The breach isn’t the problem. The spread is. →Free Assessment

What Is a CRQC? Cryptographically Relevant Quantum Computers Explained

A CRQC (cryptographically relevant quantum computer) is a quantum machine powerful enough to break today's public-key encryption like RSA and ECC using Shor's algorithm. It doesn't exist yet, but harvest-now, decrypt-later attacks make it a risk right now.

A CRQC, a cryptographically relevant quantum computer, does not exist yet. When it does, it will fundamentally change the cybersecurity landscape. A CRQC will have enough qubits and stability to break RSA, shatter elliptic curve cryptography, and decrypt the data encrypted today that adversaries are already stockpiling.

No one knows for sure when a relevant quantum computer CRQC will emerge, but cybersecurity leaders are already preparing.

What Does CRQC Stand For?

CRQC stands for Cryptographically Relevant Quantum Computer. That is the formal term for a quantum computer powerful enough to run Shor's algorithm at the scale needed to break widely used public key cryptography.1

Today's quantum computers are not CRQC machines. They are NISQ devices: noisy intermediate-scale quantum systems that lack the fault-tolerant quantum computation capabilities required to crack encryption.2

A CRQC requires thousands of logical qubits operating through quantum error correction with error rates low enough to sustain millions of sequential gate operations without accumulating fatal errors. That is the gap between where quantum computing is today and where the quantum threat becomes real.3

How Cryptographically Relevant Quantum Computers Break Public Key Cryptographic Algorithms

Why Public Key Systems Are Vulnerable

Here is why a CRQC becomes a security concern:

Public key cryptography relies on mathematical problems that classical computers cannot solve efficiently. Factoring enormous numbers (RSA) and computing discrete logarithms on elliptic curve cryptography systems are the foundations of internet security. Classical cryptography has relied on these hard problems for decades.4

Quantum algorithms change everything. Shor's algorithm can factor large integers and solve elliptic curve problems exponentially faster than any classical approach. A relevant quantum computer CRQC running Shor's algorithm would break RSA and ECC in hours or days instead of billions of years.5

Symmetric cryptography faces a different quantum threat. Grover's algorithm provides a quadratic speedup against hash functions and symmetric keys. AES-128 security drops to an effective 64 bits. But unlike public key systems, symmetric cryptography is weakened, not broken. Doubling key sizes provides adequate protection.6

Cryptography Type

Quantum Attack

Impact

RSA / ECC (public key)

Shor's algorithm

Completely broken by CRQC

AES / symmetric

Grover's algorithm

Weakened, double key sizes fixes it

Hash functions

Grover's algorithm

Quadratic speedup, increase output size

Digital signatures

Shor's algorithm

Broken, must migrate to PQC algorithms

How Many Qubits Does a CRQC Need?

How many qubits does it take to build a CRQC? The answer keeps changing, and that is what makes the quantum threat so urgent.

The Shrinking Resource Estimates

In 2019, a widely cited estimate put the cost at roughly 20 million physical qubits running for about 8 hours. By May 2025, the same lead researcher reduced this to under a million physical qubits running for less than a week.7

Resource estimates have dropped over 2,000 times in just a few years. The circuit depth required to break RSA 2048 has fallen dramatically thanks to advances in quantum algorithms and error correction techniques.8

Breaking RSA-2048 requires maintaining roughly 1,400 logical qubits through millions of sequential gate operations. Each logical qubit is built from many physical qubits using quantum error correction codes. The ratio depends on error rates, but current estimates vary from 250:1 to 1,000:1.3

  • Traditional estimate: 20 million physical qubits (2019)

  • Current best estimate: Under 1 million physical qubits (2025)

  • Pinnacle architecture: Under 100,000 physical qubits (theoretical)

  • Logical qubit requirement: Roughly 1,400 error corrected logical qubits

Every year, the qubit count needed for a CRQC drops. Quantum computing hardware roadmaps converge on 100,000+ physical qubits by the early 2030s. The gap between available hardware and these requirements is closing faster than most organizations realize.

CRQC Progress: Where Quantum Computing Stands Today

So where does CRQC progress actually stand?

