In 2019, the best public estimate for breaking a 2048-bit RSA key put the job at a quantum computer with about twenty million qubits, running for eight hours.² In May 2025, the same researcher revised the number. The new figure is fewer than one million qubits, in under a week.¹

Nothing about RSA changed. The math that has guarded your bank, your email, and your government’s secrets for thirty years is exactly as it was. We just got dramatically better at attacking it. In six years, the size of the machine you would need to break it fell by more than an order of magnitude, and almost all of that came from cleverer algorithms and error correction, not from a bigger lab.

Part 1 of this series made the case that the internet already went half-post-quantum without anyone sending a memo. The encryption that protects what you say is largely fixed. The certificates that prove who you are talking to are not. This is the other half of the story, and it is the half that runs on a clock. Because while the internet was quietly upgrading itself, two things moved that most boardrooms never noticed: the threat got closer, and the deadline became real.

The clock moved while the machine stayed small

Let me be precise about what did and did not happen, because this is exactly where the hype and the denial both live.

What did not happen: nobody built a quantum computer that can break RSA. The largest machines on earth today hold on the order of a thousand physical qubits. IBM’s Condor crossed 1,121 in late 2023; Google’s Willow, the most important chip of 2024, has 105.³ The million noisy qubits in the new estimate are still perhaps a thousandfold beyond anything that exists, and those have to be stable, error-corrected qubits, which is harder still. If you were waiting for the machine before you worried, the machine is not here.

What did happen is more unsettling, because it is structural. For years the open question was whether quantum error correction even gets better as you add hardware, or whether the noise simply scales with it and you tread water forever. In December 2024, Google’s Willow answered it: adding qubits in the right arrangement made the logical error rate fall, not rise, halving the error each time the code grew.³ Error correction that improves with scale. The obstacle that remained was cost, because that scaling still implies something like a million physical qubits, and this is where IBM has concentrated its effort. Its quantum low-density parity-check codes protect the same information with roughly ten times fewer qubits, cutting the overhead by about ninety percent.³ One lab showed the curve bends the right way; the other is working to make the bill payable. Together they move a cryptographically relevant quantum computer out of the column marked “maybe impossible” and into the one marked “hard engineering with money behind it.” IBM has now put a date on its own fault-tolerant machine, 2029, and ten billion dollars behind the roadmap.³

RSA is not even the soft target. The elliptic-curve cryptography that secures most modern key exchange and signatures is more efficient, which cuts both ways: the latest estimates put a 256-bit elliptic-curve key within reach of fewer than half a million qubits, a smaller machine than RSA needs.⁴ The thing protecting most of your traffic is the thing that falls first.

So when does the machine arrive? Nobody honest gives you a date. The most useful answer is a distribution, not a number. In the Global Risk Institute’s 2024 expert survey, the panel put somewhere between a one-in-five and a one-in-three chance that a quantum computer breaks RSA-2048 within ten years, and roughly three-in-five within twenty.⁵ The analysts have been blunter about the planning horizon than the physicists: Gartner tells its clients that by 2029, advances in quantum computing will make conventional asymmetric cryptography unsafe to use.¹⁴ Those are not the odds, or the dates, you ignore. You do not plan a building’s fire escape around the day the fire starts. You plan it around the fact that the fire is now possible and you cannot evacuate instantly.

Nothing about RSA changed. We just got much better at attacking it.

This time, the memo got sent

In Part 1, the upgrade reached half the web with no announcement. Here is the inversion that almost nobody has absorbed: on the defensive side, the announcement has already gone out. In triplicate. Three governments, on three legal systems, have written down what you must do and by when. The memo exists. Hardly anyone has read it.

It starts with the standards. In August 2024, NIST finalized the first three post-quantum algorithms as federal standards: ML-KEM for key exchange, ML-DSA and SLH-DSA for signatures.⁶ That ended the “which algorithm” debate. Everything after it is a schedule.

