What Governments Assume About Q-Day, and a Calm What-To-Do-Now List
Deadlines, not predictions
Governments rarely say "a quantum computer will break encryption in year X." They publish migration deadlines, which are a planning tool: they say when old cryptography must be gone, leaving a safety margin before any real threat. Reading deadlines as predictions is a common mistake. Several are also targets that can be revised.
NIST (United States)
NIST's Internal Report 8547, "Transition to Post-Quantum Cryptography Standards," was released as an initial public draft on 12 November 2024. I read the draft's tables: quantum-vulnerable public key algorithms at 112 bits of security strength are marked "Deprecated after 2030," and those algorithms are marked "Disallowed after 2035," with the 128-bit-or-higher strengths marked disallowed after 2035. The draft also cites National Security Memorandum 10, which sets 2035 as the primary target for completing migration across federal systems. This is a draft, so final wording could differ. See the deadlines overview and how NIST chose algorithms.
NSA (United States, national security systems)
The NSA's CNSA 2.0 advisory could not be opened directly in my research session, so I rely on a secondary summary. It reports a goal of quantum-resistant national security systems by 2035, with earlier exclusive-use targets of 2030 for software and firmware signing and for networking equipment, and 2033 for web, cloud and operating systems. It names ML-KEM-1024, ML-DSA-87, and stateful hash-based signatures (LMS or XMSS) for firmware signing. Secondary sources disagree on a few intermediate dates, so check the NSA document itself.
UK NCSC
The NCSC page I read sets three milestones. By 2028: define migration goals, run a full discovery of where you use cryptography and build an initial plan. By 2031: carry out early, highest-priority migration work and refine the plan into a thorough roadmap. By 2035: complete migration of all systems, services and products to post-quantum cryptography.
Germany BSI
A secondary report on BSI's technical guideline says operators of critical infrastructure under Germany's KRITIS rules should finish by 2030 and everyone else by 2032, and that using classical RSA, elliptic curve and Diffie-Hellman beyond those dates is incompatible with BSI's minimum security requirements. The same article does not say when a cryptographically relevant quantum computer might exist. I did not read the BSI document itself.
What the pattern tells us
Four agencies, one rough cluster: serious migration work done between 2030 and 2035. That tells you the agencies treat the risk as real enough to plan for within roughly a decade, but none of the sources above gives a Q-Day. The deadlines are shaped by how long migration takes, not by a hardware forecast. See what experts say.
A calm what-to-do-now list: individuals
- Update everything. Browsers, phones and messaging apps are adding hybrid post-quantum key exchange through ordinary updates.
- Use strong, unique passwords and a password manager. Quantum computers are not your biggest risk today. Phishing and reuse are.
- Know what you hold for the long term. Very sensitive records that must stay private for decades are the ones worth thinking about first.
- Crypto holders: avoid reusing addresses, keep your seed phrase offline, and follow your wallet's upgrade notes. See what individuals can do and exposed public keys.
- Ignore panic sales pitches. Nobody can sell you a quantum-proof guarantee.
For companies
- Inventory. List where you use RSA, elliptic curves and Diffie-Hellman, including in vendors and devices. This matches the NCSC 2028 discovery milestone.
- Rank by data lifetime. Apply the logic of harvest now, decrypt later to long-lived secrets first.
- Build crypto agility. Make algorithms swappable. See crypto agility.
- Ask vendors for their roadmaps and add post-quantum requirements to contracts.
- Pilot hybrid modes in test environments, then plan certificate and PKI changes (see PKI challenges).
- Follow the full migration checklist and track your regulator's dates.
None of this requires panic. It is the same careful maintenance good security teams already do, started early. This page is education only and not financial or security advice for your situation, and it does not predict the price of any asset. The QNT memecoin is independent of Quantinuum Ltd and of every agency named here.
Sources and further reading
- NIST IR 8547 initial public draft (November 2024): Transition to Post-Quantum Cryptography Standards
- UK NCSC: PQC migration timelines
- PostQuantum.com: NSA CNSA 2.0 overview (secondary source)
- PostQuantum.com: Germany BSI deadlines (secondary source)
- Global Risk Institute: Quantum Threat Timeline Report 2025 (page dated 9 March 2026)
Reported as of 2026-10-09. Resource estimates are theoretical preprints or whitepapers, surveys are opinion, and government dates are planning targets, so check the primary documents. Nothing here is financial advice or a prediction of any asset price. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, chain and government named on this page.
Frequently asked questions
Do governments say when Q-Day will happen?
No. The agencies I checked set migration deadlines rather than predicting a date. NIST's 2024 draft proposes deprecating at-risk algorithms after 2030 and disallowing them after 2035, and the UK NCSC sets 2028, 2031 and 2035 milestones.
What should an ordinary person do about Q-Day?
Keep devices and apps updated, use unique passwords with a password manager, and think first about data that must stay private for decades. Avoid anyone selling a quantum-proof guarantee.
What is the first step for a company?
Build an inventory of where RSA, elliptic curves and Diffie-Hellman are used, including vendors. The UK NCSC lists discovery and an initial plan as its 2028 milestone.
Keep reading
- A Plain English Post-Quantum Migration Checklist for Companies
A step by step checklist any company can follow to get ready for post-quantum cryptography, including how banks and financial firms are prioritizing. - What Individuals Can Do About Quantum Risk Today: A Calm Checklist
Practical, non-alarmist steps for crypto holders: address hygiene, wallet updates, backups and what to ignore. - Government Post-Quantum Deadlines: NIST, NSA CNSA 2.0 and Federal Migration
The dates governments have set to move off RSA and elliptic curves: NIST 2030 and 2035, NSA CNSA 2.0 milestones, and the January 1, 2027 acquisition rule.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary