Cryptographic risk observatory · Updated 19 Aug 2026

Q-DAY HASN'T
HAPPENED.

BUT THE EXPOSURE WINDOW
MAY ALREADY BE OPEN.

Encrypted information can be collected today and targeted later. QDayWatch tracks quantum progress, post-quantum migration, and the gap between them.

Assess your exposure
01

Q-Day status

NOT OBSERVED

No publicly known cryptographically relevant quantum computer exists.
02

PQC migration

UNDERWAY

NIST post-quantum standards are available for deployment now.
03

Long-term confidentiality

AT RISK

Harvest-now / decrypt-later means some future risk begins before Q-Day.
01

Mosca's inequality

ARE YOU ALREADY INSIDE
THE EXPOSURE WINDOW?

The date is unknowable. The planning relationship is still useful: data lifetime plus migration time must fit before a cryptographically relevant machine arrives.

Z Q-Day scenario

Scenario only — not a QDayWatch prediction.

DATA LIFETIME10YEARS
MIGRATION5YEARS
EXPOSURE HORIZON15YEARS
Q-DAY SCENARIO10YEARS
ResultEXPOSURE WINDOW OPEN

The planning horizon extends 5 years beyond this scenario.

Today50 years
Migration · YData lifetime · XX + Y · 15 yearsScenario Z

Migration takes Y years. Data created at the end of that migration can remain valuable for another X years—this is why the terms add.

PQC transition horizon

2035NOT A Q-DAY PREDICTION

THE CLOCK WE
CAN ACTUALLY SEE.

NIST describes a transition that removes quantum-vulnerable algorithms from its standards by 2035, with higher-risk systems moving earlier. The exact day is not specified, so QDayWatch shows a year-level horizon—not a false-precision countdown.

NIST transition guidance
Standards finalized · Aug 2024Transition horizon · 2035
Calculating transition horizon
02

Harvest now / decrypt later

THE ATTACK CAN START BEFORE
THE QUANTUM COMPUTER EXISTS.

An attacker does not need a quantum computer today to target information that will still matter when one becomes available.

01YOUCAPTURE TODAY
encrypted traffic
02SERVICELIVE CONNECTION
copy intercepted
03 · STOREARCHIVECIPHERTEXT / BLOCK 01CIPHERTEXT / BLOCK 02CIPHERTEXT / BLOCK 03CIPHERTEXT / BLOCK 04
04 · Q-DAYATTEMPT
DECRYPTION
CAPABILITY NOT OBSERVED
The practical lesson

Prioritize information whose value outlives the time needed to discover, replace, test, and retire vulnerable cryptography.

03

Cryptographic impact

QUANTUM DOES NOT BREAK
ALL ENCRYPTION.

It changes the security assumptions behind specific primitives. Public-key systems face a qualitatively different failure mode from symmetric encryption and hashing.

PrimitiveClassAssessmentMechanism
RSAPublic keyCRQC vulnerableShor · integer factorization
Diffie–HellmanPublic keyCRQC vulnerableShor · discrete logarithms
ECDH · ECDSA · EdDSAPublic keyCRQC vulnerableShor · elliptic-curve discrete logs
AES-256SymmetricMargin reducedGeneric quantum search · not Shor-broken
SHA-256HashMargin reducedQuantum search affects brute-force complexity

Why “quantum-safe” is too simple: AES and SHA are not subject to Shor's public-key break, but quantum algorithms still affect their security margins. Algorithm, key size, mode, and use case all matter.

04

Cryptographic inventory

WHERE VULNERABLE
CRYPTOGRAPHY LIVES.

Migration is an infrastructure problem. Select a layer to see why replacing an algorithm is rarely a one-line configuration change.

Selected layer

TLS

Early deployment
Cryptographic role
Authenticates servers and establishes session keys for web traffic.
Common vulnerable primitives
RSA signatures; ECDSA/EdDSA certificates; ECDH key exchange.
Migration involves
Add hybrid or PQC key establishment, then migrate certificate signatures and PKI.
Operational friction
Compatibility, handshake size, certificate ecosystems, and middleboxes.
Migration research
05

The Q-Day Watch

SIGNALS THAT MATTER MORE
THAN RAW QUBIT COUNTS.

Architectures, error rates, connectivity, code overhead, and logical operations differ. Physical qubit totals are not a common unit of cryptanalytic capability.

