Quantum computers that can break standard encryption are expected within the decade, yet 91 percent of security professionals have no formal migration plan.
Quantum computers that can break standard encryption are expected within the decade, yet 91 percent of security professionals have no formal migration plan.

Quantum computers capable of cracking RSA and ECC encryption are expected within the decade, forcing governments and enterprises to overhaul cryptographic infrastructure — but most organizations remain unprepared for the transition.
"Post-quantum cryptography readiness is no longer a future-proofing exercise — it is a present-day risk control," Deborah Guild, chair of the Financial Services Sector Coordinating Council and head of technology at PNC Financial Services Group, said.
NIST released three postquantum cryptography standards in 2024, with a target window to phase out legacy systems by 2035. The U.S. government set a 2030 compliance deadline for federal agencies. Google, Cloudflare and Microsoft aim to use quantum-resistant encryption across all products and core infrastructure by 2029. IBM plans to deliver its first quantum computer for real-world applications by 2029.
The immediate threat is "harvest now, decrypt later" — adversaries downloading encrypted data today to decrypt once quantum capabilities mature. That puts intellectual property and government intelligence at risk, Andrew McLaughlin, chief operating officer at SandboxAQ, said. The Treasury Department launched a Quantum-Readiness Task Force in coordination with the G7, which targets 2035 for the financial sector's transition.
Why factoring breaks today's encryption
Today's encryption relies on mathematical locks that are effectively impossible for ordinary computers to crack. One common method encrypts data with a massive number known as a public key; to unlock it, bad actors must factor that number into its prime components — a vexing task for classical machines. Quantum computers excel at spotting mathematical patterns and can factor very large numbers far more efficiently, making them uniquely suited to breaking the encryption underpinning online transactions, private messaging and secure website connections.
There isn't expected to be a single "Q-day" when quantum computers suddenly break standard encryption. It's likely to occur over several months or years, said Scott Aaronson, a computer-science professor at the University of Texas at Austin. Quantum computers exist today but mostly in restricted lab conditions, ill-equipped for everyday practical applications.
2030 deadlines loom as adoption lags
Quantum-safe encryption systems already exist. One leading type involves lattice-based protocols, which secure data with geometry-based problems that are difficult for both standard and quantum computers to solve. A hybrid approach combining existing and postquantum cryptography could serve as a bridge during the transition, said Ali El Kaafarani, chief executive of PQShield, a company specializing in quantum-resistant cryptography.
Signal and Apple's iMessage already use postquantum end-to-end encryption, while Meta Platforms' WhatsApp and Facebook Messenger are deploying postquantum features. Password managers Keeper Security and 1Password have adopted quantum-resistant algorithms. Financial institutions, central banks and credit-card networks are also adopting postquantum protocols.
Yet a survey published by Trusted Computing Group, a nonprofit industry-standards organization, found that 91 percent of security professionals in the U.S. and Europe have no formal road map to protect against quantum threats. The Treasury task force will divide its work among coordinating the financial sector's postquantum transition, assessing technology vendor readiness and examining risks involving digital assets. The G7 roadmap calls on financial institutions to inventory cryptography use, assess sensitive systems, develop migration plans and test quantum-resistant technology.
For consumers, the postquantum transition will largely happen behind the scenes. Keeping software updated ensures users benefit from upgrades as apps and operating systems migrate. Browser extensions such as PQSpy highlight sites that use postquantum encryption, said Nick Sullivan, an applied cryptographer and security researcher.
The stakes extend beyond individual data. Quantum-resistant migration touches every layer of the digital economy — from payment systems and cloud infrastructure to government credentials and supply chains. Organizations that delay cryptographic inventory and migration planning expose themselves to harvest-now-decrypt-later attacks on data that remains valuable for years. The 2030 federal deadline and 2035 NIST phase-out window provide a concrete timeline, but the 91 percent of security teams without road maps suggest the industry is racing the clock.
This article is for informational purposes only and does not constitute investment advice.