THE QUANTUM THREAT / INTERMEDIATE

Q-Day And Mosca's Inequality: How To Tell If You Are Already Late

Nobody knows when a quantum computer will break today's encryption. Mosca's inequality turns that uncertainty into a planning test based on data shelf life and migration time.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

“When will quantum computers break encryption?” is the question every board asks, and it has no reliable answer. The more useful question is whether your organisation would be ready if it happened within the range of dates experts consider plausible. Michele Mosca, a quantum computing researcher, gave a compact way to test that, and NIST repeats it in its draft transition guidance.1

This article defines the terms people use for the threat, explains Mosca’s inequality, and shows what current expert opinion says about the timing. The calculator lets you try your own numbers.

CRQC And Q-Day

Agencies use the term cryptographically relevant quantum computer, or CRQC, for a quantum computer able to break today’s public-key cryptography in practice. NIST’s November 2024 draft states that no such machine exists,1 and the expert survey published in March 2026 still treats one as a future event.2 Q-Day is an informal, media-friendly name for the day one does.

The phrase “Q-Day” suggests a single public moment, and that picture can mislead. The first machine capable of breaking a key might be run in secret, and early machines could take days or weeks per key before later ones are faster. For planning, it is safer to think of a window that opens gradually than of a date that will be announced.

Mosca’s Inequality

The test uses three numbers, each measured in years from today:

  • X is the shelf life: how long the data you protect today must stay confidential.
  • Y is the migration time: how long it will take to move the relevant systems to quantum-resistant cryptography.
  • Z is the threat timeline: how long until a CRQC exists.

If X plus Y is greater than Z, the migration finishes too late. Data still being encrypted with the old algorithms towards the end of the migration will need to stay secret beyond the point when a CRQC can read it. If X alone is greater than Z, even data encrypted today is exposed. NIST puts it this way: organisations must start transitioning before X plus Y exceeds Z, so even a quantum computer a decade away means starting the migration today.1

X + Y is 18 years and Z is 12 years. Anything still protected by today's public-key cryptography during the last 6 years of your migration would still need to be secret when a quantum computer arrives. Start migrating now.

Mosca’s inequality with illustrative values: data that must stay secret for 10 years, an 8-year migration, and a quantum computer in 12 years. Here, data encrypted with today’s algorithms from about year 2 of the migration onwards would still be secret when the quantum computer arrives. Change the inputs to test your own assumptions. Because nobody knows Z, try a pessimistic and an optimistic value.

The value of the inequality is that it does not need a precise Z. If X plus Y is already 20 years for some systems, the conclusion holds whether Z is 10 or 15 years away. It also shows where you have influence. Y shrinks when systems are built so that algorithms can be swapped easily, and starting early means the migration ends sooner even if Y stays the same. X is set by how long disclosure would cause harm. Deleting stored data does not shorten it, because an attacker may already hold a copy; what helps is sending less long-lived sensitive data over quantum-vulnerable channels in the first place.

Estimating Y Honestly

Organisations tend to underestimate migration time. NIST observes that past cryptographic migrations have taken more than a decade and expects this one, which is more complex, to take at least as long.1 The UK National Cyber Security Centre’s timeline spreads the work across a decade: discovery and an initial plan by 2028, priority migrations by 2031 and completion by 2035.3 A large organisation that has not yet built a cryptographic inventory should be wary of assuming a Y of only a few years.

Example DataIllustrative XWith Y = 8 years, X + YRead Against Z = 10 To 15 Years
Marketing campaign data1 year9 yearsProbably safe if migration starts now
Payment session data3 years11 yearsExposed if the pessimistic end of the range is right
Health records25 years33 yearsExposed under any current estimate
State or defence secrets50 years58 yearsExposed under any current estimate
Illustrative shelf lives only. Your own X depends on legal retention rules, contracts and how long information keeps its value.

What Experts Say About Z

A widely cited source on Z is the Quantum Threat Timeline Report from the Global Risk Institute and evolutionQ, written by Michele Mosca and Marco Piani. The 2025 edition, published on 9 March 2026, surveyed 26 experts. It describes a CRQC within 10 years as quite possible (28 to 49 percent) and within 15 years as likely (51 to 70 percent), and says the experts see the timeline as having accelerated compared with earlier editions.2

These are expert opinions, not measurements, and the ranges are wide. They are not the only signal, though. Engineering estimates of the machine needed have also fallen sharply in recent years, as described in How Many Qubits To Break RSA and Elliptic Curves Fall First.

For historical context, Mosca’s own 2015 paper estimated a one in two chance of breaking RSA-2048 by 2031.4 Governments plan on similar horizons. US National Security Memorandum 10 sets 2035 as the primary target for reducing quantum risk as far as feasible.1

Using The Test In Practice

Apply the inequality per system or per data class, not once for the whole organisation. Estimate X from retention rules and business value. Estimate Y from what the system depends on: vendor support for post-quantum algorithms, hardware refresh cycles, certificate infrastructure and partner connections. Then compare against a range for Z rather than a single number. Systems where X plus Y exceeds even the latest date in that range are exposed in every scenario and go to the front of the queue. Systems that only exceed the earliest date come next. The harvest risk that makes X so important is explained in Harvest Now, Decrypt Later.

Footnotes

  1. NIST, IR 8547 (initial public draft), “Transition to Post-Quantum Cryptography Standards”, November 2024. nvlpubs.nist.gov ↩ ↩2 ↩3 ↩4 ↩5

  2. Global Risk Institute and evolutionQ, “Quantum Threat Timeline Report 2025”, published 9 March 2026. globalriskinstitute.org ↩ ↩2

  3. UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩

  4. M. Mosca, “Cybersecurity in an era with quantum computers: will we be ready?”, IACR ePrint 2015/1075, November 2015. eprint.iacr.org ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.