What the Q-Day Timeline Calculator Tells You About Your Urgency Window

Most CISOs have now heard the instruction: start post-quantum cryptography migration. Fewer have connected that mandate to a concrete number. The question is not whether quantum risk is real. It is whether the risk is real for your organisation, given your data, your migration velocity, and the time available. That is a calculation, and QSECDEF's Q-Day Timeline Calculator performs it.

The tool is not a threat model or a vendor claim. It operationalises Mosca's inequality, a mathematical framework formalised by Michele Mosca of the University of Waterloo and Perimeter Institute, published in IEEE Security and Privacy in 2018 and referenced in NIST guidance and NCSC migration documentation. The output is an urgency score across four bands. Two organisations in the same sector, encrypting the same data classification, can produce different urgency scores depending on how long they need to retain that data and how long their migration will actually take. That difference is the insight the tool is designed to surface.

This walkthrough explains each input, the GRI 2024 probability data that anchors the time dimension, and how to read the urgency score your organisation receives. It is a technical explainer, not marketing copy.

The Mosca Inequality: The Mathematics Behind the Tool

Mosca's inequality uses three variables to determine whether an organisation is already operating within the cryptographic risk window:

  • SL (sensitivity lifetime): how many years from today the data being encrypted now must remain confidential
  • MT (migration time): how many years it will take to complete migration to quantum-safe algorithms
  • QT (quantum threat time): the estimated time until a cryptographically relevant quantum computer (CRQC) can break current public-key cryptography

If SL + MT exceeds QT, the organisation is at risk. Data encrypted today under RSA-2048 or ECDH will not remain confidential for its required lifetime. The inequality is blunt because the adversary's position is blunt: a state-level actor running a harvest-now-decrypt-later (HNDL) campaign does not need a CRQC today. They need it before the intercepted data loses its intelligence value. If a pharmaceutical company's clinical trial data has commercial value for 12 years and a CRQC arrives in 9, the harvest happened at exactly the wrong moment. The mathematics makes this visible before the breach, not after.

The Mosca inequality appears in NIST IR 8105 (April 2016) and underpins the migration urgency framing in NIST IR 8547 IPD (November 2024). It is the primary decision framework used by NCSC in its quantum security migration guidance published at ncsc.gov.uk. The tool's underlying logic is not proprietary framing; it is applied mathematics from published government documentation.

Input One: Data Sensitivity Lifetime

What Sensitivity Lifetime Actually Measures

The first input asks how many years data encrypted today must remain confidential. This is not the same as a retention period. A retention period is a legal or policy obligation governing how long data is kept. The sensitivity lifetime is a risk variable: from today, for how long must an adversary be unable to read this data?

The distinction matters. An organisation might retain financial records for 7 years under MiFID II Article 25(1) requirements, but those records may only need to remain confidential for 5 years from the transaction date if the commercial sensitivity expires before the legal retention period does. The tool uses the sensitivity lifetime, not the retention period, because the adversary's timeline is a function of when the data stops being useful to them, not when the organisation deletes it.

Common data types and their illustrative sensitivity lifetimes:

  • Session-level PII in transit (e.g. authentication tokens): minutes to hours. SL effectively zero. No material CRQC risk.
  • Financial transaction records subject to 5-year regulatory retention: SL approximately 5 years. Low risk for organisations on short migration paths.
  • Medical records under NHS Digital retention schedules (8-year minimum for adult care records): SL 8 years. Material risk if migration completion extends beyond 2027 to 2028.
  • Intellectual property, including patent-pending material and formula libraries: SL potentially 10 to 20 years depending on the commercial advantage window. High risk.
  • Regulated archives, defence contractor data, cryptographic key material: SL 15 to 25 years or indefinite. Maximum risk.

These are illustrative ranges, not regulatory mandates. The tool allows organisations to input their actual sensitivity estimates rather than default to broad categories.

The Harvest-Now-Decrypt-Later Implication

HNDL campaigns change the risk calculus in one specific way: the interception happens before the CRQC exists. NSA's August 2021 advisory on quantum computing and post-quantum cryptography explicitly documented this threat model, as did NCSC's "Preparing for Quantum-Safe Cryptography" guidance in October 2020. CISA has published similar framing. The adversary collecting encrypted traffic today faces no cryptographic barrier; the barrier only matters when they attempt decryption.

