Back to DashboardFoundationsbeginner40 min

Quantum Threat Mechanics

How quantum computers break RSA, ECC, and weaken AES — and why PQC algorithms survive.

Why this matters: Knowing exactly which algorithms Shor and Grover break — and which survive — is what separates a real risk assessment from vendor hype.

Start here: Pick an algorithm in Security Level Degradation: its classical and quantum security bits are drawn as two bars, with a BROKEN, WEAKENED or SAFE verdict and the logical qubits needed to break it.

For your role

Executive / Business Leader
Calculate your migration deadline and when signing credentials must rotate, and track logical-qubit progress against what is needed to break elliptic curves: which algorithms Shor and Grover break is what separates risk from vendor hype.
GRC / Risk & Compliance
The Security Level Degradation step and the deadline calculators put a number on the exposure; the qubit tracker is the evidence line for a risk register entry.
Developer / Engineer
See how quantum attacks reduce each algorithm's security level and compare two algorithms side by side: which of the primitives your code calls survive.
Security Architect
The full algorithm-versus-attack comparison and the credential-rotation calculator set the order in which key exchange and signatures have to move.
Researcher / Academic
The qubit tracker sets logical-qubit progress against the requirement to break ECC, and the degradation model states its assumptions; both are checkable against the sources cited.
IT Ops / DevOps
The two calculators, migration deadline and credential rotation, give the dates your certificate and key rotation plans have to meet.
Curious Explorer
How a quantum computer actually breaks today's encryption, which algorithms survive, and a calculator that turns it into a date for you.
Practice in the Simulation

Qubits & Superposition

Classical computers store information as bits — each is definitively 0 or 1. A quantum computer uses , which exploit two quantum phenomena to process information fundamentally differently.

Classical Bit
0 or 1

Always in a definite state. N bits represent exactly one of 2N values at a time.

Quantum Bit (Qubit)
α|0〉 + β|1〉

exists in a combination of 0 and 1 simultaneously. qubits can be correlated so measuring one instantly determines the other. Together, N qubits hold a superposition over all 2N basis states at once — though a measurement still returns only one of them.

Key insight: Quantum speedup doesn't come from "trying all answers at once." It comes from carefully constructing interference patterns that amplify correct answers and cancel wrong ones. Only specific algorithms (like and ) can exploit this structure.

Shor's Algorithm — Breaking &

Peter Shor showed in 1994 (Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer) that a quantum computer can solve two hard mathematical problems exponentially faster than any classical computer:

Integer Factorization (RSA)

RSA relies on the difficulty of factoring large numbers (N = p × q).

Classical: O(e1.9 · n1/3) — sub-exponential
Quantum: O(n³) — polynomial

RSA-2048 requires ~1,537 logical qubits (Gidney 2025, down from the 2016-era ~4,098 estimate). A CRQC could factor it in under a week, not billions of years.

Discrete Logarithm (ECC/DH)

ECC (, , ) and Diffie-Hellman rely on the hardness of discrete logarithms.

Classical: O(2n/2) — exponential (Pollard rho)
Quantum: O(n³) — polynomial

P-256 requires ~1,200 logical qubits (revised per Google Quantum AI, March 2026). All ECC variants (P-256, P-384, , ) are equally broken.

Impact: Every public-key algorithm based on integer factorization or discrete logarithms — RSA, DSA, ECDSA, ECDH, EdDSA, DH — provides zero security against a quantum adversary. Key size increases do not help because Shor's algorithm scales polynomially.

Grover's Algorithm — Weakening & SHA

Lov Grover showed in 1996 (A fast quantum mechanical algorithm for database search) that a quantum computer can search an unstructured database quadratically faster. This affects symmetric encryption and hash functions:

AlgorithmClassical SecurityQuantum SecurityStatus
AES-128128-bit64-bitInsufficient
AES-192192-bit96-bitAdequate
AES-256256-bit128-bitSecure
SHA-256 (collision)128-bit~85-bitSecure

Practical note: Grover's algorithm is less threatening than Shor's. It provides only a quadratic speedup (halving security bits), and the algorithm requires sequential oracle queries — it cannot be parallelized effectively. The fix is simple: double the key size (AES-128 → AES-256).

