What Do Experts Say About Q-Day? The Global Risk Institute Survey Numbers
The survey in brief
Each year the Global Risk Institute publishes a Quantum Threat Timeline Report by Michele Mosca and Marco Piani, built from a survey of quantum experts. It is the most-cited gauge of expert opinion on when Shor's algorithm could threaten RSA and other public key systems. The 2025 edition is the seventh in the series, and the Institute's page carries the date 9 March 2026. Always check which edition a quote comes from, because older editions had different numbers and some sources date this one differently.
The headline numbers I read
- Respondents: 26 experts, down from 32 in 2024 and 37 in 2023, per PostQuantum.com's analysis.
- Within 10 years: a cryptographically relevant quantum computer (CRQC) is described as "quite possible" at 28% to 49%. The 49% is the averaged optimistic reading and 28% the pessimistic reading. In 2024 the equivalent figures were 34% and 14%. The analysis calls 2025 the highest 10-year estimate in the report's history.
- Within 15 years: described as "likely" at 51% to 70%. The analysis adds that 18 of 26 respondents (69%) put it at 50% or higher.
- Within 20 years: 92% of respondents put it at 50% or higher, and nearly half judged it "extremely likely" (above 99%), as reported.
I could not obtain figures for 1, 5 or 30 years from the sources I read, so I am not giving any.
What the numbers mean
The survey defines a CRQC as a machine able to factor a 2048-bit RSA integer in under 24 hours. Why a range such as 28% to 49%? Experts answer on probability bands, and the authors compute an optimistic average (taking the top of each respondent's band) and a pessimistic one (taking the bottom). The truth of the opinion lies somewhere between. It is wrong to quote only 49% or only 28%.
Why opinions moved up
PostQuantum.com reports that the Institute attributes the shift to Google's Willow chip showing error correction beyond break-even, neutral-atom progress, Gidney's May 2025 estimate of under a million noisy qubits (see RSA estimates history) and a 2025 result reducing the logical qubit count to 1,730. The same analysis argues that major papers appeared just after the survey closed, so views may have been slightly out of date. That is the analyst's view, not the survey authors' claim.
Limits you should know
- Small sample. 26 people. A shift of two or three answers moves averages noticeably.
- Coarse bins. The middle bin spans 30% to 70%.
- Who answered. Per the analysis: 9 North American, 12 European, 3 Asian and 2 Oceanian respondents, none from China, mostly universities, few from firms building fault-tolerant hardware.
- Opinion, not measurement. Experts have been wrong in both directions about technology timelines.
- RSA only. The survey did not ask about elliptic curves, according to the analysis (see the curve estimates).
- Skewed answers. The authors themselves warn that skewed distributions and outliers can affect the interpretability of averages.
Using the Mosca inequality
The Institute and its authors popularized a simple rule: if the years your data must stay secret, plus the years your migration takes, exceed the years until a CRQC, you have a problem. You do not need to know the date. You need to compare your own two numbers against a range of possible dates. A hospital record that must stay private for 30 years and a migration that takes 8 years add to 38, which exceeds even the optimistic 10 year slice, so waiting is risky. A short-lived session token has no such issue. See harvest now, decrypt later.
How to use surveys sensibly
- Quote the range and the sample size.
- Treat it as one input beside hardware milestones and resource estimates.
- Expect revisions each year.
- Never turn a probability band into a calendar date.
This is education, not financial advice, and it makes no price call on any asset. The QNT memecoin is independent of Quantinuum Ltd. For the overview, see Q-Day explained.
Sources and further reading
- Global Risk Institute: Quantum Threat Timeline Report 2025 (page dated 9 March 2026)
- PostQuantum.com: analysis of the Quantum Threat Timeline Report 2025
- Gidney (May 2025): How to factor 2048 bit RSA integers with less than a million noisy qubits, arXiv
Reported as of 2026-10-09. Resource estimates are theoretical preprints or whitepapers, surveys are opinion, and government dates are planning targets, so check the primary documents. Nothing here is financial advice or a prediction of any asset price. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, chain and government named on this page.
Frequently asked questions
What did the Global Risk Institute survey say about the next 10 years?
The 2025 report (page dated 9 March 2026) put a cryptographically relevant quantum computer at 28% to 49% likely within 10 years, from 26 experts, depending on optimistic or pessimistic averaging.
Does 49% mean there is a 49% chance of Q-Day by 2036?
Not exactly. It is the optimistic averaged reading of a small expert survey. The pessimistic reading is 28%. It is opinion, not a forecast or a guarantee.
How reliable are expert surveys?
They are useful but limited. The sample was 26 people, the bins are coarse, and no respondents were from China according to one analysis. Use them with hardware and estimate evidence.
Keep reading
- Q-Day Explained: What It Means, Why Nobody Knows the Date, and the Early Warning Signs
Q-Day is the day a quantum computer can break today's public key cryptography. Here is what it really means, why dates are ranges, and what signs to watch. - Harvest Now, Decrypt Later: The Quantum Threat Explained
Harvest now, decrypt later means collecting encrypted data today to unlock it with a future quantum computer. What it is and who should care. - Quantum Computing Timeline: Key Milestones From 1981 to Today
A short history of quantum computing, from Feynman's 1981 idea and Shor's algorithm to cloud quantum computers and post-quantum standards.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary