Photocopying sealed letters and waiting.
Picture someone who photocopies, every day, the sealed letters going through the post. Today they can't read any of them: the seal holds. But they keep everything in a drawer, because they know that one day a tool will appear that opens that kind of seal. When it does, letters from years ago open too.
That is exactly what is called "store now, open later". The seal is public-key cryptography, the kind that agrees on the password for each secure connection (the browser padlock, payment systems, open banking, the VPN). The tool is a large enough quantum computer, which does not exist yet.
So the deadline that matters to your company is not the day the machine switches on (Q-Day). It is that day minus how long your data must stay secret, minus how long you take to change the locks. A medical record that must stay secret for 20 years, encrypted today, is already on the wrong side of any estimate.
Not all cryptography is in the crosshairs.
There are two kinds of lock. The public-key kind has a part everyone sees, like an open padlock hanging for anyone to lock, and a secret part that opens it. It agrees on passwords and signs documents: RSA, ECDH, ECDSA and the secp256k1 behind Bitcoin wallets. A large quantum computer can work out the secret part from the public one (Shor's algorithm). These break.
The shared-secret kind (AES-256 to encrypt, SHA-256 for fingerprints) has no public part to attack. The best known quantum shortcut only halves its strength, and AES-256 keeps plenty of margin. These hold.
In practice, migrating means replacing public-key locks with the new ones NIST standardized in 2024: ML-KEM to agree on passwords and ML-DSA to sign, ideally alongside the old ones during the transition.
Nobody knows the date. The estimates got shorter.
There is no measurement of Q-Day, only estimates, and they come from people with different positions. What changed in 2026 was the direction: two studies (one from Google, with superconducting qubits, and one from Oratomic, with neutral atoms) indicated that 256-bit elliptic curves, the ones behind HTTPS and Bitcoin, fall with far less machine than previously calculated.
- 2029Filippo Valsorda, cryptography engineer (formerly on Google's Go team), revised his own position in 2026 from 2035 to 2029, citing Google executives who speak of 2029.estimate
- 2030/31US government: in June 2026, the White House set 31 Dec 2030 to migrate key exchange and 31 Dec 2031 for signatures in federal systems. Not a Q-Day forecast: a compliance deadline.regulatory deadline
- ~2028BACEN: we expect Brazil's Central Bank to require it before 2028, given the weight of Open Finance and Pix. Our reading, not an official announcement.our reading
- ?Skeptics point out that the largest number ever factored on a quantum computer is still tiny, and a direct jump to RSA-2048 is not guaranteed. Even they, in public discussion, agree on starting the key-exchange migration now.counterpoint
- 2026What is moving: the bottleneck is no longer just counting qubits but keeping the machine correcting its own errors for hours without stopping. In 2026 Google showed self-recalibrating error correction, and Oratomic raised US$ 300 million for a machine of about 20,000 qubits.signal
Changing the locks, where to start.
From estimate to code: the deadline and the assessment, the regulation that should arrive, the inventory of what must change, the identity of devices that stay decades in the field, and what we measured encrypting telemetry with the new locks.
Computing without opening: the same kind of math.
The new locks rest on a mathematical problem, lattices, that also enables something that sounds impossible: computing on data that stays encrypted the whole time (FHE). A hospital adds up results without seeing patients; a bank computes risk without receiving the customer's data. We measured on our bench what is usable today and where it is still expensive.
Where are your old locks?
You tell us which algorithms you use and where. We reply within 24 business hours with a short report: what is critical, the next 90 days' roadmap and an effort estimate. No sales pitch.
- Secure connections and APIs (open banking, payments, partners)
- Certificates whose validity reaches into the risk window
- Long-retention data (health, contracts, legal)
- Server access keys and login tokens
- Blockchain wallets and identities
The day the first quantum computer able to break today's cryptography switches on. Only estimates exist.
Recording encrypted traffic now to read it on Q-Day. That is why the problem has already begun.
Systems built to change algorithm through configuration. Useful to migrate now and again, if needed.
Where this could be wrong.
The dates are estimates
No Q-Day number on this page is our measurement. The sources disagree and move; we show whose each one is.
The new locks are young
Every so often a claimed break of lattices appears; the 2024 one fell apart in about eight days. In July 2026, an AI model found the attack that removed HAWK, a candidate signature, from the NIST process; the ML-KEM and ML-DSA standards were not affected. That is why we recommend migrating with both locks together.
Signatures are harder than key exchange
The new signatures are much larger. In certificates, smart cards and small channels (satellite, sensors) they do not always fit, and identity migration lags behind.
BACEN in 2028 is our reading
No resolution has been published. We explain the reasoning on its own page, so you can agree or disagree on the merits.
← stickybit.com.br · Glossary · 24-hour assessment
- Filippo Valsorda, "CRQC timeline" (2026) and the Hacker News discussion.
- Google Research: self-recalibrating error correction (Nature, 2026; arXiv 2511.08493). Oratomic: US$ 300 million round (TechCrunch, 10 Jul 2026).
- NIST FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA), August 2024. White House: federal migration deadlines of 22 Jun 2026.
- HAWK: public discussion on the NIST pqc-forum, July 2026. Yilei Chen (2024): lattice-break claim withdrawn after an error was found.
- FHE measurements: our own bench (Apple M2, Lattigo v6.2.0), see The FHE frontier.