Observed milestoneNature · 2024

Surface-code error suppression

Λ = 2.14 ± 0.02

A distance-7 logical memory used 101 physical qubits and achieved a 0.143% logical error per correction cycle. Its lifetime exceeded its best constituent physical qubit by 2.4×.

LAB DEMONSTRATIONCRYPTOGRAPHICALLY RELEVANT
LAB DEMONSTRATION
Logical memoryBEYOND BREAKEVEN

Demonstrated for memory—not a general-purpose fault-tolerant cryptanalytic computer.

Error correctionBELOW THRESHOLD

Error decreased as code distance increased in the cited surface-code experiment.

Fault-tolerant gatesEARLY RESEARCH

Long, reliable logical circuits at cryptanalytic scale have not been publicly demonstrated.

RSA-2048 quantum breakNOT OBSERVED

No public demonstration has factored a production RSA-2048 key using quantum computing.

Resource estimate monitor

RSA-2048

NOT PUBLICLY BROKEN BY QUANTUM COMPUTING

Resource estimates are models, not machine specifications. Two estimates from related research show how assumptions and algorithmic improvements can move the result without moving hardware capability.

changed algorithms
and architecture
2025 estimate<1Mnoisy physical qubits · under a weekGidney
Both assume0.1% gate error1 μs surface-code cycle10 μs reaction time2D nearest-neighbor grid
06

Readiness

RISK DEPENDS ON
TWO RACES, NOT ONE.

Quantum capability

Logical qubits
Error correction
Gate fidelity
Algorithm efficiency
Hardware scale
Reliable runtime
VS

PQC migration

Standards
Implementations
Protocols
Operating systems
PKI
Enterprises

Positions are qualitative status indicators—not a composite Q-Day Index. A scored index would imply precision the evidence cannot yet support.

07

Standards monitor

THE REPLACEMENTS
ARE ARRIVING.

Standardized, selected, candidate, deprecated, and withdrawn are different states. QDayWatch keeps them separate.

FIPS 203Standardized

ML-KEM

Key establishment

Primary general-purpose KEM. Parameter sets: 512, 768, and 1024.

Source
FIPS 204Standardized

ML-DSA

Digital signatures

Primary lattice-based digital signature standard.

Source
FIPS 205Standardized

SLH-DSA

Digital signatures

Stateless hash-based alternative with different security assumptions.

Source
FalconSelected

FN-DSA

Digital signatures

Compact lattice-based signatures; standardization remains underway.

Source
PipelineSelected

HQC

Key establishment

Code-based backup KEM selected to add mathematical diversity.

Source
ArchivedWithdrawn

HAWK

Digital signatures

Withdrawn in 2026 after a newly discovered attack; never deployed as a NIST standard.

Source
08

The road to Q-Day

MILESTONES,
NOT PROPHECIES.

A record of observable changes in algorithms, standards, policy, and error correction.

standard

HAWK is withdrawn after a new attack

A candidate signature scheme is removed from consideration. NIST states that the finding does not affect the finalized ML-KEM or ML-DSA standards.

NIST
cryptography

RSA-2048 resource estimate drops below one million noisy qubits

A new preprint substantially reduces the estimated physical-qubit count under the paper's stated assumptions, while extending projected runtime to under a week.

Craig Gidney
standard

HQC selected as a backup KEM

NIST selects a code-based backup for general encryption, adding mathematical diversity to the standards pipeline.

NIST
quantum

Below-threshold surface-code memory demonstrated

Google Quantum AI reports that logical errors fall as code distance grows on Willow, a meaningful error-correction milestone—not a cryptanalytic break.

Nature
policy

NIST publishes its transition proposal

IR 8547 outlines an expected path to deprecate and remove quantum-vulnerable algorithms by 2035, with higher-risk systems moving earlier.

NIST
Explore the full timeline →
09

Intelligence feed

LATEST SIGNALS.

Publication date and event date are tracked separately so old events cannot look new—and new analysis can be placed in context.

HIGH
Standards

HAWK candidate withdrawn

A new attack led the HAWK team to withdraw its signature candidate. NIST says finalized PQC standards are unaffected.

Event date · 28 JUL 2026Primary source ↗
MEDIUM
Standards

FIPS 204 errata updated

NIST listed several minor issues for correction in a future revision. The ML-DSA standard remains final and available.

Event date · 31 JUL 2026Primary source ↗
MILESTONE
Cryptanalysis

RSA-2048 estimate revised

A preprint estimates that under one million noisy qubits could factor RSA-2048 in under a week—under explicit, demanding assumptions.

Event date · 21 MAY 2025Primary source ↗