What has to happen for Q-Day
Q-Day needs a cryptographically relevant quantum computer, or CRQC: a machine big and reliable enough to run Shor’s algorithm, published in 1994, on real key sizes. No machine today comes close. In May 2025, Google Quantum AI researcher Craig Gidney estimated that RSA-2048 could be factored in under a week with fewer than a million noisy qubits, down from about 20 million in a 2019 estimate.1 That is a resource estimate, not a demonstration, but it moved the goalposts much closer.
| Algorithm type | Examples | After Q-Day |
|---|---|---|
| Public-key (classical) | RSA, X25519, ECDH, ECDSA | Broken by Shor’s algorithm |
| Symmetric ciphers and hashes | AES-256, SHA-256 | Still secure at 256 bits |
| Post-quantum | ML-KEM, ML-DSA, SLH-DSA | Designed to resist it |
When is Q-Day expected?
Estimates vary, and honest ones come with ranges. Here is what the people who build and regulate cryptography have published:
| Source | What they say |
|---|---|
| Global Risk Institute survey of 26 experts (March 2026) | A CRQC is “quite possible” (28% to 49%) within 10 years and “likely” (51% to 70%) within 15.2 |
| Google (March 2026) | Moved its own post-quantum migration deadline to 2029, citing progress in hardware, error correction and factoring estimates.3 |
| Cloudflare (April 2026) | Targets full post-quantum security, including authentication, by 2029.4 |
| NIST (November 2024 draft) | Deprecate RSA-2048 and P-256 class algorithms after 2030; disallow RSA and elliptic curves after 2035.5 |
| UK NCSC (March 2025) | Migration milestones in 2028 and 2031, fully migrated by 2035.6 |
Secria keeps a public Q-Day Clock that tracks these forecasts. It counts down to a consensus estimate of January 1, 2035, inside an expert window of 2030 to 2040, and links every source it uses.
Why it matters before it happens
Q-Day won’t be announced, and it doesn’t have to arrive for today’s data to be at risk. Anything recorded now can be decrypted after it, which is the harvest now, decrypt later problem. Big migrations also take years, which is why deadlines sit ahead of the median estimates. The useful response is not alarm but timing: move sensitive communication to post-quantum encryption well before the date, whatever it turns out to be.
Secria and Q-Day
Secria was built for this. Secria Mail uses ML-KEM-1024 with X25519 on every plan, and Secria VPN adds an ML-KEM-1024 protected key to every WireGuard session. What you send today is already protected against a future quantum computer. See post-quantum email and the post-quantum VPN.
Related terms
Sources
- Craig Gidney, Google Quantum AI, How to factor 2048 bit RSA integers with less than a million noisy qubits (May 2025).
- Global Risk Institute and evolutionQ, Quantum Threat Timeline Report 2025 (March 2026).
- Google, Quantum frontiers may be closer than they appear (March 2026).
- Cloudflare, Cloudflare targets 2029 for full post-quantum security (April 2026).
- NIST, IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards (November 2024).
- UK NCSC, Timelines for migration to post-quantum cryptography (March 2025).
Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.