When will quantum computers break encryption?
Nobody knows, and anyone who gives you a confident date is selling something. Here is what is actually known, what the experts estimate, and why the answer matters less than people assume.
Read this first
There is no known date, and the honest answer is a probability rather than a year. The surveys that ask working experts put the odds of a capable machine within fifteen years at roughly half. The reason to act now is not that the date is near; it is that the deadline for anything with a long confidentiality requirement already passed, because data recorded today can be decrypted whenever that machine arrives.
What would actually have to happen
Today's public-key cryptography, RSA and elliptic curve, rests on two maths problems that classical computers cannot solve at scale: factoring very large numbers, and computing discrete logarithms. In 1994 Peter Shor showed that a sufficiently large quantum computer could solve both efficiently. That result has never been in doubt. What is in doubt is the engineering.
The machines that exist today are not small versions of the machine that would break RSA. Their qubits are noisy, and running Shor's algorithm on cryptographically relevant key sizes requires error correction, which means combining very many physical qubits into a much smaller number of reliable logical ones. The gap between current hardware and that requirement is several orders of magnitude, and closing it is a materials and engineering problem rather than a mathematical one. That is precisely why nobody can put a date on it: engineering timelines of that kind are not predictable, in either direction.
What the people who work on it estimate
The most useful signal is not a single prediction but the spread of them. The annual Quantum Threat Timeline report surveys leading researchers and publishes the distribution of their views. Its 2025 edition puts the aggregate likelihood of a cryptographically relevant quantum computer at roughly 28 to 49 percent within ten years, and 51 to 70 percent within fifteen. Those are the highest figures in the series so far.
Read that carefully, because both halves matter. It is not a prediction that encryption breaks in fifteen years. It is a statement that the people closest to the work consider it roughly a coin flip on that horizon, and that their confidence has been rising rather than falling. A coin flip is not a reason to panic. It is a reason to plan, in the same way that you insure a building you do not expect to burn down.
Why the date is the wrong thing to argue about
The instinct is to wait for a clearer signal. That instinct is what makes this risk unusual, because for confidential data the deadline is not the arrival date at all.
An adversary can record encrypted traffic today, store it, and decrypt it years later when the machine exists. Nothing about that requires them to break anything now. So for any information that must stay confidential for a long time, medical records, government and defence material, financial and legal archives, long-lived intellectual property, the exposure began the moment you first transmitted it. This is what harvest-now-decrypt-later means, and it is why the migration is urgent for reasons that have nothing to do with predicting the date.
There is a simple piece of arithmetic for turning this into a decision, Mosca's theorem: add how long your data must stay secret to how long your migration will take, and compare that to how long until a capable machine exists. If the first two together exceed the third, you are already late. For most organisations the migration alone is a multi-year programme, which is what closes the gap long before any date does.
The asymmetry that settles it
Strip out the forecasting and you are left with a straightforward comparison of consequences. Migrating too early costs engineering effort on work you would have had to do eventually. Migrating too late is unrecoverable: you cannot retroactively protect traffic somebody already has. One of those mistakes is a budget line and the other one cannot be fixed at any price.
That asymmetry, and not a prediction, is the argument. It is also why the standards bodies have stopped waiting: the algorithms were finalised in 2024, and the deadlines written into policy since then are calendar dates rather than forecasts. Whatever happens to the hardware timeline, those dates are already binding.
What to do about it
Nothing here requires a view on the date. Find out what cryptography you actually run, work out which of it protects data with a long confidentiality requirement, and fix that first. The rest follows the published deadlines. The first step is an inventory, which is work you can start this quarter and which every mandate asks for anyway.