when is Q-Day Q-Day expected Q-Day predicted

When is Q-Day? Expert estimates, dated and sourced

Adrian Maverick · · 10 min read

When is Q-Day?

Nobody knows the date, and anyone who names one is guessing. The most careful published estimate, a March 2026 survey of 26 quantum computing experts, puts the chance of a code-breaking quantum computer at 28% to 49% within 10 years and 51% to 70% within 15. Migration deadlines from governments and large tech companies fall between 2029 and 2035.

Q-Day is the day a quantum computer can break the public-key encryption that protects most of the internet. Which locks that covers, and which it doesn't, is in our piece on whether quantum computers will break encryption. This page is only about the date: who has put a number on it, what kind of number it is, and how to turn it into a deadline of your own.

One caution before the numbers. Three different things get quoted as "Q-Day estimates," and mixing them up is how a migration deadline turns into a doomsday headline.

  • Forecasts are experts giving odds that the machine exists by a certain year.
  • Engineering estimates say how big a machine would have to be. They contain no date.
  • Deadlines are dates by which an organization wants to be finished replacing old encryption. They are set early on purpose.

What do experts predict?

The longest-running forecast is the Quantum Threat Timeline Report from the Global Risk Institute and evolutionQ. Each edition asks researchers who build quantum computers for the odds of a machine that can break RSA-2048 in 24 hours. The 2025 edition, published on March 9, 2026, surveyed 26 of them.

Horizon (from the 2025 survey) What the 26 experts said
Within 5 years Most rate the risk as low. Half put it at 1% or more.
Within 10 years Averaged odds of 28% to 49%. Half put it at about 50% or higher, half below 30%.
Within 15 years Averaged odds of 51% to 70%. 18 of 26 say about 50% or higher.
Within 20 years 24 of 26 say about 50% or higher.

Two things in that table deserve attention. The 10-year row is a split, not a consensus: the report itself says "the experts are divided." And the averages come as ranges because experts answered in bands such as "less than 30%," which can be read at the low or high end. The report calls the result a "notable acceleration" compared with its earlier surveys.

The forecast is not new, either. In 2015, report co-author Michele Mosca wrote in a paper on quantum readiness: "I estimate a 1/2 chance of breaking RSA-2048 by 2031." Eleven years later the survey he runs lands in the same decade.

Read plainly, and counting from the 2025 survey, the expert view is: unlikely before 2030, somewhere between one in four and one in two by 2035, more likely than not by 2040.

Why did the estimates move in 2025 and 2026?

Because the size of the machine needed kept shrinking on paper.

  • May 2025. Craig Gidney of Google Quantum AI estimated that a 2,048-bit RSA key "could be factored in less than a week by a quantum computer with less than a million noisy qubits." His own 2019 estimate was 20 million.
  • March 31, 2026. Google Research published circuits for breaking 256-bit elliptic curves, the kind behind much of the web and most cryptocurrencies, that it says could run on "fewer than 500,000 physical qubits in a few minutes."
  • April 2026. Cloudflare, explaining its own schedule change, pointed to a further estimate, from a company called Oratomic, that breaking a 256-bit curve might need only about 10,000 qubits on a neutral-atom machine.

None of these is a demonstration. They are blueprints for a machine nobody has built. But each one lowers the bar the hardware has to clear, and forecasts follow the bar.

Is Q-Day in 2029?

No one credible has predicted that. 2029 is a deadline, and the difference matters.

On March 25, 2026, Google's security team published a post titled "Quantum frontiers may be closer than they appear". The key sentence is: "We're setting a timeline for post-quantum cryptography migration to 2029." That is the date by which Google wants its own systems moved, justified by progress in hardware, error correction and factoring estimates. It is not a claim that encryption breaks in 2029.

Two weeks later, Cloudflare set the same target: "We now target 2029 to be fully post-quantum (PQ) secure including, crucially, post-quantum authentication." It also reported that more than 65% of human traffic to its network was already post-quantum encrypted.

A deadline is supposed to sit ahead of the threat. When a company with its own quantum lab picks a date years earlier than governments did, the fair reading is "they want margin," not "they know something."

What deadlines have governments and companies set?

Who Date What it applies to
Google (March 2026) 2029 Its own post-quantum migration
Cloudflare (April 2026) 2029 Full post-quantum security, authentication included
US federal agencies, OMB M-26-15 (June 2026) End of 2030 Post-quantum key establishment on high-value and high-impact systems
US federal agencies, same memo 2031, then 2035 Signatures on those systems, then everything remaining
NIST draft IR 8547 (November 2024) After 2030, after 2035 RSA-2048 class algorithms deprecated, then all RSA and elliptic curves disallowed

The White House memo is the most direct official statement on timing. It says a cryptographically relevant quantum computer "is not yet known to exist, but steady advancements in the quantum computing field may yield a CRQC in the coming decade." The NIST plan is still a draft as of October 2026.