For a defence contractor with a 15-year IP sensitivity window, even a 14% probability of a CRQC by 2033 represents a rational operational investment for a well-resourced state actor. The GRI 2024 data places that probability at 14 to 34% across the 2033 to 2035 window. Against that probability distribution, HNDL is not a theoretical threat scenario for long-SL organisations. It is an ongoing operational reality. The HNDL Risk Calculator provides a quantified view of this exposure for your specific data categories.

Input Two: Migration Plan Duration

The second input is the number of years required to complete migration from current cryptographic algorithms (RSA, ECDH, ECDSA) to NIST-standardised post-quantum algorithms. FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) were all finalised in August 2024 and are the target algorithms. The migration time is not a fixed quantity. It depends on several variables that organisations routinely underestimate.

Cryptographic inventory completeness is the first determinant. Organisations without a completed cryptographic inventory, or CBOM (Cryptography Bill of Materials), have longer migration lead times because discovery must precede migration. An organisation that cannot enumerate its RSA usage across all systems cannot sequence a migration. A cryptographic asset register is the prerequisite input that most enterprises are missing. Structuring that register is covered in the Cryptographic Asset Register Build Guide.

Legacy system constraints compound the timeline. Hardware security modules without a vendor-confirmed firmware upgrade path to FIPS 140-3 validated ML-KEM or ML-DSA support require physical replacement, not configuration change. Operational technology systems and embedded devices with long refresh cycles add years to the tail of the migration programme. Regulatory change management cycles in financial services, aviation, and medical devices add further calendar time that does not compress regardless of engineering effort.

Industry analysis suggests most large enterprises underestimate migration timelines by a factor of two to three. An organisation that plans 18 months may take 36 to 54 months once discovery rework, vendor dependencies, and regulatory approval cycles are fully priced in. NIST IR 8547 IPD (November 2024) treats 2030 (Category 2: deprecated for new systems) and 2035 (Category 3: disallowed for all systems) as planning anchors for RSA, ECDH, ECDSA, and DSA. An organisation that enters 2027 with an 18-month migration estimate that turns out to be 36 months arrives at the 2030 deadline with no buffer.

Input Three: Target Completion Year

The third input is the calendar year by which the organisation's migration is planned to be complete. This is distinct from the current year plus migration duration because many organisations have already begun parts of their migration. Some have also delayed. The target year captures organisational intent against the actual calendar.

The tool uses this input to compute the implicit QT buffer: how much time remains between planned completion and the lower bound of the GRI 2024 CRQC probability window. The Global Risk Institute's 2024 Quantum Threat Timeline Report, authored by Dr Michele Mosca and Dr Marco Piani, places 14 to 34% probability of a CRQC capable of breaking RSA-2048 within 24 hours in the 2033 to 2035 window. That figure is derived from a rigorous expert elicitation conducted in 2024, using a 10-year horizon from the survey date. It is the most rigorous publicly available probability estimate for Q-Day and should not be conflated with GRI's 2023 report, which used a 15-year window and produced a different figure.

An organisation planning to complete migration by 2032 has a nominal buffer of approximately one year against the lower bound of the GRI 2024 risk window. Whether that buffer is adequate depends on SL: if the organisation holds data with a 10-year sensitivity lifetime, data encrypted in 2022 to 2024 is already inside the risk window regardless of when the migration completes.

Reading the Urgency Score Output

How Urgency Bands Are Calculated

The Q-Day Timeline Calculator produces an urgency score across four bands, derived directly from applying the Mosca inequality to the user's inputs and overlaying the result against the GRI 2024 probability distribution.

  • Low: SL + MT produces a completion window before 2030, with SL under 5 years. The organisation is on a trajectory to complete migration before the CRQC risk window becomes material.
  • Medium: SL + MT suggests completion between 2030 and 2033. The organisation sits at the outer edge of the GRI risk window. Migration is time-constrained but achievable within a structured programme.
  • High: SL + MT suggests completion between 2033 and 2035, or SL exceeds 10 years. The organisation falls within the primary GRI 2024 risk window. Data encrypted today under legacy algorithms carries meaningful probability of being decrypted before its sensitivity lifetime expires.
  • Critical: SL exceeds 15 years, or MT exceeds 5 years with a completion date after 2035. Both historical encrypted data and current data face material risk under the GRI 2024 14 to 34% probability range. Immediate migration prioritisation is indicated.

These thresholds align with the NIST IR 8547 IPD deprecation milestones and the GRI 2024 risk window. They are presented as a planning tool, not a regulatory verdict.

