Cybersecurity teams keep asking one question with growing urgency: will quantum computers break encryption before businesses can prepare?
For the time being, no, though one would be hard-pressed to say for how long, given that the clock is ticking. There are quantum machines in operation, and researchers put more stable qubits in place with each passing year. Yet RSA and elliptic curve cryptography are what secure the banking, healthcare, and government systems across the globe. In a sense, the chasm between what quantum can do and what it aspires to is the crux of any security discussion at present. And an attacker has no requirement for a functional quantum computer; patience will have to suffice.
We examine the actual timeline here, the new standards that are making vulnerable algorithms obsolete, and the import of post quantum cryptography on the security of your organization going forward.
The Ticking Qubit Clock: How Quantum Machines Threaten Your Data
There is a certain intractability to the task of factoring large numbers or dealing with discrete logarithms for a classical computer. The security of RSA and ECC is predicated on this very fact.
Put a quantum computer of adequate power to the job, and it will run through an infinity of potential solutions in a short order, rendering today’s encryption obsolete. One need not take this on faith; the mathematics are there in black and white. For any organisation with sensitive data to manage, the implications are a matter of altering one’s security calculus.
Shor’s Algorithm: The Math That Ends RSA’s Reign
It was Peter Shor who put it to the test some decades back, showing that with a quantum computer of sufficient power, one can undo public key encryption of the sort RSA, ECDSA, and Schnorr signatures are founded on, be it by way of integer factorization or discrete logarithms. Even an RSA key of 2,048 bits, which would stand up to any classical brute force attempt, is no match for what Shor’s theory dictates, provided there are enough qubits that have been error-corrected. The upshot is that the day will come when most of the public key systems in common use are rendered obsolete.
Why “Not Yet” Isn’t the Same as “Never”
One will not find in today’s quantum hardware the sort of stable, error-corrected qubits that are a prerequisite for Shor’s algorithm to be put to work on a scale that would put actual keys at risk. The machines of the moment are too noisy and can only manage shallow circuits. Yet “not yet” does not mean “never,” so there is no point in deferring plans until one has the luxury of certainty.
Harvest Now, Decrypt Later: The Attack Is Already Happening
Adversaries do not need a quantum computer in hand to be amassing encrypted data for future decryption. In fact, they are at it today; security researchers have a name for the threat model, harvest now and decrypt later, and you will find state-sponsored groups making it their way of doing business.
Data of a sensitive nature may be locked up for decades but is as good as exposed once a machine with the requisite quantum power comes online. So, there is present-day risk for any organization that has long-lived data in its keeping, be it defense files, medical records, or legal contracts. The very reason post-quantum cryptography is of import, even with large-scale quantum computers still some years off, is accounted for by this one threat model.
Mosca’s Theorem: The Risk Equation Every CISO Should Know
One can turn to Mosca’s theorem for a framework to deal with the risk. The IEEE has put forth security research that has the theorem factor in three things: the duration of migration, the period data needs to be kept confidential, and the projected advent of a quantum computer of cryptographic relevance.
Should the sum of the time to migrate and the necessary confidentiality outstrip the estimate for such a machine’s arrival, the organization is exposed.
NIST Draws the Battle Lines: Meet the New Cryptography Standards
The National Institute of Standards and Technology has put the finishing touches on ML-KEM, ML-DSA, and SLH-DSA, the first of their kind in post-quantum cryptography to be made into standards. It is a process NIST set in motion in 2015; over the years it has gone through 82 algorithms put forward by 25 nations to whittle down the candidates.
With these three now done, they can be used without delay in government infrastructure as well as on e-commerce sites and email systems.

A Fifth Contender and a Withdrawn Algorithm
There is more to NIST’s efforts than the three standards alone. The agency in March 2025 made HQC its fifth algorithm for post-quantum encryption, giving security teams a wider array of tools at their disposal.
A month after Executive Order 14412 was put in place in June 2026, all federal systems of high value were subject to firm deadlines as part of an expedited move across government to post quantum cryptography.
The standardization process has also proved adept at weeding out any that are not up to snuff prior to deployment. Case in point: in July 2026 Anthropic put it on record that one of its AI models had found a flaw in HAWK, a lattice-based signature algorithm being looked at, and the developers had no option but to pull it. ML-KEM and ML-DSA were not impacted by this; they are built on other mathematics and are in good standing.
Five Algorithms, One Mission: Kyber, McEliece, Dilithium, Falcon, and SPHINCS+
With its sound mix of practical performance and security, lattice-based cryptography is the preeminent method for withstanding quantum encryption. CRYSTALS-Kyber, for instance, is a module-lattice problem that performs key encapsulation in place of RSA or Diffie-Hellman, both of which are vulnerable to Shor’s algorithm. Where one requires a mathematical basis of another sort there is Classic McEliece; it provides code-based key encapsulation at the cost of a sizeable public key but with a design that has been put through its paces by cryptanalysis for decades.
