"Q-Day" refers to the point at which a quantum computer becomes powerful enough to run Shor's algorithm against the encryption protecting most of today's internet traffic — specifically the RSA and elliptic-curve cryptography used to exchange keys and sign certificates, not the AES encryption that protects the data itself. It isn't a single scheduled event; it's a threshold that gets crossed quietly, on hardware that doesn't yet exist at the scale required. This explainer works from the published research estimates and current hardware records to show exactly how far away that threshold actually is, and why regulators are already treating it as urgent regardless.
This explainer is based on peer-reviewed and preprint research papers, NIST's official standards, and hardware announcements verified as of 14 September 2026 — the same evidence-first approach we used unpacking how on-device AI actually works.
What Shor's algorithm actually threatens — and what it doesn't
Shor's algorithm gives a quantum computer a fast way to solve the specific math problems — factoring large numbers and computing discrete logarithms — that RSA and elliptic-curve cryptography (ECC) depend on for their security. Those two systems underpin how your browser establishes a secure connection and how digital certificates are signed. A sufficiently powerful quantum computer running Shor's algorithm could, in principle, derive the private key behind an RSA or ECC public key directly.
Symmetric encryption — AES, which actually encrypts the bulk of your data once a secure connection is established — is not vulnerable to Shor's algorithm at all. It's only weakened by a different, much less powerful quantum algorithm called Grover's algorithm, which merely halves the effective security of a symmetric key. AES-256 under Grover's algorithm still offers roughly the same effective security as AES-128 does today — inconvenient, not catastrophic. Q-Day is specifically about the public-key systems, not encryption broadly.
The number that keeps shrinking, and the number that isn't
| Year | Estimated physical qubits needed for RSA-2048 | Source |
|---|---|---|
| 2021 | ~20 million (8-hour runtime) | Gidney & Ekerå, Google Quantum AI research |
| 2025 | Under 1 million (similar runtime) | Gidney, updated surface-code estimate |
| 2026 (algorithmic optimizations) | As low as ~400,000–900,000 depending on hardware assumptions | Multiple 2026 preprints refining logical-qubit overhead |
Compare that trend against what actually exists. As of August 2026, the largest verified logical-qubit demonstration on record is QuEra's 96 logical qubits built from 448 physical qubits — and IBM's largest physical qubit count, on its Condor-generation chip, sits at roughly 1,121 to 1,180 physical qubits. On 30 August 2026, IBM and University of Chicago researchers announced a separate milestone: a 70-logical-qubit computation that outperformed leading classical simulation methods on a specific verifiable task, one of the largest fault-tolerant logical demonstrations reported to date.
Even the most optimistic current research puts the RSA-2048 threshold in the hundreds of thousands to low millions of physical qubits. The best demonstrated logical-qubit systems today are running in the tens to low hundreds. That gap — several orders of magnitude — is the honest answer to "how close is Q-Day," and it hasn't closed nearly as fast as raw physical-qubit headline numbers might suggest, because logical, error-corrected qubits are the resource that actually matters for Shor's algorithm, not physical qubits alone.
Why nobody is waiting for Q-Day to actually arrive
NIST finalized its first three post-quantum cryptography standards — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) — on 13 August 2024, after an eight-year evaluation process. The NSA's Commercial National Security Algorithm Suite 2.0 sets 2030 as the mandatory deadline for national security systems to migrate to these new algorithms for key establishment.
The urgency isn't about Q-Day itself — it's about a different threat called "harvest now, decrypt later." An adversary can record encrypted internet traffic today and simply store it, waiting for a future quantum computer to decrypt it retroactively. For data that needs to stay confidential for a decade or more — government records, long-term medical data, trade secrets — the encryption needs to already be quantum-resistant now, years before Q-Day, because today's traffic is the vulnerable data.
Real migration is already measurably underway: independent measurements of TLS 1.3 connections show roughly 1.8% already using post-quantum key exchange as of 2026, and Microsoft shipped general availability of ML-DSA support in Windows Server 2025's Active Directory Certificate Services on 13 May 2026 — post-quantum cryptography has moved from standards documents into production infrastructure well ahead of any quantum computer that could exploit the gap it closes, a slow-burn migration pattern similar to what we found tracking the official indicators economists use for AI spending risk.
What Q-Day does not mean
- It's not a single day. There's no announcement moment — encryption becomes vulnerable gradually as hardware crosses an unclear threshold, and different key sizes and algorithms fall at different times.
- It doesn't break everything at once. Systems still using RSA or ECC would be exposed; systems already migrated to ML-KEM or ML-DSA would not be, regardless of when Q-Day occurs.
- It doesn't touch AES-256 in any practical sense. Grover's algorithm's impact on symmetric encryption is a known, modest, quantifiable reduction — not a break.
- Nobody can currently specify a year with confidence. The gap between "estimated qubits required" and "qubits demonstrated" has narrowed on the estimate side more than the hardware side has grown, which is precisely why every credible timeline in this space is phrased as a planning deadline (2030, 2035) rather than a prediction.
Frequently asked questions
Is Q-Day expected to happen this decade?
No confident date exists. Current published estimates require several hundred thousand to a few million physical qubits for RSA-2048, while the largest demonstrated logical-qubit systems in 2026 operate in the tens to low hundreds — a gap regulatory deadlines like NSA's 2030 target are designed to get ahead of, not a prediction that Q-Day will occur by then.
Does AES-256 need to be replaced before Q-Day?
Not for the same reason RSA and ECC do. Grover's algorithm only reduces AES-256's effective security to roughly AES-128 levels, which remains considered secure; AES-256 is not broken outright the way Shor's algorithm threatens to break RSA and ECC.
Why is post-quantum migration urgent if Q-Day hasn't arrived?
Because of "harvest now, decrypt later" — encrypted data intercepted and stored today could be decrypted once a capable quantum computer exists, so data requiring long-term confidentiality needs quantum-resistant encryption well before that hardware is built.
What's the difference between a physical qubit and a logical qubit?
A physical qubit is one actual hardware quantum bit, which is noisy and error-prone. A logical qubit is built from many physical qubits combined through error correction to behave as one reliable, fault-tolerant unit — Shor's algorithm resource estimates are typically given in logical qubits, which is why raw physical-qubit counts alone can overstate how close a system is to being cryptographically relevant.
Last verified: 14 September 2026. Quantum hardware records and cryptography migration deadlines are subject to ongoing change as research and standards evolve.