Today's quantum computers are still NISQ devices. They have high error rates, limited coherence times, and nowhere near the fault tolerance needed for cryptanalysis. No one has built such a machine yet.2

Key Milestones in 2025 and 2026

But the trajectory of CRQC progress is accelerating. In June 2025, Quantinuum demonstrated the first universal, fully fault-tolerant quantum gate set with repeatable error correction. In March 2026, they followed with 94 error-protected logical qubits performing beyond break-even operations.9

IBM is targeting fault-tolerant quantum computing performance by 2029. IQM plans the transition from NISQ to error correction processors by 2027. Google moved its internal PQC transition deadline from 2030 to 2029 after new research showed timelines tightening.10

The CRQC framework assesses quantum computing readiness beyond just qubit count. Key metrics include reliability, sustained operation, and the ability to maintain coherent operation for hours while running algorithms like Shor's. A CRQC needs to execute million physical qubits level operations with fault-tolerant quantum computation precision.11

Does this mean a CRQC exists today? No, but the building blocks are falling into place faster than predicted. Estimates vary, but the projected timeline for practical CRQC capabilities is between 2030 and 2035.7

The CRQC Timeline: When Will Quantum Computers Break Encryption?

Expert Predictions and Government Deadlines

Predicting the exact date a CRQC arrives is impossible. But experts have converged on a window.

The Global Risk Institute survey shows roughly a 1 in 4 chance of a CRQC by 2030 and about a 50% probability by 2035. CRQC machines may emerge within 10 to 20 years from now.7

This is a real and growing quantum threat. Governments are mandating transitions to post quantum cryptography by 2035. The White House issued Executive Order 14412 in 2026, requiring federal agencies to submit PQC migration plans within 120 days.10

Quantum computing does not follow Moore's law in the same way classical computing did. Breakthroughs in error correction and quantum algorithms can cause sudden leaps. The timeline could compress without warning.

For national security systems, the clock is already ticking. Any organization facing the relevant quantum computer CRQC risk and protecting long-lived data like government records, medical records, and intellectual property cannot wait for the exact date to begin migrating.

Harvest Now, Decrypt Later: Why the CRQC Threat Is Already Here

The quantum threat begins now, not when quantum computers arrive, because of a certain attacker technique known as Harvest Now, Decrypt Later. Adversaries are intercepting and archiving encrypted data today, waiting for the day a quantum computer powerful enough to decrypt it becomes available.5

HNDL makes quantum threats a current concern, not a future one. Data encrypted today using quantum-vulnerable algorithms like RSA and ECC will be exposed the moment a CRQC breaks those systems.

This threat model is especially dangerous for long-lived data. Government records, financial data, medical records, classified communications, and intellectual property may retain sensitivity for decades. If the migration time from classical to quantum-safe encryption takes 5 to 10 years, and a CRQC arrives in the 2030s, organizations need to begin migrating now.6

Harvest Now, Decrypt Later poses a significant risk today. The quantum attack does not require a CRQC to be operational at the moment of interception. It only requires one to exist eventually.

Captured data can be decrypted once a CRQC exists. That makes every unprotected transmission a future liability.

Post-Quantum Cryptography: Preparing for the CRQC Era

Post-quantum cryptography is the answer to the CRQC threat. PQC algorithms are cryptographic algorithms designed to resist attacks from both classical computers and quantum computers.4

NIST Standards and Migration Steps

NIST finalized three post-quantum standards in 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). These algorithms are built on mathematical problems that even a CRQC cannot solve efficiently, including lattice and hash-based approaches.

Quantum-resistant cryptography protects digital signatures, key exchange, and encryption against such machines. But migrating is not simple. Organizations need crypto agility to swap cryptographic algorithms across their infrastructure without breaking existing systems.8

Here are the security requirements:

  • Inventory all quantum-vulnerable algorithms in your environment

  • Prioritize critical infrastructure and national security systems

  • Deploy PQC algorithms for public key encryption and digital signatures

  • Implement crypto agility for future algorithm transitions

  • Address the Harvest Now, Decrypt Later risk for long-lived data

Quantum key distribution is sometimes discussed as an alternative, but it requires specialized hardware and does not scales sufficient to protect global internet traffic the same way software-based post-quantum cryptography does.

The foreseeable future belongs to PQC algorithms. Organizations that begin migrating before a CRQC arrives will be protected, while those that wait may find their encrypted data exposed retroactively.

CRQC vs. NISQ: Error Correction and the Path Forward

What separates a CRQC from today's quantum computers?

