Q-Day Is No Longer Theoretical

Posted on 21st July 2026

Why 2028–2029 Is the Window That Matters for Business

For two decades, the idea that a quantum computer might one day break the encryption underpinning the internet was treated as a distant, almost academic risk — something for the 2040s, if ever. That consensus has collapsed. Government cyber agencies, the algorithm's own inventors, quantum hardware companies, and independent risk researchers have all converged on the same message in the last eighteen months: the migration clock is running, the early-2030s are the realistic danger zone, and organizations that haven't started planning are already behind.

This article pulls together the UK's National Cyber Security Centre (NCSC) migration roadmap, IonQ's "Q-Day" analysis, the U.S. NIST deprecation schedule, and independent expert-survey data to lay out why 2028–2029 has become the pivotal planning horizon — and what it means for business risk.

What "Q-Day" means

"Q-Day" is the informal industry term for the moment a  cryptographically relevant quantum computer (CRQC)  becomes powerful enough to run Shor's algorithm at scale and break the public-key cryptography — RSA, Diffie-Hellman, and elliptic-curve cryptography (ECC) — that currently secures almost all internet traffic, banking transactions, VPNs, digital signatures, and identity systems. It is not a single dramatic event so much as a threshold: once crossed, any data protected only by these algorithms becomes readable by anyone holding the right quantum hardware.

IonQ's analysis,  "Q-Day and the Impact of Breaking RSA2048,"  frames the stakes bluntly: RSA-2048 underpins the security of online transactions, emails, and most digital communication, and a sufficiently capable quantum computer would render it vulnerable to decryption — exposing financial transactions, government communications, personal emails, and corporate data all at once. The company's own compiled estimates from research organizations show predictions clustering broadly across the late 2020s to mid-2030s but converging on one point: the range of credible outcomes has narrowed and pulled forward, not pushed back.

Why nobody can wait for a confirmed date

The central insight from IonQ's piece — echoed across the field — is that the right question isn't "when exactly is Q-Day," but "when does preparation need to begin, working backward from a credible estimate." Three factors are collapsing the safety margin:

  • Harvest-now, decrypt-later (HNDL).  Nation-state actors are already collecting and storing encrypted traffic today, betting they'll be able to decrypt it once a CRQC exists. For data with a long shelf life — medical records, trade secrets, government files, source code — the effective compromise date isn't Q-Day itself; it's today, plus however many years the data needs to stay confidential.
  • Unpredictable algorithmic breakthroughs.  IonQ points to a 2024 UK research result that cut a quantum materials-simulation algorithm's resource requirements by a factor of four million in a single discovery. Progress in quantum computing doesn't arrive in a straight line — it moves in step-changes, and each one can quietly pull Q-Day forward. This pattern repeated in 2025, when Google researcher Craig Gidney published resource estimates showing RSA-2048 could theoretically be factored with under a million noisy qubits — roughly a 20-fold reduction from earlier estimates, and a marked acceleration in the field's own math.
  • Migration itself takes years.  Cryptographic inventories, vendor upgrades, certificate reissuance, and legacy-system replacement are multi-year efforts even under ideal conditions. If the transition takes five to seven years and the threat could land in seven, there's effectively no slack left.

The official timelines: NCSC, NIST, and NSA all point to the same decade

UK NCSC — "Timelines for Migration to Post-Quantum Cryptography" (March 2025).  The NCSC set out a three-phase roadmap with hard target dates:

Phase Deadline What's required
1 — Assess & Plan By 2028 Build a complete inventory of where cryptography is used across the organization; identify dependencies; set migration goals and an initial plan
2 — Prioritize & Upgrade By 2031 Execute the earliest, highest-priority quantum-resistant upgrades — critical systems and the most exposed data first
3 — Complete Migration By 2035 Remove vulnerable cryptography entirely from all systems, services, and products

NCSC Chief Technical Officer Ollie Whitehouse described the guidance as a direct response to the fact that "quantum computing is set to revolutionize technology, but it also poses significant risks to current encryption methods," adding that upgrading collective security is "not just important — it's essential." Notably, the NCSC's own 2028 milestone isn't a prediction of when Q-Day will hit — it's the deadline by which organizations must simply have  finished figuring out what they need to fix. That reframes 2028 less as a distant deadline and more as the last safe moment to still be in the discovery phase.

US NIST — IR 8547 (initial draft, November 2024).  NIST's own transition schedule for federal systems is more explicit about consequences: RSA, ECDSA, EdDSA, Diffie-Hellman, and ECDH are to be deprecated after 2030 and fully disallowed after 2035. Deprecation means new systems should stop using them and existing use requires a documented risk justification; disallowance means they can no longer be used at all, even in legacy systems. This aligns with the direction set by U.S. National Security Memorandum 10 (2022), and the NSA already requires quantum-resistant cryptography for new national-security-system acquisitions starting in 2027.

