← Back to Blog

When Will Quantum Computers Break Encryption?

When Will Quantum Computers Break Encryption? - QNSQY post-quantum encryption guide

The Million-Qubit Question

It is the most consequential question in cybersecurity today: when will a quantum computer be powerful enough to break RSA-2048, the encryption that protects most of the internet? The honest answer is that nobody knows with certainty. But by examining the current state of quantum hardware, the theoretical requirements for breaking encryption, and expert survey data, we can build a fact-based picture of the timeline and, more importantly, understand why the exact date matters less than most people assume.

The Current State of Quantum Computing

Quantum computing has made significant progress in recent years, but the technology remains far from the scale needed to threaten current encryption. Here is where the leading efforts stand.

IBM

IBM has been one of the most transparent quantum hardware companies in publishing roadmaps. In December 2023, IBM announced the Condor processor with 1,121 superconducting qubits, making it the first quantum processor to exceed 1,000 qubits. However, qubit count alone does not determine computational power; error rates and connectivity matter just as much. IBM's public development roadmap targets systems with 100,000 or more qubits by 2033, using modular architectures that connect multiple quantum processors.

Google

In October 2019, Google published a paper in Nature claiming "quantum supremacy" with its Sycamore processor, a 53-qubit device that performed a specific sampling task in approximately 200 seconds that Google estimated would take a classical supercomputer roughly 10,000 years. This claim was disputed; IBM argued that with sufficient classical resources, the task could be completed in days rather than millennia. Regardless of the exact speedup, the result demonstrated genuine quantum computational capability. In late 2024, Google announced the Willow processor, focusing on improved error correction rather than raw qubit count.

Other Efforts

Quantinuum (formed from the merger of Honeywell Quantum Solutions and Cambridge Quantum) pursues trapped-ion quantum computing, which offers higher qubit fidelity than superconducting approaches but has been harder to scale in qubit count. IonQ, another trapped-ion company, is publicly traded and has been deploying cloud-accessible quantum systems. PsiQuantum is pursuing photonic quantum computing with the goal of building a fault-tolerant system with one million qubits, though production timelines remain uncertain. Numerous other companies and research labs worldwide are contributing to the field.

Where Things Stand

As of early 2026, the largest quantum processors have crossed 1,000 physical qubits. Error rates have improved but remain orders of magnitude too high for the sustained, error-free computation needed to break encryption. No existing quantum computer can factor numbers large enough to threaten any widely deployed cryptographic system.

What Would It Take to Break RSA-2048?

Peter Shor published his famous algorithm in 1994, demonstrating that a quantum computer could factor large integers (and compute discrete logarithms) exponentially faster than any known classical algorithm. This directly threatens RSA, Diffie-Hellman, and elliptic curve cryptography. But running Shor's algorithm at the scale needed to break RSA-2048 requires a quantum computer far beyond anything that exists today.

The most detailed resource estimate comes from Craig Gidney and Martin Ekera, who published "How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits" in the journal Quantum in 2021. Their analysis shows that factoring a 2048-bit RSA key would require approximately 20 million noisy (non-error-corrected) qubits running for about 8 hours. Alternatively, with more advanced error correction, the computation could be performed with fewer physical qubits but would require each one to be significantly more reliable.

The key concept here is the distinction between physical qubits and logical qubits. A logical qubit is an error-corrected qubit that behaves reliably. Building one logical qubit requires many physical qubits working together to detect and correct errors. The ratio depends on the error rate of the physical qubits and the error-correction code used. Current estimates suggest that roughly 1,000 to 10,000 physical qubits are needed per logical qubit, depending on the hardware quality.

To factor RSA-2048, an estimated 4,099 logical qubits are needed (per Gidney and Ekera, 2021). At 1,000 to 10,000 physical qubits per logical qubit, the total physical qubit requirement falls in the range of 4 million to 40 million. Current systems have roughly 1,000 physical qubits with error rates that would push the ratio toward the higher end of that range.

The Gap in Numbers
Current quantum computers: approximately 1,000 physical qubits with high error rates.
Required to break RSA-2048: millions of high-quality physical qubits.
This represents a gap of roughly three to four orders of magnitude in both count and quality.

Expert Timeline Estimates

Since no one can predict the pace of engineering breakthroughs with certainty, expert surveys provide the best available estimate of when a cryptographically relevant quantum computer (CRQC) might arrive.

The Global Risk Institute (GRI) publishes an annual "Quantum Threat Timeline" report surveying leading quantum computing researchers and cryptographers. The survey asks respondents to estimate the probability that a CRQC capable of breaking RSA-2048 will exist within various timeframes. In recent reports, roughly 50% of surveyed experts estimated that a CRQC is likely to exist within the 2035 to 2040 timeframe. A smaller but notable fraction placed the estimate earlier, while some placed it later or expressed uncertainty that it would happen at all within a foreseeable horizon.

These estimates span a wide range because the path to a CRQC depends on solving multiple hard engineering challenges simultaneously: scaling qubit count, reducing error rates, improving qubit connectivity, developing practical error-correction codes, and building the classical control systems to manage it all. Progress on any one front does not guarantee progress on the others.

The important takeaway is not a specific year. It is that credible experts place the threat within a timeframe that overlaps with the useful lifetime of data being encrypted today.

