up:: Start Here

When is this going to happen?

Nobody knows, and anybody who hands you a specific year is selling something.

That sounds like a dodge, and it’s actually the most useful thing anyone can tell you, because the decision doesn’t depend on the answer. There are real numbers below, and there are also dates already on the calendar that arrive regardless of what the machine does.

The short version:

  • Expert surveys put the odds of a capable machine at 28% to 49% within 10 years and 51% to 70% within 15 years.
  • Those are ranges rather than dates, and the width mostly reflects how coarse the survey’s answer choices are.
  • The estimated requirement dropped from 20 million qubits in 2019 to under 1 million in 2025.
  • Meanwhile the deadlines are fixed: the weaker key sizes are deprecated after 2030, and all of today’s public-key encryption is disallowed after 2035 regardless of size.
  • The arrival date matters less than you’d think, because data collected today is exposed whenever it arrives.

What do the experts actually predict?

The Global Risk Institute surveys quantum researchers every year and publishes the spread rather than a single date. Its 2025 report, drawing on 26 experts, put the likelihood of a machine capable of breaking a standard encryption key at:

  • 28% to 49% within 10 years
  • 51% to 70% within 15 years

Source: M. Mosca and M. Piani, Quantum Threat Timeline Report 2025, Global Risk Institute / evolutionQ, globalriskinstitute.org.

Diverging bar chart showing how 26 surveyed experts rated the likelihood of a machine able to break RSA-2048, across 5 timeframes. At 5 years most answers sit in the least confident bins. By 15 years a majority rate it likely or better, and by 30 years 22 of the 26 do.

Source: Mosca and Piani, Quantum Threat Timeline Report 2025, Global Risk Institute, Appendix A.4.

Those two percentage ranges are worth understanding properly, because they’re the most misquoted numbers in this subject. Each expert picks a coarse option like “likely, above 70%” or “about 50%,” and the report then reads every answer twice, once at the bottom of the chosen band and once at the top, and averages both ways. The report says plainly that the gap between the two figures is “largely reflecting the width of the likelihood bins.” So the spread is mostly a property of the questionnaire rather than a measure of how much the experts argue with each other.

Roughly even odds inside 15 years leaves genuine room for the machine never arriving. It’s also a very high probability to accept on information that stays sensitive for a lifetime, like a genome or a medical history.

That’s the honest way to hold this. Not a countdown, and not a dismissal.

Why do the estimates keep moving?

Because the work is getting more efficient, and that’s the trend worth watching rather than any single figure.

YearPublished estimate to break a standard key
201920 million error-prone qubits, running for 8 hours
2025Under 1 million error-prone qubits

The hardware didn’t shrink by a factor of 20. The methods improved. Researchers found better ways to do the same job with fewer resources, and there’s no particular reason to assume that process has finished.

Source: C. Gidney and M. Ekerå, “How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits,” Quantum 5, 433, 2021, arxiv.org; C. Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits,” 2025, arxiv.org.

Bar chart of the qubits estimated as necessary to break RSA-2048: 20 million in 2019, under 1 million in 2025, and the machines actually built, which are in the low thousands and too small to appear on the same axis.

Source: Gidney and Ekerå, Quantum 5, 433 (2021); Gidney (2025).

The third column is the part that keeps this honest. The target has moved 20-fold closer, and the largest machines anybody has built are still in the low thousands of noisy qubits, which doesn’t register on the same axis. Both things are true at once, and a plan built on either one alone goes wrong in a different direction.

A forecast that assumed the 2019 number would have looked comfortable. Anyone who built a plan on it is now 20 times closer to the deadline than they thought.

What dates are actually fixed?

This is the part that doesn’t depend on anybody’s prediction.

DateWhat happens
August 2024NIST published the replacement encryption standards
March 2025NIST added a fifth algorithm as a backup
2030Today’s public-key encryption is deprecated under the U.S. schedule
2030Australia requires it to have stopped being used entirely
2031Canada requires high-priority government systems migrated
2035The U.S. schedule disallows today’s encryption

Source: NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards,” August 13, 2024; NIST IR 8547 (Initial Public Draft), November 2024; Australian Signals Directorate, “Guidelines for cryptography,” cyber.gov.au; Canadian Centre for Cyber Security, ITSM.40.001, cyber.gc.ca.

Those dates arrive whether or not a machine does. Governments set them because waiting for certainty would leave no time to act on it.

Why does the arrival date matter less than it sounds?

Because of how the damage works.

If the risk were only that a future machine could read your future traffic, then waiting would be sensible. You’d act when it got close.

The risk is that a future machine can read the traffic being collected right now. So the exposure for anything sent today is set today, and the arrival date only determines when someone gets around to reading it. A 10-year delay in the machine’s arrival does nothing for a message sent this morning, beyond postponing when it gets read.

That’s why the useful question is how long your data has to stay private, which you already know, rather than when the machine arrives. See Is someone stealing my data right now?

Questions people ask

Has anybody broken real encryption yet? No. There’s no public evidence of it, and periodic claims involve very small numbers or methods that don’t scale.

Would we be told if someone did? Probably not, and history says clearly otherwise. Covered at What does history tell us about broken codes?

Why do some people say 2030 and others say never? Because the honest range is genuinely that wide, and because some of the people naming dates have a financial interest in the date being close or far. Attribute any specific year to a named person and check what they sell.

Is 15 years long enough to relax? For your dinner plans, easily. For your medical records, your genome, and a 30-year mortgage, no. That’s the whole sorting mechanism.

What if it never arrives? Then the money spent replacing the encryption was modest insurance against a catastrophic and irreversible outcome, which is a trade most institutions make routinely. See Is this overhyped?

Where to go next

Go deeper into the technical detail

The technical version, with the full survey history, is Quantum Threat Timeline.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.