When is Q-Day? What Google, Microsoft and experts say

Nobody can name the year a quantum computer breaks today's encryption. But the cost of doing it fell by more than an order of magnitude in twelve months, and two of the largest tech companies changed their plans because of it.

Strategy · Published September 23, 2026 · 7 min read

Nobody knows when Q-Day will come, and anyone who gives you a single year is guessing. What changed in 2025 and 2026 is the cost: published estimates of the machine needed to break RSA and elliptic-curve cryptography dropped by more than ten times, Google and Microsoft both set 2029 as the deadline for their own migrations, and the Global Risk Institute’s expert survey puts the odds of a code-breaking quantum computer within ten years at 28 to 49%. If you run security, risk or technology strategy, the practical answer is to plan as if the early end of that range is possible.

What is Q-Day?

Q-Day is the point at which a quantum computer can break the public-key cryptography that protects most of the internet: RSA, Diffie-Hellman and elliptic-curve schemes. The machine that can do it is called a cryptographically relevant quantum computer, or CRQC.

Two details are often lost. First, Q-Day may not be public. A government that builds a CRQC has good reasons not to announce it. Second, Q-Day is not the day the damage starts. Encrypted traffic recorded before then becomes readable after, which is the harvest now, decrypt later problem.

How many qubits does it take to break RSA-2048?

The best public estimates fell from about 20 million physical qubits in 2019 to under 1 million in 2025 and under 100,000 in early 2026, under optimistic hardware assumptions. None of these are machines. They are resource estimates: careful calculations of what a future computer would need.

Published Who Target Physical qubits Runtime Status
2019 Craig Gidney and Martin Ekerå RSA-2048 About 20 million About 8 hours The earlier reference point
May 2025 Craig Gidney, Google Quantum AI RSA-2048 Under 1 million Under a week Preprint
Feb 2026 Webster et al. (“Pinnacle” architecture) RSA-2048 Under 100,000 Not the headline Preprint, revised May 2026
Mar 2026 Google Quantum AI 256-bit elliptic curves Under 500,000 Minutes White paper with a zero-knowledge proof
Mar 2026 Oratomic RSA-2048 and 256-bit elliptic curves on neutral atoms About 10,000 to 100,000 Days to years, depending on the design Preprint, not peer reviewed

The drops came from better algorithms and better error-correction schemes, not from better hardware. Gidney’s 2025 paper used approximate arithmetic, a denser way to store idle logical qubits and a cheaper way to prepare the “magic states” that the computation consumes. The Pinnacle paper swapped the surface code for quantum LDPC codes, which need fewer physical qubits per logical qubit but demand connections between distant qubits that are hard to build.

The March 2026 Google paper matters most for anyone who uses elliptic curves, which means most TLS connections, most mobile apps and every major cryptocurrency. It estimated that breaking 256-bit elliptic-curve cryptography needs fewer than 1,200 logical qubits and fewer than 500,000 physical qubits, with a run time of minutes. Google did not publish the circuits. It released a zero-knowledge proof that lets outsiders check the claim without learning how to run the attack.

How close are today’s quantum computers?

Not close in raw numbers. The most accurate commercial machines have around 100 physical qubits, and the attacks above need tens or hundreds of thousands of them working together, with very low error rates, for anywhere from minutes to months or longer.

A few reference points:

  • Quantinuum’s Helios, launched November 5, 2025, has 98 trapped-ion qubits with 99.921% two-qubit gate fidelity, and demonstrated 48 error-corrected logical qubits.
  • A Caltech team trapped 6,100 neutral-atom qubits in a single array in 2025, the largest reported so far. A large array is a big step, but it is not yet a machine running error-corrected computations at that size.
  • IBM’s published roadmap targets Starling in 2029: a fault-tolerant machine with 200 logical qubits running 100 million gates.

Put Starling next to the Google estimate and the gap is visible: 200 logical qubits against a requirement of about 1,200. That gap is one reason expert surveys spread the risk across the 2030s instead of concentrating it in 2029. You can follow the vendors’ plans in our overview of quantum hardware roadmaps.

The engineering assumptions also deserve attention. The Gidney and Pinnacle estimates both assume a physical error rate of 0.1%, an error-correction cycle of one microsecond and a control system that reacts within ten microseconds, sustained across the whole machine. Individual labs have reached some of those numbers on small devices. No one has reached all of them at once at scale.

Why did Google and Microsoft move their deadlines to 2029?

Both companies said the quantum threat is arriving faster than they had planned for. Google set 2029 as the deadline for its own post-quantum migration on March 25, 2026. Microsoft followed on June 30, 2026, accelerating its Quantum Safe Program so that its products and services move to post-quantum cryptography by 2029, earlier than the plan it had published the year before.

Google’s post, by Heather Adkins and Sophie Schmieg, says the timeline “reflects migration needs for the PQC era in light of progress on quantum computing hardware development, quantum error correction, and quantum factoring resource estimates.” It also shifted priority toward authentication and digital signatures, which have to be replaced before a CRQC exists because nothing can fix a forged signature after the fact.

Microsoft’s post, by Azure CTO Mark Russinovich, says: “We believe cryptographically relevant quantum computers could arrive sooner than previously expected.” It points to US government guidance of June 22, 2026 (the date Executive Order 14412 was signed) and a French decision to stop certifying products without quantum-safe encryption.