Put the deadlines next to the forecasts and they tell one story. Every finish line sits between 2029 and 2035, which is the stretch where expert odds climb from "unlikely" to as high as one in two.

Has Q-Day already happened in secret?

There is no evidence of it, and the public record makes it hard to believe. Running the code-breaking algorithm for real is still stuck on toy numbers. In an August 2025 post, Gidney explained why quantum computers have not yet factored the number 21: the circuit is more than a hundred times as expensive as the one for 15, and current hardware is too noisy to run it. (Our what-breaks guide links the post and the gate counts.)

Could a government lab be far ahead of what is published? The Global Risk Institute report raises covert research as a reason for caution. Nobody outside can rule it out, and nobody outside can measure it. That is one more reason to plan around the range and not around a headline.

How to work out your own Q-Day deadline

This is the part most Q-Day articles leave out. You do not need the date. You need to know whether your data outlives it.

The test comes from Mosca and is set out in the Global Risk Institute report. Take how long the information must stay secret (its shelf life) and add how long it will take you to move to post-quantum encryption. If that sum is longer than the time until Q-Day, the data is exposed, because anything sent under today's encryption can be recorded now and opened later. That tactic is called harvest now, decrypt later.

Turned around, it gives you a last safe year to send something under classical encryption: the Q-Day year minus the shelf life.

How long it must stay secret If Q-Day is 2030 If Q-Day is 2035 If Q-Day is 2040
2 years (a product plan, travel details) 2028 2033 2038
5 years (a contract, a salary negotiation) 2025 2030 2035
10 years (tax records, a passport scan) 2020 2025 2030
25 years or more (medical history, legal matters) 2005 2010 2015

Read across your own row. Anything with a 10-year shelf life is already past its last safe year in two of the three scenarios. Anything that should stay private for life was past it before you sent it.

Then do the second half of the sum, the migration time. For a bank, that is years of engineering. For a person, it is however long you wait to move the long-lived material to tools that already use post-quantum key exchange. For email and a VPN it can be this afternoon: Secria Mail uses ML-KEM-1024 with X25519 on every plan, free included, and Secria VPN adds an ML-KEM-1024 protected key to every WireGuard session.

What to watch for instead of headlines

Three public signposts tell you more than any single prediction.

  1. Logical qubits on real hardware. Google's elliptic-curve estimate above needs between 1,200 and 1,450 error-corrected "logical" qubits. IBM's public roadmap targets a machine called Starling, "delivered by 2029," with 200 logical qubits, and a later one, Blue Jay, with 2,000. Whether those dates hold is the best public indicator there is.
  2. The next Quantum Threat Timeline Report. If the 10-year average crosses 50%, the center of expert opinion has moved inside 2035.
  3. Deadlines being pulled forward. Google and Cloudflare moved to 2029 in spring 2026. If NIST's final plan or another government follows, margins are being cut.

We keep all of this in one place on the Q-Day Clock, a countdown we built from the forecasts and deadlines above. It currently counts to a consensus estimate of January 1, 2035, inside an expert window of 2030 to 2040, links every source, and moves when the research does.

Frequently asked questions

What year is Q-Day expected? There is no agreed year. The March 2026 expert survey gives averaged odds of 28% to 49% by about 2035 and 51% to 70% by about 2040. Most official migration plans finish in 2035.

Did Google say Q-Day is 2029? No. Google set 2029 as the date to finish its own move to post-quantum cryptography. It cited faster progress in hardware, error correction and factoring estimates, but made no prediction of when encryption breaks.

Is Q-Day real or hype? The math has been settled since 1994. The open question is engineering, and the people doing that engineering now give it roughly even odds within 10 to 15 years. A US government memo from June 2026 says such a machine "may" arrive "in the coming decade."

Will we know when Q-Day happens? Not necessarily. A lab that reaches it first has reasons to stay quiet, and decrypting recorded traffic leaves no trace for the victim. That is why the planning dates are set by forecasts and not by waiting for an announcement.

What should I do before Q-Day? Sort your data by how long it must stay private, and move the long-lived part to services that already use post-quantum key exchange such as ML-KEM. Keep your browser and apps updated, since that is how most of this protection reaches you.

The date will stay uncertain until it has passed. The range is clear enough to act on: check your row in the table, and move what can't wait. Secria's free plan is one place to start.

Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.