What is Q-Day?

by Zoya Cochran, Managing Editor, AT&T

Q-Day is the point when a quantum computer could break public-key encryption, the security method that protects websites, payments, software updates, and digital identity. The risk starts earlier because attackers can collect encrypted data now and decrypt it later.

Business leaders should focus on systems using Rivest–Shamir–Adleman (RSA) and elliptic-curve cryptography (ECC), two common public-key methods, plus data that must stay confidential for years. Preparation starts with visibility, crypto agility, and upgrades tied to post-quantum standards across applications, networks, devices, and vendors.

  • Q-Day risk could affect secure websites, virtual private networks (VPNs), software updates, and identity systems.
  • Q-Day has no confirmed date, so systems may not fail in one visible moment.
  • Archives, backups, and long-lived records may face greater exposure than short-term data.
  • Many post-quantum upgrades will happen inside software, networks, devices, and cloud platforms before users notice.

Put simply, what is Q-Day? It’s the future point when quantum computing can defeat widely used public-key cryptography. The exact date remains uncertain, but the risk is already shaping security planning because some data stolen today may remain valuable for years.

What Q-Day means for cryptography

Q-Day is a threat to the trust systems that keep digital activity secure. Although all encryptions won’t fail, Q-Day does mean that widely used public-key cryptography could become weak once quantum computers become powerful enough.

Why public-key cryptography is exposed

Public-key systems help websites prove identity, exchange encryption keys, and verify software updates. Two widely used public-key methods that protect data in transit and verify digital signatures across the internet, RSA and ECC, are especially exposed. RSA and ECC rely on math problems that classical computers can’t solve fast enough to help attackers.

A powerful quantum computer running Shor’s algorithm could solve those problems much faster. That could weaken key exchange, digital signatures, authentication, and identity systems.

Systems and algorithms most affected

Q-Day risk reaches technologies that support digital trust, including:

  • Transport Layer Security (TLS)
  • Virtual private networks
  • Secure Shell (SSH)
  • Code-signing systems
  • Email encryption
  • Device onboarding
  • Firmware verification

Symmetric encryption faces a smaller quantum threat. The Advanced Encryption Standard (AES) can keep stronger protection with 256-bit keys. Organizations can also use stronger hash functions, such as Secure Hash Algorithm 384 or Secure Hash Algorithm 512.

The core issue isn’t quantum computing alone. The concern is that some current security systems depend on math that quantum algorithms may later defeat. That makes Q-Day a planning risk before it becomes a live technical event.

The timing risk is easy to miss. Attackers don’t need quantum power today to create future exposure. Encrypted data stolen now may become readable later if the data stays valuable long enough.

Why Q-Day risk starts before Q-Day

Q-Day risk starts before a quantum computer can break current public-key cryptography. The reason is data lifespan. Some encrypted information stays valuable long after attackers steal it.

Legal records, healthcare information, manufacturing and financial services data, merger files, intellectual property, government communications, critical infrastructure data, and long-term customer records may need protection for years or decades. Archives and backups need close attention because they often last longer than production data and may receive less frequent review.

Harvest-now, decrypt-later exposure

In a harvest-now, decrypt-later attack, attackers can collect encrypted traffic, files, and archives today. Later, when quantum capabilities improve, attackers may decrypt the captured data. That makes Q-Day a current confidentiality risk for data that must stay protected for years.

You can reduce exposure by limiting retention, separating sensitive archives, rotating keys, and strengthening encryption for long-lived data. Having a post-quantum cryptography strategy in place can also limit your exposure.

Stored data can create future risk even when today’s encryption still works. If upgrades fall behind quantum progress, the damage may look less like a systemwide crash and more like a slow loss of digital trust.

[Read: Preparing for harvest now, decrypt later]

Potential impacts if Q-Day arrives

If Q-Day arrives before your systems are upgraded, early effects may appear in secure communications, digital signatures, authentication, and software checks. The risk centers on trust: whether communicating parties are authentic, software is legitimate, and old records remain private.

Attackers could decrypt previously captured data, impersonate trusted systems, or weaken confidence in signed software and digital identity. Q-Day could affect secure web sessions, remote access, certificate systems, code signing, device authentication, and sensitive file exchange.

