Q Day Planning
Why Q-Day is a poor basis for migration planning
Q-Day is shorthand for the point at which a quantum computer can break deployed public key cryptography. It is a useful communication device and a poor planning unit, because it compresses a probability distribution into a date, implies a single global event, and describes something that will not be observable when it happens.
What does post-quantum mean?
Post-quantum cryptography is conventional cryptography, run on ordinary computers, designed to resist attack by quantum computers. The post-quantum meaning is often misread as cryptography that uses quantum physics, which is a different field entirely.
The distinction matters because the two are procured and deployed differently. Post-quantum algorithms such as ML-KEM and ML-DSA are software, distributed through the same libraries, certificates and protocols already in use. Quantum key distribution uses physical properties of light over dedicated optical links, addresses only key exchange, and provides no authentication. The NCSC does not recommend it as a substitute for post-quantum cryptography in enterprise or government deployments.
Two related terms are used interchangeably in the market. Quantum-safe and quantum-resistant mean the same thing as post-quantum in practice. Quantum cryptography means the physics-based approach and should not be used to describe algorithms.
What Q-Day is meant to describe
Q-Day refers to the arrival of a cryptographically relevant quantum computer, meaning a machine able to run Shor's algorithm at the scale required to recover RSA and elliptic curve private keys.
As a communication device it works. It gives a board a single concept to hold, and it explains why an abstract mathematical development creates an operational obligation. The problem arises when the concept is used to schedule work.
Why Q-Day fails as a planning unit
It converts a distribution into a date
Expert opinion on quantum timelines is a wide distribution, not a consensus. The Global Risk Institute's Quantum Threat Timeline Report published in March 2026 found that between 28 and 49 per cent of surveyed experts assigned a probability above 50 per cent to a cryptographically relevant machine existing within ten years. That is a range spanning decades of planning implication. Selecting a single date from it discards the information that makes the estimate useful, which is the shape of the uncertainty.
Capability will be uneven, not simultaneous
There is no single threshold. Breaking a 256-bit elliptic curve key requires substantially fewer resources than breaking RSA-2048, and published estimates for the two have moved independently and by different amounts. The first machines will also be scarce, expensive and slow, which means an adversary will use them selectively against high-value long-lived keys rather than against traffic in general. Different algorithms, key sizes and asset classes therefore become vulnerable at different points, and a single date cannot express that.
The arrival will not be announced
A capability of this kind is a strategic asset before it is a product. There is no reason to expect disclosure, and detection at the victim is largely impossible: decryption of previously captured traffic leaves no trace, and a forged signature is only detectable if the organisation is monitoring for it. Planning that waits for confirmation is planning against an event that may never be confirmed.
It encourages deferral
The most damaging effect is behavioural. A date in 2035 reads as a decade of headroom, which invites the conclusion that action can wait. That conclusion holds only if migration is quick, and migration is not quick. In DigiCert's 2026 Quantum Readiness Outlook, 39 per cent of organisations expected full transition to take three to five years, the largest single group, and discovery is the longest single activity within that.
What post-quantum planning should measure instead
Six quantities carry actual planning information. Each is measurable, and five of the six are internal.

The first two are the core of a quantum risk assessment, and together they determine whether an organisation is early or late. Neither requires any view on when a quantum computer will exist.
How exposure actually accrues
Q-Day framing implies that risk begins on a date. It does not; it accrues differently for the two categories of cryptographic function.
Confidentiality exposure has already begun for long-lived data. Encrypted traffic captured today can be stored indefinitely and decrypted later. For any data class with a confidentiality requirement extending past the arrival of a capable machine, the exposure was created when the data crossed the network, not when the machine is built. Nothing done in future recovers that position.
Authentication exposure is different. A forged signature has no retrospective dimension: it becomes possible at the point of capability and enables immediate access. Compromised code signing keys, root certificates and long-lived credentials fall into this category, which is why platform providers brought forward their internal targets to 2029 as capability estimates shortened, prioritising authentication over encryption.
The practical instruction that follows is not to work back from a date. It is to protect long-lived confidential data now, because that exposure is live, and to prioritise long-lived signing keys next, because those are the assets an early and scarce capability would be aimed at.
Where Q-Day language is still useful
Q-Day retains value in board and stakeholder communication, provided it is presented as a distribution rather than a date. Stating that a material proportion of surveyed experts place a capable machine within ten years, and that published resource estimates have fallen by more than an order of magnitude since 2019, conveys the position accurately.
What should not be presented to a board is a countdown clock. Vendor material frequently uses one, and it is a marketing device rather than an analytical one. It replaces a range with a false precision that the underlying evidence does not support, and it is a reasonable signal to scrutinise the rest of the vendor's claims.
Common errors in post-quantum migration planning
The first is scheduling backwards from 2035. That date is the completion deadline in NCSC and NIST guidance, not the start point, and the NCSC expects discovery and an initial plan to be complete by 2028 with highest-priority migration done by 2031.
The second is planning a single cutover. There is no coordinated switch. Migration proceeds asset class by asset class, constrained by supplier availability and refresh cycles, over years.
The third is treating the whole estate as having one exposure profile. Exposure varies by data lifetime and asset longevity, and an averaged view conceals the classes that need action immediately.
The fourth is waiting for certainty about the threat before starting work that does not depend on it. Discovery, inventory, certificate lifecycle automation and crypto agility all deliver value regardless of when a capable machine appears, and all of them are prerequisites for migration whenever it happens.
How Unsung helps
Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, defence, healthcare, financial services and critical national infrastructure.
We build migration plans against measurable constraints rather than predicted dates, starting with discovery through our PKI health check and cryptographic bill of materials services, and continuing into target architecture and the certificate lifecycle management capability that makes algorithm change routine. Being vendor-neutral, we have no interest in accelerating a purchase by shortening a forecast.
For the algorithms themselves, see our comparison of the NIST post-quantum algorithms.
Frequently asked questions
What does post-quantum mean?
When is Q-Day expected?
Will we be told when a quantum computer can break encryption?
If Q-Day is decades away, why start now?
Is there a single date by which all cryptography becomes vulnerable?
Should we plan against 2035 or an earlier date?


