A CRQC, a cryptographically relevant quantum computer, does not exist yet. When it does, it will fundamentally change the cybersecurity landscape. A CRQC will have enough qubits and stability to break RSA, shatter elliptic curve cryptography, and decrypt the data encrypted today that adversaries are already stockpiling.
No one knows for sure when a relevant quantum computer CRQC will emerge, but cybersecurity leaders are already preparing.
What Does CRQC Stand For?
CRQC stands for Cryptographically Relevant Quantum Computer. That is the formal term for a quantum computer powerful enough to run Shor's algorithm at the scale needed to break widely used public key cryptography.1
Today's quantum computers are not CRQC machines. They are NISQ devices: noisy intermediate-scale quantum systems that lack the fault-tolerant quantum computation capabilities required to crack encryption.2
A CRQC requires thousands of logical qubits operating through quantum error correction with error rates low enough to sustain millions of sequential gate operations without accumulating fatal errors. That is the gap between where quantum computing is today and where the quantum threat becomes real.3
How Cryptographically Relevant Quantum Computers Break Public Key Cryptographic Algorithms
Why Public Key Systems Are Vulnerable
Here is why a CRQC becomes a security concern:
Public key cryptography relies on mathematical problems that classical computers cannot solve efficiently. Factoring enormous numbers (RSA) and computing discrete logarithms on elliptic curve cryptography systems are the foundations of internet security. Classical cryptography has relied on these hard problems for decades.4
Quantum algorithms change everything. Shor's algorithm can factor large integers and solve elliptic curve problems exponentially faster than any classical approach. A relevant quantum computer CRQC running Shor's algorithm would break RSA and ECC in hours or days instead of billions of years.5
Symmetric cryptography faces a different quantum threat. Grover's algorithm provides a quadratic speedup against hash functions and symmetric keys. AES-128 security drops to an effective 64 bits. But unlike public key systems, symmetric cryptography is weakened, not broken. Doubling key sizes provides adequate protection.6
Cryptography Type | Quantum Attack | Impact |
RSA / ECC (public key) | Shor's algorithm | Completely broken by CRQC |
AES / symmetric | Grover's algorithm | Weakened, double key sizes fixes it |
Hash functions | Grover's algorithm | Quadratic speedup, increase output size |
Digital signatures | Shor's algorithm | Broken, must migrate to PQC algorithms |
How Many Qubits Does a CRQC Need?
How many qubits does it take to build a CRQC? The answer keeps changing, and that is what makes the quantum threat so urgent.
The Shrinking Resource Estimates
In 2019, a widely cited estimate put the cost at roughly 20 million physical qubits running for about 8 hours. By May 2025, the same lead researcher reduced this to under a million physical qubits running for less than a week.7
Resource estimates have dropped over 2,000 times in just a few years. The circuit depth required to break RSA 2048 has fallen dramatically thanks to advances in quantum algorithms and error correction techniques.8
Breaking RSA-2048 requires maintaining roughly 1,400 logical qubits through millions of sequential gate operations. Each logical qubit is built from many physical qubits using quantum error correction codes. The ratio depends on error rates, but current estimates vary from 250:1 to 1,000:1.3
Traditional estimate: 20 million physical qubits (2019)
Current best estimate: Under 1 million physical qubits (2025)
Pinnacle architecture: Under 100,000 physical qubits (theoretical)
Logical qubit requirement: Roughly 1,400 error corrected logical qubits
Every year, the qubit count needed for a CRQC drops. Quantum computing hardware roadmaps converge on 100,000+ physical qubits by the early 2030s. The gap between available hardware and these requirements is closing faster than most organizations realize.
CRQC Progress: Where Quantum Computing Stands Today
So where does CRQC progress actually stand?
Today's quantum computers are still NISQ devices. They have high error rates, limited coherence times, and nowhere near the fault tolerance needed for cryptanalysis. No one has built such a machine yet.2
Key Milestones in 2025 and 2026
But the trajectory of CRQC progress is accelerating. In June 2025, Quantinuum demonstrated the first universal, fully fault-tolerant quantum gate set with repeatable error correction. In March 2026, they followed with 94 error-protected logical qubits performing beyond break-even operations.9
IBM is targeting fault-tolerant quantum computing performance by 2029. IQM plans the transition from NISQ to error correction processors by 2027. Google moved its internal PQC transition deadline from 2030 to 2029 after new research showed timelines tightening.10
The CRQC framework assesses quantum computing readiness beyond just qubit count. Key metrics include reliability, sustained operation, and the ability to maintain coherent operation for hours while running algorithms like Shor's. A CRQC needs to execute million physical qubits level operations with fault-tolerant quantum computation precision.11
Does this mean a CRQC exists today? No, but the building blocks are falling into place faster than predicted. Estimates vary, but the projected timeline for practical CRQC capabilities is between 2030 and 2035.7
The CRQC Timeline: When Will Quantum Computers Break Encryption?
Expert Predictions and Government Deadlines
Predicting the exact date a CRQC arrives is impossible. But experts have converged on a window.
The Global Risk Institute survey shows roughly a 1 in 4 chance of a CRQC by 2030 and about a 50% probability by 2035. CRQC machines may emerge within 10 to 20 years from now.7
This is a real and growing quantum threat. Governments are mandating transitions to post quantum cryptography by 2035. The White House issued Executive Order 14412 in 2026, requiring federal agencies to submit PQC migration plans within 120 days.10
Quantum computing does not follow Moore's law in the same way classical computing did. Breakthroughs in error correction and quantum algorithms can cause sudden leaps. The timeline could compress without warning.
