Stickybit.← Post-quantumPortuguêsThe deadline · CRQC · 2026
CRQC · the deadline

Today's lock has an expiry date.

Almost everything that travels encrypted on the internet uses locks that a large enough quantum computer opens in minutes. Nobody knows the day: serious estimates range from 2029 to 2035. The useful question is a different one: how long your data must stay secret, and how long changing the lock takes.

Ask for the 24-hour assessmentDo the math
Specimen · how much time you have

0years to spare
0years of exposed data
0year everything is switched
0days to 1 Jan 2029

This is Michele Mosca’s math: if the time the data must stay secret plus the time the switch takes exceeds the time until the computer arrives, you are already late. Arrival years are third-party estimates (sources at the end of the page); the rest is arithmetic.

In everyday terms

A sealed letter in someone else’s safe.

Imagine someone photographs every sealed envelope that goes through the post. Today they cannot open any of them. But they keep the photos, because they know the tool will exist one day. When it does, they open everything at once, including what you sent years earlier.

On the internet this has a name: harvest now, decrypt later. Whoever records encrypted traffic today does not need to break anything today. Today’s conversation is the leak of the day the quantum computer switches on.

That is why the deadline that matters is not the computer’s date. It is how long the data must stay secret. A five-minute access code does not care; a medical record kept for 20 years does.

TODAYencrypted trafficis recorded YEARS STOREDin the safe ofwhoever recorded COMPUTER ARRIVESthe keyis recovered the messagebecomes readable
The data is recorded today, kept, and opened once the tool exists. None of this requires anyone to break into your systems.
What changed

From 2035 to 2029.

For years the informal consensus among cryptographers was that it was fine to wait until around 2035. In early 2026, Filippo Valsorda, a cryptographer who worked on the Go team at Google and author of the age tool, publicly revised his own view: the critical deadline became 2029.

Two research papers moved the estimate: one from Google, estimating that 256-bit elliptic curves (today’s most used lock) would fall in minutes with far fewer qubits than previously thought; another from the Oratomic group, estimating a path with about 10,000 physical qubits on neutral atoms. They are resource estimates, not demonstrations: nobody has broken a real key.

In 2026 two more signals pointed the same way: Google published quantum error correction that recalibrates itself without stopping the computation (a prerequisite for running for days), and Oratomic raised US$300 million for a computer of about 20,000 qubits. There are serious sceptics: the largest number ever factored by a quantum computer is still 21. Nobody knows the day. The decision is about risk, not certainty.

where most estimates fall 202420262028203020322034203620382040 TODAY 2029Valsorda, revised (2026)Google: security leaders 2035earlier viewNIST: retire the old locks
Estimates of when today’s cryptography falls, and the 2026 shift. The dates are third-party; the range is uncertain both ways.
What is exposed

The problem is all one kind of lock.

Today’s cryptography uses two kinds of lock. Single-key locks (like AES, which scrambles a file with a key both ends already share) hold up well: a quantum computer only halves their strength, and AES-256 stays strong. Key-pair locks (RSA and elliptic curves, used to agree on a key when connecting and to sign) fall completely.

And key-pair locks are exactly the ones that are everywhere: in the browser padlock, in open-banking and instant-payment APIs, in server certificates, in crypto wallets and in remote access to machines.

CriticalBrowser padlock, APIsOpen banking, instant payments, regulatory APIs: a conversation recorded today becomes readable later.
CriticalServer certificatesAny certificate issued now that is valid until 2027–2029 lives inside the window.
CriticalLong-lived dataMedical records (kept at least 20 years), contracts, personal data under privacy law.
CriticalBlockchains and identitiesWallets and permanent identities cannot be changed without agreement across the whole network.
HighRemote access and tokensSSH keys, signed tokens (JWT), long-lived internal certificates.
SafeSingle-key (symmetric)AES-256, SHA-256, HMAC: still strong. No need to change.
How the lock is changed

Two locks on the same door.

The switch the industry adopted is called a hybrid key exchange: the connection agrees on a key using the old lock (elliptic curve) and the new one, ML-KEM, standardised by NIST in August 2024 (FIPS 203). The final secret combines both. If a quantum computer opens the old one, the new one holds. If a flaw is found in the new one, the old one still counts.

Google, Cloudflare and Apple’s iMessage already run hybrid exchange in production. For signatures there is ML-DSA (FIPS 204). We implemented both in Go, open and auditable, and ran the harvest-now-decrypt-later scenario end to end:

$ go run ./fhe/11_crqc_migration
2026 encrypted message (AES-GCM): dfae9b4357d2… (96 bytes)
2029 the computer runs Shor(public key) → private key, in minutes
2029 message opened: "CONFIDENTIAL: master key…"
     with hybrid exchange (ML-KEM-768 + curve): nothing to open

See the post-quantum stack running →

old lockelliptic curve new lockML-KEM (NIST, 2024) mix final secret opening one is not enough
Hybrid exchange: the final secret depends on both locks. Opening one is not enough.
How we work

Three levels. You choose where to start.

Level 1 · entryAssessment2 weeks
  • Inventory of keys and algorithms
  • Exposure score per system (how long each piece of data must stay secret)
  • Prioritised 24-month plan
  • Workshop with CTO and CISO
  • Executive report ready for the regulator
Level 2 · pilotPilot switch3 months
  • Everything in level 1
  • One critical service on hybrid exchange in production
  • Integration in the TLS terminator or API gateway
  • Load tests and measurements
  • Training for the in-house team
Level 3 · programmeFull programme12 months
  • Everything in level 2
  • End-to-end switch across all services
  • Continuous governance and compliance
  • Embedded team (2 to 4 engineers)
  • Continuous key monitoring and 24 months of support
24-hour assessment · free

Your company’s exposure map, in 24 hours.

Fill in the form below. We reply within 24 business hours with a three-page PDF: the critical inventory, a 90-day roadmap and an investment estimate. No sales pitch.

Locks you use today (tick all that apply)
No commitment. Reply within 24 business hours.
Three words on this page
Harvest now, decrypt later

Recording encrypted traffic now to open it once the tool exists. That is why the deadline has already started.

Hybrid exchange

Agreeing on a key with the old lock and the new one at the same time. Protects even if one of them fails.

Margin

Years until the computer arrives, minus how long the data must stay secret and how long the switch takes. Negative means late.

Limits

Where this could be wrong.

The dates are estimates

2029 and 2035 are experts’ readings of research papers, not announcements. It may come later, or sooner. The margin calculation works for any year you pick.

There are serious sceptics

The largest number factored by a quantum computer is still 21. Part of the community finds 2029 alarmist. The prudent answer does not depend on who is right: starting the key-exchange switch is cheap.

Hardware moves slowly

Key vaults (HSMs), tokens and certificate authorities change generation every 3 to 5 years. Even with the software ready, the full switch may take longer than the specimen assumes.

The new locks are new too

ML-KEM and ML-DSA are recent standards. That is why hybrid exchange keeps the old lock alongside: a flaw in the new one does not leave the door open.

See also

← Post-quantum · stickybit.com.br

Sources