Q-Day
the deadline nobody can date

Key facts
- 2029-2030milestones, not Q-Day
- Hardware targets
- 2035federal migration backstop
- US deadline
- ~1 millionphysical, for RSA-2048
- Qubits needed
- Noneno lab dates a break
- Official forecast
A date with no calendar entry. Nobody can tell you when a machine will break RSA, which is exactly the problem: you cannot wait for the announcement, because by then it will already have happened.
Q-Day is the name given to the moment a quantum computer can break the public-key cryptography protecting the internet, banking, government communication and cryptocurrency. It is the deadline the whole post-quantum migration is racing, and the single most important thing to understand about it is that nobody has a date.
Why no one will name a date
The confusion in most coverage comes from mixing two different kinds of claim.
Hardware companies publish roadmaps with dates on them: milestones for qubit counts, error rates and fault-tolerant demonstrations, with several clustering around 2029 and 2030. Those are engineering targets for building machines, and they are frequently reported as though they were forecasts for breaking encryption. They are not. No major laboratory has published a date on which it expects to break RSA.
The credible estimates come instead from expert surveys, which ask cryptographers to put probabilities on a break within given timeframes rather than name a year. Those consistently place meaningful risk in the 2030s rather than this decade, with a long tail of uncertainty in both directions.
The size of the gap
Breaking RSA-2048 with Shor’s algorithm requires roughly a few thousand perfect logical qubits. Because physical qubits are error-prone, each logical qubit must be built from many physical ones. Published estimates for a full attack once ran to twenty million physical qubits; the leading 2025 estimate, from Google’s Craig Gidney, is under a million noisy qubits running for under a week.
Today’s largest machines count in the hundreds to low thousands of physical qubits, with demonstrated logical qubits in the tens. That is not a small gap, and it will not be closed by one announcement. What makes complacency dangerous is that progress is not linear: error-correction breakthroughs can cut the required qubit count sharply, and estimates have already fallen substantially as the algorithms improved.
Why the deadline is not Q-Day
The migration deadline is earlier than Q-Day for a specific reason. An attacker can record encrypted traffic today and store it until a quantum computer exists, a strategy known as harvest now, decrypt later. Any secret that must stay secret for a decade is therefore already at risk, whatever the eventual date.
This is why deadlines are set by policy rather than physics. United States federal agencies work towards a 2035 backstop for migrating to post-quantum cryptography, and the NSA’s CNSA 2.0 suite sets its own timeline for national security systems. Those dates exist to force the work to start now, not because anyone believes 2035 is the year.
What actually happens
Q-Day is unlikely to be a day. The most probable version is a classified capability held by a state, unannounced, for some period before anyone outside knows, which is the strongest argument for migrating before the announcement rather than after it.