Quantum risk · Executive briefing

Migrate before the machine arrives

No quantum computer can break deployed public-key cryptography today. That is not a reason to wait: sensitive data can be collected now, migrations take years, and attack-cost estimates continue to move.

Evidence reviewed 2026-09-06
Decision signal

Do not use “no demonstrated break” as a migration deadline.

Plan against the lifetime of your sensitive data and the time required to replace exposed RSA and ECC—not against a speculative Q-day forecast.

Demonstrated break
None

RSA-2048 / P-256

RSA estimate
<1M

noisy qubits · 2025 preprint

Earlier estimate
≈20M

noisy qubits · 2021

Vendor target
2029

200 logical qubits

Capability gap

Progress is real. A cryptographic break is not yet demonstrated.

The comparison below uses logical-qubit counts only. It does not claim that qubit count alone measures attack capability.

Published demonstrationVendor target—not observedAttack estimate

Logarithmic scale. Logical-qubit definitions, error rates, code performance and executable circuit depth differ. Threshold lines are research estimates, not forecasts or engineering specifications.

Cryptographic exposure

What changes—and what your program should do

Public-key and symmetric cryptography face different quantum effects. Treating them as one problem creates the wrong priorities.

RSA-2048

B
Public key · Shor
Quantum effect

Private-key recovery; complete break if the circuit succeeds.

Resource estimate

≈3,000 algorithmic logical qubits

≈20 million noisy qubits

Migration postureReplace RSA / ECCSource · 2021-04-15

RSA-2048 · revised estimate

B
Public key · Shor
Quantum effect

Same complete break, with a substantially reduced theoretical hardware estimate.

Resource estimate

Not separately headlined

<1 million noisy qubits

Migration postureReplace RSA / ECCSource · 2025-05-21

ECC P-256

B
Public key · Shor
Quantum effect

Private-key recovery from a public key; complete break if the circuit succeeds.

Resource estimate

≈2,330 logical qubits

Not estimated in the cited paper

Migration postureReplace RSA / ECCSource · 2017-06-21

AES-128

B
Symmetric · Grover
Quantum effect

Quadratic search speedup; effective security is approximately 64 bits, not an automatic break.

Resource estimate

≈2,953 circuit width

Not estimated in the cited paper

Migration postureRetain strong key sizesSource · 2016-01-25

AES-256

B
Symmetric · Grover
Quantum effect

Quadratic search speedup; effective security remains approximately 128 bits.

Resource estimate

≈6,681 circuit width

Not estimated in the cited paper

Migration postureRetain strong key sizesSource · 2016-01-25

Estimates preserve each source’s units and assumptions. They are not directly comparable and should not be converted into a date prediction.

Milestone timeline

From physical scale to fault-tolerance roadmaps

Observed experiments and future company targets are separated, so the sequence does not imply a smooth march toward cryptanalysis.

  1. 2019-10-23Observed hardware

    Google Quantum AI · Sycamore

    53 physical qubits used for random-circuit sampling

    A programmable superconducting processor completed a specialized sampling experiment beyond the reported classical baseline.

    Why it matters: Random-circuit sampling is not a cryptographic attack and the device did not use fault-tolerant logical qubits.

    Primary source
  2. 2023-10-24Observed hardware

    Atom Computing · Neutral-atom array

    1,180 atoms populated in a 1,225-site array

    The company reported the first neutral-atom system to exceed 1,000 populated qubit sites.

    Why it matters: Array size does not establish circuit depth, error correction, or the ability to execute Shor's algorithm.

    Primary source
  3. 2023-12-04Observed hardware

    IBM · Condor

    1,121-qubit superconducting processor

    IBM presented Condor as a scale milestone while emphasizing lower-error Heron processors for useful circuits.

    Why it matters: These are noisy physical qubits, not an error-corrected logical-qubit register suitable for cryptanalysis.

    Primary source
  4. 2024-04-03Error correction

    Quantinuum / Microsoft · H-Series logical qubits

    4 logical qubits; reported logical error rate 800× below physical error rate

    A trapped-ion processor and qubit-virtualization system demonstrated repeated error correction on four logical qubits.

    Why it matters: Four logical qubits are a proof of error suppression, not a cryptanalytic computer, and logical-qubit definitions vary by code and task.

    Primary source
  5. 2024-12-09Error correction

    Google Quantum AI · Willow

    Below-threshold surface-code scaling through code distance 7

    Increasing surface-code size suppressed logical errors, demonstrating the scaling behavior required for fault tolerance.

    Why it matters: The experiment studied a logical memory, not thousands of logical qubits executing a cryptographic algorithm.

    Primary source
  6. 2029 targetRoadmap target

    IBM · Starling target

    Roadmap target: 200 logical qubits and 100 million gates in 2029

    IBM published a modular fault-tolerant architecture and a target for its Starling system.

    Why it matters: This is a vendor target, not observed capability; IBM states roadmap goals may change or be withdrawn.

    Primary source