Skip to content
DopeSwagYolo

Quantum Computing

When Will Quantum Computers Break Encryption?

No one knows. Estimates run from a few years to a few decades, and a survey published in March 2026 put the average odds within 10 years at 28% to 49%. Migration deadlines run from 2029 to 2035.

By DopeSwagYolo4 min read

Researched and fact-checked by AI, with no human review. 18 sources listed below. How we verify

No one knows, and credible estimates differ by decades. The open question is when a quantum computer will be able to break today's public-key encryption. The US National Institute of Standards and Technology (NIST) says expert estimates range from a few years to a few decades. As of early October 2026, no such machine has been publicly demonstrated. The schedule for replacing vulnerable encryption is firmer. The deadlines below run from 2029 to 2035.

What encryption could a quantum computer break?

The target is public-key cryptography, chiefly RSA and elliptic-curve schemes. These are used to set up secure connections and to create digital signatures. Their security rests on math problems, such as factoring very large numbers. Conventional computers cannot solve those problems in practical time. A large, reliable quantum computer could in theory. Such a machine is called a cryptographically relevant quantum computer, or CRQC.

In a "harvest now, decrypt later" attack, an adversary records encrypted data today and waits for a CRQC to unlock it. NIST cites that risk as a reason to adopt post-quantum encryption early.

How powerful would the quantum computer need to be?

Published estimates keep falling, though all are theoretical. For 2048-bit RSA, the figure dropped from about a billion physical qubits in 2012 to 20 million in 2019, according to a Google summary. Newer results cut further:

  • In May 2025, Google researcher Craig Gidney posted a preprint on factoring a 2048-bit RSA number. It estimates the job could be done in less than a week with fewer than one million noisy qubits. That assumes a gate error rate of 0.1%.
  • In March 2026, a team led by Google Quantum AI estimated what it would take to break 256-bit elliptic-curve cryptography. Google says most cryptocurrencies rely on that kind of cryptography. The team estimated it could be broken in minutes by a superconducting machine with fewer than 500,000 physical qubits.
  • Two other 2026 preprints assume different error-correcting codes or hardware and go lower. Sydney-based Iceberg Quantum puts 2048-bit RSA at fewer than 100,000 physical qubits. Researchers at Oratomic, Caltech and UC Berkeley give as few as 10,000 atomic qubits. The runtimes are days or longer.

Hardware remains far from those figures. Google's 2025 summary put quantum computers with relevant error rates at roughly 100 to 1,000 qubits. The Google team's elliptic-curve circuits call for just under 1,200 or 1,450 error-corrected "logical" qubits, depending on design. IBM's roadmap targets 200 logical qubits by 2029 and 2,000 in a later system.

Quantum hardware remains far from the qubit counts that published code-breaking estimates call for.

What do experts predict?

Forecasts are informed opinions, and they diverge. One gauge is an annual survey by the Global Risk Institute and evolutionQ. The 2025 edition was published in March 2026. It asked 26 specialists how likely a quantum computer is to factor a 2048-bit number in under 24 hours.

Averaged, they put the chance at 28% to 49% within 10 years and 51% to 70% within 15 years. The authors called that a notable acceleration from earlier surveys. The full report shows a divided panel. For the next five years, half rated the chance below 1%. For the next 10, half put it below 30% and half at about 50% or higher.

The report also describes a 2025 study issued by Germany's cybersecurity agency, the BSI. According to the report, the study conservatively estimated that a CRQC is likely within 15 years. The study said that could fall to about 10 years or less, the report says. NIST's quantum computing primer is more cautious. It says a machine able to run Shor's code-breaking algorithm may need millions of error-free qubits. It says such a machine is probably much further off than nearer-term noisy devices.

The report's summary adds that secret research could bring the threat closer than public results suggest. It also says a funding pullback could slow the field.

Expert odds of a code-breaking quantum computer
  • Within 10 years, low28%
  • Within 10 years, high49%
  • Within 15 years, low51%
  • Within 15 years, high70%

Each pair of bars is the low and high end of the averaged range the survey reports for that time span. Source: Quantum Threat Timeline Report 2025

What are the deadlines for post-quantum cryptography?

NIST finalized its first three post-quantum standards in August 2024. It called them ready for immediate use and encouraged administrators to start integrating them. The main deadlines:

  • 2029: Google said in March 2026 that it had set this year as its timeline for post-quantum migration. It cited progress in hardware, error correction and factoring estimates. It gave no date for a CRQC.
  • 2030 and 2031: An executive order signed in June 2026 gives US federal agencies two dates for high-value assets and high-impact systems. It directs agencies to move them to post-quantum key establishment by the end of 2030. It directs the move to post-quantum digital signatures by the end of 2031. National security systems are excluded.
  • 2035: A NIST plan was still in draft in early October 2026. Under it, RSA and elliptic-curve algorithms at the 112-bit security level would be deprecated after 2030. Both families would be disallowed after 2035. A 2022 White House memorandum set 2035 as a target for mitigating quantum risk. The UK's National Cyber Security Centre uses that year for completing migration.

NIST says fully adopting a new algorithm has historically taken 10 to 20 years. That is one reason the deadlines come before any confirmed threat.

The bottom line

The best available answer is a range of probabilities, not a date. The Global Risk Institute report offers a rule of thumb. By that rule, data is at risk if a CRQC arrives sooner than the time the data must stay secret plus the time needed to migrate.

Sources

  1. What Is Post-Quantum Cryptography?, National Institute of Standards and Technology (NIST)
  2. Quantum Computing Explained, National Institute of Standards and Technology (NIST)
  3. How to factor 2048 bit RSA integers with less than a million noisy qubits, arXiv (Craig Gidney, preprint)
  4. Tracking the Cost of Quantum Factoring, Google
  5. Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly, Google Research
  6. Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations, arXiv (Babbush et al., preprint)
  7. The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100 000 physical qubits using quantum LDPC codes, arXiv (Webster et al., Iceberg Quantum, preprint)
  8. Shor's algorithm is possible with as few as 10,000 reconfigurable atomic qubits, arXiv (Cain et al., preprint)
  9. IBM Sets the Course to Build World's First Large-Scale, Fault-Tolerant Quantum Computer at New IBM Quantum Data Center, IBM Newsroom
  10. Quantum Threat Timeline Report 2025, Global Risk Institute
  11. Quantum Threat Timeline Report 2025 (full report, PDF), Global Risk Institute and evolutionQ
  12. Executive Summary: Quantum Threat Timeline Report 2025 (PDF), Global Risk Institute and evolutionQ
  13. Quantum frontiers may be closer than they appear, Google
  14. NIST Releases First 3 Finalized Post-Quantum Encryption Standards, National Institute of Standards and Technology (NIST)
  15. Securing the Nation Against Advanced Cryptographic Attacks (Executive Order 14412), The White House
  16. NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards, NIST Computer Security Resource Center
  17. National Security Memorandum on Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems, The White House (archived)
  18. Timelines for migration to post-quantum cryptography, UK National Cyber Security Centre

More from Quantum Computing

See all in Quantum Computing