-quantum readiness with expert-led cryptographic assessment, migration strategy, and hands-on implementation aligned to NIST standards.

How Close Are We? The Resource Estimates Are Shrinking

One of the clearest signals in the CRQC debate is not a date but a trend: the estimated resources needed to break RSA-2048 keep falling. In 2019, a widely cited estimate (Gidney and Ekera) put the cost at roughly 20 million noisy qubits running for about 8 hours. In May 2025, a new estimate from the same lead researcher reduced this to under 1 million noisy qubits running for less than a week, roughly a 20-fold reduction in qubit count, driven by advances in algorithms and error correction. The author was explicit that this does not mean a CRQC will exist by 2030; rather, it argues that security should not depend on quantum progress being slow.

For scale, today’s most advanced quantum processors are measured in the hundreds to low thousands of physical qubits, and leading roadmaps (for example IBM’s) target a few hundred logical qubits and error-corrected systems around the end of the decade, with far larger machines beyond that. Breaking RSA-2048 still requires thousands of logical qubits and millions of physical qubits, so a CRQC remains several hardware generations away, but the target keeps getting easier to hit.

What the Experts Predict

Because no CRQC exists, timelines are expressed as probabilities, not certainties. The most-cited longitudinal source, the Global Risk Institute’s annual Quantum Threat Timeline (produced with evolutionQ and Michele Mosca), surveys leading experts each year. Recent editions place a meaningful and rising probability on a CRQC emerging within a decade, with commonly referenced figures around a 1-in-4 chance by roughly 2030 and around a 1-in-2 chance by roughly 2035. The 2025 survey reported its highest 10-year estimates in the series’ history, reflecting recent hardware and algorithmic progress.

What the Numbers Say

The direction of expert opinion is consistent even where the exact figures differ. Successive annual surveys have nudged the estimated probability of a near-term CRQC upward rather than downward, and the 2025 edition of the most-cited survey reported its highest ten-year likelihood since the series began, explicitly attributing the shift to recent hardware and algorithmic progress.

At the same time, the resource cost of an attack has fallen faster than many expected, from roughly twenty million qubits in 2019 to under one million in 2025 for the same RSA-2048 target. Two independent trends, rising probability estimates and falling attack costs, point the same way: the safe assumption is that the window is narrowing, not widening.

The honest summary is that experts disagree on the exact year, but the distribution of opinion has shifted earlier, and essentially no serious analyst rules out a CRQC within the planning lifetime of data being protected today.

Why the CRQC Date Is Not Your Real Deadline

Focusing only on when a CRQC arrives is a mistake, because two factors mean the deadline to act is much sooner:

  • Harvest now, decrypt later: Adversaries can capture and store encrypted data today and decrypt it once a CRQC exists. Any data that must stay confidential for years, medical records, financial and legal data, government secrets, is therefore at risk right now if it is protected only by RSA or ECC.

Mosca’s Theorem: if the time you need to keep data secret (x) plus the time you need to migrate (y) is greater than the time until a CRQC arrives (z), you are already exposed. Because migration can take years, even a CRQC that is a decade away can put long-lived data past the safe line today.

    In other words, the CRQC timeline sets the clock, but your data’s shelf life and your migration time determine whether you are already late. For many organizations with long-lived data, the answer is yes.

    The Regulatory Timeline Is Already Fixed

    While the CRQC date is uncertain, the compliance deadlines are not; governments have set concrete dates:

    Body / instrumentTimeline
    NIST FIPS 203/204/205Finalized August 2024 (ML-KEM, ML-DSA, SLH-DSA), ready to deploy
    NIST IR 8547 (draft)RSA/ECC deprecated after 2030, disallowed after 2035
    NSA CNSA 2.0Phased adoption of PQC for national security systems, targeting full migration by 2030 to 2033
    Broader government guidanceFederal and sector deadlines increasingly cluster in the 2030 to 2035 window

    The clear message across all of these is consistent: plan to have quantum-vulnerable public-key cryptography out of critical systems well before 2035, and start now. Verify the latest specific dates and mandates for your jurisdiction and sector at planning time, as guidance continues to be issued and updated.

