Minutes, Not Decades.
The quantum deadline already on your cryptography.

Could you answer the questions below — today, with confidence? Most organisations cannot. A passive external assessment is where the honest answers begin: what you expose to the outside world, and who owns that risk.

Assess Your Exposure →

There is a claim doing the rounds that quantum computers will crack today’s passwords “in minutes, not decades.” Like most compressions of a hard problem, it is half right — and the half it gets wrong is the half a security lead notices first. Getting the distinction correct is not pedantry. It is the entire basis of a defensible transition plan, because it tells you which controls to replace, which to keep, and in what order.

What quantum actually breaks

Two different algorithms threaten two different kinds of cryptography, and conflating them produces bad plans.

Shor’s algorithm attacks asymmetric cryptography — RSA, Elliptic-Curve Diffie-Hellman (ECDH) and the Elliptic-Curve Digital Signature Algorithm (ECDSA). This is the machinery behind key exchange, TLS sessions, VPN tunnels and digital signatures. Against these, a quantum computer offers an exponential speed-up. This is the genuine “infeasible today, tractable tomorrow” story, and it is where the “minutes” figure lives.

Grover’s algorithm attacks symmetric cryptography — AES and the like — and hashing. Here the speed-up is only quadratic. In practice that halves effective strength: AES-256 drops to roughly 128-bit security, which remains strong. Symmetric encryption and hashing survive the quantum era provided key sizes are increased. They are not the emergency.

The distinction, in one line The confidentiality and authentication layer collapses. The bulk-data cipher holds — if you sized the keys correctly. That gap is your transition.

So the accurate version of the headline is this: quantum does not render all security irrelevant. It breaks the asymmetric layer that establishes trusted sessions and proves identity, while leaving symmetric encryption standing. The figure below tracks a single account’s protection through all three states — how it is protected today, how a classical attacker fares, and what happens when a capable quantum machine is pointed at the same stack.

Post-quantum cryptography: how Shor and Grover break an account's protection layers (RSA, ECDH, ECDSA vs AES)Three-panel comparison of an account's protection layers today, under classical attack, and under a cryptographically-relevant quantum computer. 1  Protected today 2  Classical attacker 3  Quantum (CRQC) Layer 1 · Login Password + hash Symmetric-ish · slow hash HOLDS Strong password safe Guessing stays impractical MOSTLY HOLDS Grover halves strength Longer keys / hashes = safe Layer 2 · Session TLS key exchange RSA-2048 / ECDHE — asymmetric HOLDS > age of the universe Brute force is infeasible BREAKS · SHOR RSA-2048 → hours Session confidentiality lost Layer 3 · Identity Certificates & signatures ECDSA — asymmetric HOLDS Signatures trustworthy Forgery is infeasible BREAKS · SHOR ECC-256 → minutes* Identity can be forged Layer 4 · Transport VPN / IPsec tunnel Asymmetric handshake HOLDS Tunnel confidential Harvested traffic unreadable BREAKS · SHOR Handshake unwrapped Old captures decrypt * Google (Mar 2026) estimates ECC-256 solvable in minutes with fewer than ~1M physical qubits — a machine that does not yet exist. RSA-2048 needs thousands of logical qubits. Both remain future capability.
Figure 1. One account, three states. The asymmetric layers (2–4) are the emergency; the symmetric login layer survives with larger keys. "Minutes" is real but belongs to elliptic-curve key-breaking under a machine no one has built.

Who actually holds quantum computers now

The honest answer, verified against current roadmaps: real quantum computers exist and are advancing quickly, but no publicly known machine is a cryptographically-relevant quantum computer (CRQC) — none can yet run Shor’s algorithm against RSA-2048 — and no vendor claims one.

  • IBM fields the largest superconducting systems (on the order of a thousand physical qubits) and the most detailed fault-tolerance roadmap: roughly 200 error-corrected logical qubits by 2029, and around 2,000 in the early 2030s. Even that would not be a CRQC.
  • Google’s Willow chip demonstrated the key milestone — logical error rates falling as the error-correcting code grows — and targets a useful fault-tolerant machine by the end of the decade.
  • China (USTC, Jiuzhang) leads on specialised photonic sampling machines, which are impressive but not general-purpose code-breakers.
  • The gap: breaking RSA-2048 needs thousands of error-corrected logical qubits running deep circuits; the best machines today field dozens.

