Q-Day Probability by Year: What the Research Actually Says

Vendor presentations and press coverage produce two incompatible pictures of Q-Day. One places it five years away and treats it as an existential event requiring immediate panic. The other dismisses the timeline as speculative and recommends waiting until the science matures. Neither framing is useful for a security decision-maker who needs to present a defensible planning position to a board or a regulator.

Q-Day refers to the point at which a cryptographically relevant quantum computer (CRQC) can run Shor's algorithm at sufficient scale and fidelity to break RSA-2048 in a practical timeframe. For a foundational explanation of what Q-Day means and why it matters, see what is Q-Day. That capability does not exist today. What exists is a probability distribution over a range of future years, shaped by progress in logical qubit fidelity, error correction overhead, qubit connectivity, and algorithm implementation. Understanding that distribution, its methodology, its limitations, and its planning implications is more useful than accepting either extreme.

The Global Risk Institute's 2024 Quantum Threat Timeline Report, produced by Michele Mosca and Marco Piani, is the most rigorous publicly available expert elicitation on this question. It places a 14 to 34 per cent probability of a CRQC capable of breaking RSA-2048 within 24 hours arriving by the 2033 to 2035 range. This article explains what that means, how it was derived, and what it implies for organisations making planning decisions today.

The GRI 2024 Survey: Methodology and Headline Numbers

What the GRI Survey Measures

The GRI survey uses structured expert elicitation (SEE): a formal methodology for aggregating expert judgment on questions where empirical data is limited. Respondents are quantum computing researchers and security experts. They provide probability estimates for a specific, precisely defined question: "What is the probability that a quantum computer capable of breaking RSA-2048 within 24 hours will exist by year X?" The 24-hour threshold is a planning convention that corresponds to approximately 4,000 logical qubits running an optimised Shor circuit. It is reproducible and specific, not a vague "powerful quantum computer" definition.

The GRI 2024 report produces two headline numbers depending on the aggregation method. The lower bound (14 per cent) reflects respondents with conservative views of hardware progress. The upper bound (34 per cent) reflects respondents who are more optimistic about error correction progress. Both numbers apply to the same ten-year window from the 2024 survey date, placing the relevant range at 2033 to 2035.

Structured expert elicitation has a track record in other high-stakes domains. The IPCC uses it for climate risk quantification when empirical data cannot directly resolve a question. Nuclear safety analysis uses it for failure mode probability estimation. The methodology accounts for respondent overconfidence, which is common in expert elicitation on emerging technology, and aggregates results across respondents with different technical backgrounds. This is not a poll. It is a calibrated elicitation protocol with documented methodology.

Comparison with the GRI 2023 Report

The GRI 2023 report used a 15-year window and produced a lower-bound figure of approximately 17 per cent. This is a different number using a different window length. Mixing the 2023 and 2024 figures produces a meaningless comparison. The correct reference for current planning is the 2024 figure: 14 to 34 per cent within ten years, pointing to the 2033 to 2035 range.

The 2024 report reflects more recent expert assessment of hardware progress including Google's Willow demonstration in December 2024. Using the 2023 figure in a 2026 planning document is not merely outdated: it understates the upper-bound probability because it uses a longer window and earlier hardware data. Any board presentation or regulatory compliance argument that cites the old 17 per cent figure should be updated.

What "Breaking RSA-2048" Technically Requires

Logical Qubit Requirements

Breaking RSA-2048 using Shor's algorithm requires approximately 4,099 logical qubits with surface code error correction at a physical error rate of 0.1 per cent (p = 0.001), as estimated by Webber et al. in 2022, at a cycle time of one microsecond. Webber et al. (2022), "The impact of hardware specifications on reaching quantum advantage in the fault tolerant regime" (AVS Quantum Science), also analyses the resource-runtime trade-off and suggests that under optimised Shor circuit compilation the required logical qubit count can be reduced to approximately 1,458 at surface code distance d=27, though at the cost of a longer runtime. The GRI metric's 24-hour threshold corresponds to a specific resource-time trade-off within this optimised range.