    What Organizations Should Do Now

    1. Build a cryptographic inventory: Discover where quantum-vulnerable cryptography (RSA, ECC, Diffie-Hellman) is used across your systems, applications, and supply chain. You cannot migrate what you cannot see.
    2. Prioritize by risk: Rank systems by data shelf life and exposure, so long-lived and high-value data (the most vulnerable to harvest-now-decrypt-later) is migrated first.
    3. Build crypto-agility: Design systems so algorithms can be swapped without re-architecture, and adopt hybrid mode (classical plus PQC) during the transition.
    4. Migrate to PQC: Begin phased migration to the finalized NIST standards (ML-KEM, ML-DSA, SLH-DSA), aligned to the IR 8547 timeline.

    PQC Advisory Services

    Gain post-quantum readiness with expert-led cryptographic assessment, migration strategy, and hands-on implementation aligned to NIST standards.

    How Encryption Consulting Helps

    The uncertainty in the CRQC timeline is exactly why a structured, risk-based plan matters. Encryption Consulting’s PQC Advisory Services provide expert-led cryptographic assessment, cryptographic discovery and inventory (via CBOM), and a prioritized migration strategy aligned to the finalized NIST standards and the IR 8547 timeline, including crypto-agility and hybrid deployment. We help you act on the timeline with confidence rather than waiting for a date no one can predict. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.

    Frequently Asked Questions

    What is a CRQC?

    A Cryptographically Relevant Quantum Computer (CRQC) is a quantum computer powerful and stable enough to break the public-key cryptography that secures modern communication, specifically by running Shor’s algorithm to break RSA, Diffie-Hellman, and Elliptic Curve Cryptography. It is distinct from today’s quantum computers, which are far too small for this. No CRQC exists as of 2026, but its eventual arrival is what drives the global migration to post-quantum cryptography, because data encrypted today could be exposed once a CRQC is built.

    When will a quantum computer be able to break encryption?

    No one knows the exact date, and no CRQC exists as of 2026. Expert surveys, such as the Global Risk Institute’s annual Quantum Threat Timeline, place a meaningful and rising probability on a CRQC within about a decade, with commonly cited figures near a 1-in-4 chance by around 2030 and a 1-in-2 chance by around 2035. Government bodies like NIST and the NSA are planning transitions in the 2030 to 2035 window. Because of harvest-now-decrypt-later, organizations should migrate well before any CRQC actually arrives.

    How many qubits are needed to break RSA-2048?

    Estimates have fallen sharply. A widely cited 2019 analysis suggested about 20 million noisy physical qubits running for roughly 8 hours. A May 2025 estimate from the same lead researcher reduced this to under 1 million noisy qubits running for less than a week, about a 20-fold reduction, thanks to better algorithms and error correction. Breaking RSA-2048 still requires thousands of logical qubits and on the order of a million physical qubits, which is well beyond current hardware, but the resource bar has been dropping steadily.

    What is ‘harvest now, decrypt later’?

    It is an attack strategy in which adversaries record and store encrypted data today, intending to decrypt it later once a CRQC exists. It makes the quantum threat a present concern rather than a future one, because any data that must remain confidential for years, such as medical, financial, legal, or government records, is already at risk if it is protected only by quantum-vulnerable algorithms like RSA or ECC. This is a central reason organizations should begin migrating to post-quantum cryptography now.

    Does the uncertain CRQC timeline mean we can wait?

    No. Even though the exact CRQC date is unknown, waiting is risky for two reasons. First, harvest-now-decrypt-later means long-lived data is exposed today. Second, Mosca’s Theorem shows that if your data’s required secrecy lifetime plus your migration time exceeds the time until a CRQC, you are already too late, and migrations often take years. Combined with fixed regulatory deadlines (NIST and NSA targeting 2030 to 2035), the prudent course is to start discovery and migration now.

    Will quantum computers break AES and SHA-256 too?

    Not in the same way. Symmetric algorithms like AES and hash functions like SHA-256 are only modestly affected by quantum computing. The relevant algorithm, Grover’s, provides just a quadratic speedup, effectively halving security, so moving to AES-256 and SHA-384 or higher keeps them secure. The serious quantum threat is to public-key cryptography (RSA, ECC, Diffie-Hellman), which Shor’s algorithm can break outright. That is why post-quantum standardization has focused on replacing key exchange and digital signatures.

    Act on the Timeline, Do Not Wait for the Date

    The CRQC timeline is uncertain, but the need to prepare is not. Explore Encryption Consulting’s PQC Advisory Services to assess your quantum risk, inventory your cryptography, and build a migration roadmap aligned to NIST’s finalized standards.