The quantum industry has spent years debating Q-Day » the point at which a cryptographically relevant quantum computer can break the public-key systems protecting digital communications, identities and software. The date matters. But it is the wrong deadline for most organisations.
No board can schedule investment around a date that remains fundamentally uncertain. Q-Day depends not on one breakthrough but on several arriving together: better physical qubits, fault-tolerant error correction, efficient decoding and control, enough engineering scale, and algorithms capable of turning that machinery into a practical cryptanalytic system. Expert estimates can inform risk models, but they cannot produce the certainty of a depreciation schedule or a regulatory deadline. Even specialists acknowledge that the threat timeline is not known.
Table of Content
The date is uncertain. The exposure is not.
The clock starts before Q-Day
Infrastructure cannot patch itself overnight
Quantum impact will arrive unevenly
Standards are the starting gun, not the finish line
Governments are planning for migration, not prediction
Find the cryptography before trying to replace it
Procurement is where strategy becomes real
Crypto-agility is the real destination
The deadline is your own upgrade cycle
1. The date is uncertain. The exposure is not.
That uncertainty is often used to justify delay. It should have the opposite effect.
The mistake is to treat quantum risk as a forecasting problem when it is really a problem of decision-making under uncertainty. An organisation does not need to know the exact arrival date of a cryptographically relevant quantum computer. It needs to know whether the data and systems it is deploying now will remain exposed when one becomes available.
A more useful test has three variables:
the required lifetime of the information,
the time needed to migrate the systems protecting it, and
the estimated time to the threat.
If data must remain confidential for ten years and migration will take six, waiting for a high-confidence five-year warning is already too late. The same logic applies to digital signatures, device identities and roots of trust that may remain embedded in products for years or decades.
2. The clock starts before Q-Day.
This is why “harvest now, decrypt later” is not just a slogan about a distant future. An adversary can collect encrypted traffic today and retain it until the means to decrypt it becomes available. US federal policy has explicitly prioritized cryptographic inventories for systems containing data that would still be sensitive if captured now and decrypted in 2035/
The exposure clock therefore starts when information is intercepted, not when the first large-scale quantum attack is publicly confirmed. For organisations holding long-lived intellectual property, critical infrastructure data, defence-related information or regulated personal data, that difference is decisive.
3. Infrastructure cannot patch itself overnight.
For critical infrastructure, the problem is broader than stored secrets.
A rail network, energy operator, telecoms provider or industrial manufacturer depends on cryptography for remote access, equipment authentication, secure boot, signed firmware, software updates, machine identities, private networks and supplier connections.
These environments are difficult to change by design. Operational assets often remain in service for many years, maintenance windows are limited, safety and availability take precedence, and the operator may not control the firmware, silicon, certificates or cryptographic libraries embedded in the system. CISA’s guidance for operational technology therefore stresses prioritisation by criticality, connectivity, protected function and data lifetime.
4. Quantum impact will arrive unevenly.
Q-Day is a poor metaphor because it implies a single global event after which everything changes at once. In reality, the first useful cryptanalytic capability is likely to be scarce, selective and applied first against the highest-value targets.
A technically capable machine is not automatically an operational cryptanalytic service. Its usefulness will depend on reliability, throughput, access, target selection and the strategic value of each use. The first affected organisations may therefore face a very different deadline from the broader market.
5. Standards are the starting gun, not the finish line.
NIST finalized its first three principal post-quantum standards in August 2024.
ML-KEM for key establishment and ML-DSA and SLH-DSA for signatures
and now advises organisations to begin migration. That is a major milestone, but publishing algorithms does not instantly make products, protocols, validation regimes and supply chains ready.
Implementation, interoperability, performance tuning, certification and operational testing still need to happen across a fragmented technology estate. That is especially hard in sectors where hardware, embedded software and fielded devices have long replacement cycles.
6. Governments are planning for migration, not prediction.
This is already visible in public policy. The UK National Cyber Security Centre expects large organisations to complete discovery and planning by 2028, complete high-priority migrations by 2031 and finish migration across systems, services and products by 2035.
The European Commission has said Member States should start transitioning to post-quantum cryptography by the end of 2026 and move critical infrastructure no later than the end of 2030. In the United States, 2026 federal policy accelerated priority migrations for key establishment to 2030 and digital signatures to 2031, while retaining 2035 for the broader estate.
These dates are not forecasts of Q-Day.
They are evidence that governments see migration lead time - not prediction accuracy -as the binding constraint.digital-strategy.
7. Find the cryptography before trying to replace it.
For boards, the immediate objective should be to reduce migration time and preserve options. That starts with cryptographic discovery:
identifying where vulnerable public-key algorithms are used,
what business process each use supports,
which data or control function is protected,
who owns the system and which supplier controls the upgrade path.
The next task is prioritization.
Not every use of RSA or elliptic-curve cryptography carries the same risk. Long-lived confidential data should move early because retrospective decryption is possible, while long-lived signatures, update mechanisms and roots of trust deserve special attention because replacing them may require coordinated changes across hardware, firmware, PKI and fielded assets.
8. Procurement is where strategy becomes real.
Procurement may become the most effective migration tool.
Requirements for post-quantum support, upgradeable cryptographic modules, algorithm transparency, supported product lifetimes and documented migration paths can shift the burden upstream to suppliers.
A supplier that cannot explain where cryptography sits in its product, how algorithms can be replaced, or what happens to deployed devices during an update is not offering crypto-agility. It is transferring future replacement cost and operational risk to the buyer.
9. Crypto-agility is the real destination.
This is the deeper commercial point. The market opportunity is not simply to label products “quantum-safe.” It is to help customers discover hidden dependencies, test implementations, redesign key-management processes, validate performance on constrained devices and coordinate change across suppliers and operators.
Crypto-agility is therefore the durable outcome.
It means designing products and protocols so that algorithms, keys, certificates and trust anchors can be replaced without rebuilding the whole system. NCSC guidance for operational technology explicitly recommends protocols that can switch cryptographic algorithms so that a product’s operational lifetime is not constrained by the lifetime of its cryptography.
Conclusion
Post-quantum migration should not be framed as a one-off cybersecurity patch. It is closer to infrastructure renewal:
it reaches into asset management, enterprise architecture, product engineering, procurement, supplier assurance and capital planning.
Q-Day remains a useful shorthand for a real and serious threat. But it becomes a dangerous planning tool when it encourages organisations to wait for a definitive signal. By the time a cryptographically relevant quantum computer is demonstrated -or publicly disclosed, the real deadline may already have passed for data already harvested, products already shipped and infrastructure that cannot be replaced quickly.
Now, this is only the first question, not the final answer. I’ll expand this to a Deep Dive later where I will map the real post-quantum migration challenge from cryptographic inventories and software supply chains to secure firmware, long-lived assets and crypto-agility, because the decisive risk is no longer merely when Q-Day arrives, but whether critical systems can move in time.




