DOI: https://doi.org/10.58248/RR112
Overview
Sensitive digital information, such as banking details, internet connections, and passwords are protected by encryption, a process that scrambles data. A key is required to unlock it meaningfully. Cryptography is the broader science of securing information.
The most common digital security method involves public-key cryptography. Common public-key cryptography systems, like RSA or ECC, act like digital padlocks that protect online communications and use two linked keys:
- a public key that anyone can use to lock (encrypt) information
- a private key that only the recipient holds to unlock (decrypt) it
Only the intended recipient who holds the private key can decrypt the information. An eavesdropper who intercepts the message cannot easily open or read the data.
A quantum computer could undermine public-key cryptography. While present day quantum computers cannot carry out such attacks, it is unclear when they will be capable of doing so.
To address this risk, post-quantum cryptography (PQC) relies on new types of mathematical problems that are too difficult for even the most powerful supercomputers or quantum computers to solve. Because today’s cyber attackers have not found any shortcuts to solve these problems, the data currently remains secure.
International standards for PQC are now available, and the UK National Cyber Security Centre (NCSC) recommends that organisations complete discovery and planning by 2028, migrate their highest-priority systems by 2031, and aim to complete migration by 2035.
Why could quantum computers threaten today’s encryption?
Most public-key cryptography today depends on mathematical problems that are very difficult for conventional computers to solve. For instance, RSA relies on the difficulty of finding the prime factors of a very large number. These mathematical methods are used to make shared encryption keys, and to provide digital signatures that authenticate people, organisations, devices and software. For example, UK passports use digital signatures to help prevent forgery.
Breaking this kind of encryption would require infeasible computation time using conventional computers. Conventional computers calculate by manipulating ‘bits’ of information in a step-by-step manner, where each bit can be in one of two states, typically 1 or 0. However, quantum computers represent information using quantum bits, or ‘qubits’. Qubits can be in a more complex state than a bit, meaning quantum computers could process considerably more information at one time than conventional computers with an equivalent number of bits.
In 1994, mathematician Peter Shor showed that a sufficiently capable quantum computer could solve the types of problems on which RSA and ECC are built (PDF). This does not mean all cryptography would fail to a powerful quantum computer. For example, ‘symmetric encryption’, such as AES, is different, and can generally be protected by choosing appropriate key sizes.
What new kinds of encryption would resist quantum computing?
The primary defence against this threat is PQC. In 2024, the US National Institute of Standards and Technology (NIST) published the first three PQC standards following an international assessment process that began in 2016. These include methods based on mathematical structures called lattices and hash functions. NIST is currently developing additional standards to provide alternative approaches.
Another approach for some specialised applications is quantum key distribution, which uses quantum physics to distribute encryption keys. It relies on the fundamental quantum rule that any attempt to observe or eavesdrop on quantum particles (such as photons of light) alters their physical state, immediately alerting both communicating parties to the interception.
However, the NCSC says migrating encryption to PQC is the primary mitigation for the challenge to existing public-key cryptography, as unlike quantum key distribution it can largely operate on conventional computing and communications infrastructure.
When could public-key cryptography become vulnerable?
Hypothetical quantum computers powerful and reliable enough to attack real cryptographic systems are referred to as a cryptographically relevant quantum computer (CRQC). It is unknown when the first CRQC may become available.
NIST said estimates range from a few years away to a few decades. A 2026 report from the Alan Turing Institute’s Centre for Emerging Technology and Security said that expert estimates ranged from around 5 to 30 years, with many placing the threat beyond 2035.
Ongoing research shows why these timeline estimates vary. For instance, a 2021 study estimated that factoring a 2048-bit RSA key in eight hours would require roughly 20 million physical qubits, but by 2025, US researchers said that solving an equivalent problem for ECC could be possible with fewer than one million physical qubits through advances in quantum algorithms and error-correction techniques.
Figure 1 shows examples of advances in the number of physical qubits at IBM and Google, with around a 100-qubit quantum computer currently feasible.

