July 27, 2026

Should you be worried about Q-Day?

Abstract metallic sphere surrounded by circular ring structures, representing quantum computing, advanced technology, or cybersecurity concepts.

Security specialists have a name for the day a quantum computer becomes powerful enough to break the encryption protecting nearly everything online: Q-Day.

It isn’t a date on a calendar, and no machine can do it yet, but the idea has shifted from a fringe worry to a genuine planning assumption inside governments and major companies.

The concern is mathematical. Q-Day would mark the point at which a quantum computer running Shor’s algorithm could crack RSA, Diffie-Hellman and elliptic-curve cryptography, the maths problems that modern encryption relies on being too hard for ordinary computers to solve in any useful timeframe. A sufficiently powerful quantum computer changes that equation entirely, turning a problem that would take a classical computer longer than the age of the universe into something solvable in hours or days.

Translation: the systems underpinning HTTPS websites, VPNs, banking, code signing and most digital certificates. Break that, and a huge share of the internet’s trust infrastructure goes with it, along with the padlock icon most people have spent decades learning to trust without a second thought.

Here’s the complication: nobody actually needs a working quantum computer today for the threat to be real right now. Security researchers call it “harvest now, decrypt later.” Sophisticated attackers, often state-backed, are already intercepting and storing encrypted data with no ability to read it, banking on the assumption that a sufficiently powerful quantum computer will exist eventually.

Anything with a long shelf life for secrecy, government cables, medical records, intellectual property, is exposed to this strategy today, years before Q-Day itself arrives. A defence contract negotiated now, or a patient’s genomic data collected this year, doesn’t need to stay secret for a decade to matter. It just needs to stay secret longer than the time it takes quantum computing to catch up, and for some of that information, that’s a very low bar to clear.

The hardware gap is still substantial. The largest quantum processors running in 2026 hold roughly 1,180 noisy qubits. Breaking RSA-2048 encryption is estimated to require somewhere under a million stable, error-corrected qubits, a bar that once looked impossibly distant. Noisy qubits, unlike the error-corrected kind researchers are chasing, lose their quantum state quickly and introduce errors that compound the more of them you chain together, which is part of why the jump from today’s machines to a genuine code-breaking one isn’t simply a matter of building more of the same hardware.

That estimate has been falling fast, though. Google Quantum AI research published earlier this year cut the estimated qubit requirement dramatically from a 2019 figure of 20 million, a sign the timeline is compressing even if a breakthrough machine still doesn’t exist. Progress on error correction, rather than raw qubit count alone, has been doing most of the work behind that shift, and it’s the kind of incremental, unglamorous research that tends to get less attention than a splashy new chip announcement.

Most experts place meaningful risk sometime in the 2030s, with few expecting it before 2030. But organisations are being told not to wait for certainty. The US National Institute of Standards and Technology has set 2030 as the point it will start deprecating vulnerable algorithms, with a full removal deadline of 2035. Google has set its own internal migration deadline of 2029. NIST has already published its first set of post-quantum cryptography standards, giving vendors and developers something concrete to build toward rather than a moving theoretical target.

The reason for urgency isn’t just the arrival of the hardware, it’s how long the fix takes. Migrating an organisation’s cryptography across every system, vendor and application is slow, technical work, and security professionals warn the transition could take just as long as the wait for Q-Day itself. Certificates need reissuing, software libraries need updating, hardware that can’t support new algorithms may need replacing outright, and all of it has to happen without breaking systems that are currently working fine, which is its own kind of institutional inertia to overcome.

For most people, that means the practical response is patience paired with pressure on the institutions holding your data to get moving now. Checking whether your bank, employer or key service providers have a stated post-quantum migration plan is a reasonable thing to ask about, even if the answer today is simply that it’s on the roadmap. Q-Day may still be years away. The exposure it creates for information already circulating today is not.

Subscribe for weekly news

Subscribe For Weekly News

* indicates required