Blog

Q Day Planning

Q-Day treats a probability distribution as a date. Learn the post-quantum meaning behind the term and the six planning units that replace it in practice.

Why Q-Day is a poor basis for migration planning

Q-Day is shorthand for the point at which a quantum computer can break deployed public key cryptography. It is a useful communication device and a poor planning unit, because it compresses a probability distribution into a date, implies a single global event, and describes something that will not be observable when it happens.

What does post-quantum mean?

Post-quantum cryptography is conventional cryptography, run on ordinary computers, designed to resist attack by quantum computers. The post-quantum meaning is often misread as cryptography that uses quantum physics, which is a different field entirely.

The distinction matters because the two are procured and deployed differently. Post-quantum algorithms such as ML-KEM and ML-DSA are software, distributed through the same libraries, certificates and protocols already in use. Quantum key distribution uses physical properties of light over dedicated optical links, addresses only key exchange, and provides no authentication. The NCSC does not recommend it as a substitute for post-quantum cryptography in enterprise or government deployments.

Two related terms are used interchangeably in the market. Quantum-safe and quantum-resistant mean the same thing as post-quantum in practice. Quantum cryptography means the physics-based approach and should not be used to describe algorithms.

What Q-Day is meant to describe

Q-Day refers to the arrival of a cryptographically relevant quantum computer, meaning a machine able to run Shor's algorithm at the scale required to recover RSA and elliptic curve private keys.

As a communication device it works. It gives a board a single concept to hold, and it explains why an abstract mathematical development creates an operational obligation. The problem arises when the concept is used to schedule work.

Why Q-Day fails as a planning unit

It converts a distribution into a date

Expert opinion on quantum timelines is a wide distribution, not a consensus. The Global Risk Institute's Quantum Threat Timeline Report published in March 2026 found that between 28 and 49 per cent of surveyed experts assigned a probability above 50 per cent to a cryptographically relevant machine existing within ten years. That is a range spanning decades of planning implication. Selecting a single date from it discards the information that makes the estimate useful, which is the shape of the uncertainty.

Capability will be uneven, not simultaneous

There is no single threshold. Breaking a 256-bit elliptic curve key requires substantially fewer resources than breaking RSA-2048, and published estimates for the two have moved independently and by different amounts. The first machines will also be scarce, expensive and slow, which means an adversary will use them selectively against high-value long-lived keys rather than against traffic in general. Different algorithms, key sizes and asset classes therefore become vulnerable at different points, and a single date cannot express that.

The arrival will not be announced

A capability of this kind is a strategic asset before it is a product. There is no reason to expect disclosure, and detection at the victim is largely impossible: decryption of previously captured traffic leaves no trace, and a forged signature is only detectable if the organisation is monitoring for it. Planning that waits for confirmation is planning against an event that may never be confirmed.

It encourages deferral

The most damaging effect is behavioural. A date in 2035 reads as a decade of headroom, which invites the conclusion that action can wait. That conclusion holds only if migration is quick, and migration is not quick. In DigiCert's 2026 Quantum Readiness Outlook, 39 per cent of organisations expected full transition to take three to five years, the largest single group, and discovery is the longest single activity within that.

What post-quantum planning should measure instead

Six quantities carry actual planning information. Each is measurable, and five of the six are internal.

The first two are the core of a quantum risk assessment, and together they determine whether an organisation is early or late. Neither requires any view on when a quantum computer will exist.

How exposure actually accrues

Q-Day framing implies that risk begins on a date. It does not; it accrues differently for the two categories of cryptographic function.

Confidentiality exposure has already begun for long-lived data. Encrypted traffic captured today can be stored indefinitely and decrypted later. For any data class with a confidentiality requirement extending past the arrival of a capable machine, the exposure was created when the data crossed the network, not when the machine is built. Nothing done in future recovers that position.