NIST has now published, in draft, the schedule itself. Its transition document proposes that the classical workhorses, RSA-2048 and the 256-bit elliptic curves, be deprecated after 2030 and disallowed after 2035 for federal use.⁷ Deprecated means allowed but discouraged. Disallowed means off. It is still a draft, so treat the dates as direction rather than law, but the direction is unambiguous, and it does not stand alone.

The National Security Agency’s CNSA 2.0 suite is firmer. It requires software and firmware signing to use post-quantum algorithms exclusively by 2030, networking equipment by 2030, operating systems and most other systems by 2033, and the full transition of national security systems by 2035, with new acquisitions expected to default to the new suite from January 2027.⁸ Above all of that sits actual law: a 2022 National Security Memorandum set 2035 as the federal target, the Quantum Computing Cybersecurity Preparedness Act made migration a statutory obligation, and the Office of Management and Budget has required agencies to keep an annual cryptographic inventory ever since.⁹

This is not only an American posture. In June 2025, the European Union’s member states published a coordinated roadmap with the same shape: high-risk and critical-infrastructure use cases secured by the end of 2030, full transition by 2035.¹⁰ The United Kingdom’s National Cyber Security Centre had already set its own three dates a few months earlier: complete your discovery by 2028, migrate your highest-priority systems by 2031, finish everything by 2035.¹¹

Look at what just happened across those paragraphs. Three jurisdictions, drafting independently under different legal traditions, converged on the same two years: 2030 and 2035. That is not fashion. It is what happens when separate teams each do the arithmetic on how long a migration of this size actually takes and arrive at the same answer.

One caution worth naming, since it is the world I work in. Europe’s product-security rules, the Cyber Resilience Act and the Radio Equipment Directive, do not say the word “quantum” anywhere. What they say is “state of the art.” That phrase is not static. As post-quantum cryptography becomes the documented norm across these government roadmaps, the floor that a connected product must clear to be sold in Europe rises with it, whether or not a regulation ever names the threat. The deadline can reach you through procurement and product law, not just through a compliance memo addressed to you.

Three governments, three legal systems, one pair of numbers: 2030 and 2035.

Why 2035 is the wrong number to plan around

Here is where most organizations make the same mistake. They read “2035” and hear “a decade.” They do not have a decade. They have a decade minus two other quantities, and for some of their data the subtraction has already gone negative.

The cleanest way to see this is a piece of arithmetic the cryptographer Michele Mosca wrote down years ago. Call X the number of years your data must stay secret. Call Y the number of years it takes you to migrate your systems. Call Z the number of years until a quantum computer can break today’s cryptography. If X plus Y is greater than Z, you are already too late.¹²

Put numbers in it. Suppose a piece of your data has to stay confidential for ten years, which is unremarkable for a contract, a health record, or a national secret. Suppose, honestly, that migrating your estate takes five years, which is optimistic for a large enterprise that has not started. That means you need the quantum computer to be more than fifteen years away to be safe. The expert distribution does not give you fifteen comfortable years. And remember the attack from Part 1: Harvest Now, Decrypt Later. The adversary does not need the quantum computer today. They need only to be recording today, and decrypt when the machine arrives. For anything with a long secrecy requirement, the clock that matters started the day the data was first transmitted, not the day the machine boots.

So the real deadline is not 2035. It is 2035 minus your migration time minus your data’s required shelf life. For an organization sitting on secrets that must outlive the decade, that deadline is not in the future. It is in the past, and the only honest response is to start now and shorten Y as aggressively as possible.

If your data must outlive the decade, your deadline was yesterday.

