Risk & Strategy / CRQC Scenario Planner
§6.1What this is for: Plan for cryptographically relevant quantum computer threat scenarios.
What a good answer looks like: A plan that survives the machine arriving early. If your roadmap only works at the median estimate, it is a forecast, not a plan.
Worked example: Set the CRQC arrival year to 2030 and tick your compliance deadlines: the tool lists which of RSA-2048, ECDSA P-256 and the others are broken by then, and the HNDL exposure window for data you keep past that year.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- Set the CRQC arrival year and read which of RSA-2048, ECDSA P-256 and the others are broken by then, and the HNDL exposure window for data kept past that year; the default is the 2038 consensus median.
- GRC / Risk & Compliance
- Tick your compliance deadlines against the arrival year you chose: the Compliance Deadlines panel shows which obligations fall before the algorithms break, which is the order the controls have to land in.
Pre-filled from your assessment. Scenario seeded from GRI 2025 consensus median (2038).
CRQC Arrival Year
Adjust the slider to model when a cryptographically relevant quantum computer might arrive. See the cascading impacts on algorithms, compliance, and data exposure.
Default year is the median CRQC arrival from the Global Risk Institute's 2025 Quantum Threat Timeline survey (2038, consensus of its 26 experts' low and high bounds) — the same curve the Breach Scenario Simulator and Cost of Inaction Analyzer use. Move the slider to model an earlier or later arrival; the slow and fast bounds are 2040 and 2035. Aligned to NIST CSWP 39 §2.3 (Constant Need of Transition) and §6.1 (Resource Considerations).
asymmetric algorithms vulnerable to Shor's
algorithms unaffected by quantum attack
compliance deadlines before CRQC arrives
data captured today decryptable in 2038
Algorithms Broken at 2038
Vulnerable to Shor’s algorithm. Immediate migration priority.
Replace with: ML-KEM-768 / ML-DSA-65
Larger keys do not protect against quantum attack. Same urgency as RSA-2048.
Replace with: ML-KEM-1024 / ML-DSA-87
Still vulnerable to Shor’s algorithm regardless of key size.
Replace with: ML-KEM-1024 / ML-DSA-87
Elliptic curve cryptography broken by Shor’s algorithm.
Replace with: ML-DSA-44 / SLH-DSA
Larger curves do not help against quantum attack.
Replace with: ML-DSA-65 / SLH-DSA
Key exchange vulnerable to Shor’s algorithm. Hybrid mode available now.
Replace with: ML-KEM-768 / X25519MLKEM768
Classic Diffie-Hellman broken by Shor’s algorithm.
Replace with: ML-KEM-768
Compliance Deadlines
Due before CRQC arrival (8 years before)
Due before CRQC arrival (8 years before)
Due before CRQC arrival (5 years before)
Due before CRQC arrival (8 years before)
Due before CRQC arrival (3 years before)
Non-binding guidance — no legislative mandate
HNDL Exposure Window
Data encrypted today with quantum-vulnerable algorithms can be stored by adversaries and decrypted when a CRQC arrives. The table below shows exposure for different data retention periods.
| Data Retention | Data Captured Today | Still Valid At | CRQC Arrives | At Risk? |
|---|---|---|---|---|
| 1 years | 2026 | 2027 | 2038 | Safe |
| 3 years | 2026 | 2029 | 2038 | Safe |
| 5 years | 2026 | 2031 | 2038 | Safe |
| 7 years | 2026 | 2033 | 2038 | Safe |
| 10 years | 2026 | 2036 | 2038 | Safe |
| 15 years | 2026 | 2041 | 2038 | AT RISK |
| 25 years | 2026 | 2051 | 2038 | AT RISK |
CRQC Scenario — Export
Export this scenario analysis as a shareable document.
- /assess — compliance frameworks step— Step 5 captures policy + framework registry
- /compliance — framework explorer
- /leaders — stakeholder ecosystem
- /library — policy & governance docs
- NIST CSWP.39-upd1 — Considerations for Achieving Crypto Agility (Dec 2025, upd. Jun 2026)
- NIST IR 8547 — Transition to PQC Standards
- ENISA — Post-Quantum Cryptography Integration Study
- NIST Computer Security Resource Center (Americas)
- NIST News & Events (Americas)
- NSA Media Defense Portal (Americas)
- CISA Quantum Page (Americas)
- BSI Post-Quantum Cryptography (EMEA)
- ANSSI Cryptography Guidelines (EMEA)
Try it
Move the CRQC arrival year earlier. What appears in the Algorithms Broken panel?
Next step
Next in Risk & Strategy: Risk Register BuilderRisk Register Builder is the next Risk & Strategy tool in the Command Center.