Quick Facts
- Only 7% of organizations have deployed quantum-safe or hybrid cryptography across most of their digital certificates, per a DigiCert survey of 1,001 IT and security leaders.
- Google set an internal post-quantum cryptography migration deadline of 2029, ahead of the NSA’s 2031 target and NIST’s 2035 guideline.
- President Trump signed Executive Order 14412 on June 22, 2026, requiring federal agencies to migrate sensitive systems to post-quantum encryption by December 31, 2030.
The threat known as Q-Day — when quantum computers gain the power to break today’s encryption standards — is arriving faster than most organizations have planned for. New data, government mandates, and hardware breakthroughs published in 2025 and 2026 put that timeline between now and 2029. Most companies are not ready.
A DigiCert survey published in July 2026 found that 87% of organizations report planning, testing, or implementing post-quantum cryptography initiatives. But actual deployment grew by just two percentage points over the prior year. Only 7% of organizations have rolled out quantum-safe or hybrid cryptography across most of their digital certificates.
The Hardware Gap Is Closing Fast
Three research papers published between May 2025 and March 2026 revised the quantum resources needed to break RSA-2048 encryption sharply downward — from 20 million qubits to fewer than one million, and potentially as low as 100,000 qubits using newer architectures. IBM researchers recently completed a quantum computation using 70 error-corrected logical qubits that classical methods could not practically reproduce.
IBM has also outlined a roadmap to deliver a fault-tolerant quantum computer by 2029, codenamed Starling, capable of running around 200 logical error-corrected qubits and executing 100 million quantum gates in a single computation. Google’s Willow chip already operates at 105 qubits.
Governments Are Setting Hard Deadlines
Google set 2029 as its own internal migration deadline, citing advances in quantum hardware, error correction, and factoring resource estimates. Heather Adkins, Google’s VP of Security Engineering, stated in a company blog that the world is on the cusp of a quantum computer emerging that can break current encryption.
Executive Order 14412, signed June 22, 2026, gives federal agencies until December 31, 2030, to migrate their most sensitive systems to post-quantum encryption standards. Federal contractors face the same deadline for post-quantum FIPS compliance. The NSA’s CNSA 2.0 standard already prohibits new acquisitions into national security systems that do not support post-quantum cryptography starting January 1, 2027.
The Immediate Risk: Harvest Now, Decrypt Later
Organizations face a threat that does not require quantum computers to exist yet. Intelligence agencies across multiple countries are publicly warning that nation-state adversaries are collecting encrypted data today, at scale, with plans to decrypt it once quantum capability arrives. Targets include government communications, intellectual property, healthcare records, financial histories, and classified intelligence.
A Ponemon Institute study, sponsored by Entrust Corp., found that only 38% of organizations globally report actively transitioning to post-quantum cryptography. Axiad IDS found that 51% of enterprise security leaders have never formally tested their public-facing infrastructure for post-quantum key exchange, and nearly half lack a named leader responsible for the migration.
The Readiness Gap by Industry
Retail shows the lowest preparedness levels among industries surveyed. Manufacturing is the most divided, with sharp variation between companies. MedTech and Telecommunications expressed the greatest confidence in their quantum readiness. Across all sectors, 81% of respondents said their cryptographic libraries and hardware security modules were not ready for post-quantum integration.
Cryptographic agility — the ability to swap encryption algorithms without overhauling entire systems — ranked as the top infrastructure hurdle, cited first by 44.7% of respondents. That means the problem is not simply adopting new algorithms. For many organizations, the underlying architecture cannot support a fast swap at all.
What This Means for Tech Companies
Software companies that handle sensitive customer data, process financial transactions, or operate under compliance frameworks should treat the 2030 federal deadline as a ceiling, not a target. Any data transmitted or stored today under RSA or ECC is a potential harvest target. Companies that rely on federal contracts face hard legal exposure starting in January 2027 under CNSA 2.0. Starting a cryptographic inventory now — mapping which systems use which algorithms — is the minimum first step before any migration can begin.
Read more: Q-Day is approaching. Most organizations aren’t ready
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
