It isn’t the hardware that moved the deadline forward. It’s math.
For most of the last decade, “Q-Day” — the moment a quantum computer becomes powerful enough to break the encryption protecting the modern world — was a comfortably distant fixture on the horizon. Ask a cryptographer in 2019 how many qubits it would take to factor a 2048-bit RSA key, and the answer was around 20 million physical qubits: a number so large it effectively functioned as a permission slip to worry about something else first.
That permission slip has been quietly revoked. Not because a bigger quantum computer got built, but because the algorithms got smarter.
The Shrinking Number Nobody Budgeted For
In 2025, a widely discussed piece of research showed that the same RSA-2048 factoring job could, in principle, be done in about a week using well under a million physical qubits — roughly twenty times fewer than the 2019 estimate. Crucially, the improvement didn’t come from better hardware. Researchers used the same error rates and physical assumptions as before; they simply found a far more efficient way to run the algorithm on the hardware that logic already implied was coming.
Then, in early 2026, a research group proposed an alternative error-correction architecture — swapping the traditional “surface code” approach for a quantum low-density parity-check design. Under the conditions the team modeled, that approach suggested RSA-2048 might eventually fall to fewer than 100,000 physical qubits. For elliptic curve cryptography, the algorithm underpinning most digital signatures and a large share of blockchain security, separate estimates from Google researchers have put the number below 500,000 qubits.
None of this means a cryptographically relevant quantum computer exists today. It doesn’t. But the distance between what exists and what would be needed has collapsed by more than an order of magnitude in under two years — and distance, not existence, is what risk models are built on.
A Chip, a Blog Post, and a Roadmap: Three Signals From the Same Season
The theoretical shift hasn’t stayed in academic papers. Three developments from the past several months illustrate how fast the ground is moving underneath enterprise security teams:
Verifiable advantage, demonstrated. Google’s Willow chip ran a benchmark algorithm thousands of times faster than the best classical supercomputer could manage on the same problem — the kind of milestone the field has pointed to for years as proof that the trajectory is real, not promotional.
The industry’s own alarm. In a public call to action, Google’s leadership in global affairs and quantum research argued that the encryption protecting today’s financial transactions and private communications could realistically be broken by a large-scale quantum computer within years, not decades — and warned that adversaries are unlikely to wait for that machine to exist before they start harvesting data to decrypt later.
Governments moving in lockstep. In January 2026, the G7 Cyber Expert Group adopted a coordinated roadmap for the transition to post-quantum cryptography — a signal that this is no longer a national initiative but an allied one. NIST’s own guidance now points toward phasing out quantum-vulnerable algorithms after 2030 and disallowing them entirely by 2035, while the NSA’s Commercial National Security Algorithm Suite 2.0 requires new national security systems to be quantum-safe by January 2027 — three years sooner than NIST’s broader civilian timeline.
The Gap Between “Aware” and “Ready”
Here is where the story turns uncomfortable. A recent industry survey found that while roughly half of organizations are actively investigating their quantum exposure, fewer than a third have started implementing quantum-resistant solutions. Awareness has outpaced action, and the reason is structural, not a lack of will: locating every place an organization uses vulnerable cryptography — buried in legacy systems, third-party software, embedded devices, and vendor contracts — can take months by itself, before a single line of code is rewritten.
That process doesn’t compress well. Testing, validation, and staged rollout across a large enterprise realistically add years to a migration, regardless of how urgent the threat becomes. Which means the organizations best positioned for whatever year Q-Day actually lands on are the ones who treated cryptographic inventory as a 2026 project — not a 2029 one.
What “Harvest Now, Decrypt Later” Actually Costs
The math above isn’t abstract for anyone whose data has a shelf life longer than a few years. Trade secrets, government records, M&A plans, health data, long-term financial structures — anything that still needs to be confidential five or ten years from now is, by definition, already exposed to an adversary patient enough to store it today and wait.
That reframes the planning question CISOs need to be asking their boards. It’s no longer “when will quantum computers be able to break our encryption” — a question nobody can answer with precision. It’s “which of our current data assets would still hurt us if they were decrypted in 2030, 2032, or 2035” — a question every organization can answer today, and one that should determine what gets migrated first.
The Bottom Line
Q-Day has never been a single event. It’s a moving estimate that has spent the last two years moving almost exclusively in one direction: closer. The qubit counts keep shrinking, the government mandates keep tightening, and the algorithmic breakthroughs keep arriving from directions few forecasters priced in.
The organizations that treat post-quantum migration as a scheduling problem — something to slot in once the timeline is finally certain — are optimizing for a certainty that quantum research keeps proving doesn’t exist. The ones that treat it as a standing discipline, starting with the data that matters most, are the ones who won’t be caught re-reading their risk models when the estimate shrinks again.
It will.
Three Questions Worth Asking at Your Next Board Meeting
For CISOs, the shrinking qubit estimate isn’t a talking point — it’s a reason to revisit three things that may currently be sitting on autopilot:
Where is your cryptographic inventory, really? Not the one from the last audit cycle — the current one. If you can’t say with confidence which systems, vendors, and data stores still rely on RSA or ECC, that gap is now the single biggest variable in your migration timeline, and it’s the one most within your control to close first.
Which assets have you explicitly prioritized for early migration? Not everything needs to move first. Data with a long confidentiality shelf life — IP, M&A material, health records, classified or regulated communications — is the data already being harvested today. A prioritized list, reviewed and owned at the board level, is worth more than an enterprise-wide roadmap with no sequencing.
Does your vendor and procurement language already require PQC readiness? Migration isn’t only an internal engineering problem. Every third-party system, cloud service, and embedded device you don’t control still needs to get quantum-safe on someone’s timeline. Contract language and procurement standards are the lever CISOs have over infrastructure they don’t own outright — and it’s cheaper to write that requirement in now than to renegotiate it later under deadline pressure.
None of these require knowing the exact year Q-Day arrives. They require treating the uncertainty itself as the risk to manage — which is a posture a security organization can adopt this quarter, not five years from now.