Skip to content
ContentLora

    Tip: press / anywhere to search.

    Analysis

    How fast must we move to post-quantum cryptography?

    Nobody knows when a quantum computer will break today's public-key cryptography, but in 2026 Google and Cloudflare moved their own migration targets to 2029, earlier than the 2030-2035 deadlines most governments have set.[1][2][3][4][5] The debate is over how much to accelerate, given shrinking attack estimates, the slowness of past migrations and the risk of rushing young algorithms.[6][7][8]

    Editor reviewedStrict sourcingUpdated Post-quantum cryptography and securityTech policyComputing
    Show:

    The question

    Everyone agrees on the destination: replacing RSA and elliptic-curve cryptography with post-quantum algorithms. The disagreement is about pace. Should organizations treat 2035 as the finish line, as US National Security Memorandum 10 and the UK NCSC do, or aim for 2029, as Google and Cloudflare now do?[9][5][2][3]

    What we know

    • No one knows when a cryptographically relevant quantum computer will exist. NIST says expert estimates range from a few years to a few decades.[1]
    • Attack estimates fell. The qubit count for RSA-2048 dropped from 20 million (2019) to under a million (2025).[10] In March 2026 Google put 256-bit elliptic-curve cryptography at under 500,000 physical qubits running for a few minutes.[6] Cloudflare reported an Oratomic estimate of about 10,000 neutral-atom qubits for P-256, with key details withheld.[11]
    • Past migrations have taken 10 to 20 years from standard to full deployment.[7]
    • Government deadlines: the US executive order of June 2026 sets 31 December 2030 for post-quantum key establishment and 31 December 2031 for signatures in high-value and high-impact federal systems.[4] The UK NCSC sets 2028, 2031 and 2035 milestones.[5] The EU wants all member states to start by the end of 2026 and high-risk uses moved by the end of 2030.[12] NIST’s draft plan would deprecate 112-bit RSA and ECC after 2030 and disallow quantum-vulnerable algorithms after 2035.[13] NSA’s CNSA 2.0 suite expects US national security systems to complete the transition by 2035, with exclusive use of the new algorithms required earlier for some product types: 2030 for networking equipment and 2033 for operating systems.[14] The EU roadmap aims to move as many systems as practically feasible by 2035. Its FAQ notes that Australia’s end-2030 target is the most ambitious among the governments it compares.[15][16]
    • Corporate targets: Google set 2029 in March 2026 and Cloudflare followed in April. Both now prioritize authentication.[2][17][3]
    • In September 2026 the G7 cybersecurity working group said recent advances suggest such quantum computers may come sooner than anticipated.[18]

    Three views

    Accelerate. The case for 2029 rests on the trend more than any single estimate. Each new resource estimate has been lower than the last. Elliptic-curve cryptography, the basis of most web authentication, now looks cheaper to break than RSA.[10][6] If migrations take a decade or more, waiting for clear evidence of a working machine means finishing too late.[7] Large platforms can move faster than governments: over 65% of human traffic to Cloudflare was already post-quantum encrypted by April 2026.[19]

    Government deadlines are enough. NIST’s range of expert estimates runs from a few years to a few decades, so a cryptographically relevant machine before the 2030-2035 deadlines is possible but far from established.[1] Staged deadlines let organizations inventory systems first, as the NCSC’s 2028 discovery milestone intends. They also put the most sensitive systems first, which is how the US order is built.[5][4] Forcing every organization onto a platform company’s schedule could waste money on rushed, low-quality migrations.

    Agility over speed. New algorithms carry their own risk. SIKE was broken by a classical attack after reaching NIST’s fourth round.[8] NIST is keeping backups based on different math, hqc and slh-dsa.[20][21] Hybrids stay secure if either component holds, but NIST warns they add complexity.[22][23] Cloudflare argued that the US order should define “done” to include turning off quantum-vulnerable cryptography, and that it ignores crypto-agility.[24] On this view, the priority is building systems that can change algorithms again. See crypto-agility.

