up:: For Press

A timeline of the quantum transition

Dated events rather than projections. Each entry says what actually happened and what it established, because several of these are routinely described as bigger or smaller than they were.

The pattern worth noticing: the mathematics has been settled for over 30 years, the replacement has existed since 2024, and the deployment started before most people had heard of the problem.

The short version:

  • 1994 the attack was published. Nothing about it has been contested since.
  • 2023 to 2025 the fix quietly shipped into phones and browsers.
  • August 2024 the replacement standards were finalized, which ended “we’re waiting for standards.”
  • 2030 and 2035 are the retirement dates already on the calendar.
  • The only thing that hasn’t happened is a machine capable of running the 1994 attack.

What has already happened?

WhenWhat happenedWhat it established
1994Peter Shor publishes his algorithmA quantum computer could break RSA and elliptic-curve cryptography. Public, checked, uncontested for 30+ years.
2016NIST announces a public competition for replacementsThe response would be open and international rather than proprietary
2019Gidney and Ekerå estimate 20 million noisy qubits, 8 hours, to break RSA-2048The first widely cited resource estimate
2022NSA publishes CNSA 2.0National-security systems get their own timeline
Dec 2022Quantum Computing Cybersecurity Preparedness Act signed (PL 117-260)Congress requires federal agencies to inventory and migrate
2023Signal deploys PQXDHThe first major consumer messaging platform to ship post-quantum protection
Aug 2023CISA, NSA, and NIST publish joint quantum-readiness guidance3 federal agencies name harvest-now-decrypt-later a present-day concern
Oct 202314,000 reused passwords at 23andMe expose 6.9 million peopleGenetic data escapes at scale, without the company being breached
Feb 2024Apple ships PQ3 in iMessageHundreds of millions of devices upgraded, with no public announcement to users
Jul 2024OMB reports $7.1 billion to migrate federal civilian systemsThe first authoritative cost figure
Aug 13, 2024NIST publishes FIPS 203, 204, and 205The replacement encryption is finished. “Waiting for standards” stops being accurate.
Nov 2024Chrome and Edge enable post-quantum key exchange by defaultThe web’s default connection changes
Nov 2024NIST IR 8547 draft publishedThe retirement schedule appears: deprecated 2030, disallowed 2035
Feb 2025Firefox ships post-quantum key exchangeBrowser coverage effectively complete
Mar 2025NIST selects HQC as a fifth algorithmA non-lattice backup, in case the lattice family has a flaw
Mar 21, 2025California AG issues an urgent 23andMe consumer alertRegulators treat genetic data as at risk from a corporate failure
Mar 23, 202523andMe files for Chapter 11Genetic data from millions becomes a saleable asset
Jun 2026White House issues OMB M-26-15Federal civilian agencies directed to execute the migration

Vertical timeline of when post-quantum encryption actually shipped, from Cloudflare in October 2022 through Signal, Apple, Chrome and Firefox, with the NIST standards finalized on 13 August 2024 marked as the point where the algorithm changed.

Source: NIST, Apple, Google and Mozilla announcements, plus Signal, Microsoft and Cloudflare.

Two things in that chart get lost in most coverage. Deployments before 13 August 2024 ran on a draft algorithm that the finished standards can’t talk to, so Chrome had to swap rather than add. And every one of these protects how a key is agreed, which means the certificates proving a website’s identity are still protected by the old mathematics.

What is still ahead?

WhenWhat happens
April 2026 onwardCanada requires departmental migration plans and annual reporting
End of 2030Australia requires RSA, Diffie-Hellman, ECDH, and ECDSA to cease being used entirely
After 2030US: today’s public-key cryptography is deprecated, meaning permitted with risk formally accepted
End of 2031Canada requires high-priority government systems migrated
After 2035US: today’s public-key cryptography is disallowed
End of 2035Canada requires remaining systems migrated
UnknownA machine capable of running Shor’s algorithm against real keys

That last row is the only genuinely undated entry, and every other line on this page arrives regardless of it.

What do the dates actually tell you?

The attack is old news. Shor published in 1994. Nobody has disputed that the method works. Anyone framing the mathematics as speculative is 30 years behind.

The response was deliberate rather than panicked. NIST ran an open international competition for 8 years before finalizing anything. That’s the opposite of a rushed reaction, and it’s why the standards have broad international adoption.

The fix arrived before the alarm. Signal shipped in 2023 and Apple in early 2024, both before NIST had finalized anything and years before most people heard of the problem. Companies with the most to lose moved first, voluntarily.

August 2024 is the date that changes arguments. Before it, “we’re waiting for the standards to be finalized” was a legitimate position. After it, that sentence is checkably wrong, and it remains one of the most common things organizations say.

The 2019-to-2025 gap is the trend to watch. The estimated machine required fell roughly 20-fold in 6 years, driven by better methods rather than better hardware. A plan built on the 2019 figure is now 20 times closer to its deadline than it looked.

Sources

Shor’s algorithm: arxiv.org. Resource estimates: Gidney and Ekerå 2019, Gidney 2025. Standards: NIST, August 13, 2024 and HQC, March 2025. Retirement schedule: NIST IR 8547. Federal guidance: CISA/NSA/NIST joint factsheet and OMB Report on PQC, July 2024. Consumer deployments: Signal messenger, Apple, Google, Mozilla. 23andMe: California Attorney General. Australia: Australian Signals Directorate. Canada: Canadian Centre for Cyber Security.

Questions people ask

Which single date matters most? August 13, 2024. Before it, waiting for the standards was defensible. After it, that position is checkably wrong.

Why did companies move before any requirement existed? Because harvested traffic is exposed retroactively, so waiting means every message sent in the interim is already lost. Signal and Apple both concluded that math resolved in favor of acting early.

Is the 2030 date or the 2035 date the real deadline? Both are real and they mean different things. 2030 deprecates, meaning use is permitted with the risk formally accepted. 2035 disallows.

Why does Australia’s date come first? Its signals directorate decided the international consensus left too little margin, so it requires the old cryptography gone by the end of 2030. It’ll be the first national deadline anyone actually reaches.

What happens if the machine never arrives? Every dated row on this page still happens. The deadlines are regulatory rather than contingent on the hardware.

Where to go next

Go deeper into the technical detail

The technical version, with the full expert-survey distribution behind these dates, is Quantum Threat Timeline.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.