Read carefully, neither company says Q-Day is 2029. They are saying their own migration has to be finished by then to leave a margin. That distinction matters when a vendor tells you the quantum threat “arrives in 2029.”

What do experts expect?

The most cited expert survey spreads the risk over the next fifteen years, with meaningful probability inside ten. The Global Risk Institute’s Quantum Threat Timeline Report 2025, published March 9, 2026 and written by Michele Mosca and Marco Piani, surveyed 26 experts.

They judged a CRQC within 10 years “quite possible” (28 to 49%) and within 15 years “likely” (51 to 70%). The report describes the timeline as accelerated compared with earlier editions. A 28% chance of losing the confidentiality of your long-lived data within a decade is a number most risk committees would act on for any other threat.

Are there reasons to doubt the faster timelines?

Yes, and they are worth taking seriously. Resource estimates are not hardware, several of the newest ones have not been peer reviewed, and each assumes engineering that nobody has demonstrated at scale.

Maria Violaris of Oxford Quantum Circuits told Physics World that Oratomic’s space-efficient design rests on components “demonstrated to work individually in state-of-the-art academic labs,” while its time-efficient design “relies on more speculative assumptions.” A design that needs few qubits can also need a very long run time: Oratomic’s own scenarios range from days to years. And the quantum LDPC codes behind the Pinnacle estimate need connections between distant qubits that current chips do not provide at scale.

There is also a history of optimism in the field. Roadmaps slip, and the step from a demonstration with dozens of logical qubits to one with a thousand logical qubits running long computations is large. A reasonable reading is that the estimates moved the plausible window earlier without making a specific year certain.

Does the exact date matter for your company?

Less than it seems. What matters is whether the time your data must stay secret plus the time your migration will take runs past Q-Day, a test Michele Mosca proposed in 2015.

If your customer records must stay confidential for 15 years and your migration takes five, you need Q-Day to be at least 20 years away to be safe, and the Global Risk Institute survey puts the odds of a CRQC within 15 years above 50%. Regulators have also stopped waiting for a date. NIST’s draft transition plan proposes deprecating RSA and elliptic curves after 2030 and disallowing them after 2035, and the US, EU and UK have attached deadlines to those years. The full list is in our piece on post-quantum migration deadlines.

For boards in Latin America, this changes the question from “when will it happen?” to “what do we fix first, and who has to pay for it?” Banks, insurers and government agencies with long-lived data face that question first. Answering it takes a dated plan tied to signals you can check, such as a vendor’s logical-qubit milestone, a new resource estimate or a regulator’s deadline. That is the work of a quantum strategy and roadmap engagement, and if the cryptography side is the urgent part, a quantum readiness assessment is the shorter first step.

Sources

  1. Craig Gidney, How to factor 2048 bit RSA integers with less than a million noisy qubits, arXiv, May 21, 2025
  2. Webster et al., The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100 000 physical qubits using quantum LDPC codes, arXiv, February 12, 2026
  3. Google Research, Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly, March 31, 2026
  4. Physics World, New findings shorten the road to cryptographically relevant quantum computers, May 26, 2026
  5. Global Risk Institute, Quantum Threat Timeline Report 2025, March 9, 2026
  6. Google, Our timeline for the post-quantum cryptography migration, March 25, 2026
  7. Microsoft Security Blog, Accelerating the quantum-safe timeline, June 30, 2026
  8. IBM Quantum, How IBM will build the world's first large-scale, fault-tolerant quantum computer, June 10, 2025
  9. Quantinuum, Commercial launch of the Helios quantum computer, November 5, 2025

Questions we get about this

What is Q-Day?

Q-Day is the day a quantum computer becomes able to break the public-key cryptography in wide use today, such as RSA and elliptic-curve cryptography. Such a machine is called a cryptographically relevant quantum computer (CRQC). It does not exist yet, and its arrival might not be announced publicly.

When will quantum computers break RSA-2048?

No one knows. In a survey of 26 experts published in March 2026, the Global Risk Institute found a 28 to 49% chance of a cryptographically relevant quantum computer within 10 years and 51 to 70% within 15 years. Google and Microsoft have both set 2029 as the deadline for their own post-quantum migrations.

How many qubits are needed to break RSA-2048?

Published estimates fell from about 20 million noisy physical qubits in 2019 to under 1 million in Craig Gidney's May 2025 paper, and under 100,000 in a February 2026 preprint that assumes more advanced error-correcting codes. Those numbers assume error rates and speeds that no machine has reached at that scale. The most accurate commercial systems today have on the order of 100 physical qubits.

Why did Google and Microsoft move their post-quantum deadlines to 2029?

Google said in March 2026 that its 2029 target reflects progress in quantum hardware, error correction and factoring resource estimates. Microsoft said in June 2026 that cryptographically relevant quantum computers could arrive sooner than previously expected, and accelerated its Quantum Safe Program so that its products and services move to post-quantum cryptography by 2029.

Should my company wait until Q-Day is closer to migrate?

No. Data recorded today can be decrypted after Q-Day, large migrations take years, and regulators are setting deadlines of 2030 and 2035 regardless of when Q-Day comes. The exact date matters less than whether your data's secrecy period plus your migration time runs past it.

Keep reading

Get in before the queue forms

We are taking a short list of companies for our first readiness assessments and post-quantum migrations. Tell us what you are working on and we will get back to you within two business days.

Write to us