    What to watch

    Signals that would favour acceleration: further drops in resource estimates, or error-corrected logical qubits scaling faster than roadmaps (see quantum computing crash course). Signals pointing the other way: hardware progress stalling at today’s scale. Key policy markers are OMB’s implementation of the US order, the FAR rule for contractors, the EU’s end-2026 national roadmaps and finalization of NIST IR 8547.[25][12][26] Our expectation, held with moderate confidence: more large technology companies will adopt 2029-2030 targets during 2027. Most regulated sectors will plan to the 2030-2035 government dates.

    Competing views

    Accelerate: aim for 2029

    Attack estimates fell sharply in 2025-2026 and the G7 warns quantum computers may come sooner than thought. Google and Cloudflare now target 2029, including authentication.[2][3][6][18]

    Government deadlines are the right pace

    Timing is genuinely uncertain, from a few years to a few decades. Staged deadlines from 2028 to 2035 balance urgency with what large organizations can actually deliver.[1][5][4][12]

    Speed matters less than agility and hedging

    Post-quantum candidates have failed before. Hybrids, backup algorithms and the ability to swap algorithms protect against both quantum computers and flaws in the new math.[8][22][20][24]

    Questions readers ask

    When is "Q-Day", the day a quantum computer breaks current encryption?

    Unknown. NIST says expert estimates range from a few years to a few decades.[1]

    What are the main government deadlines?

    The US requires its most sensitive federal systems to use post-quantum key establishment by the end of 2030 and signatures by the end of 2031. The UK NCSC targets full migration by 2035, and the EU wants high-risk uses moved by the end of 2030.[4][5][12]

    Why did Google and Cloudflare pick 2029?

    Google cited progress in quantum hardware, error correction and factoring estimates. Cloudflare pointed to new 2026 estimates from Google and Oratomic for breaking elliptic-curve cryptography.[2][11]

    Is it risky to deploy new post-quantum algorithms quickly?

    It carries some risk. SIKE was broken in 2022 after reaching NIST's fourth round. That is why most deployments use hybrids, which stay secure if either component holds.[8][22]

    Sources

    Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.

    1. [1]

      NIST says no one knows when a quantum computer able to threaten current encryption will appear, with expert estimates ranging from a few years to a few decades. confirmedas of 2026-10-10

    2. [2]

      On 25 March 2026 Google set 2029 as its timeline for post-quantum cryptography migration, citing progress in quantum hardware, quantum error correction and factoring resource estimates. confirmedas of 2026-03-25

    3. [3]

      On 7 April 2026 Cloudflare said it was targeting full post-quantum security, including authentication, across its entire product suite by 2029. confirmedas of 2026-04-07

    4. [4]

      The order requires agencies to move all high value assets and high-impact systems to PQC for key establishment by 31 December 2030 and for digital signatures by 31 December 2031. confirmedas of 2026-06-25

    5. [5]

      The UK NCSC's March 2025 guidance sets three milestones, define goals and complete discovery by 2028, carry out the highest-priority migration by 2031, and complete migration of all systems by 2035. confirmedas of 2025-03-20

    6. [6]

      In March 2026 Google researchers estimated that breaking 256-bit elliptic-curve cryptography would need fewer than 1,200 logical qubits and 90 million Toffoli gates, or under 500,000 physical superconducting qubits running for a few minutes. confirmedas of 2026-03-31

    7. [7]

      NIST says it has historically taken 10 to 20 years from the standardization of a new algorithm until it is fully integrated into information systems. confirmedas of 2026-10-10

    8. [8]

      In 2022 researchers at KU Leuven published a classical attack that broke SIKEp434, an instance of the isogeny-based SIKE scheme then in NIST's fourth round, in about ten minutes on a single core. confirmedas of 2022-07-30

    9. [9]

      US National Security Memorandum 10 sets 2035 as the goal for mitigating as much quantum risk as feasible across federal systems. confirmedas of 2024-11-12

    10. [10]

