Cryptographic risk observatory · Updated 19 Aug 2026

Q-DAY ESTIMATE :
2034

EXPOSURE WINDOW
MAY ALREADY BE OPEN.

What is Q-Day? The point when a quantum computer becomes powerful and reliable enough to break the public-key cryptography protecting today's internet—especially RSA and elliptic-curve systems.

Encrypted data can be stolen now and decrypted later, so the exposure window may open years before Q-Day itself. QDayWatch tracks the technology, migration progress, and the gap between them.

See below for the expert inputs, weighting, and calculation behind the estimate.

See how it's calculated

QDayWatch composite · Updated August 2026

WEIGHTED Q-DAY
ESTIMATE · 2034

Central estimate2034

8 years from the current data review

Source envelope · 2029–2038
2028203020322034203620382040
QDAYWATCH · 2034
Global Risk Institute2038
Gartner2029
IBM2034
IonQ2030
Google2029
SourcePublishedInput classPublished basisModel yearWeight
Global Risk InstituteSourceMAR 202626-expert survey50% crossing interpolated from the 10- and 15-year probability ranges203845%
GartnerSourceFEB 2025Threat forecastPublic-key cryptographic algorithms expected to break by 2029202920%
IBMSourceMAR 2026Hardware roadmap2,000 logical qubits and one billion gates targeted for 2033+203415%
IonQSourceAUG 2026Hardware roadmap80,000 logical qubits targeted for 2030203010%
GoogleSourceMAR 2026Security deadlineCompany-wide post-quantum migration target202910%
WEIGHTING LOGIC

Independent expert aggregation receives the largest weight. Direct threat research follows. Vendor roadmaps and migration deadlines receive smaller weights because they measure different parts of the path to cryptographic capability.

CALCULATION

(2038 × 45%) + (2029 × 20%) + (2034 × 15%) + (2030 × 10%) + (2029 × 10%)

= 2034
01

Mosca's inequality

ARE YOU ALREADY INSIDE
THE EXPOSURE WINDOW?

Use the QDayWatch estimate—or choose another scenario—to test whether data lifetime plus migration time fit before a cryptographically relevant machine arrives.

Z Q-Day estimate / scenario

QDayWatch weighted estimate: 8 years · 2034.

DATA LIFETIME10YEARS
MIGRATION5YEARS
EXPOSURE HORIZON15YEARS
Q-DAY SCENARIO8YEARS
ResultEXPOSURE WINDOW OPEN

The planning horizon extends 7 years beyond this scenario.

Today50 years
Migration · YData lifetime · XX + Y · 15 yearsScenario Z

Migration takes Y years. Data created at the end of that migration can remain valuable for another X years—this is why the terms add.

PQC transition horizon

2035ONE YEAR AFTER THE MODEL ESTIMATE

THE MIGRATION CLOCK
IS CLOSING.

NIST describes a transition that removes quantum-vulnerable algorithms from its standards by 2035, with higher-risk systems moving earlier. The QDayWatch composite currently centers Q-Day in 2034.

NIST transition guidance
Standards finalized · Aug 2024Transition horizon · 2035
Calculating transition horizon
02

Harvest now / decrypt later

THE ATTACK CAN START BEFORE
THE QUANTUM COMPUTER EXISTS.

An attacker does not need a quantum computer today to target information that will still matter when one becomes available.

01YOUCAPTURE TODAY
encrypted traffic
02SERVICELIVE CONNECTION
copy intercepted
03 · STOREARCHIVECIPHERTEXT / BLOCK 01CIPHERTEXT / BLOCK 02CIPHERTEXT / BLOCK 03CIPHERTEXT / BLOCK 04
04 · Q-DAYATTEMPT
DECRYPTION
CAPABILITY NOT OBSERVED
The practical lesson

Prioritize information whose value outlives the time needed to discover, replace, test, and retire vulnerable cryptography.

03

Cryptographic impact

QUANTUM DOES NOT BREAK
ALL ENCRYPTION.

It changes the security assumptions behind specific primitives. Public-key systems face a qualitatively different failure mode from symmetric encryption and hashing.

PrimitiveClassAssessmentMechanism
RSAPublic keyCRQC vulnerableShor · integer factorization
Diffie–HellmanPublic keyCRQC vulnerableShor · discrete logarithms
ECDH · ECDSA · EdDSAPublic keyCRQC vulnerableShor · elliptic-curve discrete logs
AES-256SymmetricMargin reducedGeneric quantum search · not Shor-broken
SHA-256HashMargin reducedQuantum search affects brute-force complexity

Why “quantum-safe” is too simple: AES and SHA are not subject to Shor's public-key break, but quantum algorithms still affect their security margins. Algorithm, key size, mode, and use case all matter.

04

Cryptographic inventory

WHERE VULNERABLE
CRYPTOGRAPHY LIVES.

Migration is an infrastructure problem. Select a layer to see why replacing an algorithm is rarely a one-line configuration change.