CRQC Timeline Projections

A is one powerful enough to run Shor's algorithm against production-size keys. Experts disagree on when this will happen, but major agencies are planning for it now:

NIST IR 8547 — Deprecate by 2030, disallow by 2035
NSA CNSA 2.0 — Exclusive use 2030/2033 by category; NSM-10: all NSS by 2035
Global Risk Institute — ~49% within a decade on averaged expert estimates; half of 26 experts put it at 50% or more (2025 Quantum Threat Timeline Report)
BSI Germany — Recommend hybrid migration now
ANSSI France — Recommends hybrid now; no regulatory obligation today; obligations for product qualification targeted from 2027

What the sources say, in their own words

  • Open question

    A 2025 survey of 26 experts (Global Risk Institute with evolutionQ) found a cryptographically relevant quantum computer "quite possible" (28-49%) within 10 years and "likely" (51-70%) within 15.

    Made by Global Risk Institute and evolutionQ (survey of 26 experts, published March 2026) · Last checked 3 October 2026

    Why: A forecast of something that has not happened; nobody can show it right or wrong today.

    What each source says
  • Settled

    NIST's initial public draft IR 8547 (November 2024) proposes that 112-bit RSA, ECDSA and EdDSA be deprecated after 2030 and that quantum-vulnerable algorithms be disallowed after 2035.

    Made by NIST (IR 8547, initial public draft, November 2024) · Last checked 3 October 2026

    Why: What the draft says is checked against the draft itself. It is a draft: the comment period closed on 2025-01-10 and no final version was found on 2026-07-30.

    The source
  • Settled

    NSA's December 2024 CNSA 2.0 FAQ (version 2.1) says that by 31 December 2030 all equipment and services that cannot support CNSA 2.0 must be phased out, and that by 31 December 2031 CNSA 2.0 algorithms are mandated for use, unless otherwise noted.

    Made by NSA, "The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ", version 2.1, December 2024 · Last checked 3 October 2026

    Why: What the FAQ says is checked against the FAQ itself. These are migration dates NSA sets for its own systems, not a prediction of when a quantum computer will exist. The FAQ is newer than NSA's September 2022 announcement; it updates it and does not replace it.

    The source
    Earlier statements
    • Updates an earlier statement. The FAQ gives general phase-out and mandate dates and says NSA's update to CNSSP 15 set several dates. It does not restate the 2022 announcement's category dates, which are not withdrawn. Where the two give different dates for the same equipment, the newer governs.

      What changed (2 points)
      • When equipment and algorithms must move to CNSA 2.0

        Earlier

        September 2022 announcement: by category. Software and firmware signing exclusively CNSA 2.0 by 2030; web browsers and servers and cloud services by 2033.

        “exclusively use CNSA 2.0 by 2030”

        Newer

        December 2024 FAQ: by 31 December 2030 equipment and services that cannot support CNSA 2.0 must be phased out, and by 31 December 2031 CNSA 2.0 algorithms are mandated, unless otherwise noted.

        “By December 31, 2030, all equipment and services that cannot support CNSA 2.0 must be phased out unless otherwise noted, and by December 31, 2031, CNSA 2.0 algorithms are mandated for use unless otherwise noted.”
      • Web browsers and servers, cloud services

        Earlier

        September 2022 announcement: exclusive use of CNSA 2.0 by 2033.

        “Web browsers/servers and cloud services: support and prefer CNSA 2.0 by 2025, and exclusively1 use CNSA 2.0 by 2033.”

        Newer

        December 2024 FAQ: CNSA 2.0 algorithms mandated by 31 December 2031 unless otherwise noted; the FAQ does not restate a 2033 date.

