The Quantum Deadline Has Already Started
No one knows exactly when a quantum computer capable of breaking today’s widely used public-key cryptography will arrive. Estimates vary, technologies are advancing at different rates, and breakthroughs are difficult to predict.
Waiting can feel rational when the timing of a technological threat remains uncertain. The closer the threat appears, the easier it seems to quantify, budget for, and address. That logic becomes dangerous when preparation itself may take years.
Organizations already have enough information to determine when preparation should begin. Their timeline is being shaped by two practical questions: how long must their sensitive information remain secure, and how long will it take to migrate the systems that protect it?
For governments, companies, financial institutions, healthcare organizations, and operators of critical infrastructure, the answers to those questions can reach many years into the future. That makes quantum readiness a present-day cybersecurity and infrastructure challenge, even while cryptographically relevant quantum computers remain a future technology.
The easiest way to understand why is through three clocks.
Three clocks are already running
The first is the Quantum Clock. It measures the time until sufficiently powerful quantum computers can threaten today’s widely deployed public-key cryptography.
We do not know when that clock will reach zero.
Progress in quantum computing is real, but building a machine capable of breaking widely deployed public-key cryptography at meaningful scale remains an enormous scientific and engineering challenge. Predictions differ substantially, making the Quantum Clock difficult to use as the sole basis for strategic planning.
Its uncertainty, however, does not stop it from ticking.
Fortunately, organizations have two other clocks they can measure much more accurately.
The second is the Data Clock: how long does information created today need to remain secure?
For some data, the answer may be months. For other information, it may be ten, twenty, or even thirty years. Government secrets, defense information, intellectual property, health records, diplomatic communications, research, and information related to critical infrastructure can retain their sensitivity for very long periods.
The Data Clock creates a direct connection between today’s information and tomorrow’s quantum capabilities.
Encrypted information can be intercepted and stored today with the intention of decrypting it in the future. This approach is commonly known as Harvest Now, Decrypt Later. An attacker needs access to encrypted information today and the ability to preserve it until more powerful decryption capabilities become available.
If information stolen today will still be valuable when the Quantum Clock reaches zero, its exposure has effectively begun before a cryptographically relevant quantum computer exists.
That is why the security lifetime of data matters as much as predictions about the technology itself.
The Migration Clock
The third clock may ultimately be the one organizations underestimate most: the Migration Clock.
It measures how long an organization will need to identify, replace, test, and deploy the cryptography that protects its digital environment.
Modern cryptography is deeply embedded in digital infrastructure. It protects websites, applications, identities, certificates, software updates, cloud services, APIs, VPNs, devices, communications, payment systems, digital signatures, and countless connections between machines.
For a large organization, the transition to post-quantum security will require far more than installing a software update.
Before anything can be replaced, an organization needs to discover where vulnerable cryptography exists. It then needs to classify systems by risk, understand external dependencies, determine which technologies can be upgraded and which must be replaced, test new implementations, coordinate vendors, and deploy changes without disrupting critical operations.
The complexity increases further in environments containing legacy infrastructure, operational technology, embedded systems, or equipment designed to remain in service for decades. Some systems can be upgraded remotely. Others may require hardware replacement, recertification, regulatory approval, procurement cycles, or coordination across an entire supply chain.
A single business process may depend on multiple vendors, certificates, protocols, applications, and systems. Changing one component can affect another.
This is why organizations such as NIST increasingly emphasize cryptographic discovery, inventory, interoperability, and migration planning as essential parts of the transition to post-quantum cryptography.
For a large organization, the Migration Clock can run for years.
And that changes the calculation completely.
When the clocks overlap
Imagine an organization holds information today that must remain confidential for fifteen years.
Now assume, purely for planning purposes, that a cryptographically relevant quantum computer becomes available fourteen years from today. At first glance, the organization might believe it still has plenty of time.
Now add the Migration Clock.
If discovering cryptographic dependencies, testing alternatives, replacing vulnerable systems, coordinating suppliers, and completing deployment takes five years, waiting ten years to begin would leave the organization attempting a five-year migration with only four years remaining on the Quantum Clock.
The Data Clock makes the situation even more demanding. Information intercepted during those years may still retain value when quantum decryption becomes possible.
This is where the three clocks converge.
The Quantum Clock tells us how much time may remain before the technology changes the threat environment. The Data Clock tells us how long today’s information needs protection. The Migration Clock tells us how much of the remaining time an organization will need simply to prepare.