Figure 1: Examples of the increase in physical qubits in quantum computers at IBM and Google from 2016. Data was taken from the latest IBM roadmap, and an article on the history of Google Quantum AI. Where there was uncertainty in the number of qubits in a range of years, only the smallest number of qubits at the earliest year was used. Advances in quantum computing happens over a number of technologies, not just on the number of qubits.
IBM plans for a fault-tolerant machine with 200 qubits by 2029, much lower than the estimated millions of qubits needed to break widely used RSA encryption. However, Oxford physicist Tim Palmer’s 2026 theoretical framework suggested there may be fundamental physical limits on the maximum number of useful qubits.
In March 2026, Google announced that it intends to complete its transition to PQC by 2029, citing progress in hardware, error correction, and analytic resource estimates.
Who will be first to develop a powerful quantum computer?
A CRQC would require substantial expertise, specialised facilities, supply chains, capital, and engineering capability. This means governments and large technology companies, with more access to these factors, may be more likely to develop a CRQC than criminal groups acting independently. However, private and state capabilities are not completely separate: the UK National Quantum Computing Centre said that advanced quantum research is carried out through partnership between academia, government and industry.
The security consequences would depend on who obtained the capability and how it was used. An actor able to recover private cryptographic keys could potentially decrypt susceptible information, impersonate users or organisations, or compromise digital signatures. Data intercepted before such a machine exists may also remain vulnerable if it is stored until the technology becomes available. NIST refers to this as “harvest now, decrypt later”, which is most relevant for information that must remain confidential for many years.
It is difficult to know whether the first advanced capability would necessarily become public. For example, commercial developers have incentives to publish results, attract investment and benchmark their systems. But governments may have incentives to withhold some capabilities where they provide an intelligence or national security advantage. Building a large machine would require substantial personnel, specialist components, facilities and energy and cooling infrastructure, and complete secrecy could be difficult.
What needs to happen before then?
The NCSC proposed a three-phase PQC migration plan. They said organisations should:
- identify where the public-key cryptography is used by 2028.
- develop a migration plan by 2028
- complete their highest-priority migrations by 2031, and aim to move all systems, services and products to PQC by 2035
However, different jurisdictions have different timetables, as shown in the table below.
Table 1: Comparison of announced timelines for transitioning to post-quantum cryptography in the UK and selected international jurisdictions.
| Jurisdiction | Initial Plan | Migration | Completion |
| UK | 2028 | 2031 | 2035 |
| EU | 2026 | 2030 | 2035 |
| Australia | 2026 | 2028 | 2030 |
| Canada | 2028 | 2031 | 2035 |
| United States | Already Started | 2030 to 2031 | 2035 |
Large organisations may need to identify cryptography embedded in software, hardware, certificates, industrial systems and supply chains. NIST also recommended cryptographic agility: designing systems so that cryptographic algorithms can be changed without rebuilding the entire service. For many smaller organisations, suppliers and technology providers are expected to carry out much of the transition through normal product upgrades.
NIST said that it can take 10 to 20 years for new cryptographic algorithms to move from standardisation into widespread deployment. This means migration decisions depend on the probability of a future quantum attack and how long particular systems and information need to remain secure.
What capability does the UK have?
The UK has a substantial quantum research and industrial base. The government’s National Quantum Strategy committed £2.5 billion over 10 years from 2024, while a further package of up to £2 billion was announced in March 2026 to accelerate research, infrastructure, skills and procurement.
The government’s long-term mission is for accessible UK-based quantum computers to perform one trillion coherent operations by 2035. The National Quantum Computing Centre (NQCC) at Harwell is developing national infrastructure and has established testbeds using several hardware approaches, including neutral atoms, photonics, trapped ions, superconducting circuits and silicon-based qubits.
The UK Quantum Skills Taskforce reported in 2025 that there were at least 160 companies in the UK quantum sector and identified continuing demand for specialist physics and mathematics skills as well as growing needs for engineering and technical expertise.
Acknowledgements
Yogachandran Rahulamathavan is a Reader in Cybersecurity and Privacy at Loughborough University, Varuna De Silva is the Parliamentary Thematic Research Lead for AI and Digital, and Sarah Bunn is Head of the Science, Digital and Technology Hub in the UK Parliament.
Questions about this briefing should be referred to Simon Brawley, who acted as POST lead for this work.