        “by December 31, 2031, CNSA 2.0 algorithms are mandated for use unless otherwise noted”
      Read the earlier statement by NSA (CNSA 2.0, 2022)
      Settled
      NSA's CNSA 2.0 expects national security systems to finish the transition to quantum-resistant algorithms by 2035, and to use CNSA 2.0 exclusively for software and firmware signing by 2030.

      Made by NSA (CNSA 2.0, 2022) · Last checked 3 October 2026

      Why: These are dates the NSA sets for its own systems, checked against the NSA document. They are migration deadlines, not a prediction of when a quantum computer will exist.

      A newer statement updates this one.

      What each source says
  • Settled

    ANSSI's current FAQ on post-quantum cryptography says it will not be reasonable to buy products that do not include post-quantum cryptography after 2030, and strongly insists on hybrid protection wherever post-quantum protection is needed.

    Made by ANSSI (France), FAQ on post-quantum cryptography (a page that refers to events of early October 2025, so it is from October 2025 or later) · Last checked 3 October 2026

    Why: What the FAQ says is checked against the FAQ itself. It is a purchasing recommendation (the FAQ says there is no regulatory obligation), not a prediction of when a quantum computer will exist. It is newer than ANSSI's 2022 position paper.

    What each source says
    Earlier statements
    • Updates an earlier statement. The FAQ adds a purchasing recommendation (no products without post-quantum cryptography after 2030) and keeps the hybrid recommendation. It does not withdraw the 2022 paper's phase roadmap.

      What changed (1 point)
      • What ANSSI says about 2030

        Earlier

        2022 position paper: standalone post-quantum cryptography becomes an option, probably not earlier than 2030.

        “Phase 3 (probably not earlier than 2030): optional standalone post-quantum cryptography.”

        Newer

        Current FAQ: it will not be reasonable to buy products that do not include post-quantum cryptography after 2030.

        “L'ANSSI indique qu'il ne sera pas raisonnable d'acheter des produits qui n'intègrent pas de la PQC après 2030.”
      Read the earlier statement by ANSSI (France), position paper of January 2022, updated 2023
      Settled
      ANSSI's 2022 position paper puts standalone post-quantum cryptography as an option "probably not earlier than 2030" and recommends hybrid use until then.

      Made by ANSSI (France), position paper of January 2022, updated 2023 · Last checked 3 October 2026

      Why: What the paper says is checked against the paper. It is a transition milestone, not a date for when a quantum computer will exist; the paper gives no such date.

      A newer statement updates this one.

      What each source says
  • Settled

    BSI's technical guideline TR-02102-1 (version 2026-01) recommends using classical key agreement alone only until the end of 2031, recommends that applications with very high protection requirements move to quantum-safe mechanisms by the end of 2030, and recommends classical signatures only until the end of 2035.

    Made by BSI (Germany), TR-02102-1, version 2026-01, 23 January 2026 · Last checked 3 October 2026

    Why: What the guideline says is checked against the guideline itself. These are migration recommendations, not a prediction of when a quantum computer will exist.

    What each source says

Other questions that are still open

  • Open question

    Fewer than one million physical qubits are enough to break RSA-2048 (Craig Gidney, June 2025).

    Made by Craig Gidney (Google), June 2025, as reported by Cloudflare (2025) and Project Eleven (2026)

    Why: A resource estimate for a machine that does not exist, based on assumptions about hardware and error rates. It cannot be checked until such a machine is built; other groups may publish other figures.

    What each source says
    Earlier statements
    • Replaces an earlier statement. Cloudflare describes the 20 million figure as the earlier estimate and credits the June 2025 paper for the lower one. The newer figure is still an estimate.

      What changed (1 point)
      • Physical qubits needed to break RSA-2048 on superconducting machines

        Earlier

        Earlier estimate: about 20 million qubits.

        “We thought we’d need about 20 million qubits with the superconducting approach to break RSA-2048.”

        Newer

        June 2025 estimate: fewer than one million qubits.