Q-Day may not cause systems to crash all at once. Instead, Q-Day could slowly weaken the trust layer behind digital services. That risk makes early preparation important.

The key risk isn’t one visible failure. The larger risk is a loss of confidence in systems that prove identity, protect confidentiality, and verify authenticity. Timing matters, but uncertainty isn’t a reason to delay action.

How quickly should your business prepare? Because the timeline remains uncertain, organizations should prepare without relying on a specific forecast.

Why experts disagree on Q-Day timing

Q-Day forecasts vary because quantum computing still faces major engineering hurdles. A quantum computer strong enough to break modern cryptography would need many reliable qubits, strong error correction, and long calculations that don’t lose accuracy.

Scale is the main challenge. Today’s quantum systems are still far from the fault-tolerant machines needed to break RSA and ECC at enterprise key sizes.

Progress in algorithms, hardware design, or error correction could shorten timelines. Problems with reliability, manufacturing, or system design could extend timelines.

Some forecasts focus on rapid investment, prototype advances, and possible breakthroughs. Others focus on the gap between today’s machines and the stable, large-scale systems needed for cryptographic attacks.

Organizations should treat the date as uncertain rather than assume it’s remote. Planning for uncertainty is safer than waiting for a precise forecast.

Rather than plan around one forecast, organizations should reduce current exposure and prepare for phased migration.

How organizations can prepare for Q-Day

Preparation starts with visibility. Most organizations use cryptography across applications, cloud services, devices, certificates, databases, identity platforms, and software pipelines. Many still lack a complete inventory.

Organizations should prioritize systems and data with the longest exposure windows. Pair cryptographic discovery with data classification, vendor review, and phased migration planning.

Build a cryptographic inventory

A cryptographic inventory should show where you use RSA, ECC, TLS, SSH, Internet Protocol Security (IPsec), certificates, hardware security modules, and signing keys. The inventory should also identify machine identities, certificate authorities, trust stores, software libraries, and hard-coded cryptography in applications or embedded systems.

A cryptographic inventory gives cybersecurity, engineering, and procurement teams a shared baseline. The inventory helps you sequence work based on risk, system importance, and upgrade difficulty.

Classify data by confidentiality lifetime

Classify data based on how long each record type must stay private. Data that needs protection for years or decades should receive higher priority than short-lived operational data.

Long-lived archives, regulated records, backups, and sensitive intellectual property need stronger controls. Retention rules should also remove data your organization no longer needs to keep.

Build cryptographic agility

Cryptographic agility means systems can change algorithms without major redesign. Agility requires modern libraries, configurable settings, standard interfaces, testing, and rollback processes.

Procurement requirements should address crypto agility. New applications, network equipment, cloud services, and embedded systems should support algorithm updates and vendor roadmaps for post-quantum cryptography.

Plan post-quantum migration

The National Institute of Standards and Technology (NIST) finalized its first post-quantum cryptography standards in 2024.

  • ML-KEM, based on CRYSTALS-Kyber, supports key establishment.
  • ML-DSA, based on CRYSTALS-Dilithium, supports digital signatures.
  • SLH-DSA provides a stateless hash-based signature option.1 2 3

Track support for NIST standards across operating systems, browsers, servers, networking gear, cloud services, security tools, and hardware security modules. Start your pilot program in lower-risk environments so teams can test performance, compatibility, and operations before wider rollout.

Preparation works best when you combine discovery, priority setting, and upgrade flexibility. You don’t need to solve every migration challenge at once. You do need a clear view of where risk lives.

Internal planning must align with the standards and protocol changes that governments, standards bodies, and protocol groups are setting. That’s the technical path that enterprise migration plans will likely follow.

What governments and standards bodies are doing

Governments and standards bodies are building the technical foundation for quantum-resistant security. Their work gives vendors and enterprises standardized algorithms, transition guidance, and protocol updates for moving away from vulnerable public-key cryptography.

NIST’s 2024 standards give vendors and enterprises standardized algorithms for key establishment and digital signatures. Those two areas face the greatest risk from a quantum computer strong enough to break encryption.4 ML-KEM supports key establishment. ML-DSA and SLH-DSA support digital signatures.