Two terms require precision here. A physical qubit is a real hardware component: a superconducting transmon, a trapped ion, a photon, or a spin. A logical qubit is an error-corrected qubit constructed from many physical qubits. The relationship between the two is determined by the physical error rate and the chosen error correction code. A surface code logical qubit at practical error rates requires roughly 1,000 to 10,000 physical qubits depending on the target error rate and the code distance. This distinction is the reason IBM's 1,121-qubit Condor processor does not represent meaningful progress toward RSA-2048 attacks.

Physical Qubit Count Versus Logical Qubit Requirements

Three hardware reference points place the current gap in perspective:

IBM Condor (2023): 1,121 physical qubits, superconducting architecture. IBM Condor does not implement fault-tolerant error correction at scale. Its qubit count provides no meaningful signal about proximity to RSA-2048 cryptanalysis capability. The physical-to-logical conversion at practical error rates means 1,121 physical qubits might produce a handful of logical qubits, not the 1,458 to 4,099 required.

Google Willow (December 2024): demonstrated below-threshold error correction in a 105-qubit surface code system. This is a genuine milestone. It is the first demonstration of error rates decreasing as the code distance increases, confirming that surface code error correction can in principle be scaled to larger systems. It does not produce logical qubits usable for cryptographic attacks in its current form. Its significance is as an engineering proof point that fault-tolerant quantum computing is on a credible path, not as a capability that threatens current cryptography. See our earlier coverage of logical qubit requirements and the Q-Day timeline calculation for a fuller treatment.

Quantinuum H2 (2024): demonstrated logical qubit operations at error rates below 10^-4 per logical gate in a 56-qubit trapped-ion system. This represents the current leading edge for fault-tolerant logical qubit demonstration. The scale gap between 56 high-fidelity logical qubits and the minimum 1,458 required for RSA-2048 under optimistic algorithmic assumptions remains substantial.

Why NIST Finalised Its Standards in August 2024 Regardless of the Q-Day Date

NIST finalised FIPS 203 (ML-KEM, based on CRYSTALS-Kyber), FIPS 204 (ML-DSA, based on CRYSTALS-Dilithium), and FIPS 205 (SLH-DSA, based on SPHINCS+) on 13 August 2024. The finalisation was driven by migration planning timelines, not by a confirmed CRQC timeline. NIST's position is that migration takes years and should begin now so that it completes before the risk window opens.

NIST IR 8547 Initial Public Draft (November 2024) translates this into specific deprecation dates. RSA and ECDSA/ECDH are Category 2 (deprecated for new systems after 2030) or Category 3 (disallowed after 2035). The 2035 boundary is set to provide adequate migration time under the most conservative CRQC probability estimates, not because 2035 is a confirmed Q-Day.

The August 2024 finalisation removes the "standards are not ready" objection that delayed migration planning in many organisations for the preceding two years. That argument closed in August 2024. Organisations still citing it are using outdated information. For the practical implementation picture that followed FIPS finalisation, see our coverage of when quantum computers become a real threat.

The Mosca-Piani Survey Methodology: Why It Is the Best Available Estimate

The GRI survey's value lies in its methodology rather than in any single number it produces. Structured expert elicitation uses a specific elicitation protocol designed to draw out calibrated probability estimates rather than unconstrained opinions. Respondents provide probabilities, not dates. The question is defined precisely so that different respondents are answering the same question. The aggregation accounts for overconfidence, which is a documented bias in expert forecasting on technology timelines.

The key feature that makes GRI estimates more reliable than vendor claims or analyst reports is the annual repeat. By surveying the same expert community each year with the same methodology, the GRI can track how expert opinion evolves as hardware progress occurs. The trend across survey years is itself informative: it shows whether the expert community is updating its estimates upward or downward in response to actual developments.

Alternative public Q-Day probability estimates tend to fail on one of three grounds: they are not independently peer-reviewed, they use different capability thresholds (a "powerful quantum computer" rather than a specific RSA-2048 break criterion), or they are produced by parties with commercial interests in a particular outcome. The GRI survey is the only publicly available estimate that is methodologically transparent, peer-reviewed, and produced by parties without a commercial stake in the answer.