        “we need fewer than one million qubits”
      Read the earlier statement by The earlier estimate, as described by Cloudflare (2025)
      Replaced by a newer statement
      About 20 million superconducting qubits are needed to break RSA-2048.

      Made by The earlier estimate, as described by Cloudflare (2025) · Last checked 3 October 2026

      Why: Cloudflare itself says the 20 million figure was the earlier one and that newer software work shows much less is needed.

      The source
  • Open question

    For high-security systems BSI works on the hypothesis that cryptographically relevant quantum computers will be available in the early 2030s, and says this is a timeline for risk assessment, not a forecast.

    Made by BSI (Germany), brochure "Quantum-safe cryptography – fundamentals, current developments and recommendations", 2021 · Last checked 3 October 2026

    Why: A working hypothesis about a machine that does not exist, which BSI itself calls a risk-assessment timeline and not a forecast. The brochure is from 2021; no newer BSI statement of it was found.

    What each source says

Bottom line: Whether a CRQC arrives in 2030 or 2040, migration takes years. Organizations handling long-lived data (government, healthcare, finance) must begin now because of the Harvest Now, Decrypt Later threat.

The most urgent quantum threat is not future code-breaking — it's data being intercepted today for future decryption. This attack is called Harvest Now, Decrypt Later (HNDL), also known as "Store Now, Decrypt Later" or "retrospective decryption."

📡
Phase 1: Harvest

Adversaries intercept encrypted traffic today (VPN, TLS, email) and store it.

💾
Phase 2: Store

Data is archived — storage is cheap. Adversaries wait for quantum capability.

🔓
Phase 3: Decrypt

Once CRQC is available, Shor's breaks the key exchange. Symmetric keys are recovered, all data is decrypted.

Mosca's Theorem (Migration Deadline): If your data must remain secure for X years, your migration will take Y years, and a CRQC is expected in Z years, you must start migrating within Z − X − Y years. For data with 25-year sensitivity, a 5-year migration time, and a CRQC in 2035 (the midpoint of the 2030–2041 planning range this site uses), migration should have started by 2005.

HNDL targets confidentiality. HNFL targets authenticity and integrity. Adversaries collect signed artifacts today — firmware images, certificate chains, code-signing blobs — and store them. Once a CRQC arrives, Shor's algorithm recovers the signer's private key, enabling forged signatures on any document or binary.

📂
Phase 1: Capture

Collect signed artifacts — firmware images, CA certificates, code-signing blobs. Public-key material is often publicly accessible.

💾
Phase 2: Store

Archive for years to decades. No active attack is needed — the adversary waits for quantum capability.

✍️
Phase 3: Forge

CRQC runs Shor's algorithm on the signer's public key, recovers the private key, and forges arbitrary signatures retroactively.

High-risk targets
  • • hierarchies & root CA certificates
  • • Firmware signing (medical devices, industrial, automotive)
  • • Software update pipelines & code-signing certs
  • • Government ePassports & digital ID credentials
Why it's urgent now

A Root CA issued today with a 20-year validity period will still be trusted in 2046. If a CRQC arrives within the planning range this site uses (2030–2041), that CA's RSA or ECDSA key is breakable — and every certificate it ever signed becomes forgeable. Migration to or must complete before CRQC arrival.

HNFL vs HNDL: HNDL requires intercepting encrypted traffic. HNFL does not — signed artifacts are often public. The re-issuance deadline formula is simpler: Re-issuance Deadline = CRQC Year − Re-issuance Time. Use the Step 5 workshop to calculate your credential migration window.

Related Resources

Explore Interactively

Use the Workshop to visualize security degradation, compare algorithms, and calculate your HNDL migration deadline.

Check off all sections and mark this reading done.

Check your understanding

15 questions on Quantum Threats, each with its answer and the reason.

Take the quiz

Next step

Continue the Foundations track: PQC Candidates & Lifecycle

PQC Candidates & Lifecycle is the next module in the Foundations track.

Learning module content can be inaccurate. Please double-check its information. Report inaccuracies in PQC Today GitHub Discussions.