How you actually migrate

The reassuring part, and I mean this genuinely, is that the hard scientific problem is already solved. Part 1 proved it: the algorithms exist, they are standardized, and they are running at planetary scale inside the software you already use. What is left is not a research breakthrough. It is logistics, and logistics is a thing organizations know how to manage once they decide to. The published frameworks, from the joint CISA, NSA, and NIST guidance to the NIST migration practice guide, agree on roughly the same sequence.¹³

First, inventory. You cannot migrate cryptography you cannot see, and almost no one knows where all of theirs lives: in applications, in firmware, in third-party libraries, in hardcoded keys, in protocols negotiated by systems no one has logged into for years. Cryptographic discovery, captured as a Cryptographic Bill of Materials, is the unglamorous first step and the long pole of the entire project. It is also the part you can start tomorrow with nothing more than a decision.

Second, prioritize by risk. Rank what you found by the Mosca arithmetic. Long-lived secrets, code-signing and firmware keys, root certificate authorities, and operational-technology systems with twenty-year lifespans go first, because they have the largest X and the slowest Y. Ephemeral session data that is worthless in a year can wait.

Third, build for agility, not for one swap. The goal is not to replace RSA with ML-KEM and declare victory. ML-DSA will not be the last algorithm you ever deploy either. The durable win is architecting so that the algorithm is a configuration choice, not a hardcoded assumption, so the next transition is a policy change rather than another multi-year excavation.¹³ NIST now treats this crypto-agility as a discipline in its own right.

Fourth, test the hybrids, then deploy and rotate. The hybrid key exchanges from Part 1 are already in your toolchain; the work is validating them across TLS, then SSH, certificates, VPNs, and your hardware security modules, and then rotating keys and certificates onto post-quantum or hybrid footing. And last, the step everyone forgets: decommission the classical algorithms when you are done. As long as RSA is still offered, an attacker can try to force a connection back down to it. The migration is not finished when the new path works. It is finished when the old one is gone and there is nothing left to downgrade to.

Where this leaves us

Put the two parts of this series together. The technology is ready and already carries half the web. The threat is accelerating and the deadlines are written down. The gap between those two facts is the entire problem, and it is a gap of organizational will, not of science.

The mistake I watch capable people make is to file this under 2035 and move on. The numbers do not support that comfort. The quantum computer that breaks RSA still does not exist. The deadline to be ready for it already does, and for long-lived data it has already passed.

And the harder half is still ahead. Confidentiality, the part Part 1 showed was largely fixed, was the emergency you could solve by flipping defaults. Authentication, the certificates and signatures that prove identity, is the renovation: larger signatures, heavier chains, and a migration that depends on certificate authorities, browsers, and device makers moving together. That is the work I spend my days on, and it is where the 2030 and 2035 dates will actually be won or lost. The standards are done. The clock is running. The only variable left is when you start.

This concludes the two-part series. Part 1, “The Internet Already Went Post-Quantum. Nobody Sent a Memo,” covers what shipped and why half the web is already quantum-safe. If your organization is sitting on the inventory step and is not sure where to start, that is the conversation worth having now, while the arithmetic is still on your side.

Tim McAllister is Regional Field CTO at DigiCert, leading customer-facing technical strategy for device trust, PKI, and post-quantum cryptography. He participates in NIST, SAE EVPKI, Matter, and CharIN standards bodies. Views are his own.

AI tools used (companion video)

In the spirit of the transparency this series argues for, the companion video was produced with AI-assisted tooling:

  • Narration voice: tts.ai (Kokoro model), “George” British male voice

  • Animation and render: Remotion (programmatic React video), 1080p

  • Research, script, and assembly: Anthropic Claude (Claude Code, Opus 4.8)

  • Audio and graphics: ffmpeg, plus HTML and CSS rendered via headless Chromium

Every statistic was verified against the primary sources cited below. The analysis, claims, and final edit are the author’s own.

Sources

[1] Craig Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits,” arXiv:2505.15917, May 21, 2025. Estimate assumes 0.1 percent gate error, a 1-microsecond surface-code cycle, and 10-microsecond reaction time; it is a theoretical estimate for a fault-tolerant machine, not a built device.

