Elegant architectural at Dubai International Airport in Dubai, United Arab Emirates

The quantum clock is moving faster than you think

What every security leader needs to know and do right now

The cryptography protecting your organization today, the math behind every encrypted email, signed certificate and secure transaction, was designed for a world without quantum computers. That world is changing.

The window for an orderly, planned migration to quantum-safe cryptography is narrowing. Acting now, with a structured program, is far better than reacting later under pressure.

What has changed and why it matters

For years, the security community has operated on a working assumption: breaking the public-key cryptography in widespread use today would require a quantum computer of enormous scale, with millions of physical qubits, and that level of capability was decades away.

Recent research points to much more aggressive timeline: advances in quantum resource estimation, Shor’s algorithm circuit efficiency, elliptic curve cryptography risk and hardware-specific quantum approaches suggest that the estimated resources required for a bad actor to mount an attack with a cryptographically relevant quantum computer might be lower than previously assumed. IBM experts, in addition to multiple independent research teams, working with different hardware architectures, are arriving at similar conclusions.

This issue is not a single dramatic event. Quantum capability is advancing on multiple fronts simultaneously: hardware qubit counts are rising, error correction is improving and algorithm efficiency is increasing. The convergence of these trends is what security leaders need to watch.

The practical implication: estimates of when quantum computers could pose a realistic risk to the most widely used cryptographic algorithms are shifting earlier. Exactly when remains uncertain. What is clear is the direction of travel: sooner, not later.

IBM Z

Quantum Cryptography: The Future of Data Security Starts Now

Learn how IBM Z uses advanced quantum-safe cryptography to protect your data from emerging quantum threats. Get insights into securing sensitive information with cutting-edge encryption techniques built for the quantum era.

The risk is already here

There is a dimension of quantum risk that does not wait for a future capability threshold. It is happening now.

Sensitive data such as strategic communications, intellectual property, regulated personal information and financial records can be collected by adversaries today and held until they have access to future sufficiently capable quantum computers to decrypt it. Security professionals call this “harvest now, decrypt later.”

This means that information with a long confidentiality horizon is already in the quantum risk window. If data needs to remain secret for five, ten or fifteen years, the relevant question is not just when quantum computers will be powerful enough to break today’s encryption. It is whether that threshold will be reached within the data’s required protection period.

The Coherence Times | 1 Sept, Season 2, episode 5

Quantum explained: The Coherence Times

Whether you’re a scientist, tech enthusiast, innovator, or simply curious about quantum computing, The Coherence Times offers in‑depth discussions on quantum mechanics, computing challenges, and industry‑changing breakthroughs. New episodes every other Tuesday at 7 AM ET.

Why migration takes longer than most leaders expect

Public-key cryptography is not a single system that you can update in a scheduled maintenance window. It is woven through every layer of modern digital infrastructure.

Consider what uses RSA or elliptic curve cryptography in a typical enterprise environment:

  • TLS and HTTPS connections across every web application and API
  • Digital certificates and certificate authorities
  • Software signing and update verification
  • Identity systems, authentication and access controls
  • VPNs and encrypted network communications
  • Cloud service authentication
  • Connected devices and embedded systems
  • Third-party and supply chain integrations

Organizations need to know what they have, where it lives, who owns it and how it connects to everything else. Then, they need prioritization, architecture decisions, vendor coordination, testing and staged deployment. In many organizations, this approach can become a multi-year effort.

The organizational challenge of post-quantum cryptography migration is often underestimated. The standards exist. Three algorithms have been standardized by National Institute of Standards and Technology, with more under consideration. The technical path is becoming clearer. What takes time is execution across complex, interconnected enterprise environments.

Three actions security leaders should take now

Security leaders do not need to wait for perfect certainty before acting. The practical work starts with understanding cryptographic exposure, prioritizing the highest-risk systems and building a migration program that can adapt as standards, threats and technology continue to evolve.

Understand your cryptographic risk exposure

You cannot protect what you cannot see. The starting point is a comprehensive cryptographic inventory: where RSA, ECC and other cryptography are being used, what systems depend on them, which data they protect and how difficult each dependency will be to replace.

This inventory should be approached as a risk-informed exercise, not just a technical audit. The output should map cryptographic dependencies to business processes, data sensitivity and operational criticality, so that when prioritization decisions are made, they are grounded in business context.

Prioritize what matters most

Not all cryptographic exposure carries equal risk. Organizations should focus first on:

  • Systems protecting long-lived sensitive data, including information that must remain confidential for years
  • Critical trust infrastructure, including certificate authorities, code signing systems and identity providers
  • Environments that are slow or costly to update such as embedded systems, operational technology and long-lifecycle platforms
  • Third-party and supply chain connections where cryptographic dependencies are outside direct control

A risk-tiering methodology can help organizations make these prioritization decisions systematically by weighing cryptographic exposure against business impact, data sensitivity and operational constraints.

Build and execute a phased migration program
 

  • Discovery and prioritization set the foundation. The next step is a structured, governed migration program with clear milestones, executive accountability and a roadmap that sequences the highest-risk systems first.
  • Organizations should design for crypto agility, with architectures that make it possible to swap cryptographic algorithms without rebuilding systems from scratch. This aspect is valuable not just for the quantum transition, but for ongoing cryptographic resilience as standards and threats evolve.
  • NIST published the first set of post-quantum cryptographic standards in 2024. In June 2026, White House executive order added further urgency by directing federal agencies to transition high-value and high-impact systems to post-quantum cryptography for key establishment by 2030 and digital signatures by 2031. The standards are ready and likely to expand, government momentum is building and the question for most organizations is execution speed.

IBM’s position and perspective
 

IBM has been investing in both quantum computing and quantum-safe technology for more than a decade. IBM researchers contributed to the development of post-quantum cryptography standards published by NIST, including work behind ML-KEM and ML-DSA, two algorithms standardized for post-quantum key exchange and digital signatures. And the third published standard, SLH-DSA was co-developed by a scientist who has since joined IBM.

That combined depth across quantum computing, cryptographic research and enterprise security is why IBM views this moment as significant. IBM Quantum Safe™ and IBM Guardium® Cryptography Manager help organizations assess cryptographic risk, prioritize migration and build crypto-agility before urgency turns into pressure.

Cryptographically relevant quantum computing will not arrive as a single, definitive event. It is arriving as a progression, and that progression is accelerating. The organizations best positioned to manage this transition recognize that preparation takes time, start their programs early and build the organizational muscle to adapt as the technical landscape continues to evolve.

The time to begin, or to accelerate, is now.

Explore IBM Guardium Cryptography Manager

Learn how to prepare for Q-Day

Build crypto-agility with IBM

Authors

Jai S. Arun

Product Management Leader, Strategy & Go-To-Market, IBM Quantum Safe and Crypto-Agility Products

IBM

James McGugan

Chief Architect, Quantum Safe Tools

Walid Rjaibi

Global Product Architect for Quantum Safe

Related solutions
Quantum-safe on IBM Z®

Quantum-safe security for IBM Z uses cryptographic methods to protect data from quantum computer threats.

Explore quantum-safe security
IBM Quantum® computing solutions

Bringing useful quantum computing to the world through Qiskit® Runtime and IBM Quantum Safe.

Explore quantum computing solutions
IBM Quantum® Safe services

Safeguard your enterprise against post-quantum cryptography risks with IBM Quantum Safe transformation services.

Explore quantum safe services
Take the next step

Strengthen your cryptographic defenses against future quantum threats with IBM’s quantum-safe solutions.

  1. Explore Quantum-Safe cryptography
  2. Discover IBM Quantum technology