Quantum Computing: Separating the Decade from the Demonstration
A sober reading of error-correction progress, what it implies for cryptographic migration timelines, and the small number of things worth doing about it immediately.
Separating two questions
Discussion of quantum computing routinely conflates two very different questions: when will quantum machines do something useful, and when will they break current cryptography.
These have different answers and different implications. Useful quantum advantage in chemistry or materials simulation may arrive incrementally and benefit whoever is positioned to use it. Cryptographically relevant quantum computing is a threshold event with security consequences that must be prepared for well in advance.
Conflating them produces both complacency and panic, often in the same organisation.
Where error correction actually stands
The genuine progress of recent years has been in error correction rather than raw qubit count. Demonstrations that logical error rates fall as physical qubits are added — that the correction is working faster than the noise accumulates — are the meaningful milestone, because they establish that the approach scales in principle.
The remaining gap is nonetheless large. Cryptographically relevant machines require logical qubit counts several orders of magnitude beyond current demonstrations, sustained for long computations. Closing that gap is an engineering problem of considerable difficulty, and estimates from serious researchers span a wide range.
Honest summary: the direction is established, the timeline is not, and anyone offering a confident date is overreaching.
Why uncertainty still compels action
The security case does not depend on knowing the date, because of harvest-now-decrypt-later. An adversary can capture encrypted traffic today and decrypt it whenever capability arrives.
The relevant question is therefore not when quantum computers will exist but how long your data must stay confidential. Data with a twenty-year secrecy requirement — health records, diplomatic traffic, long-term commercial agreements — is already exposed under any plausible timeline.
This reframing is what turns an uncertain research question into a definite present obligation for a specific subset of data.
The short list
Three actions are justified now, and they are unglamorous.
First, inventory: know where cryptography is used across your estate, including in embedded systems and vendor products. Most organisations cannot answer this, and the inventory takes longer than the migration. Second, prioritise by secrecy lifetime rather than by system importance. Third, require crypto-agility in procurement, so that algorithms can be replaced without replacing the system.
Building a quantum computer is not on the list. For almost every organisation, the correct posture is preparation for the consequences rather than participation in the race.