Q-Day status
Cryptographic risk observatory · Updated 19 Aug 2026
Q-DAY HASN'T
HAPPENED.
BUT THE EXPOSURE WINDOW
MAY ALREADY BE OPEN.
Encrypted information can be collected today and targeted later. QDayWatch tracks quantum progress, post-quantum migration, and the gap between them.
Assess your exposure ↓PQC migration
UNDERWAY
NIST post-quantum standards are available for deployment now.Long-term confidentiality
AT RISK
Harvest-now / decrypt-later means some future risk begins before Q-Day.Mosca's inequality
ARE YOU ALREADY INSIDE
THE EXPOSURE WINDOW?
The date is unknowable. The planning relationship is still useful: data lifetime plus migration time must fit before a cryptographically relevant machine arrives.
The planning horizon extends 5 years beyond this scenario.
Migration takes Y years. Data created at the end of that migration can remain valuable for another X years—this is why the terms add.
PQC transition horizon
2035NOT A Q-DAY PREDICTIONTHE CLOCK WE
CAN ACTUALLY SEE.
NIST describes a transition that removes quantum-vulnerable algorithms from its standards by 2035, with higher-risk systems moving earlier. The exact day is not specified, so QDayWatch shows a year-level horizon—not a false-precision countdown.
NIST transition guidance ↗Calculating transition horizonHarvest now / decrypt later
THE ATTACK CAN START BEFORE
THE QUANTUM COMPUTER EXISTS.
An attacker does not need a quantum computer today to target information that will still matter when one becomes available.
DECRYPTIONCAPABILITY NOT OBSERVED
Prioritize information whose value outlives the time needed to discover, replace, test, and retire vulnerable cryptography.
Cryptographic impact
QUANTUM DOES NOT BREAK
ALL ENCRYPTION.
It changes the security assumptions behind specific primitives. Public-key systems face a qualitatively different failure mode from symmetric encryption and hashing.
Why “quantum-safe” is too simple: AES and SHA are not subject to Shor's public-key break, but quantum algorithms still affect their security margins. Algorithm, key size, mode, and use case all matter.
Cryptographic inventory
WHERE VULNERABLE
CRYPTOGRAPHY LIVES.
Migration is an infrastructure problem. Select a layer to see why replacing an algorithm is rarely a one-line configuration change.
Selected layer
TLS
Early deployment- Cryptographic role
- Authenticates servers and establishes session keys for web traffic.
- Common vulnerable primitives
- RSA signatures; ECDSA/EdDSA certificates; ECDH key exchange.
- Migration involves
- Add hybrid or PQC key establishment, then migrate certificate signatures and PKI.
- Operational friction
- Compatibility, handshake size, certificate ecosystems, and middleboxes.
The Q-Day Watch
SIGNALS THAT MATTER MORE
THAN RAW QUBIT COUNTS.
Architectures, error rates, connectivity, code overhead, and logical operations differ. Physical qubit totals are not a common unit of cryptanalytic capability.
Surface-code error suppression
Λ = 2.14 ± 0.02A distance-7 logical memory used 101 physical qubits and achieved a 0.143% logical error per correction cycle. Its lifetime exceeded its best constituent physical qubit by 2.4×.
Demonstrated for memory—not a general-purpose fault-tolerant cryptanalytic computer.
Error decreased as code distance increased in the cited surface-code experiment.
Long, reliable logical circuits at cryptanalytic scale have not been publicly demonstrated.
No public demonstration has factored a production RSA-2048 key using quantum computing.
Resource estimate monitor
RSA-2048
Resource estimates are models, not machine specifications. Two estimates from related research show how assumptions and algorithmic improvements can move the result without moving hardware capability.
and architecture
Readiness
RISK DEPENDS ON
TWO RACES, NOT ONE.
Quantum capability
PQC migration
Positions are qualitative status indicators—not a composite Q-Day Index. A scored index would imply precision the evidence cannot yet support.
Standards monitor
THE REPLACEMENTS
ARE ARRIVING.
Standardized, selected, candidate, deprecated, and withdrawn are different states. QDayWatch keeps them separate.
ML-KEM
Key establishment
Primary general-purpose KEM. Parameter sets: 512, 768, and 1024.
Source ↗ML-DSA
Digital signatures
Primary lattice-based digital signature standard.
Source ↗SLH-DSA
Digital signatures
Stateless hash-based alternative with different security assumptions.
Source ↗FN-DSA
Digital signatures
Compact lattice-based signatures; standardization remains underway.
Source ↗HQC
Key establishment
Code-based backup KEM selected to add mathematical diversity.
Source ↗HAWK
Digital signatures
Withdrawn in 2026 after a newly discovered attack; never deployed as a NIST standard.
Source ↗The road to Q-Day
MILESTONES,
NOT PROPHECIES.
A record of observable changes in algorithms, standards, policy, and error correction.
HAWK is withdrawn after a new attack
A candidate signature scheme is removed from consideration. NIST states that the finding does not affect the finalized ML-KEM or ML-DSA standards.
NIST ↗RSA-2048 resource estimate drops below one million noisy qubits
A new preprint substantially reduces the estimated physical-qubit count under the paper's stated assumptions, while extending projected runtime to under a week.
Craig Gidney ↗HQC selected as a backup KEM
NIST selects a code-based backup for general encryption, adding mathematical diversity to the standards pipeline.
NIST ↗Below-threshold surface-code memory demonstrated
Google Quantum AI reports that logical errors fall as code distance grows on Willow, a meaningful error-correction milestone—not a cryptanalytic break.
Nature ↗NIST publishes its transition proposal
IR 8547 outlines an expected path to deprecate and remove quantum-vulnerable algorithms by 2035, with higher-risk systems moving earlier.
NIST ↗Intelligence feed
LATEST SIGNALS.
Publication date and event date are tracked separately so old events cannot look new—and new analysis can be placed in context.
HAWK candidate withdrawn
A new attack led the HAWK team to withdraw its signature candidate. NIST says finalized PQC standards are unaffected.
FIPS 204 errata updated
NIST listed several minor issues for correction in a future revision. The ML-DSA standard remains final and available.
RSA-2048 estimate revised
A preprint estimates that under one million noisy qubits could factor RSA-2048 in under a week—under explicit, demanding assumptions.