      A May 2025 Google preprint estimated that 2048-bit RSA could be factored in less than a week by a quantum computer with fewer than a million noisy qubits, down from a 2019 estimate of 20 million noisy qubits. confirmedas of 2026-10-10

    11. [11]

      Cloudflare reported that the company Oratomic published a resource estimate in 2026 suggesting P-256 elliptic-curve cryptography could be broken with about 10,000 qubits on a neutral-atom quantum computer, while withholding some details. reportedas of 2026-04-07

    12. [12]

      Under the EU coordinated roadmap adopted in June 2025, all member states should start transitioning to PQC by the end of 2026, and high-risk use cases should move to PQC no later than the end of 2030. confirmedas of 2025-06-23

    13. [13]

      NIST's draft transition plan (IR 8547, November 2024) proposes deprecating RSA and elliptic-curve algorithms at 112-bit security after 2030 and disallowing quantum-vulnerable public-key algorithms after 2035. confirmedas of 2024-11-12

    14. [14]

      NSA's CNSA 2.0 advisory expects US national security systems to complete the move to quantum-resistant algorithms by 2035, in line with NSM-10, and sets earlier dates for using CNSA 2.0 algorithms exclusively, such as 2030 for software and firmware signing and networking equipment and 2033 for operating systems. confirmedas of 2022-09-07

    15. [15]

      The EU's coordinated PQC roadmap says the transition should be completed for as many systems as practically feasible by 2035, and that quantum-vulnerable public-key mechanisms should not be used on their own after the end of 2030 for high-risk use cases or after the end of 2035 for medium-risk ones. confirmedas of 2025-06-11

    16. [16]

      An April 2026 EU FAQ on the roadmap says its 2035 target matches the UK, US and Canadian timelines, while Australia's signals directorate recommends finishing migration by the end of 2030. confirmedas of 2026-04-15

    17. [17]

      Google said it had adjusted its threat model to prioritize post-quantum migration of authentication services and digital signatures, and recommended other engineering teams do the same. confirmedas of 2026-03-25

    18. [18]

      The G7 Cybersecurity Working Group said in September 2026 that several recent advances suggest quantum computers able to break widely used public-key cryptography may be developed sooner than anticipated. confirmedas of 2026-09-03

    19. [19]

      As of April 2026, Cloudflare said over 65% of human traffic to its network was post-quantum encrypted. confirmedas of 2026-04-07

    20. [20]

      On 11 March 2025 NIST selected HQC as a backup to ML-KEM for general encryption, built on error-correcting codes rather than structured lattices. confirmedas of 2025-03-11

    21. [21]

      NIST described SLH-DSA as a backup signature method in case ML-DSA proves vulnerable. confirmedas of 2024-08-13

    22. [22]

      Hybrid schemes combine a quantum-resistant and a classical algorithm and are typically designed to stay secure if at least one of the two components is secure. confirmedas of 2024-11-12

    23. [23]

      NIST notes that hybrid solutions add complexity, which can raise security risks and costs, and expects them to be temporary steps toward a second transition to PQC-only tools. confirmedas of 2024-11-12

    24. [24]

      Cloudflare called the executive order an important milestone but argued that it needs a clear definition of "done" that includes disabling quantum-vulnerable cryptography, and that it says nothing about crypto-agility. confirmedas of 2026-06-23· interpretation

    25. [25]

      The order directs the FAR Council to propose a rule requiring covered federal contractors to comply with NIST's post-quantum FIPS by 31 December 2030. confirmedas of 2026-06-25

    26. [26]

      As of October 2026 NIST IR 8547 remained an initial public draft dated 12 November 2024. confirmedas of 2026-10-10

    Revision history (2)
    1. Page created.
    2. Added NSA CNSA 2.0 and EU 2035 deadlines from primary documents.

    Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.

    Cite this page

    "How fast must we move to post-quantum cryptography?." ContentLora, updated Oct 10, 2026. https://contentlora.com/analysis/pqc-migration-timeline-debate

    Spotted an error? Suggest a correction or emailcorrections@contentlora.com.