[2] Craig Gidney and Martin Ekerå, “How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits,” arXiv:1905.09749, May 2019 (published in Quantum, 2021). The 2025 paper cites this figure directly; the comparison (20 million to under 1 million in roughly six years) is the author’s own.

[3] Google, “Meet Willow, our state-of-the-art quantum chip,” blog.google, and “Quantum error correction below the surface code threshold,” Nature, December 9, 2024 (105 physical qubits; logical error suppressed by a factor of about 2.14 with each two-step increase in code distance, roughly a halving). IBM’s distinct contribution is qubit efficiency: the bivariate-bicycle (“gross”) quantum low-density parity-check code of S. Bravyi et al., “High-threshold and low-overhead fault-tolerant quantum memory,” Nature, 2024, protects 12 logical qubits in 144 data qubits at a high (~0.7 percent) error threshold, roughly a tenfold (about 90 percent) reduction in physical-qubit overhead versus the surface code. IBM Quantum hardware: Condor reached 1,121 physical qubits (December 2023); Heron, 156; fault-tolerant “Starling” targeted for 2029. Physical qubits are the raw hardware; the million-qubit estimates refer to physical qubits supporting a much smaller number of stable logical qubits.

[4] Craig Gidney, Dan Boneh, and others, updated resource estimates for breaking 256-bit elliptic-curve cryptography with fewer than roughly 500,000 noisy qubits, Google Quantum AI, 2026. Elliptic-curve keys require a smaller machine than RSA of comparable classical strength.

[5] Michele Mosca and Marco Piani, “2024 Quantum Threat Timeline Report,” Global Risk Institute, December 6, 2024. A survey of 32 experts; depending on how the likelihood bins are read, roughly a one-in-five to one-in-three chance of breaking RSA-2048 within ten years, and about three-in-five within twenty.

[6] NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards,” August 13, 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA).

[7] NIST, IR 8547, “Transition to Post-Quantum Cryptography Standards,” Initial Public Draft, November 2024 (still a draft as of mid-2026). Proposes deprecating 112-bit-equivalent classical algorithms (including RSA-2048 and 256-bit elliptic curves) after 2030 and disallowing all quantum-vulnerable public-key algorithms after 2035. Dates are proposed direction, not final regulation.

[8] NSA, “Commercial National Security Algorithm Suite 2.0” (CNSA 2.0). Software and firmware signing: exclusive use by 2030; networking equipment by 2030; operating systems and most other systems by 2033; full National Security Systems transition by 2035; new NSS acquisitions expected to default to CNSA 2.0 from January 1, 2027.

[9] White House, National Security Memorandum 10 (May 2022), setting 2035 as the federal migration target; Quantum Computing Cybersecurity Preparedness Act, Public Law 117-260 (December 21, 2022); OMB Memorandum M-23-02 (November 18, 2022), requiring annual cryptographic inventories.

[10] European Union (NIS Cooperation Group, supported by the European Commission and ENISA), “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography,” June 23, 2025: high-risk and critical use cases secured by the end of 2030, full transition by 2035. Predecessor: Commission Recommendation of April 11, 2024.

[11] UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography,” March 2025: define migration goals and complete discovery by 2028; migrate highest-priority systems by 2031; complete migration of all systems by 2035.

[12] Michele Mosca, “Cybersecurity in an era with quantum computers: will we be ready?” IACR ePrint 2015/1075 (also ISACA Journal, 2015). The inequality: if X (required data-secrecy time) plus Y (migration time) exceeds Z (time until a quantum computer arrives), protection fails.

[13] CISA, NSA, and NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography,” August 2023; NIST National Cybersecurity Center of Excellence, SP 1800-38, “Migration to Post-Quantum Cryptography” (practice guide, in draft); NIST CSWP 39, “Considerations for Achieving Cryptographic Agility,” December 2025.

[14] Gartner, “Postquantum Cryptography: The Time to Prepare Is Now!” July 2024: “By 2029, advances in quantum computing will make conventional asymmetric cryptography unsafe to use.”