Quantum Computing Quantum Threat

The Quantum Threat in Five Ideas

The threat to cryptography is the most investable part of the theme because its demand is driven by regulation and timelines, not by whether quantum computers work yet. A future fault-tolerant machine would break the encryption that secures the internet.
ConceptWhat it means
Q-DayThe day a quantum computer can break RSA-2048 and elliptic-curve cryptography. Consensus estimates cluster around 2030, give or take a few years.
Harvest now, decrypt laterAdversaries capture encrypted data today to decrypt once a quantum computer exists, so long-lived secrets are already at risk regardless of when Q-Day actually arrives.
Shor's algorithmThe quantum algorithm that breaks RSA and elliptic-curve cryptography. It needs a large fault-tolerant machine that does not yet exist at scale.
Post-quantum cryptographyNew encryption based on math believed hard even for quantum computers. NIST finalized the first standards in 2024 and the migration can start now.
Mandated spendOMB estimates roughly $7.1B for US federal civilian agencies alone (2025 to 2035); private-sector and global spend is a large multiple, and the deadlines are fixed.

NIST Post-Quantum Cryptography Standards

The standardized algorithms that replace today's quantum-vulnerable encryption. NIST finalized the first three in August 2024, with two more on the way as backups based on different underlying math.
StandardAlgorithmStatus
FIPS 203ML-KEM (from Kyber)Final (Aug 2024)
FIPS 204ML-DSA (from Dilithium)Final (Aug 2024)
FIPS 205SLH-DSA (from SPHINCS+)Final (Aug 2024)
FIPS 206FN-DSA (from FALCON)Draft
FIPS 207HQCSelected 2025, target 2027

Post-Quantum Migration Deadlines

The binding government deadlines forcing the migration to post-quantum cryptography. The clustering of hard dates between 2027 and 2035 is what makes this a near-certain, multi-year spend across government, defense, finance, and infrastructure.
USEUFranceUK

Post-Quantum Security Vendors

Companies selling into the migration, by layer. The pure-plays are tiny-revenue and narrative-sensitive; the large-caps treat post-quantum cryptography as one feature among many. This is the investable surface of the quantum threat.
CompanyTicker
Arqit QuantumARQQ
SEALSQLAES
Quantum eMotionQNC
CloudflareNET
Palo Alto NetworksPANW
IBMIBM
ThalesHO
ID Quantique / QuantinuumIONQ / QNT

Expert Survey: Likelihood of a CRQC

Global Risk Institute 2025 survey of 26 experts. Averaged likelihood of a cryptographically relevant quantum computer is 28 to 49 percent within 10 years and 51 to 70 percent within 15 years, depending on how responses are read. Expert opinion, not a scheduled date.

What the $7.1B Federal PQC Figure Includes

OMB and ONCD's July 2024 rough order of magnitude for prioritized federal civilian systems, 2025 to 2035, in 2024 dollars. National-security systems and the private sector are outside this number. Agencies must update the estimate annually.
ScopeAmount
Prioritized federal civilian systems$7.1B (2024 dollars)
National-security systemsNot in the $7.1B
State, local, and private sectorNot estimated here

Harvest Now, Decrypt Later

Why the migration is already a spend even though a cryptographically relevant quantum computer does not exist. Adversaries can record ciphertext today. NIST, CISA, and OMB treat long-lived secrets as already inside that window. Explanation, not a recommendation.
IdeaDetail
The recording is happening nowEncrypted traffic and stored ciphertext can be copied today. Decryption is deferred until a CRQC exists. The harvest does not wait for Q-Day.
Data lifetime vs Q-DayIf a secret must stay secret for 20 years and experts put a non-trivial CRQC probability inside 15 years, that secret is already inside the HNDL window.
What is most exposedLong-lived classified records, health data, legal archives, industrial IP, and any public-key handshake that will still matter after a CRQC arrives.
Why mandates do not waitNIST IR 8547 deprecates RSA/ECC in 2030 and disallows them in 2035. NSA CNSA 2.0 and OMB inventories run on the same logic: migration lead times are longer than remaining secrecy windows.
What this is notHNDL is not proof that a CRQC is imminent. It is the reason regulators treat PQC as a cryptography-modernization program rather than a quantum-hardware bet.
Sterling

Prefer Sterling in Google

Add sterlingcharts.com as a preferred source so our charts can appear with a preferred badge in Google Top Stories, AI Mode, and AI Overviews.

Add as preferred source

Ask Sterling

Register for a premium account to gain access to Sterling AI.

Get Started

Things you can ask Sterling:

Summarize Tesla's latest earnings reportWhy did NVIDIA's margins expand?Compare Apple vs Microsoft's cash flowWhat's driving EV industry growth?
Menu
Favorites
Quantum Computing Quantum Threat: Market Data | Sterling