NISQ devices have hundreds to a few thousand physical qubits with high error rates. They cannot run deep circuits. They cannot maintain coherence long enough for running Shor's algorithm against real-world key sizes. Such machines are useful for research and optimization, but not for cryptanalysis.2

Such a system operates with full fault-tolerant quantum computing at scales sufficient to break public key cryptography. It needs thousands of logical qubits, millions of physical qubits in the most conservative resource estimates, and the ability to sustain coherent operations for hours or days.3

Feature

NISQ Devices

CRQC

Physical qubits

Hundreds to thousands

Hundreds of thousands to millions

Error correction

None or limited

Full fault tolerant quantum error correction

Coherence time

Microseconds to milliseconds

Hours to days

Cryptographic impact

None

Breaks RSA, ECC, digital signatures

Timeline

Available now

Estimated 2030 to 2035

Quantum error correction is the bridge between these two worlds. When quantum computing crosses the fault tolerance threshold with enough physical qubits at low enough error rates, a cryptanalytically capable machine becomes possible.9

Sources

  1. PostQuantum.com, "Cryptographically Relevant Quantum Computers (CRQCs)," https://postquantum.com/post-quantum/crqc/

  2. Palo Alto Networks, "Brief: Cryptographically Relevant Quantum Computers (CRQC)," https://www.paloaltonetworks.com/cyberpedia/crqcs-cryptographically-relevant-quantum-computers

  3. Encryption Consulting, "CRQC Timelines: When Will Quantum Break Encryption?," https://www.encryptionconsulting.com/education-center/crqc-timelines-quantum-threat-landscape/

  4. CISA, "Post-Quantum Cryptography Initiative," https://www.cisa.gov/topics/risk-management/quantum

  5. Palo Alto Networks, "Harvest Now, Decrypt Later: Quantum Security Risk," https://www.paloaltonetworks.com/cyberpedia/harvest-now-decrypt-later-hndl

  6. Cloud Security Alliance, "Harvest Now, Decrypt Later: Quantum Risk to AI Infrastructure," https://labs.cloudsecurityalliance.org/research/ai-infrastructure-post-quantum-harvest-now-decrypt-later-v1/

  7. QRAMM, "Quantum Computing Threat Timeline: When Will Quantum Computers Break Encryption?," https://qramm.org/learn/quantum-threat-timeline.html

  8. PostQuantum.com, "The CRQC Scorecard: How Close Is Each Quantum Modality to Breaking Your Encryption?," https://postquantum.com/post-quantum/crqc-scorecard-how-close/

  9. Quantinuum / Paper Guide, "Quantum Computing Research 2026: Error Correction & Hardware," https://paperguide.ai/research-reviews/quantum-computing/

  10. Cloudflare Blog, "The White House's Post-Quantum Executive Order," https://blog.cloudflare.com/post-quantum-eo-2026/

Frequently Asked Questions

A CRQC (Cryptographically Relevant Quantum Computer) is a quantum computer with enough qubits, low error rates, and fault-tolerant quantum computation capability to run quantum algorithms like Shor's at the scale needed to break public key cryptography including RSA and elliptic curve cryptography.1
Estimates vary. The projected timeline for practical CRQC capabilities is between 2030 and 2035. Experts estimate a 1 in 4 chance of a CRQC by 2030 and roughly 50% by 2035. The exact date is uncertain, but the trend in quantum computing research is accelerating.
Current best resource estimates suggest under a million physical qubits to break RSA 2048, down from 20 million just a few years ago. The requirement depends on error rates, error correction efficiency, and circuit depth required for the specific quantum algorithms used.
NISQ devices are today's quantum computers with limited, noisy physical qubits and no meaningful error correction. A CRQC is a future fault-tolerant quantum computing system with thousands of logical qubits and the sustained coherence needed for running Shor's algorithm against real encryption. NISQ devices cannot break encryption; a CRQC can.
Harvest Now, Decrypt Later (HNDL) is a threat model where adversaries capture encrypted data today and store it until a CRQC capable of breaking the encryption becomes available. This makes the quantum threat a current risk even though no CRQC exists yet, particularly for long-lived data like government records and intellectual property.
Organizations should begin migrating to post-quantum cryptography now. That means inventorying quantum-vulnerable algorithms, deploying PQC algorithms for public key encryption and digital signatures, building crypto agility, and prioritizing critical infrastructure protection. The migration time required makes early action essential.
A CRQC weakens symmetric cryptography through Grover's algorithm, which provides a quadratic speedup against hash functions and symmetric keys. But it does not break them. Doubling key sizes (e.g., moving from AES-128 to AES-256) restores security against quantum computers.
Share

The Era Has Shifted. Has Your Architecture?

Download the three-part Containment Era whitepaper series. Then see your own blast radius with a Workload Attack Path Assessment.

Cta pattren Image