up:: Start Here
When is this going to happen?
Nobody knows, and anybody who hands you a specific year is selling something.
That sounds like a dodge, and it’s actually the most useful thing anyone can tell you, because the decision doesn’t depend on the answer. There are real numbers below, and there are also dates already on the calendar that arrive regardless of what the machine does.
The short version:
- Expert surveys put the odds of a capable machine at 28% to 49% within 10 years and 51% to 70% within 15 years.
- Those are ranges rather than dates, and the width mostly reflects how coarse the survey’s answer choices are.
- The estimated requirement dropped from 20 million qubits in 2019 to under 1 million in 2025.
- Meanwhile the deadlines are fixed: the weaker key sizes are deprecated after 2030, and all of today’s public-key encryption is disallowed after 2035 regardless of size.
- The arrival date matters less than you’d think, because data collected today is exposed whenever it arrives.
What do the experts actually predict?
The Global Risk Institute surveys quantum researchers every year and publishes the spread rather than a single date. Its 2025 report, drawing on 26 experts, put the likelihood of a machine capable of breaking a standard encryption key at:
- 28% to 49% within 10 years
- 51% to 70% within 15 years
Source: M. Mosca and M. Piani, Quantum Threat Timeline Report 2025, Global Risk Institute / evolutionQ, globalriskinstitute.org.

Source: Mosca and Piani, Quantum Threat Timeline Report 2025, Global Risk Institute, Appendix A.4.
Those two percentage ranges are worth understanding properly, because they’re the most misquoted numbers in this subject. Each expert picks a coarse option like “likely, above 70%” or “about 50%,” and the report then reads every answer twice, once at the bottom of the chosen band and once at the top, and averages both ways. The report says plainly that the gap between the two figures is “largely reflecting the width of the likelihood bins.” So the spread is mostly a property of the questionnaire rather than a measure of how much the experts argue with each other.
Roughly even odds inside 15 years leaves genuine room for the machine never arriving. It’s also a very high probability to accept on information that stays sensitive for a lifetime, like a genome or a medical history.
That’s the honest way to hold this. Not a countdown, and not a dismissal.
Why do the estimates keep moving?
Because the work is getting more efficient, and that’s the trend worth watching rather than any single figure.
| Year | Published estimate to break a standard key |
|---|---|
| 2019 | 20 million error-prone qubits, running for 8 hours |
| 2025 | Under 1 million error-prone qubits |
The hardware didn’t shrink by a factor of 20. The methods improved. Researchers found better ways to do the same job with fewer resources, and there’s no particular reason to assume that process has finished.
Source: C. Gidney and M. Ekerå, “How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits,” Quantum 5, 433, 2021, arxiv.org; C. Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits,” 2025, arxiv.org.

Source: Gidney and Ekerå, Quantum 5, 433 (2021); Gidney (2025).
The third column is the part that keeps this honest. The target has moved 20-fold closer, and the largest machines anybody has built are still in the low thousands of noisy qubits, which doesn’t register on the same axis. Both things are true at once, and a plan built on either one alone goes wrong in a different direction.
A forecast that assumed the 2019 number would have looked comfortable. Anyone who built a plan on it is now 20 times closer to the deadline than they thought.
What dates are actually fixed?
This is the part that doesn’t depend on anybody’s prediction.
| Date | What happens |
|---|---|
| August 2024 | NIST published the replacement encryption standards |
| March 2025 | NIST added a fifth algorithm as a backup |
| 2030 | Today’s public-key encryption is deprecated under the U.S. schedule |
| 2030 | Australia requires it to have stopped being used entirely |
| 2031 | Canada requires high-priority government systems migrated |
| 2035 | The U.S. schedule disallows today’s encryption |
Source: NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards,” August 13, 2024; NIST IR 8547 (Initial Public Draft), November 2024; Australian Signals Directorate, “Guidelines for cryptography,” cyber.gov.au; Canadian Centre for Cyber Security, ITSM.40.001, cyber.gc.ca.
Those dates arrive whether or not a machine does. Governments set them because waiting for certainty would leave no time to act on it.
Why does the arrival date matter less than it sounds?
Because of how the damage works.
If the risk were only that a future machine could read your future traffic, then waiting would be sensible. You’d act when it got close.
The risk is that a future machine can read the traffic being collected right now. So the exposure for anything sent today is set today, and the arrival date only determines when someone gets around to reading it. A 10-year delay in the machine’s arrival does nothing for a message sent this morning, beyond postponing when it gets read.
That’s why the useful question is how long your data has to stay private, which you already know, rather than when the machine arrives. See Is someone stealing my data right now?
Questions people ask
Has anybody broken real encryption yet? No. There’s no public evidence of it, and periodic claims involve very small numbers or methods that don’t scale.
Would we be told if someone did? Probably not, and history says clearly otherwise. Covered at What does history tell us about broken codes?
Why do some people say 2030 and others say never? Because the honest range is genuinely that wide, and because some of the people naming dates have a financial interest in the date being close or far. Attribute any specific year to a named person and check what they sell.
Is 15 years long enough to relax? For your dinner plans, easily. For your medical records, your genome, and a 30-year mortgage, no. That’s the whole sorting mechanism.
What if it never arrives? Then the money spent replacing the encryption was modest insurance against a catastrophic and irreversible outcome, which is a trade most institutions make routinely. See Is this overhyped?
Where to go next
- Is this overhyped? states the strongest case that this is being oversold.
- What of mine is actually worth stealing? is how you work out whether 15 years is long enough for you.
- What’s a quantum computer? covers how far the machines actually are.
Go deeper into the technical detail
The technical version, with the full survey history, is Quantum Threat Timeline.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.