Hardware Milestones That Would Compress the Timeline

Planning should account for the technical milestones that would bring the timeline inside the current lower-bound estimates. Three are worth tracking:

Below-threshold error correction at scale. Google Willow demonstrated below-threshold error correction at 105 qubits. The next milestone is demonstrating this at 1,000 or more physical qubits with sufficient qubit connectivity to implement a full surface code lattice. For a detailed examination of how quantum error correction affects the Q-Day timeline, see quantum error correction and the Q-Day timeline. Achieving this would indicate that a fault-tolerant CRQC is on a credible five-to-seven-year engineering path. It has not yet been achieved.

Magic state distillation at scale. Shor's algorithm requires T-gates, which are not transversal in surface codes and must be produced through magic state distillation: a resource-intensive process requiring additional physical qubits. No large-scale distillation factory has been demonstrated. Efficient magic state distillation is one of the unresolved engineering challenges between current hardware and a fault-tolerant CRQC. Progress here would materially reduce the physical qubit count required.

Topological qubits. Microsoft's Majorana 1 chip, announced in February 2025, aims to produce logical qubits with intrinsically lower error rates using topological protection. If the claimed error rates are validated at scale, the physical-to-logical qubit overhead would fall substantially, making a CRQC achievable with fewer physical qubits than surface code architectures require. The programme remains in early-stage validation.

What the Uncertainty Means for Planning

The 14 to 34 per cent GRI 2024 probability range is not a narrow interval. The upper and lower bounds differ by more than a factor of two. This reflects genuine expert disagreement about the pace of hardware progress, not a failure of the methodology. Planning under this uncertainty requires a specific approach.

Apply Mosca's inequality with the conservative lower-bound CRQC estimate. If x (migration time) plus y (data sensitivity lifetime) exceeds z (CRQC timeline at the lower bound), the inequality is satisfied even under the most cautious reading of the expert evidence. For most large organisations, this calculation produces a result that warrants action now, because migration timelines of 18 to 36 months and data retention periods extending to 2030 and beyond already consume the available window under the 2033 lower-bound estimate.

The honest uncertainty bands for planning purposes:

  • Optimistic position (lower-bound experts): CRQC unlikely before 2040. Migration is not urgent for organisations with short data sensitivity lifetimes and infrastructure on rapid refresh cycles. A structured inventory programme with a 2028 pilot migration target is adequate.
  • Consensus position (GRI 2024): 14 to 34 per cent probability by 2033 to 2035. Migration should begin in 2025 to 2027 for organisations with moderate to long data sensitivity lifetimes. This is the planning frame for most regulated enterprises.
  • Pessimistic position (upper-bound experts): CRQC possible before 2030. This is a minority view held by credentialed quantum computing researchers, not fringe commentators. For organisations with high-value long-lived data or critical infrastructure obligations, this frame requires an accelerated migration programme beginning immediately. For a tool to apply these planning frames to your organisation's specific data profile, see the Q-Day timeline risk calculator.

Honest Limitations of the Current Estimates

The GRI survey reflects expert opinion, not empirical measurement. Experts have systematically underestimated the pace of progress in AI: GPT-3 to GPT-4 in under two years was not widely predicted in advance. Google Willow's December 2024 demonstration surprised many experts who had placed below-threshold error correction further away. Expert elicitation on emerging technology timelines carries a known overconfidence-in-slowness bias: experts routinely underestimate how quickly engineering challenges get resolved when sufficient capital and talent are directed at them.

The 24-hour RSA-2048 break threshold is a useful planning convention, but it understates the risk for organisations with high-value static data. A CRQC that takes a week to break RSA-2048 is still dangerous for long-term archives, sensitive long-lived key material, and government-classified records. Using the 24-hour threshold as the sole planning criterion overestimates the safe window for some data categories.

No timeline estimate accounts for classified government quantum computing programmes. The US declared over $3.7 billion in quantum computing investment between 2021 and 2025. China's estimated quantum programme expenditure exceeds $15 billion (various analyst estimates, 2022 to 2024 range: $10 billion to $15 billion). The EU Quantum Flagship has committed $7.2 billion. The public record covers academic and commercial progress only. If government programmes have produced capability not reflected in published research, expert estimates based on public information would systematically understate the near-term risk.

Apply This to Your Planning Horizon

Quantum Security Defence provides structured Q-Day probability briefings tailored to board and executive audiences, mapping GRI research to your organisation's specific data categories, regulatory obligations, and migration timeline. Contact us to discuss a quantum threat assessment that translates the research into a defensible planning position.