Authentication exposure is different. A forged signature has no retrospective dimension: it becomes possible at the point of capability and enables immediate access. Compromised code signing keys, root certificates and long-lived credentials fall into this category, which is why platform providers brought forward their internal targets to 2029 as capability estimates shortened, prioritising authentication over encryption.

The practical instruction that follows is not to work back from a date. It is to protect long-lived confidential data now, because that exposure is live, and to prioritise long-lived signing keys next, because those are the assets an early and scarce capability would be aimed at.

Where Q-Day language is still useful

Q-Day retains value in board and stakeholder communication, provided it is presented as a distribution rather than a date. Stating that a material proportion of surveyed experts place a capable machine within ten years, and that published resource estimates have fallen by more than an order of magnitude since 2019, conveys the position accurately.

What should not be presented to a board is a countdown clock. Vendor material frequently uses one, and it is a marketing device rather than an analytical one. It replaces a range with a false precision that the underlying evidence does not support, and it is a reasonable signal to scrutinise the rest of the vendor's claims.

Common errors in post-quantum migration planning

The first is scheduling backwards from 2035. That date is the completion deadline in NCSC and NIST guidance, not the start point, and the NCSC expects discovery and an initial plan to be complete by 2028 with highest-priority migration done by 2031.

The second is planning a single cutover. There is no coordinated switch. Migration proceeds asset class by asset class, constrained by supplier availability and refresh cycles, over years.

The third is treating the whole estate as having one exposure profile. Exposure varies by data lifetime and asset longevity, and an averaged view conceals the classes that need action immediately.

The fourth is waiting for certainty about the threat before starting work that does not depend on it. Discovery, inventory, certificate lifecycle automation and crypto agility all deliver value regardless of when a capable machine appears, and all of them are prerequisites for migration whenever it happens.

How Unsung helps

Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, defence, healthcare, financial services and critical national infrastructure.

We build migration plans against measurable constraints rather than predicted dates, starting with discovery through our PKI health check and cryptographic bill of materials services, and continuing into target architecture and the certificate lifecycle management capability that makes algorithm change routine. Being vendor-neutral, we have no interest in accelerating a purchase by shortening a forecast.

For the algorithms themselves, see our comparison of the NIST post-quantum algorithms.

Frequently asked questions

What does post-quantum mean?

Post-quantum cryptography means conventional algorithms, running on ordinary computers, designed to resist attack by quantum computers. It does not mean cryptography that uses quantum physics. Quantum-safe and quantum-resistant are used interchangeably with it, while quantum cryptography refers to the physics-based approach such as quantum key distribution.

When is Q-Day expected?

There is no agreed date. Surveyed experts place a capable machine across a range spanning roughly a decade to several decades, and published resource estimates for breaking RSA-2048 have fallen substantially since 2019. National guidance uses 2035 as a migration completion deadline, which is a policy date rather than a prediction.

Will we be told when a quantum computer can break encryption?

Probably not at the point it happens. The first such capability would most likely be state-held and treated as classified. Detection at the victim is also unlikely, since decryption of harvested traffic leaves no trace and forged signatures are only visible where monitoring exists.

If Q-Day is decades away, why start now?

Because migration duration, not the threat date, is the binding constraint. In DigiCert's 2026 survey, 39 per cent of organisations expected full transition to take three to five years, and discovery is the longest single activity within that. Long-lived confidential data is also exposed from the moment it is transmitted, regardless of when the capability arrives.

Is there a single date by which all cryptography becomes vulnerable?

No. Different algorithms and key sizes require different quantum resources, and early machines will be scarce and slow. Elliptic curve keys are expected to fall before larger RSA keys, and a limited capability would be directed at high-value long-lived keys rather than used broadly.

Should we plan against 2035 or an earlier date?

Plan against 2031 at the latest. The NCSC expects highest-priority migration complete by then, US federal key establishment deadlines fall in 2030, and major platform providers have set internal targets of 2029. Working to 2035 assumes the most favourable available estimate of the threat.
Author
Unsung Ltd
October 22, 2026
-