IBM Quantum's Roadmap: Condor, Flamingo, and What 1,121 Qubits Actually Means for Post Quantum Cryptography

IBM's Scale-First Strategy
IBM has pursued the most aggressive publicly announced quantum scale-up strategy. Each year from 2019 to 2024 IBM announced a new superconducting processor with more qubits than the last. This has produced impressive headline numbers and an equally impressive amount of confusion about what those qubit counts actually mean for cryptography.
The IBM Roadmap in Numbers
| Processor | Qubits | Year | Note |
|---|---|---|---|
| Eagle | 127 | 2021 | |
| Osprey | 433 | 2022 | |
| Condor | 1,121 | Dec 4, 2023 | Heavy-hex layout |
| Flamingo | 462 | 2024 | Quantum link between chips; 3 linked = 1,386 qubits |
| Kookaburra | 1,386 multi-chip | 2025-26 (planned) | 3-chip linked = 4,158 qubits (projection) |
The Pivot from Monolithic to Modular
Condor was the culmination of IBM's single-chip scale-up. Subsequent roadmaps emphasize modular architectures: smaller chips (Heron, Flamingo) connected with quantum communication links. This signals that monolithic qubit count is no longer IBM's primary metric; what matters is effective logical qubits across modules.
Why 1,121 Qubits Does Not Break RSA
Condor's qubits are noisy physical qubits with per-gate error rates around 10^-3. Running Shor's algorithm requires logical error rates around 10^-10. Bridging this gap requires quantum error correction (surface code, for example), which consumes roughly 1,000 physical qubits per logical qubit.
With 1,121 physical qubits under surface code, IBM could in principle produce a single logical qubit. One logical qubit is not enough for Shor. Shor on RSA-2048 requires thousands of logical qubits, meaning millions of physical qubits. Gidney and Ekera's 2021 estimate of roughly 20 million physical qubits at current fidelity remains the standard reference.
Quantum Volume and Circuit Layer Operations Per Second (CLOPS)
IBM advocates metrics like Quantum Volume (QV) and CLOPS alongside raw qubit count. QV measures the largest reliable random circuit the processor can run. CLOPS measures real-world throughput. For cryptographic work, neither QV nor CLOPS directly maps to breaking RSA, but both track hardware quality more honestly than raw qubit count.
IBM and Post Quantum Cryptography
IBM Research contributes directly to PQC:
- Ward Beullens, an IBM Research cryptographer, broke Rainbow in February 2022 (IACR ePrint 2022/214) with a laptop-scale attack, eliminating a NIST PQC Round 3 finalist.
- IBM Quantum Safe offers enterprise PQC migration services including cryptographic inventory and ML-KEM deployment.
- IBM contributes to OpenSSL PQC integrations via the oqs-provider ecosystem.
DARPA QBI Participation
IBM is one of 11 companies advanced to Stage B of the DARPA Quantum Benchmarking Initiative (November 2025). DARPA's stated goal is independent verification of whether a fault-tolerant, utility-scale quantum computer can exist by 2033.
Implications
- Do not interpret annual IBM qubit-count announcements as CRQC signals.
- Do watch for IBM logical-qubit demonstrations, especially scaling the surface code beyond Willow's distance 7.
- Use IBM Quantum Safe or comparable tooling (evolutionQ, ISARA, QNSQY) for cryptographic inventory.
- Deploy hybrid ML-KEM today regardless of where IBM's hardware sits on the roadmap.
Frequently Asked Questions
When was IBM Condor unveiled?
December 4, 2023 at the IBM Quantum Summit. 1,121 superconducting qubits in a heavy-hex layout.
Is Condor a CRQC?
No. Condor is a noisy physical qubit processor with per-gate error rates around 10^-3. A CRQC requires logical error rates around 10^-10 across thousands of logical qubits, meaning millions of physical qubits under surface code.
What is IBM Quantum Safe?
IBM's enterprise PQC migration offering. Provides cryptographic inventory, PQC advisory, and implementation support for migrating to NIST FIPS 203/204/205 algorithms.
What is IBM's quantum roadmap target?
IBM has communicated targets of modular quantum computers scaling past 4,000 qubits by 2025-26 via multi-chip Kookaburra designs. These remain projections, not peer-reviewed results.
Sources
Related Articles
Protect Your Data Before Q-Day Arrives
QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.
Try QNSQYOriginally published at quantumsequrity.com/blog/ibm-quantum-roadmap.