What the Score Does Not Tell You

The urgency score is not a compliance status. It does not tell an organisation whether it is in breach of NIS2 Article 21(2)(h), which requires that cybersecurity risk management measures include cryptographic policies and procedures. It does not measure alignment with DORA Article 6, which covers ICT risk management framework requirements for EU and EEA financial entities. Note that DORA applies to EU and EEA financial entities specifically; UK financial institutions operate under FCA operational resilience requirements and NCSC guidance rather than DORA. The tool provides a mathematical risk position, not a compliance audit. Those are distinct questions requiring distinct assessments.

Worked Example: Two Organisations, Same Data, Different Urgency

The value of the tool becomes clearest in comparison. Consider two organisations, both encrypting customer financial records subject to a 7-year retention requirement under applicable regulations.

Organisation A is a large financial services firm with a legacy HSM estate. It has completed a cryptographic inventory revealing 3,000 certificate types. Migration plan: 4 years. Target completion: 2029. Applying the Mosca inequality, SL + MT = 7 + 4 = 11 years; planned completion at 2029 precedes the lower bound of the GRI 2024 risk window, but data encrypted between 2024 and 2026 carries a sensitivity lifetime extending to 2031 to 2033, placing it at the boundary of the risk window. Urgency score: Medium.

Organisation B is a mid-market insurer without a cryptographic inventory. It estimates migration at 18 months. Target completion: 2028. If discovery adds 12 months, as industry data suggests is common, the actual migration does not begin until late 2026 and completes at 2028 to 2029. Data encrypted in 2024 to 2025 carries a sensitivity lifetime extending to 2031 to 2032. The SL + MT calculation places that data inside the GRI 2024 risk window. Urgency score: Medium to High, depending on actual discovery time.

Organisation B may look safer on paper because its planned completion year is earlier than Organisation A's. It is not. The migration estimate has not been stress-tested against the inventory it has not yet completed. That is the tool's core insight: urgency is organisation-specific. The score is not derived from sector averages or peer benchmarks. It derives from the three numbers the organisation actually provides.

Common Misconceptions

Q-Day is a single date. It is not. The GRI 2024 data gives a probability distribution (14 to 34%) across a window (2033 to 2035). Planning against a point estimate misrepresents the underlying uncertainty and tends to produce false precision about when action is required.

If data expires before Q-Day, we are safe. Only if the sensitivity lifetime is genuinely short. An organisation retaining encrypted records for 7 years from today faces exposure in 2031 to 2033, which falls within the GRI risk window regardless of where Q-Day actually lands.

The tool is a compliance checker. It is a risk quantification tool. It does not replace a cryptographic inventory or a legal compliance review, and it does not produce a compliance status.

Symmetric encryption has the same problem. It does not. AES-256-GCM is classified as Category 1 in NIST IR 8547 IPD, meaning it is considered quantum-resistant and requires no migration. Grover's algorithm provides only a quadratic speedup against symmetric ciphers, halving the effective key length. AES-256-GCM provides 128-bit post-Grover security. The Mosca inequality addresses public-key cryptography, not symmetric encryption. AES-256-GCM is the appropriate standard for data at rest.

For a full treatment of the GRI 2024 research underpinning these probability figures, see Q-Day Probability Research Synthesis 2024.

Next Steps After Receiving Your Urgency Score

A Medium or High urgency score does not require immediate crisis response. It requires a structured response. The first step is verifying the inputs: is the sensitivity lifetime estimate accurate, or is it based on a default data classification that does not reflect actual retention practice? Is the migration timeline a validated estimate based on a completed cryptographic inventory, or is it an aspiration?

If the inputs are solid and the score is High or Critical, the appropriate action is escalation to CISO level and initiation of a cryptographic inventory programme if one has not already begun. The inventory determines what migration actually costs and how long it actually takes. Without it, the urgency score is directionally correct but lacks the specificity needed to build a credible migration programme. The Mosca Inequality Calculator walkthrough covers the mathematical context in depth for teams that want to work through the inequality manually before using the tool.

The tool is available at /insights/q-day-timeline-risk-calculator/. Run it with your actual retention policies and your actual migration programme timeline. The output is only as useful as the inputs.


About the Author

Steven Vaile is Director of Quantum Security Defence. He advises organisations on post-quantum cryptography migration strategy, regulatory readiness, and quantum threat assessment.