Independent expert surveys — Global Risk Institute / evolutionQ Quantum Threat Timeline Report 2025.  This annual survey of quantum computing experts (now in its sixth year) found the estimated probability of a CRQC emerging within 10 years now sits between 28–49% , and  within 15 years between 51–70%  — both figures up sharply from the 2024 survey, marking the steepest year-over-year jump since the report began in 2019. The researchers frame this through "Mosca's Inequality," which weighs how long data needs to stay secure against how long migration takes and how soon the threat might arrive — and conclude that many organizations are already carrying more risk than they realize.

Taken together, these three independent bodies — a UK government agency, a US federal standards body, and an academic risk-research consortium — are not just each pointing to the same rough decade; they're using 2028 specifically as the moment by which foundational work has to be done, precisely because credible expert opinion now puts meaningful CRQC risk inside the following few years.

The business gap: awareness is high, readiness is not

If the timelines above sound urgent, current preparedness levels are the more alarming half of the story:

  • A Keyfactor/Wakefield Research survey of 450 cybersecurity leaders found  48% of organizations report being unprepared  for the transition, rising to  56% among mid-sized organizations , despite most already viewing quantum risk as real.
  • Bain & Company's survey of technology leaders at 180 companies found 90% lack systems in place  to defend against quantum threats, even though 71% expect quantum-enabled attacks within five years and a third expect them within three. Only 11% believe their current safeguards will hold up.
  • Forescout Research (Vedere Labs) found that while PQC-capable SSH deployment has grown 72% year-over-year,  only 11.8% of internet-facing SSH servers currently support post-quantum cryptography  — meaning roughly nine in ten remain exposed.
  • Barriers cited most often are not budget or belief, but execution: a shortage of skilled personnel, competing priorities, and uncertainty about which standards to build to first.

The gap matters because migration is not a weekend patch. It requires a full cryptographic asset inventory, vendor and supply-chain coordination, hybrid classical/post-quantum deployment (the approach most regulators, including France's ANSSI, now require), certificate and PKI overhauls, and testing across legacy systems that were never designed to be cryptographically agile. Organizations that start this work only after Q-Day is confirmed will already have lost the years of lead time the process needs.

What this means for businesses

  • Long-lived sensitive data is at risk right now, not in 2030.  Encrypted data being exfiltrated or intercepted today — trade secrets, M&A material, health records, government and defence communications — can be stored and decrypted retroactively once a CRQC exists. If that data needs to stay confidential for 10+ years, the relevant deadline has already arrived.
  • 2028 is the realistic point to have a plan, not a shrug.  Whether or not a quantum computer capable of breaking RSA-2048 exists by 2028, that is the date by which regulators, insurers, and enterprise customers are increasingly expected to see a documented cryptographic inventory and migration roadmap.
  • Regulatory and compliance exposure will arrive before Q-Day does.  NIST's 2030 deprecation and 2035 disallowance dates, and the NCSC's aligned phases, are already being folded into procurement requirements, cyber-insurance underwriting, and frameworks like the EU's DORA and NIS2 — meaning non-compliance risk is a near-term business issue independent of the underlying quantum timeline.
  • Vendors and supply chains need to be part of the plan.  Much of an organization's cryptographic exposure lives in third-party software, hardware, and cloud services outside its direct control — a dependency mapping exercise is as important as internal upgrades.
  • The advantage goes to early movers.  Keyfactor's survey found organizations already investing in PQC readiness cite stronger security posture, better customer trust, and even reduced cyber-insurance premiums as tangible benefits — suggesting migration is becoming a competitive differentiator, not just a defensive cost.

The bottom line

No one — not NCSC, not NIST, not IonQ, not the Global Risk Institute's surveyed experts — claims to know the exact date a quantum computer will break today's encryption. What has changed is the shape of the uncertainty: credible estimates that once clustered in the 2040s have moved into the early-to-mid 2030s, with a meaningful and rising probability attached to the 2028–2030 window specifically once harvest-now-decrypt-later exposure and migration lead times are factored in.

Every major roadmap — government and independent alike — treats the next two to three years as the last stretch in which "start now" is still an option rather than a scramble. For businesses holding data that needs to stay confidential for years to come, the practical deadline isn't the day the quantum computer arrives. It's the day before.

Sources:
UK National Cyber Security Centre, "Timelines for Migration to Post-Quantum Cryptography" (March 2025);
IonQ, "Q-Day and the Impact of Breaking RSA2048" (December 2024); NIST IR 8547 (Initial Public Draft, November 2024);
Global Risk Institute / evolutionQ, "Quantum Threat Timeline Report 2025"; Keyfactor/Wakefield Research, "Digital Trust Digest:
The Quantum Readiness Edition"; Bain & Company quantum-readiness survey; Forescout Research (Vedere Labs) PQC adoption data.

Back To Blog »
© Copyright 2026 Andrew Williams ConsultingWeb Design By Toolkit Websites