LatticeScan

Guide

When will a quantum computer break RSA?

The honest answer is that nobody knows, and anyone who gives you a confident date is guessing. What can be said clearly is this: no quantum computer today can break RSA or elliptic-curve encryption, the requirements to do so are enormous, and none of that is a reason to wait.

What it would actually take

Breaking RSA-2048 with Shor’s algorithm requires a quantum computer with thousands of stable, error-corrected qubits. Because real qubits are noisy, each stable logical qubit is built from many physical ones, so the physical-qubit count runs into the millions. Today’s most advanced machines have far fewer qubits than that, and they are not error-corrected at the scale required. The gap is large, and closing it is a hardware problem that has resisted easy prediction.

Why there is no firm date

Estimates from serious researchers range across the 2030s and beyond, and they move as the engineering does. Progress is real but not smoothly predictable: a breakthrough could pull the date in, and a hard wall could push it out. NIST and other standards bodies deliberately avoid naming a year, and instead treat the threat as a matter of when, not if. Basing a migration plan on a specific predicted date is a bet you do not need to make.

The deadline that actually governs you

Because of harvest now, decrypt later, the relevant deadline is not the arrival of the machine. It is how long your data must stay confidential. Data recorded today that must stay secret for ten years is already inside the risk window, whatever the exact break date turns out to be.

Regulators have turned that logic into fixed dates. In the United States, federal systems must move to post-quantum key establishment by the end of 2030 and to post-quantum signatures by the end of 2031. Draft NIST guidance proposes deprecating RSA and elliptic-curve algorithms after 2030 and disallowing them after 2035. Those dates, not a predicted quantum-computing milestone, are what a plan should be built around.

What that means in practice

Treat the break date as unknowable and act on the deadlines you can see. Inventory your cryptography, move key exchange to a post-quantum method where data has a long confidentiality lifetime, and keep your systems agile enough to swap algorithms again if estimates change. The organizations that wait for certainty will be doing this work under pressure; the ones that start now will not.

See where this stands for a real domain. Type one in and get a post-quantum readiness grade from its public connections, with the reasoning behind it.

Run a scan