Mosca's Theorem: Why the Exact Date May Not Matter

Michele Mosca, a professor at the University of Waterloo and co-founder of the Institute for Quantum Computing, formulated a simple but powerful framework for thinking about quantum risk. It is commonly known as Mosca's theorem, and it states:

If X is the number of years your data must remain secure, and Y is the number of years it will take to deploy post-quantum cryptography across your systems, and Z is the number of years until a CRQC exists, then you are at risk if X + Y > Z.

In plain terms: if the time your data needs to stay secret, plus the time it takes to migrate, is greater than the time until quantum computers can break your encryption, you are already too late.

Consider a concrete example. Suppose your organization handles medical records that must remain confidential for 25 years (X = 25). Suppose your PQC migration will take 5 years from start to completion (Y = 5). Then you need to have started migrating before Z = 30 years from now. If a CRQC arrives in 2045, you needed to start by 2015. If it arrives in 2055, you needed to start by 2025. The earlier the CRQC arrives, the further behind you already are.

For many organizations, X + Y already exceeds even the most optimistic estimates for Z. The migration window is not approaching. For long-lived data, it may already be closing.

The "Harvest Now, Decrypt Later" Reality

The most commonly overlooked dimension of the quantum threat is that attackers do not need a quantum computer today to benefit from one tomorrow. The strategy is simple: intercept and store encrypted communications now, then decrypt them when quantum computers become available.

This is not theoretical. Intelligence agencies have the storage capacity, network access, and institutional patience to execute this strategy. Data intercepted from undersea cables, satellite links, and internet exchange points can be archived for decades. When a CRQC becomes available, any RSA or ECC-encrypted data in those archives becomes readable.

This means the effective threat timeline is not "when will a CRQC exist" but rather "when was the data I need to protect intercepted, and will a CRQC exist before the data loses its sensitivity?" For data intercepted today that must remain confidential for 15 or more years, the quantum threat is not a future problem. It is a present one.

Which Data Is Most at Risk?
Data that is both transmitted over networks (making it interceptable) and must remain confidential for a long period is at the highest risk from "harvest now, decrypt later." This includes: medical and health records, financial records and transactions, government classified information, trade secrets and intellectual property, legal communications, and long-term personal data.

What Should Organizations Do Now?

Given the uncertainty in the timeline but the certainty of the eventual threat, the responsible course of action is clear:

1. Do Not Wait for a Specific Date

Waiting for confirmation that a CRQC exists is equivalent to waiting until your locks are already picked before changing them. By then, any data previously encrypted with classical-only cryptography and intercepted in transit is already compromised. The time to act is before the threat materializes, not after.

2. Inventory Your Cryptographic Exposure

Identify every system in your organization that relies on RSA, ECC, Diffie-Hellman, or other quantum-vulnerable algorithms. Understand what data each system protects and how long that data must remain confidential. This is the essential first step recommended by both NIST (SP 1800-38) and CISA.

3. Begin Hybrid Deployment

Deploy hybrid encryption that combines classical and post-quantum algorithms. This provides protection against quantum computers while maintaining the proven security of classical cryptography. NIST, the NSA (CNSA 2.0), and ETSI all recommend the hybrid approach as the safest migration path.

4. Prioritize by Data Lifetime

Systems protecting data with the longest required confidentiality periods should be migrated first. A database of patient records that must remain confidential for 50 years is a higher priority than a session token that expires in 30 minutes.

5. Build Crypto Agility

Design systems so that cryptographic algorithms can be updated without a complete system redesign. The quantum threat is the most immediate driver for this, but crypto agility is valuable against any future cryptographic advance or vulnerability.

6. Start with File-Level Encryption

Migrating entire network infrastructure to post-quantum protocols takes years. But encrypting individual files with hybrid PQC can begin today with no infrastructure changes. This provides immediate protection for your most sensitive archives, backups, and documents while the broader migration proceeds.

The Bottom Line

No one can predict the exact year a quantum computer will break RSA-2048. Expert estimates center on the 2030s and 2040s, but with wide uncertainty bands. Breakthroughs could accelerate the timeline; engineering challenges could delay it.

What we know with certainty:

  • Shor's algorithm is mathematically proven to break RSA, ECC, and Diffie-Hellman given a sufficiently large quantum computer.
  • Current quantum hardware is orders of magnitude away from that capability, but the field is advancing steadily.
  • Data intercepted today can be decrypted retroactively once a CRQC exists.
  • NIST-standardized post-quantum algorithms (FIPS 203, 204, 205) are available now.
  • Hybrid deployment provides protection against both classical and quantum attacks with no downside.

The question is not whether quantum computers will eventually break today's encryption. It is whether your organization will have migrated before that happens. For data with long confidentiality requirements, the time to begin is now.

To learn more about the algorithms that will protect your data in the post-quantum era, see our guides on post-quantum cryptography, ML-KEM, and the Harvest Now, Decrypt Later threat.

Sources

Related Articles

Protect Your Data Before the Quantum Threat Arrives

QNSQY uses NIST-standardized hybrid post-quantum encryption to keep your data safe today and in the quantum future.

Try QNSQY

Originally published at quantumsequrity.com/blog/quantum-computing-encryption-timeline.