Quantum Computing Timeline: Key Milestones From 1981 to Today
| Year | Milestone |
|---|---|
| 1981 | Richard Feynman argues that simulating quantum physics needs a computer that itself follows quantum rules. |
| 1985 | David Deutsch describes a universal quantum computer. |
| 1994 | Peter Shor publishes an algorithm that could break RSA and elliptic curve cryptography on a large quantum computer. See post-quantum crypto. |
| 1996 | Lov Grover publishes a quantum search algorithm with a quadratic speed-up. |
| Late 1990s | First small quantum computers demonstrate a couple of qubits in the lab. |
| 2016 | IBM puts a small quantum processor online for public cloud access. |
| 2019 | Google reports a sampling task completed faster than classical supercomputers could manage, a claim that was debated. See quantum advantage. |
| 2024 | NIST publishes its first post-quantum cryptography standards, and researchers report progress on error correction. |
What the timeline shows
Theory ran ahead of hardware for decades. Today's machines are real but small, and the next big step is reliable error correction. Learn about the building blocks in what quantum computing is and the hardware types.
What each milestone did and did not show
| Milestone | What it showed | What it did not show |
|---|---|---|
| Shor, 1994 | A quantum computer could factor large numbers far faster than any known classical method. | That anyone could build a machine big enough. Estimates for breaking 2048-bit RSA run to roughly 20 million noisy qubits (Gidney and Ekera, 2021). |
| Grover, 1996 | A quadratic speed-up for unstructured search. | Anything dramatic: it is provably close to the best possible for that task. |
| IBM, 2001 | A seven-qubit machine factored 15 into 3 times 5. | A real Shor run. Some small demos used prior knowledge of the answer to simplify the circuit. |
| IBM, 2016 | Public cloud access to a five-qubit superconducting processor. | Anything faster than a laptop. It was a learning tool. Earlier cloud access existed too, such as the University of Bristol project. |
| Google, 2019 and Willow, 2024 | Sampling tasks beyond classical reach, then error rates that fell as encoded grids grew from 3x3 to 5x5 to 7x7 on a 105-qubit chip. | A practical commercial use. Google itself says useful real-world problems are still a goal. |
| NIST, 2024 | Three finalized post-quantum standards: FIPS 203, 204 and 205. | That a code-breaking machine exists. It is preparation, and NIST urged people to start integrating the standards now. |
Worked example: why Grover is a modest speed-up
Searching an unsorted list of N items takes about N/2 checks on average on a classical computer. Grover's algorithm needs about (pi/4) times the square root of N steps. For a list of 1,000,000 items, that is about 500,000 checks versus about 785 quantum steps. Impressive, but notice the shape: the saving is a square root, not an exponential jump, which is why it matters far less for cryptography than Shor's algorithm does. See Grover's Algorithm Explained Step by Step and Shor's Algorithm Explained Step by Step.
How to read a milestone headline yourself
- Find the task. Was it a useful problem or a benchmark chosen to favor quantum hardware?
- Count logical qubits, not just physical ones. Error-corrected qubits are what matter for big algorithms. See Logical vs Physical Qubits.
- Look for the classical rebuttal. Several quantum advantage claims were later matched by better classical methods. See Google's Supremacy Claim, IBM's Rebuttal and the Classical Catch-Up.
- Check for a paper. A peer reviewed paper beats a press release. Use the red flag checklist.
Common mistakes
- Treating qubit count as a score. Quality and error rates matter as much as quantity.
- Assuming the 2019 result means quantum computers can already break encryption. They cannot.
- Assuming a slow history means a dead end. Error correction results like Willow's are the kind of step the field was waiting for, and that is a genuine reason for optimism.
For deeper dives into each era, read Quantum History Part 2, Quantum History Part 4 and Quantum History Part 5. This page is education only and not financial advice. It makes no prediction for any token, and the QNT memecoin is independent of any quantum company.
Sources and further reading
- NIST: first 3 finalized post-quantum encryption standards (13 August 2024)
- Wikipedia: Shor's algorithm (1994 paper, 2001 factoring of 15, resource estimates)
- Wikipedia: Grover's algorithm (quadratic speed-up, about pi/4 times the square root of N steps)
- Google: Meet Willow (105 qubits, below-threshold error correction, caveats)
- IBM newsroom, 4 May 2016: quantum computing on IBM Cloud (five superconducting qubits)
- eWEEK: IBM brings quantum computing to the masses (notes earlier Bristol cloud access)
Facts checked 2026-10-09 against the linked pages. Education only, not financial advice. Nothing here predicts the price of any asset, and the QNT memecoin is an independent community token with no link to Quantinuum Ltd or any lab, chain or exchange named on this page.
Frequently asked questions
Who invented quantum computing?
There is no single inventor. Richard Feynman and David Deutsch are among the key early thinkers in the 1980s.
When will quantum computers be useful?
Nobody knows. It depends mainly on progress in error correction and hardware scale.
What was the first quantum computer?
It depends on the definition. Small lab demonstrations with a few qubits appeared in the late 1990s, and in 2016 IBM offered a five-qubit processor to the public through the cloud.
Did anyone really factor numbers with Shor's algorithm?
Only tiny ones. A 2001 IBM experiment factored 15, and even that used simplifications. Breaking real encryption would need vastly larger, error-corrected machines.
What did Google's Willow chip show?
Google reported that errors fell by about half each time its encoded qubit grid grew from 3x3 to 5x5 to 7x7 on a 105-qubit chip. It is a milestone for error correction, not a finished fault-tolerant computer.
Why did NIST publish standards before quantum computers could break encryption?
Because data can be recorded now and unlocked later, and migrating systems takes years. NIST encouraged administrators to start integrating the standards immediately.
Is quantum computing history mostly hype?
No. The theory is solid and the hardware is improving, but timelines have repeatedly proved harder than headlines suggested. Judge each claim on evidence.
Keep reading
- What Is Quantum Computing? A Plain English Guide
Quantum computers use qubits instead of bits. Learn what quantum computing is, what it is good at, and why the crypto world pays attention. - Quantum Supremacy vs Quantum Advantage Explained
What the terms quantum supremacy and quantum advantage mean, and why headline claims are often debated. - Post-Quantum Cryptography and Crypto: What It Means
Why large quantum computers could threaten blockchain signatures, and what post-quantum cryptography is doing about it.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary