Key facts
- Q-Day prediction
- Google expects Q-Day as soon as 2029
- US government call
- Development of a quantum computer by 2028
- Post-quantum algorithms
- ML-KEM, ML-DSA, SLH-DSA selected by NIST
- Threat
- Harvest now, decrypt later (HNDL) already happening
- Regulation
- EU DORA requires cryptographic resilience
Background
Quantum computing, an advanced field leveraging quantum physics, can solve complex problems exponentially faster than current supercomputers. This capability threatens standard public-key encryption, which underpins digital trust in online banking, cloud services, and remote authentication.
The term 'Q-Day' refers to the hypothetical milestone when quantum computers become powerful enough to break public-key encryption. Google has officially announced it expects Q-Day as soon as 2029, and the US government has called for a quantum computer by 2028.
Standards bodies and regulators are already working on replacements. The US National Institute of Standards and Technology (NIST) has selected post-quantum algorithms: ML-KEM for key establishment, and ML-DSA and SLH-DSA for digital signatures. A further standard, FIPS 206, is nearing draft approval.
Current situation
Despite these developments, many boards are acting as if the risk does not exist. The uncomfortable truth is that inaction is increasingly an indefensible risk decision, according to Antony Russel, chief technology officer at Telviva.
Two distinct risks face businesses. The first is the day after Q-Day, when attackers could access encrypted sessions and decode them. The second, already happening, is 'harvest now, decrypt later' (HNDL), where bad actors capture encrypted traffic today and store it cheaply, decrypting it once Q-Day arrives.
Quantum readiness is a governance problem, not a configuration bug. The EU's Digital Operational Resilience Act (DORA) requires financial entities to understand their cryptographic dependencies and prove resilience when threat models change.
Impacts
If Q-Day arrives, cryptographic trust could be devalued or destroyed. Attackers could derive private keys from public keys, enabling them to read or forge secure communications. This would affect customer logins, payment flows, API gateways, and remote access.
Cloud communications and contact centres are particularly exposed, as they sit at the intersection of sensitive customer interactions and the public internet. Businesses outsourcing these services are outsourcing a significant slice of their cryptographic posture.
The 'harvest now, decrypt later' risk means that today's secure communications could become tomorrow's leaks. Organisations that delay action may face breaches of data that was captured years earlier.
Future outlook
Scenario analysis: The possibilities below are not certain predictions.
The precise date of Q-Day will only be obvious in hindsight, probably because of a breach or a quiet standards update. It may never happen, but prudent planning is essential.
If Q-Day arrives as Google predicts, organisations that have prepared with cryptographic bills of materials and post-quantum adoption will have robust protections. Those that waited may struggle to explain their inaction.
If Q-Day is delayed or never occurs, preparations will still strengthen security. The industry has moved from 'if' to 'how fast', and businesses should demand quantum-resistant products from providers.
Source: it-online.co.za



