Quantum Supremacy vs Cryptographically Relevant Quantum (CRQC): The Difference That Matters for Quantum Safe Encryption

The Headline That Confuses Everyone
Nearly every year since 2019 a major tech company or national lab has announced a quantum supremacy or quantum advantage milestone. Google Sycamore in October 2019. Jiuzhang in December 2020. Zuchongzhi 2.1 in 2021. Google Willow in December 2024 at 105 qubits with below-threshold error correction. Zuchongzhi 3.0 in March 2025 at 105 qubits. Each announcement triggers a wave of articles asking "Is RSA broken yet?" The answer, every single time, has been no. Understanding why is the difference between a contrived benchmark and a Cryptographically Relevant Quantum Computer.
What Quantum Supremacy Actually Means
Quantum supremacy (sometimes called quantum advantage) is the claim that a quantum computer has performed some computation that is beyond the practical reach of a classical computer. The defining papers so far have all used Random Circuit Sampling (RCS) or Gaussian boson sampling, both of which are contrived problems designed to be easy for the quantum hardware and hard for classical simulation.
These benchmarks are scientifically important. They prove that quantum hardware can exist in genuinely entangled states that classical computers struggle to simulate. They are not useful for anything most people care about, including cryptanalysis.
What a Cryptographically Relevant Quantum Computer Looks Like
A Cryptographically Relevant Quantum Computer, or CRQC, is one capable of running Shor's algorithm on real-world cryptographic parameters, such as a 2048-bit RSA modulus or a P-256 elliptic curve private key. The difference from supremacy hardware is staggering.
A CRQC needs:
- Thousands of logical qubits (not physical), each continuously error-corrected.
- Long coherence times across hours of computation, not microseconds.
- Billions of fault-tolerant gates, each below the error-correction threshold.
- Scalable interconnect between qubit modules.
Estimates for breaking RSA-2048 with Shor's algorithm vary, but a widely cited 2021 paper by Gidney and Ekera puts it at roughly 20 million noisy physical qubits for an 8-hour attack. Google Willow's 105 physical qubits and IBM Condor's 1,121 physical qubits do not change this equation.
Why the Gap Is Huge (Not Just Big)
Quantum error correction is the bridge between noisy physical qubits and reliable logical qubits. The current state of the art uses surface codes, which require roughly 1,000 physical qubits to build a single logical qubit of useful quality. Google Willow's big announcement was not the 105 qubit count itself; it was the demonstration that scaling from a 3x3 to a 5x5 to a 7x7 surface code reduced the error rate at each step. This is the "below threshold" claim, and it is a necessary milestone. It is not remotely sufficient.
The Seven-Year Survey
The Global Risk Institute has published an annual expert survey on the quantum threat timeline since 2019. The 2025 report, based on responses from dozens of quantum computing and cryptography experts worldwide, reports a 10-year likelihood of a CRQC emerging between 28 percent (pessimistic) and 49 percent (optimistic). This is the highest 10-year range in the survey's history, reflecting the Willow and Zuchongzhi announcements. It also reflects uncertainty: a majority of experts still place most of the probability mass beyond 10 years.
Why This Matters for Your PQC Decision
Two practical consequences follow from the distinction:
- Do not panic at every headline. Willow, Condor, Zuchongzhi 3.0, and their successors will keep improving, but a journal announcement of 200 or 500 qubits does not change when RSA breaks.
- Do not relax either. The right calculation is Mosca's theorem: if your data must stay confidential for X years, migration takes Y years, and a CRQC arrives in Z years, then X + Y > Z means you should have started already. For data with 10+ year sensitivity, that's almost every industry, you are already inside the migration window.
Concrete Signposts to Watch
Instead of watching qubit-count press releases, watch for these specific CRQC milestones:
- First demonstration of a logical qubit with error rate below 10^-6. (Willow's 7x7 surface code gets close but not there.)
- First magic state factory capable of supporting fault-tolerant T gates at scale.
- First verified execution of Shor's algorithm on a 30+ bit integer. (Current demos are limited to tiny numbers, with the 2022 Bao Yan paper's claim that 372 qubits could factor RSA-2048 widely disputed by Scott Aaronson and Bruce Schneier.)
- NIST, NSA, or equivalent statement that CRQC is inside a specific decade window. (NSA CNSA 2.0 currently says 2035 for all National Security Systems, which is a policy deadline, not a CRQC prediction.)
Frequently Asked Questions
What is the difference between quantum supremacy and CRQC?
Quantum supremacy is a demonstration that a quantum computer has solved some problem faster than any classical computer, using problems chosen to be easy for the quantum hardware. CRQC is a quantum computer capable of breaking real-world cryptography by running Shor's algorithm on actual RSA or elliptic curve parameters. All current quantum supremacy demonstrations use contrived benchmarks like random circuit sampling and cannot run Shor on real keys.
Is Google Willow a CRQC?
No. Willow has 105 physical qubits and demonstrated below-threshold error correction, a scientific milestone. Breaking RSA-2048 would require on the order of 20 million noisy physical qubits per Gidney and Ekera's 2021 estimate. Willow is roughly five orders of magnitude away from that scale.
When will a CRQC actually exist?
Nobody knows. The Global Risk Institute's 2025 expert survey puts 10-year likelihood between 28 percent and 49 percent. NSA CNSA 2.0 uses 2035 as its planning deadline, but that is policy, not a scientific prediction. The honest answer is that CRQC may arrive in 10 years, 20 years, or 40 years, and the cost of waiting is irreversible.
Why does it matter if CRQC is 30 years away?
Because of harvest now, decrypt later. Adversaries collect encrypted data today, store it cheaply, and decrypt once CRQC exists. If your data needs to remain secret for 30 years, and CRQC arrives in 30 years, your traffic today is already in the attacker's archive. Migration today, not later, is the only defense.
Sources
- Gidney & Ekera (2021). How to factor 2048-bit RSA
- Google Willow announcement (Dec 2024)
- Zuchongzhi 3.0 (PRL 134, 090601)
- Global Risk Institute Quantum Threat Timeline 2025
- NSA CNSA 2.0 FAQ
Related Articles
- CRQC Explained
- Google Willow: 105 Qubits Below Threshold
- Logical Qubits vs Physical Qubits
- Quantum Error Correction and PQC
- Shor's Algorithm Explained
Protect Your Data Before Q-Day Arrives
QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.
Try QNSQYOriginally published at quantumsequrity.com/blog/quantum-supremacy-vs-cryptographic-relevance.