The Internet Engineering Task Force is also working on post-quantum and hybrid approaches for internet protocols such as TLS. Hybrid designs combine classical and post-quantum methods. Organizations can use hybrid designs to test new protections while keeping systems compatible during the transition.5

NIST has also outlined transition planning based on inventories, priority setting, compatibility, and phased migration.6 NIST guidance supports a controlled move away from vulnerable public-key cryptography as products and protocols mature.

The standards process gives organizations clearer direction, but implementation will still take time. Migration depends on product support, vendor readiness, testing, budgets, and operational sequencing.

After the standards discussion, you still might have practical questions about Q-Day and how to properly prepare.

What is Q-Day FAQs

These questions address common concerns you may have after learning the basics. The answers are short enough to confirm key points before moving into planning.

How soon could Q-Day arrive?

No single forecast can settle the timing. You should plan around uncertainty and reduce exposure for data that must stay confidential for years.

Which systems are most at risk from Q-Day?

Systems that use RSA or ECC for key exchange, digital signatures, authentication, or identity face the greatest risk. Priority areas include internet-facing systems, certificate systems, software signing, remote access, and long-life devices.

Does Q-Day mean symmetric encryption must be replaced?

Most organizations don’t need to replace symmetric encryption. Consider AES-256 for symmetric encryption and SHA-384 or SHA-512 for hashing, based on system and risk requirements.

What can organizations do before post-quantum cryptography is widely deployed?

Build cryptographic inventories, shorten certificate lifetimes, rotate keys, strengthen controls around long-lived data, and test hybrid approaches where vendors support them. Those steps reduce exposure while post-quantum tools mature.

How should leaders manage performance concerns?

Post-quantum algorithms can affect bandwidth, latency, memory, and processing needs. Run pilots in realistic environments, benchmark results, and work with vendors before broad deployment.

Q-Day has an uncertain timeline, but the preparation work is clear. The highest-value steps are inventory, priority setting, cryptographic agility, and focused protection for long-lived data.

Q-Day is the future point when quantum computing could break the public-key cryptography that supports digital trust. The timing is uncertain, but the risk has already started because attackers can steal encrypted data today for later decryption. Business leaders should prepare with cryptographic inventories, data classification, stronger controls for long-lived records, cryptographic agility, and migration plans aligned with post-quantum standards.

The strongest response is disciplined preparation, not prediction. Organizations that start with visibility and risk-based sequencing will be better positioned as standards, products, and quantum technology continue to advance.

Prepare your network for the post-quantum era with AT&T Business. AT&T Dynamic Defense with Palo Alto Networks delivers enterprise-grade security. To connect with an expert who knows business, contact your AT&T Business representative.

Why AT&T Business

See how ultra-fast, reliable fiber, protected by built-in security, and 5G connectivity give you a new level of confidence in the possibilities of your network. Let our experts work with you to solve your challenges and accelerate outcomes. Your business deserves the AT&T Business difference—a new standard for networking.


1National Institute of Standards and Technology, Module-Lattice-Based Key-Encapsulation Mechanism Standard, FIPS 203, 2024, https://doi.org/10.6028/NIST.FIPS.203.

2National Institute of Standards and Technology, Module-Lattice-Based Digital Signature Standard, FIPS 204, 2024, https://doi.org/10.6028/NIST.FIPS.204.

3National Institute of Standards and Technology, Stateless Hash-Based Digital Signature Standard, FIPS 205, 2024, https://doi.org/10.6028/NIST.FIPS.205.

4ibid.

5Deirdre Connolly, “ML-KEM Post-Quantum Key Agreement for TLS 1.3,” Internet-Draft, Internet Engineering Task Force Datatracker, updated August 14, 2026, https://datatracker.ietf.org/doc/draft-ietf-tls-mlkem/.

6Dustin Moody, Ray Perlner, Andrew Regenscheid, Angela Robinson, and David Cooper, Transition to Post-Quantum Cryptography Standards, NIST IR 8547 IPD, National Institute of Standards and Technology, 2024, https://doi.org/10.6028/NIST.IR.8547.ipd.