The same care must be taken with digital signatures. CRYSTALS-Dilithium is a fast, lattice-based option for signing that will see wide use at any number of security levels. Falcon is well suited to the task in mobile or IoT environments, where bandwidth is limited, as it produces compact signatures from NTRU lattices. Then there is SPHINCS+, a stateless, hash-based solution using Merkle trees. It forgoes a degree of efficiency to maintain a more conservative margin of security; one did not predicate on lattice assumptions.
In all, the five algorithms put real options before the security architect as opposed to a single point of failure.

Q-Day Countdown: When Could Encryption Actually Break?
There is no consensus on the figures, yet for the most part experts will tell you a device to get around current encryption is likely to be with us in ten years’ time; some researchers put it nearer 2035.
In any event, NIST has set 2035 as the date by which federal systems must do away with algorithms vulnerable to quantum computing, according to the transition guidance in its NIST IR 8547. One can find the origins of that schedule in the 2022 National Security Memorandum 10.
The Adoption Gap Nobody Talks About
There is a marked lack of urgency when it comes to adoption. Studies that have quantified the numbers show that post-quantum cryptography is being used in production traffic by OpenSSH and Google Chrome, but nowhere else; all told, it accounts for only about 0.029 percent of the connections measured. The chasm between available standards and their actual deployment is the industry’s most pressing vulnerability, even more so than the quantum hardware gap.
Who’s Already Quantum-Proofing? Apple, Google, and Cloudflare Lead the Way
A few of the big names in technology are well on their way to making the transition to post-quantum cryptography; one need only look at what they have done to see what is in store for the rest of the industry.
Apple, for instance, has put post-quantum safeguards in place with its iMessage PQ3 protocol, a combination of classical and quantum-resistant algorithms to secure messages. In a similar vein, Google and Cloudflare have put hybrid TLS into service on some of their infrastructure, using CRYSTALS-Kyber and other lattice-based approaches alongside conventional key exchange. Such early action from these companies shows there is no need to do away with all systems in an overnight fashion to be quantum resistant.
For the most part though, save for a select number of large platforms, you will not find this kind of widespread use. The engineering wherewithal to conduct a complete cryptographic inventory and then carry out a phased migration is beyond the means of many smaller concerns. So, the chasm between what the standards are and what gets put in place is only getting larger, while the quantum encryption menace draws nearer with every qubit record set.
Will Quantum Computers Break Encryption: Busting Common Myths
Confusion over the true timeline is a problem for some security teams, and it has a way of putting off action. There is a prevailing notion, for instance, that one is not at risk until quantum computers are in existence. The fact of the matter is data that has been harvested is left open to decryption from the instant it can be done, interception time notwithstanding. Or take the belief that migration is as easy as a software update; to do away with the cryptography in legacy systems, third-party vendor code, and hardware security modules is a matter of years in most cases.
Then there are those who consider post-quantum cryptography an option to be put aside until the feds set a deadline. But the private sector has no such regulatory leeway when it comes to the “harvest now, decrypt later” scenario that puts its data at risk. Security leaders would do well to sense these things to put their migration budgets where they need to be, instead of waiting for a deadline to compel them to act.
Your Post-Quantum Migration Checklist
One does not make a strategy of waiting for certainty. It is incumbent on security teams to put in place several concrete steps without delay. Start by taking stock of all systems that are RSA- or ECC-dependent. An assessment should then be made as to what data must be kept confidential for the long haul; such information is open to the harvest now, decrypt later threat of the present day.
Ensure applications have cryptographic agility so that an algorithm can be changed later without requiring a complete rebuild. Develop a workable migration plan and assess the support vendors are providing for NIST-standardized algorithms. And keep an eye on NIST and the industry for any new guidance, given how fast this area is and how a best practice of a few months back may well be superseded.
QEncrypt: Built for the Quantum Era from Day One
There is a cost to retrofitting encryption in the wake of a breach, not to mention the time it takes. QEncrypt has made a point of doing things another way; post-quantum cryptography is part of its architecture from the outset. With CRYSTALS-Kyber and Classic McEliece for key encapsulation, any communication encrypted by QEncrypt will stand up to classical as well as quantum attacks. On the authentication and integrity side, digital signature workflows are put through CRYSTALS-Dilithium, Falcon, and SPHINCS+, so users have the benefit of layered protection and are not reliant on one algorithm. In this manner, the quantum encryption gap is dealt with head-on, not put off as something for down the road, answering the will quantum computers break encryption question with action rather than uncertainty.
The day an organization must answer for its present encryption practices need not be when a cryptographically relevant quantum computer makes its appearance. Proper migration is a matter of years, and what is harvested today can be decrypted later. By putting in place infrastructure that is NIST-aligned and quantum-resistant, one is safeguarding data of the future before the threat has even come to pass.
Explore how QEncrypt secures your organization’s security future and start the migration conversation before Q-Day arrives, rather than after.