Two things have sharpened the topic. A February 2026 shift in expert consensus moved the estimate for useful machines from “decades” toward “within a decade.” And in March 2026 Google published a revised estimate cutting the resources needed to break elliptic-curve cryptography roughly twenty-fold. Neither means a CRQC exists. Both mean the runway is shorter than it looked. Working preparedness dates now cluster around 2029–2035.

Why “years away” is not “later”

Harvest now, decrypt later. Encrypted data captured today — TLS sessions, VPN traffic, stored backups — can be retained and decrypted the moment a CRQC exists. This is passive, undetectable, and, by multiple governments’ assessment, already underway. Any data whose confidentiality must survive into the 2030s is already exposed.

Migration is a multi-year programme, not a patch. Replacing asymmetric cryptography touches PKI, identity, certificates, network protocols, applications and every third-party dependency at once. Comparisons to Y2K in scope are not hyperbole.

Mosca’s inequality makes it arithmetic. If the time your data must stay secret plus the time your migration takes exceeds the time until a CRQC arrives, you are already too late. For most regulated organisations holding long-life data, that sum comfortably exceeds any credible arrival date.

The Australian obligation — and the milestones

This is not advisory in Australia; it is documented direction. The ASD’s Information Security Manual recommends ceasing use of traditional asymmetric cryptography (RSA, DH, ECDH, ECDSA) by the end of 2030, replacing it with ASD-approved post-quantum algorithms. That 2030 date already bakes in contingency — organisations are expected to add their own buffers for legacy systems and vendor dependencies. The standardised algorithms underpinning the transition are NIST’s, finalised in August 2024: FIPS 203 (ML-KEM) for key establishment, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for signatures.

ASD ISM post-quantum cryptography transition timeline, end-2026 to end-2030 (NIST FIPS 203, 204, 205)ASD ISM post-quantum transition timeline against rising quantum risk, from end of 2026 to end of 2030. rising CRQC risk → 2026 Refined plan Crypto inventory Map every use of asymmetric crypto 2028 Begin migration Critical systems first Long-life sensitive data, hybrid schemes 2030 Transition complete Cease RSA / ECC PQC by default; monitor & validate ASD ISM · recommended PQC transition milestones
Figure 2. The ASD ISM sequence. The end-of-2026 milestone is the one with your name on it right now: a refined, organisation-specific transition plan accounting for data value, dependencies and risk tolerance.

Note the leverage: CPS 234 already obliges APRA-regulated entities to implement information-security controls proportionate to the criticality of their information assets — standing authority to treat quantum-resistant cryptography as ongoing risk management, even though it names no specific algorithm. Layer in SOCI obligations and the long retention periods mandated elsewhere, and the harvest-now-decrypt-later exposure becomes board-reportable today.

Start Here — What To Do Before The End Of 2026

  • Build a cryptographic inventory (a CBOM). Map where public-key cryptography lives — systems, protocols, certificates, applications, every third-party integration. You cannot migrate terrain you have not surveyed.
  • Rank data by confidentiality shelf-life. Data that must stay secret into the 2030s is already exposed to harvest-now-decrypt-later and moves to the front of the queue.
  • Design for crypto-agility. Treat algorithms as swappable configuration, not hard-coded assumptions, so the next transition is a parameter change, not a rebuild.
  • Adopt tested hybrid (classical + PQC) schemes where suitable, so you are protected against weaknesses in either primitive during changeover.
  • Push PQC into procurement. Ask vendors to demonstrate working FIPS 203/204/205 support in your environment. Contracts signed today should not lock in quantum-vulnerable dependencies.
  • Map the programme to your obligations. Anchor it to the ASD ISM milestones and, where relevant, CPS 234 and SOCI, so the transition is governed and evidenced, not improvised.

The quantum threat rewards the unglamorous discipline good GRC already prizes: know what you have, know what it protects, and change it in a governed order before you are forced to. A CRQC may be years away. Your inventory, your data-retention exposure and your vendor lock-in are present-tense. Start with the survey.

Sources & references

Is Your Vendor Stack
Assessed and Documented?

A BlackFlag Advisory vendor risk assessment gives your Board an independent, evidenced view of what your third-party providers expose — before an incident makes it an urgent question.

Request an Assessment →
Passive Only — No Systems Accessed

All BlackFlag Advisory assessments use exclusively passive OSINT techniques and publicly available data sources. No systems, networks, or accounts are accessed, probed, or tested at any time. Board-ready output delivered within three to seven business days.