Risk & Strategy / CRQC Scenario Planner

What this is for: Plan for cryptographically relevant quantum computer threat scenarios.

What a good answer looks like: A plan that survives the machine arriving early. If your roadmap only works at the median estimate, it is a forecast, not a plan.

Worked example: Set the CRQC arrival year to 2030 and tick your compliance deadlines: the tool lists which of RSA-2048, ECDSA P-256 and the others are broken by then, and the HNDL exposure window for data you keep past that year.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Executive / Business Leader
Set the CRQC arrival year and read which of RSA-2048, ECDSA P-256 and the others are broken by then, and the HNDL exposure window for data kept past that year; the default is the 2038 consensus median.
GRC / Risk & Compliance
Tick your compliance deadlines against the arrival year you chose: the Compliance Deadlines panel shows which obligations fall before the algorithms break, which is the order the controls have to land in.

Pre-filled from your assessment. Scenario seeded from GRI 2025 consensus median (2038).

CRQC Arrival Year

Adjust the slider to model when a cryptographically relevant quantum computer might arrive. See the cascading impacts on algorithms, compliance, and data exposure.

Default year is the median CRQC arrival from the Global Risk Institute's 2025 Quantum Threat Timeline survey (2038, consensus of its 26 experts' low and high bounds) — the same curve the Breach Scenario Simulator and Cost of Inaction Analyzer use. Move the slider to model an earlier or later arrival; the slow and fast bounds are 2040 and 2035. Aligned to NIST CSWP 39 §2.3 (Constant Need of Transition) and §6.1 (Resource Considerations).

202820382045
12 years remainingLOW URGENCY
Algorithms Broken
7

asymmetric algorithms vulnerable to Shor's

Quantum-Safe
3

algorithms unaffected by quantum attack

Pre-CRQC Deadlines
6

compliance deadlines before CRQC arrives

HNDL Window
12 yr

data captured today decryptable in 2038

Algorithms Broken at 2038

RSA-2048Broken

Vulnerable to Shor’s algorithm. Immediate migration priority.

Replace with: ML-KEM-768 / ML-DSA-65

RSA-3072Broken

Larger keys do not protect against quantum attack. Same urgency as RSA-2048.

Replace with: ML-KEM-1024 / ML-DSA-87

RSA-4096Broken

Still vulnerable to Shor’s algorithm regardless of key size.

Replace with: ML-KEM-1024 / ML-DSA-87

ECDSA P-256Broken

Elliptic curve cryptography broken by Shor’s algorithm.

Replace with: ML-DSA-44 / SLH-DSA

ECDSA P-384Broken

Larger curves do not help against quantum attack.

Replace with: ML-DSA-65 / SLH-DSA

ECDH / X25519Broken

Key exchange vulnerable to Shor’s algorithm. Hybrid mode available now.

Replace with: ML-KEM-768 / X25519MLKEM768

DH-2048Broken

Classic Diffie-Hellman broken by Shor’s algorithm.

Replace with: ML-KEM-768

Compliance Deadlines

CNSA 2.0 — Software/Firmware Signing (exclusive use)2030

Due before CRQC arrival (8 years before)

CNSA 2.0 — Traditional networking (TLS/IPsec)2030

Due before CRQC arrival (8 years before)

CNSA 2.0 — Web / cloud / servers / OS exclusive2033

Due before CRQC arrival (5 years before)

NIST — RSA/ECC Deprecation (NIST IR 8547, draft; SP 800-131A Rev.3, draft)2030

Due before CRQC arrival (8 years before)

NIST — RSA/ECC Disallowed (NIST IR 8547, draft; SP 800-131A Rev.3, draft)2035

Due before CRQC arrival (3 years before)

EU/ANSSI — PQC Guidance (advisory)2030

Non-binding guidance — no legislative mandate

HNDL Exposure Window

Data encrypted today with quantum-vulnerable algorithms can be stored by adversaries and decrypted when a CRQC arrives. The table below shows exposure for different data retention periods.

Data RetentionData Captured TodayStill Valid AtCRQC ArrivesAt Risk?
1 years202620272038Safe
3 years202620292038Safe
5 years202620312038Safe
7 years202620332038Safe
10 years202620362038Safe
15 years202620412038AT RISK
25 years202620512038AT RISK

CRQC Scenario — Export

Export this scenario analysis as a shareable document.

Try it

Move the CRQC arrival year earlier. What appears in the Algorithms Broken panel?

Next step

Next in Risk & Strategy: Risk Register Builder

Risk Register Builder is the next Risk & Strategy tool in the Command Center.