Together, they provide a much more useful definition of quantum readiness:
Your quantum deadline begins when the security lifetime of your sensitive data overlaps with the time required to migrate the systems protecting it.
For some organizations, that point may still be years away. For others, the clocks may already be overlapping.
The Migration Clock is already moving
The global response increasingly reflects this reality.
In 2024, the U.S. National Institute of Standards and Technology finalized its first three post-quantum cryptography standards and encouraged organizations to begin integrating them into their systems. Governments and technology companies have since accelerated planning and migration efforts.
The UK’s National Cyber Security Centre has published a roadmap aimed at completing migration to post-quantum cryptography by 2035, with earlier milestones for discovery, planning, and high-priority migration.
Major technology companies are moving as well. Google has established a migration timeline extending toward 2029. Meta has described its framework for prioritizing systems, building cryptographic inventories, managing external dependencies, and implementing post-quantum protections. Cloud providers and technology vendors are increasingly incorporating post-quantum capabilities into products and roadmaps.
These timelines are important because they reveal something about the Migration Clock. Large organizations are beginning years in advance because transforming complex digital infrastructure takes time.
You do not have to believe that a cryptographically relevant quantum computer will arrive tomorrow to believe that migration should begin today.
Measure the clocks you can control
For organizational leaders, the uncertainty surrounding the Quantum Clock can easily dominate the conversation.
But the other two clocks are much closer to home.
Organizations can begin measuring the Data Clock by identifying their most sensitive information and determining how long it must remain protected. Data that loses its value quickly creates a very different risk profile from intellectual property, government information, or strategic records that may need to remain confidential for decades.
They can begin measuring the Migration Clock by discovering where cryptography lives across their environment.
This can be far more difficult than it sounds. Cryptography has accumulated inside technology environments over decades. It may exist in internally developed applications, products purchased from vendors, cloud services, network equipment, embedded devices, identity systems, certificates, software libraries, and systems that few people inside the organization still fully understand.
Organizations also need to map their dependencies. Migration will often rely on vendors, cloud providers, equipment manufacturers, software companies, and partners moving at different speeds.
Leaders cannot control the Quantum Clock, but they can measure the other two. They can determine the security lifetime of their most sensitive data and begin estimating how long migration will take.
Those two measurements turn an uncertain future threat into a risk that can be managed today.
Build a better Migration Clock
There is another reason to begin this work early.
The Migration Clock does not have to remain fixed.
Organizations that understand their cryptographic environment and design systems for change can shorten future migrations. Organizations that continue embedding cryptography deep inside inflexible systems may lengthen them.
This is where cryptographic agility becomes important: the ability to identify, replace, and update cryptographic mechanisms without redesigning entire systems every time the security environment changes.
For decades, cryptographic algorithms have often been treated as relatively permanent components of infrastructure. They were implemented, certified, and expected to remain in place for many years.
The Quantum Era challenges that assumption. Algorithms will evolve. Standards will change. New vulnerabilities may emerge. Technologies considered secure today may eventually need to be replaced again.
Cryptographic agility therefore does more than help organizations complete the current post-quantum transition. It changes the Migration Clock itself, reducing the time required to respond to future changes in cryptography.
That may prove to be one of the most important lessons of this transition.
Quantum readiness is a leadership decision
The three clocks also make clear why quantum readiness extends beyond cybersecurity teams.
The Data Clock involves decisions about which information matters and how long its value must be protected.
The Migration Clock touches applications, procurement, hardware, cloud infrastructure, suppliers, compliance, budgets, and long-term technology architecture.
And the Quantum Clock creates the external strategic pressure against which all those decisions must be measured.
Boards and executive teams do not need to become quantum physicists or cryptographers. They need to ensure their organizations understand these timelines.
How long must our most sensitive information remain secure? Where does vulnerable cryptography exist across our environment? Which systems will be hardest to migrate? Which dependencies are outside our control? What are our technology providers doing? Are new systems being designed with post-quantum migration in mind? Can our infrastructure change cryptographic mechanisms again when necessary?
Those are governance questions as much as technical ones.
Leaders may never know exactly when the Quantum Clock will reach zero. They do not need to.
They can measure the Data Clock. They can measure the Migration Clock. And they can act while both still leave them time to prepare.
The organizations best prepared for the Quantum Era will be those that understand their own clocks before the Quantum Clock forces the decision upon them.
The quantum deadline has already started.
In my next article, I will examine one of the first problems organizations encounter when they try to measure their Migration Clock: they do not actually know where their cryptography is. Before an organization can migrate to the Quantum Era, it first has to find what needs to change.

