hourglass
– Getty Images

Q-day is shorthand for the point when a cryptographically relevant quantum computer can break widely used public-key cryptography.

Preparations for Q-day have drawn comparisons with Y2K, but the analogy is useful only up to a point. Before the calendar rolled over to 2000, organizations had to find, update, and test systems that might mishandle the new date. PQC migration requires a similarly extensive technology overhaul, but without Y2K’s fixed deadline.

What is post-quantum cryptography?

Post-quantum cryptography (PQC) uses mathematical algorithms designed to resist attacks by conventional and quantum computers. Unlike quantum key distribution (QKD), which requires specialized quantum communications hardware to distribute keys, PQC can run on existing computing and network infrastructure.

Current RSA and elliptic-curve cryptography secure online connections, digital identities, and software signatures with public keys that mathematical problems and conventional computers find extremely difficult to handle. A sufficiently powerful quantum computer could solve those problems efficiently. Symmetric encryption, where one shared key both encrypts and decrypts data, faces a less severe threat, and sufficiently large keys can generally preserve security.

In 2024, The National Institute of Standards and Technology (NIST) finalized its first three PQC standards. Module lattice-based key-encapsulation mechanism (ML-KEM) enables two parties to establish a shared secret key; module lattice-based digital signature (ML-DSA) provides digital signatures; and stateless hash-based digital signature algorithm (SLH-DSA) is an alternative hash-based signature standard built on different mathematical foundations, providing a backup should ML-DSA prove vulnerable.

Why prepare before Q-day?

Waiting for quantum computers to break today’s cryptography would be too late. Attackers can collect encrypted information now and retain it until a future quantum computer can decrypt it, a threat known as “harvest now, decrypt later” or “store now, decrypt later.”

The urgency depends on how long data must remain confidential and how long the systems protecting it will take to migrate. Organizations should prioritize information with a long confidentiality lifetime, particularly information held in complex or difficult-to-update infrastructure.

Confidentiality and authentication run on different clocks. Harvest now, decrypt later makes confidentiality a present concern. Signature forgery becomes possible once a sufficiently capable quantum computer exists, but authentication may take longer to migrate because certificates, hardware roots of trust, software-signing systems, and third parties form complex dependency chains.

The practical question is not when Q-day will arrive, but whether vulnerable cryptography can be replaced before it does.

What is driving PQC migration now?

That urgency is translating into deadlines and production deployments. NIST says organizations should begin migrating now. Under its proposed transition timetable, NIST expects to remove quantum-vulnerable algorithms from its standards by 2035, with high-risk systems transitioning earlier.

The U.K.’s National Cyber Security Centre (NCSC) sets more specific milestones: discovery and initial planning by 2028, priority migrations by 2031, and completion by 2035.

Major infrastructure providers are moving faster. Google Cloud plans full PQC readiness by 2029, and already supports hybrid ML-KEM across several services. Cloudflare is also targeting 2029. Its Automatic Key Exchange has helped increase post-quantum protection between its network and origin servers to around 45 billion connections per day.

How should organizations prepare?

Preparation begins with finding where vulnerable cryptography is used. The NCSC recommends mapping key services and applications, the data they process, how it is protected in transit and at rest, and its expected lifetime. An inventory should also cover algorithms, keys, certificates, protocols, software libraries, hardware, suppliers, and third-party services.

That inventory provides the basis for assessing risk. Internet-facing services, critical systems, long-lived infrastructure, and information that must remain confidential for years should come first.

Testing should use representative environments rather than isolated demonstrations. Larger public keys, signatures, and certificates can affect network bandwidth and latency, constrained hardware, interoperability, and operational processes.

PQC algorithms can also change compute and memory requirements. For example, hybrid implementations by Amazon Web Services (AWS) measured between 80 and 150 microseconds of additional compute time per transport-layer security (TLS) "handshake" for operations using ML-KEM cryptography.

Migration should be phased rather than treated as a single upgrade. Hybrid approaches combine classical and post-quantum algorithms during the transition. Systems should also be "crypto-agile," allowing algorithms to be replaced without rebuilding entire applications or networks.

What should organizations ask their suppliers?

An organization cannot complete its migration while critical suppliers remain dependent on vulnerable cryptography. It should establish which NIST standards each provider supports, a timetable, and who is responsible for upgrading certificates, libraries, hardware, and integrations.

PQC support alone is insufficient. Organizations should ask how products prevent systems from downgrading to vulnerable algorithms in the event of an attack. They also need to know how they maintain interoperability, accommodate future standards, and whether monitoring and audit capabilities show which protections are active.

The aim is to assess each supplier’s complete migration path, including its own dependencies, rather than accept a “quantum-safe” label.

Prepare for readiness, not a prediction

Organizations do not need to predict Q-day. They need visibility into their cryptography, a risk-based migration plan, and infrastructure that can adapt as standards evolve. Q-day itself may be uncertain, but waiting for certainty is no longer a viable migration strategy.