Glossary

What is Q-Day?

Q-Day is the day a quantum computer becomes powerful enough to break the public-key encryption most of the internet relies on, such as RSA and elliptic-curve cryptography. Nobody knows the date. Expert surveys put it most likely in the 2030s, and standards bodies have already set deadlines to move off the algorithms it would break.

Also called: Y2Q, the day a cryptographically relevant quantum computer (CRQC) arrives

Updated September 2026. Sources are numbered and listed at the end.

What has to happen for Q-Day

Q-Day needs a cryptographically relevant quantum computer, or CRQC: a machine big and reliable enough to run Shor’s algorithm, published in 1994, on real key sizes. No machine today comes close. In May 2025, Google Quantum AI researcher Craig Gidney estimated that RSA-2048 could be factored in under a week with fewer than a million noisy qubits, down from about 20 million in a 2019 estimate.1 That is a resource estimate, not a demonstration, but it moved the goalposts much closer.

What a CRQC would and wouldn’t break.
Algorithm typeExamplesAfter Q-Day
Public-key (classical)RSA, X25519, ECDH, ECDSABroken by Shor’s algorithm
Symmetric ciphers and hashesAES-256, SHA-256Still secure at 256 bits
Post-quantumML-KEM, ML-DSA, SLH-DSADesigned to resist it

When is Q-Day expected?

Estimates vary, and honest ones come with ranges. Here is what the people who build and regulate cryptography have published:

SourceWhat they say
Global Risk Institute survey of 26 experts (March 2026)A CRQC is “quite possible” (28% to 49%) within 10 years and “likely” (51% to 70%) within 15.2
Google (March 2026)Moved its own post-quantum migration deadline to 2029, citing progress in hardware, error correction and factoring estimates.3
Cloudflare (April 2026)Targets full post-quantum security, including authentication, by 2029.4
NIST (November 2024 draft)Deprecate RSA-2048 and P-256 class algorithms after 2030; disallow RSA and elliptic curves after 2035.5
UK NCSC (March 2025)Migration milestones in 2028 and 2031, fully migrated by 2035.6

Secria keeps a public Q-Day Clock that tracks these forecasts. It counts down to a consensus estimate of January 1, 2035, inside an expert window of 2030 to 2040, and links every source it uses.

Why it matters before it happens

Q-Day won’t be announced, and it doesn’t have to arrive for today’s data to be at risk. Anything recorded now can be decrypted after it, which is the harvest now, decrypt later problem. Big migrations also take years, which is why deadlines sit ahead of the median estimates. The useful response is not alarm but timing: move sensitive communication to post-quantum encryption well before the date, whatever it turns out to be.

Secria and Q-Day

Secria was built for this. Secria Mail uses ML-KEM-1024 with X25519 on every plan, and Secria VPN adds an ML-KEM-1024 protected key to every WireGuard session. What you send today is already protected against a future quantum computer. See post-quantum email and the post-quantum VPN.

Sources

  1. Craig Gidney, Google Quantum AI, How to factor 2048 bit RSA integers with less than a million noisy qubits (May 2025).
  2. Global Risk Institute and evolutionQ, Quantum Threat Timeline Report 2025 (March 2026).
  3. Google, Quantum frontiers may be closer than they appear (March 2026).
  4. Cloudflare, Cloudflare targets 2029 for full post-quantum security (April 2026).
  5. NIST, IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards (November 2024).
  6. UK NCSC, Timelines for migration to post-quantum cryptography (March 2025).

Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.

Questions about Q-Day

When is Q-Day expected?+

Nobody knows. A March 2026 survey of 26 experts put the chance of a code-breaking quantum computer at 28% to 49% within 10 years and 51% to 70% within 15. Governments have set migration deadlines around 2030 to 2035.

Has Q-Day already happened?+

No. No public quantum computer can break RSA-2048 or elliptic-curve keys today. The best published estimate says it would take fewer than a million noisy qubits running for less than a week, far beyond any machine that exists.

Will Q-Day break all encryption?+

No. It breaks public-key algorithms like RSA and elliptic-curve cryptography. Symmetric ciphers like AES-256 and hashes like SHA-256 stay secure, and post-quantum algorithms like ML-KEM are designed to resist it.

What should I do before Q-Day?+

Move sensitive communication to services that already use post-quantum key exchange, such as ML-KEM, so what you send now can’t be decrypted later. For email and VPN, that means choosing a provider that has it on by default.

Email that’s ready for what comes next. Post-quantum encryption on every plan, free included.