up:: For Press
A timeline of the quantum transition
Dated events rather than projections. Each entry says what actually happened and what it established, because several of these are routinely described as bigger or smaller than they were.
The pattern worth noticing: the mathematics has been settled for over 30 years, the replacement has existed since 2024, and the deployment started before most people had heard of the problem.
The short version:
- 1994 the attack was published. Nothing about it has been contested since.
- 2023 to 2025 the fix quietly shipped into phones and browsers.
- August 2024 the replacement standards were finalized, which ended “we’re waiting for standards.”
- 2030 and 2035 are the retirement dates already on the calendar.
- The only thing that hasn’t happened is a machine capable of running the 1994 attack.
What has already happened?
| When | What happened | What it established |
|---|---|---|
| 1994 | Peter Shor publishes his algorithm | A quantum computer could break RSA and elliptic-curve cryptography. Public, checked, uncontested for 30+ years. |
| 2016 | NIST announces a public competition for replacements | The response would be open and international rather than proprietary |
| 2019 | Gidney and Ekerå estimate 20 million noisy qubits, 8 hours, to break RSA-2048 | The first widely cited resource estimate |
| 2022 | NSA publishes CNSA 2.0 | National-security systems get their own timeline |
| Dec 2022 | Quantum Computing Cybersecurity Preparedness Act signed (PL 117-260) | Congress requires federal agencies to inventory and migrate |
| 2023 | Signal deploys PQXDH | The first major consumer messaging platform to ship post-quantum protection |
| Aug 2023 | CISA, NSA, and NIST publish joint quantum-readiness guidance | 3 federal agencies name harvest-now-decrypt-later a present-day concern |
| Oct 2023 | 14,000 reused passwords at 23andMe expose 6.9 million people | Genetic data escapes at scale, without the company being breached |
| Feb 2024 | Apple ships PQ3 in iMessage | Hundreds of millions of devices upgraded, with no public announcement to users |
| Jul 2024 | OMB reports $7.1 billion to migrate federal civilian systems | The first authoritative cost figure |
| Aug 13, 2024 | NIST publishes FIPS 203, 204, and 205 | The replacement encryption is finished. “Waiting for standards” stops being accurate. |
| Nov 2024 | Chrome and Edge enable post-quantum key exchange by default | The web’s default connection changes |
| Nov 2024 | NIST IR 8547 draft published | The retirement schedule appears: deprecated 2030, disallowed 2035 |
| Feb 2025 | Firefox ships post-quantum key exchange | Browser coverage effectively complete |
| Mar 2025 | NIST selects HQC as a fifth algorithm | A non-lattice backup, in case the lattice family has a flaw |
| Mar 21, 2025 | California AG issues an urgent 23andMe consumer alert | Regulators treat genetic data as at risk from a corporate failure |
| Mar 23, 2025 | 23andMe files for Chapter 11 | Genetic data from millions becomes a saleable asset |
| Jun 2026 | White House issues OMB M-26-15 | Federal civilian agencies directed to execute the migration |

Source: NIST, Apple, Google and Mozilla announcements, plus Signal, Microsoft and Cloudflare.
Two things in that chart get lost in most coverage. Deployments before 13 August 2024 ran on a draft algorithm that the finished standards can’t talk to, so Chrome had to swap rather than add. And every one of these protects how a key is agreed, which means the certificates proving a website’s identity are still protected by the old mathematics.
What is still ahead?
| When | What happens |
|---|---|
| April 2026 onward | Canada requires departmental migration plans and annual reporting |
| End of 2030 | Australia requires RSA, Diffie-Hellman, ECDH, and ECDSA to cease being used entirely |
| After 2030 | US: today’s public-key cryptography is deprecated, meaning permitted with risk formally accepted |
| End of 2031 | Canada requires high-priority government systems migrated |
| After 2035 | US: today’s public-key cryptography is disallowed |
| End of 2035 | Canada requires remaining systems migrated |
| Unknown | A machine capable of running Shor’s algorithm against real keys |
That last row is the only genuinely undated entry, and every other line on this page arrives regardless of it.
What do the dates actually tell you?
The attack is old news. Shor published in 1994. Nobody has disputed that the method works. Anyone framing the mathematics as speculative is 30 years behind.
The response was deliberate rather than panicked. NIST ran an open international competition for 8 years before finalizing anything. That’s the opposite of a rushed reaction, and it’s why the standards have broad international adoption.
The fix arrived before the alarm. Signal shipped in 2023 and Apple in early 2024, both before NIST had finalized anything and years before most people heard of the problem. Companies with the most to lose moved first, voluntarily.
August 2024 is the date that changes arguments. Before it, “we’re waiting for the standards to be finalized” was a legitimate position. After it, that sentence is checkably wrong, and it remains one of the most common things organizations say.
The 2019-to-2025 gap is the trend to watch. The estimated machine required fell roughly 20-fold in 6 years, driven by better methods rather than better hardware. A plan built on the 2019 figure is now 20 times closer to its deadline than it looked.
Sources
Shor’s algorithm: arxiv.org. Resource estimates: Gidney and Ekerå 2019, Gidney 2025. Standards: NIST, August 13, 2024 and HQC, March 2025. Retirement schedule: NIST IR 8547. Federal guidance: CISA/NSA/NIST joint factsheet and OMB Report on PQC, July 2024. Consumer deployments: Signal messenger, Apple, Google, Mozilla. 23andMe: California Attorney General. Australia: Australian Signals Directorate. Canada: Canadian Centre for Cyber Security.
Questions people ask
Which single date matters most? August 13, 2024. Before it, waiting for the standards was defensible. After it, that position is checkably wrong.
Why did companies move before any requirement existed? Because harvested traffic is exposed retroactively, so waiting means every message sent in the interim is already lost. Signal and Apple both concluded that math resolved in favor of acting early.
Is the 2030 date or the 2035 date the real deadline? Both are real and they mean different things. 2030 deprecates, meaning use is permitted with the risk formally accepted. 2035 disallows.
Why does Australia’s date come first? Its signals directorate decided the international consensus left too little margin, so it requires the old cryptography gone by the end of 2030. It’ll be the first national deadline anyone actually reaches.
What happens if the machine never arrives? Every dated row on this page still happens. The deadlines are regulatory rather than contingent on the hardware.
Where to go next
- When is this going to happen covers the forecast for the one undated row.
- What are other countries doing compares the national deadlines in detail.
- What does history tell us about broken codes covers the much longer history this sits inside.
- For Press returns to the index.
Go deeper into the technical detail
The technical version, with the full expert-survey distribution behind these dates, is Quantum Threat Timeline.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.