For national security systems, the clock is already ticking. Any organization facing the relevant quantum computer CRQC risk and protecting long-lived data like government records, medical records, and intellectual property cannot wait for the exact date to begin migrating.
Harvest Now, Decrypt Later: Why the CRQC Threat Is Already Here
The quantum threat begins now, not when quantum computers arrive, because of a certain attacker technique known as Harvest Now, Decrypt Later. Adversaries are intercepting and archiving encrypted data today, waiting for the day a quantum computer powerful enough to decrypt it becomes available.5
HNDL makes quantum threats a current concern, not a future one. Data encrypted today using quantum-vulnerable algorithms like RSA and ECC will be exposed the moment a CRQC breaks those systems.
This threat model is especially dangerous for long-lived data. Government records, financial data, medical records, classified communications, and intellectual property may retain sensitivity for decades. If the migration time from classical to quantum-safe encryption takes 5 to 10 years, and a CRQC arrives in the 2030s, organizations need to begin migrating now.6
Harvest Now, Decrypt Later poses a significant risk today. The quantum attack does not require a CRQC to be operational at the moment of interception. It only requires one to exist eventually.
Captured data can be decrypted once a CRQC exists. That makes every unprotected transmission a future liability.
Post-Quantum Cryptography: Preparing for the CRQC Era
Post-quantum cryptography is the answer to the CRQC threat. PQC algorithms are cryptographic algorithms designed to resist attacks from both classical computers and quantum computers.4
NIST Standards and Migration Steps
NIST finalized three post-quantum standards in 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). These algorithms are built on mathematical problems that even a CRQC cannot solve efficiently, including lattice and hash-based approaches.
Quantum-resistant cryptography protects digital signatures, key exchange, and encryption against such machines. But migrating is not simple. Organizations need crypto agility to swap cryptographic algorithms across their infrastructure without breaking existing systems.8
Here are the security requirements:
Inventory all quantum-vulnerable algorithms in your environment
Prioritize critical infrastructure and national security systems
Deploy PQC algorithms for public key encryption and digital signatures
Implement crypto agility for future algorithm transitions
Address the Harvest Now, Decrypt Later risk for long-lived data
Quantum key distribution is sometimes discussed as an alternative, but it requires specialized hardware and does not scales sufficient to protect global internet traffic the same way software-based post-quantum cryptography does.
The foreseeable future belongs to PQC algorithms. Organizations that begin migrating before a CRQC arrives will be protected, while those that wait may find their encrypted data exposed retroactively.
CRQC vs. NISQ: Error Correction and the Path Forward
What separates a CRQC from today's quantum computers?
NISQ devices have hundreds to a few thousand physical qubits with high error rates. They cannot run deep circuits. They cannot maintain coherence long enough for running Shor's algorithm against real-world key sizes. Such machines are useful for research and optimization, but not for cryptanalysis.2
Such a system operates with full fault-tolerant quantum computing at scales sufficient to break public key cryptography. It needs thousands of logical qubits, millions of physical qubits in the most conservative resource estimates, and the ability to sustain coherent operations for hours or days.3
Feature | NISQ Devices | CRQC |
Physical qubits | Hundreds to thousands | Hundreds of thousands to millions |
Error correction | None or limited | Full fault tolerant quantum error correction |
Coherence time | Microseconds to milliseconds | Hours to days |
Cryptographic impact | None | Breaks RSA, ECC, digital signatures |
Timeline | Available now | Estimated 2030 to 2035 |
Quantum error correction is the bridge between these two worlds. When quantum computing crosses the fault tolerance threshold with enough physical qubits at low enough error rates, a cryptanalytically capable machine becomes possible.9
Sources
PostQuantum.com, "Cryptographically Relevant Quantum Computers (CRQCs)," https://postquantum.com/post-quantum/crqc/
Palo Alto Networks, "Brief: Cryptographically Relevant Quantum Computers (CRQC)," https://www.paloaltonetworks.com/cyberpedia/crqcs-cryptographically-relevant-quantum-computers
Encryption Consulting, "CRQC Timelines: When Will Quantum Break Encryption?," https://www.encryptionconsulting.com/education-center/crqc-timelines-quantum-threat-landscape/
CISA, "Post-Quantum Cryptography Initiative," https://www.cisa.gov/topics/risk-management/quantum
Palo Alto Networks, "Harvest Now, Decrypt Later: Quantum Security Risk," https://www.paloaltonetworks.com/cyberpedia/harvest-now-decrypt-later-hndl
Cloud Security Alliance, "Harvest Now, Decrypt Later: Quantum Risk to AI Infrastructure," https://labs.cloudsecurityalliance.org/research/ai-infrastructure-post-quantum-harvest-now-decrypt-later-v1/
QRAMM, "Quantum Computing Threat Timeline: When Will Quantum Computers Break Encryption?," https://qramm.org/learn/quantum-threat-timeline.html
PostQuantum.com, "The CRQC Scorecard: How Close Is Each Quantum Modality to Breaking Your Encryption?," https://postquantum.com/post-quantum/crqc-scorecard-how-close/
Quantinuum / Paper Guide, "Quantum Computing Research 2026: Error Correction & Hardware," https://paperguide.ai/research-reviews/quantum-computing/
Cloudflare Blog, "The White House's Post-Quantum Executive Order," https://blog.cloudflare.com/post-quantum-eo-2026/