Selected layer

TLS

Early deployment
Cryptographic role
Authenticates servers and establishes session keys for web traffic.
Common vulnerable primitives
RSA signatures; ECDSA/EdDSA certificates; ECDH key exchange.
Migration involves
Add hybrid or PQC key establishment, then migrate certificate signatures and PKI.
Operational friction
Compatibility, handshake size, certificate ecosystems, and middleboxes.
Migration research
05

The Q-Day Watch

SIGNALS THAT MATTER MORE
THAN RAW QUBIT COUNTS.

Architectures, error rates, connectivity, code overhead, and logical operations differ. Physical qubit totals are not a common unit of cryptanalytic capability.

Observed milestoneNature · 2024

Surface-code error suppression

Λ = 2.14 ± 0.02

A distance-7 logical memory used 101 physical qubits and achieved a 0.143% logical error per correction cycle. Its lifetime exceeded its best constituent physical qubit by 2.4×.

LAB DEMONSTRATIONCRYPTOGRAPHICALLY RELEVANT
LAB DEMONSTRATION
Logical memoryBEYOND BREAKEVEN

Demonstrated for memory—not a general-purpose fault-tolerant cryptanalytic computer.

Error correctionBELOW THRESHOLD

Error decreased as code distance increased in the cited surface-code experiment.

Fault-tolerant gatesEARLY RESEARCH

Long, reliable logical circuits at cryptanalytic scale have not been publicly demonstrated.

RSA-2048 quantum breakNOT OBSERVED

No public demonstration has factored a production RSA-2048 key using quantum computing.

Resource estimate monitor

RSA-2048

NOT PUBLICLY BROKEN BY QUANTUM COMPUTING

Resource estimates are models, not machine specifications. Two estimates from related research show how assumptions and algorithmic improvements can move the result without moving hardware capability.

changed algorithms
and architecture
2025 estimate<1Mnoisy physical qubits · under a weekGidney
Both assume0.1% gate error1 μs surface-code cycle10 μs reaction time2D nearest-neighbor grid
06

Readiness

RISK DEPENDS ON
TWO RACES, NOT ONE.

Quantum capability

Logical qubits
Error correction
Gate fidelity
Algorithm efficiency
Hardware scale
Reliable runtime
VS

PQC migration

Standards
Implementations
Protocols
Operating systems
PKI
Enterprises

These indicators track the two forces that move the QDayWatch estimate: accelerating quantum capability and the remaining migration gap.

07

Standards monitor

THE REPLACEMENTS
ARE ARRIVING.

Standardized, selected, candidate, deprecated, and withdrawn are different states. QDayWatch keeps them separate.

FIPS 203Standardized

ML-KEM

Key establishment

Primary general-purpose KEM. Parameter sets: 512, 768, and 1024.

Source
FIPS 204Standardized

ML-DSA

Digital signatures

Primary lattice-based digital signature standard.

Source
FIPS 205Standardized

SLH-DSA

Digital signatures

Stateless hash-based alternative with different security assumptions.

Source
FalconSelected

FN-DSA

Digital signatures

Compact lattice-based signatures; standardization remains underway.

Source
PipelineSelected

HQC

Key establishment

Code-based backup KEM selected to add mathematical diversity.

Source
ArchivedWithdrawn

HAWK

Digital signatures

Withdrawn in 2026 after a newly discovered attack; never deployed as a NIST standard.

Source
08

The road to Q-Day

MILESTONES THAT
MOVE THE ESTIMATE.

A record of observable changes in algorithms, standards, policy, and error correction.

standard

HAWK is withdrawn after a new attack

A candidate signature scheme is removed from consideration. NIST states that the finding does not affect the finalized ML-KEM or ML-DSA standards.

NIST
cryptography

RSA-2048 resource estimate drops below one million noisy qubits

A new preprint substantially reduces the estimated physical-qubit count under the paper's stated assumptions, while extending projected runtime to under a week.

Craig Gidney
standard

HQC selected as a backup KEM

NIST selects a code-based backup for general encryption, adding mathematical diversity to the standards pipeline.

NIST
quantum

Below-threshold surface-code memory demonstrated

Google Quantum AI reports that logical errors fall as code distance grows on Willow, a meaningful error-correction milestone—not a cryptanalytic break.

Nature
policy

NIST publishes its transition proposal

IR 8547 outlines an expected path to deprecate and remove quantum-vulnerable algorithms by 2035, with higher-risk systems moving earlier.

NIST
Explore the full timeline →
09

Intelligence feed

LATEST SIGNALS.

Publication date and event date are tracked separately so old events cannot look new—and new analysis can be placed in context.

HIGH
Standards

HAWK candidate withdrawn

A new attack led the HAWK team to withdraw its signature candidate. NIST says finalized PQC standards are unaffected.

Event date · 28 JUL 2026Primary source ↗
MEDIUM
Standards

FIPS 204 errata updated

NIST listed several minor issues for correction in a future revision. The ML-DSA standard remains final and available.

Event date · 31 JUL 2026Primary source ↗
MILESTONE
Cryptanalysis

RSA-2048 estimate revised

A preprint estimates that under one million noisy qubits could factor RSA-2048 in under a week—under explicit, demanding assumptions.

Event date · 21 MAY 2025Primary source ↗