Blog | Emerging Technologies

Will Quantum Computing Break Encryption?

Will Quantum Computing Break Encryption?
share on
by Sanjeev Kapoor 01 Oct 2026

Will Quantum Computing Break Your Encryption?

Quantum computing sounds like a problem for physicists and scientists rather than something that concerns IT teams. That’s however a big mistake. In the coming decades, may be somewhere between now and the mid-2040s, a sufficiently capable quantum computer will be able to break the RSA (Rivest–Shamir–Adleman) and elliptic-curve encryption that currently protects almost every secure connection on the internet. Nobody knows the exact date this becomes possible, which is precisely why waiting for certainty is the wrong strategy. Attackers don’t need a working quantum computer today. They only need to capture your encrypted traffic now and decrypt it later. Therefore, if your organization handles data with a shelf life longer than five years, that clock is already running. In this context, it’s important for modern organizations to understand what’s actually changing, and what to do about it before the deadline arrives.

Math That Keeps CISOs Up at Night

Emerging Technologies or something else.
Let's help you with your IT project.

Two quantum algorithms make current cryptography vulnerable. Shor’s algorithm can factor large numbers efficiently, which breaks RSA. It can also solve the discrete logarithm problem, which breaks elliptic-curve cryptography. Grover’s algorithm offers a smaller advantage against symmetric encryption like AES (Advanced Encryption Standard), mainly by speeding up brute-force search, and iss manageable by simply doubling key length. The real danger sits with RSA and ECC (Elliptic-curve cryptography), which currently secure everything from HTTPS connections to VPN (Virtual Private Network) tunnels and digital signatures.

Recent changes are not about the algorithms. They are about the hardware estimates. In 2019, researchers thought that breaking RSA-2048 would require roughly 20 million physical qubits, which was actually a number that felt safely distant. By 2025, improved algorithms had cut that estimate to under a million. Moreover, newer architectural approaches proposed in 2026 pushed some estimates below 100,000 qubits. This is still ahead of anything built today, but a fraction of where the field stood a few years ago.

This trend line matters more than any single prediction. Every year, the resource bar keeps dropping while investment in quantum hardware keeps climbing. Quantum threats don’t need to arrive by a specific date to be worth planning for now. They need to arrive before your data stops being sensitive, and for most organizations, that’s a much closer deadline than 2035.

Harvest Now, Decrypt Later Is Already Happening

The paradox is that you do not need a working quantum computer to start exploiting this gap. Intelligence agencies and criminal groups are already running a strategy known as “harvest now, decrypt later”. This is about capturing encrypted traffic today, storing it, and decrypting it once quantum hardware catches up. This turns encryption security into a question of timing rather than strength. A cipher that’s unbreakable today only stays useful for as long as the data inside it matters.

Some industries feel this more sharply than others. For example, financial services, healthcare, government and defense, energy and critical infrastructure, and telecommunications all handle information that stays sensitive for a decade or longer. Think about medical histories,

infrastructure blueprints, long-term financial records, classified communications. If your organization sits in one of these categories, assume that some of your traffic is already sitting in someone else’s storage, waiting.

The takeaway is not that you must panic. It is that you have to prioritize. Not every system needs to migrate to quantum-resistant algorithms this quarter. But the systems protecting data with a multi-year sensitivity window must move to the front of the queue, because the encryption risks tied to that data are compounding every day it sits unmigrated. In this direction, companies should map out which of their data stores actually carry that kind of long shelf life before deciding where to spend their migration budgets.

NIST Already Handed You the Answer

The good news is that you don’t have to invent a solution. In August 2024, after an eight-year public evaluation process, NIST finalized three post-quantum cryptography standards: ML-KEM for general encryption and key exchange, and ML-DSA and SLH-DSA for digital signatures. In March 2025, NIST added a fifth algorithm, namely Hamming Quasi-Cyclic (HQC), as a backup encryption standard built on different mathematical assumption. HQC was develope, in case a weakness is later found in ML-KEM.

This process isn’t finished, and that’s worth knowing rather than worrying about. In July 2026, NIST withdrew a candidate algorithm called HAWK, after researchers found a vulnerability during further review. This is exactly how a standards process is supposed to work. The three core standards from 2024 remain unaffected.

Regulatory pressure is building around these standards. Google has set an internal 2029 deadline for migrating its own systems to post-quantum cryptography. NIST plans to deprecate today’s vulnerable algorithms after 2030 and disallow them entirely by 2035. Those dates sound distant until you remember that large organizations typically need three to five years to migrate cryptographic infrastructure across every application, certificate, and hardware device that touches it.

Building Encryption That Survives the Transition

In this landscape, companies had better start with visibility. Most organizations don’t actually know where every instance of RSA or ECC lives in their infrastructure, buried in old libraries, embedded devices, and third-party software they don’t control. Thus, building a cryptographic inventory, sometimes called a Cryptographic Bill of Materials, is a tediuous yet very useful work. In reality t’s the only way to know what needs to change. Next, it also important to prioritize using Mosca’s theorem, which offers a framework to assess the risk and necessary timeframe for transitioning to quantum-resistant cryptographic systems. In particular, if the time your data needs to stay secure (Y) plus the time it takes you to migrate (X) exceeds the time until a quantum computer can break your encryption (Q), you’re already too late for that dataset. Running this calculation for your most sensitive systems tells you which ones can’t wait for a company-wide rollout.

Finally, you must build for crypto-agility rather than a one-time swap. Choose systems and libraries that let you change cryptographic algorithms through configuration rather than a rewrite. This is because the standards themselves may still shift, as the HAWK withdrawal showed. Pilot ML-KEM in a non-critical VPN or TLS connection this year. The organizations that treat this as a multi-year program will be in a very different position than the ones that wait for a deadline or alert to force their hand.

Overall, nobody can tell you the exact day a quantum computer breaks RSA-2048. However, that uncertainty is the point, not an excuse to wait. The standards exist, the migration path is documented, and the data most worth protecting is the data already at risk today under harvest-now-decrypt-later attacks. Start with an inventory of where your sensitive, long-lived data actually lives, and then pilot the NIST-approved algorithms on one system this quarter. Ultimately, the gap between organizations that started early and those that did not, will be measured in outcomes and not in good intentions.

Leave a comment

Recent Posts

get in touch

We're here to help!

Terms of use
Privacy Policy
Cookie Policy
Site Map
2026 IT Exchange, Inc