What is Q-Day? A plain English FAQ [2026]

Started by MemoryAnchor, Today at 08:41 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: What is Q-Day? A plain English FAQ [2026]   Views(Read 20 times)
Active members in this topic:
MemoryAnchor(1)

MemoryAnchor

This forum is named after Q-Day, so it seems right to have a clear, sourced explanation of what it means. The term gets used loosely in headlines, sometimes to frighten people and sometimes to sell products. This FAQ sets out what Q-Day is, what it would and would not break, what the experts think about timing and what is being done about it. Every answer is based on official guidance or published research, linked at the bottom

The questions

1. What is Q-Day? It is the point when a quantum computer becomes powerful enough to break the public key encryption that protects much of the internet. The UK's NCSC calls such a machine a cryptographically relevant quantum computer, or CRQC. It is sometimes called Y2Q, a nod to the Y2K bug
2. What would it break? Public key systems based on factoring or discrete logarithms. The NCSC lists RSA, Diffie-Hellman, ECDH, DSA, ECDSA and EdDSA. These protect website connections, VPNs, digital signatures, software updates and cryptocurrencies
3. What would it not break? According to the NCSC, symmetric encryption with keys of at least 128 bits, such as AES, can continue to be used, and hash functions such as SHA-256 are not significantly affected. Your encrypted files and strong passwords are not the main target
4. Does a machine like that exist today? No. Today's leading quantum computers have somewhere from around a hundred to a few thousand physical qubits, and their error rates are still far too high to run the long calculations needed
5. How big would it need to be? In May 2025, Google's Craig Gidney estimated that RSA-2048 could be factored in under a week with fewer than one million noisy qubits, down from 20 million in a 2019 estimate. In March 2026, Google Quantum AI estimated that the elliptic curve used by Bitcoin could be broken with fewer than half a million physical qubits. The estimates keep falling as algorithms improve
6. When will it happen? Nobody knows. In the Global Risk Institute's latest Quantum Threat Timeline Report, published in March 2026, 26 experts judged a CRQC within 10 years to be quite possible, at 28 to 49 percent, and within 15 years to be likely, at 51 to 70 percent
7. Would anyone announce it? Not necessarily. A government or organisation that built one might keep quiet, which is one reason security agencies want the switch to new encryption done well in advance
8. What is harvest now, decrypt later? NIST describes it as adversaries collecting encrypted data now with the goal of decrypting it once quantum technology matures. It means data with long term value, such as health, legal or state secrets, is already at risk today
9. What is Mosca's theorem? A simple rule from Michele Mosca. If the number of years your data must stay secret, plus the years it takes you to migrate, is greater than the years until a CRQC exists, you have a problem now
10. What is being done? NIST published the first post quantum standards, ML-KEM, ML-DSA and SLH-DSA, in August 2024, and picked HQC as a backup in March 2025. Browsers, Apple devices, Signal and OpenSSH already use post quantum key exchange by default
11. What are the official deadlines? The NCSC wants organisations to plan by 2028, migrate priority systems by 2031 and finish by 2035. NIST's draft transition plan deprecates vulnerable algorithms after 2030 and disallows them after 2035. The NSA requires new US national security purchases to be compliant from 2027 and all such systems to be quantum resistant by 2035
12. What should ordinary people do? Keep devices and software updated. The NCSC says that for most users the switch will arrive as part of normal software updates and should happen seamlessly. Businesses should ask their suppliers about post quantum plans
13. What about Bitcoin? Google's March 2026 paper estimates that around 6.7 to 6.9 million bitcoin sit in addresses with exposed public keys. There is a separate thread on the forum covering where the Bitcoin proposals stand

Q-Day is a real risk with an uncertain date, not a fixed deadline and not a myth. The sensible response is steady preparation rather than panic. If you have a question that is not covered here, reply below and it can be added to the list

Last updated: 4 October 2026

Sources:



https://quantumai.google/static/site-assets/downloads/cryptocurrency-whitepaper.pdf
Quantum Threat Timeline Report 2025 - Global Risk Institute
https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
NIST Releases First 3 Finalized Post-Quantum Encryption Standards
https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF
Michele Mosca - Wikipedia