Quantum computing risk: the corporate threat starts today

16/09/2026

Quantum computing is usually presented as a technology of the future. For corporate security it is not. Encrypted data intercepted today can be stored and decrypted once a sufficiently powerful quantum computer exists. The question is not when that machine will arrive, but how long your information needs to stay confidential, and whether that period ends before or after it arrives.

Almost all the cryptography that protects banking, communications, digital identity, industrial control systems and supply chains relies on public-key algorithms such as RSA and elliptic curves. A large, fault-tolerant quantum computer running Shor’s algorithm would break them. No such machine is publicly known to exist today. Even so, regulators in the United States, the European Union and the United Kingdom have already set migration deadlines, and the first post-quantum cryptography standards from NIST have been in force since 2024. The threat has not yet materialised technically, but the obligation to act has already materialised in regulation.

The argument of this analysis is the following: quantum risk is not an IT problem to be solved in 2035. It is a strategic, contractual and third-party risk that is already running today, because the data being captured now will still be sensitive when it can be read. Organisations that treat it as a technological curiosity will face the transition under regulatory pressure, with no inventory and no leverage over their suppliers.

3
NIST post-quantum
standards finalised (2024)
< 1 M
Noisy qubits estimated
to break RSA-2048
2030
EU target for
high-risk systems
2035
Horizon to retire
RSA and ECC

These four figures summarise the problem. The replacement standards already exist. The estimated hardware threshold needed to break current encryption has fallen by more than an order of magnitude in six years. And the regulatory calendar for migration is already fixed. What is still missing in most organisations is the first step: knowing what cryptography they use, where it is, and which data depends on it.

Quantum computing risk timeline: NIST post-quantum standards 2024, EU and NCSC PQC migration milestones 2030 and 2035, and the harvest now decrypt later exposure window

Source: own elaboration · ACK3® Global Hybrid SOC

“Most boards still think quantum risk starts the day the machine exists. It doesn’t. It starts the day someone copies your encrypted traffic and stores it. If a merger, a tender, a patent or a government contract has to stay confidential for ten years, that information is already exposed today.”

— Antonio García, Senior Operations Coordinator (GPC), ACK3® · Strategic Risk Consulting

What quantum computing changes, and what it does not

Quantum computing does not make every system vulnerable, and it will not replace classical computing. Its impact on security is specific and serious. Public-key cryptography (RSA, Diffie-Hellman, elliptic curves), which underpins key exchange, digital signatures, certificates and secure communications, would be broken by a cryptographically relevant quantum computer. Symmetric cryptography (such as AES) and hash functions are affected much less, and larger key sizes are generally enough to keep them secure. The core challenge is therefore not that “encryption stops working”. The challenge is that the mechanisms used to establish trust between systems, people and organisations have to be replaced across the entire digital infrastructure.

Harvest now, decrypt later

The most immediate threat has a name: harvest now, decrypt later. State-level actors with the capacity to intercept and store large volumes of encrypted traffic do not need a quantum computer today. They only need to believe they will have one before the information loses its value. Exposure therefore depends less on when the machine arrives and more on how long the data must stay secret: diplomatic and defence information, intellectual property, M&A strategy, health records, critical infrastructure designs and biometric identity data.

The Mosca inequality: a board-level test

Cryptographer Michele Mosca, co-founder of the Institute for Quantum Computing, framed the problem in a simple test. If the time your data must remain secure (X) plus the time it will take you to migrate your systems (Y) is greater than the time until a cryptographically relevant quantum computer exists (Z), you already have a problem. In large organisations, migrations of this kind are usually measured in years. That shortens the margin considerably, even under conservative estimates of Z.

 

The regulatory clock is already running

The debate on when quantum computing will break current cryptography remains open. The debate on when organisations must migrate has largely been settled by regulators.

Authority Framework and milestones Reading for the company
NIST (United States) FIPS 203, 204 and 205 published in August 2024. A transition roadmap proposes deprecating quantum-vulnerable algorithms from 2030 and disallowing them by 2035. The de facto global reference. Technology vendors will align their products with it, whether or not the client operates in the US.
NSA · CNSA 2.0 A phased transition for national security systems, with milestones by product category, to be completed within the 2030–2035 window. A direct requirement for defence contractors and their supply chains working with US programmes.
European Union A coordinated roadmap under which Member States begin the transition by the end of 2026, protect high-risk use cases and critical infrastructure by 2030, and migrate as much as feasible by 2035. It links directly to NIS2 and DORA obligations. Essential entities and financial institutions will be asked for evidence.
NCSC (United Kingdom) Discovery and planning by 2028, priority migrations by 2031, full migration by 2035. The clearest planning model for structuring an internal programme in three phases.
Spain Guidance from the National Cryptologic Centre (CCN) and a national strategy for quantum technologies. A reference point for the public sector, the defence industry and critical operators working with the Spanish administration.

 

Where the impact lands: sector exposure

Exposure is not uniform across sectors. It depends on how long the data needs to stay confidential, how much legacy technology is in use and how complex the supply chain is.

Sector Why it is exposed Priority reading
Defence and security Classified information that must remain secret for decades, and state actors targeting it. The main target of harvest now, decrypt later. Contractual requirements will reach suppliers first.
Financial services Payments, digital signatures, interbank communications and long-lived customer data. DORA already requires cryptographic risk management. Systemic interdependence multiplies the impact.
Energy, water and critical infrastructure Industrial control systems with lifespans of 20 to 30 years and cryptography embedded in the hardware. Equipment installed today will still be running when the threat materialises. Purchasing decisions made now matter.
Healthcare and pharmaceuticals Clinical records, genetic data and R&D with very long confidentiality periods. Personal data that cannot be “reissued” once exposed, unlike a password or a card.
Telecoms, ports and logistics Network infrastructure, connected devices and multi-party trust chains. A weak link in any operator compromises the whole chain.
Corporate and legal M&A negotiations, patents, litigation and board communications. The value of the information is strategic, and so is the value of stealing it.

Quantum processor and the corporate cyber risk of quantum computing, monitored by the ACK3® Global Hybrid SOC

Quantum hardware · Faster progress than expected

Error correction is the real milestone to watch

The variable to watch is not the number of qubits announced in each press release. It is progress in quantum error correction, which is what separates an experimental processor from a machine capable of running Shor’s algorithm at scale. Recent advances by the main manufacturers, together with increasingly efficient factoring algorithms, have reduced the estimated resources needed to break RSA-2048. The gap has not closed, but it has narrowed faster than many forecasts anticipated.

“The critical question is not technological. It is who in your supply chain holds your data, what cryptography they use, and whether your contracts let you demand a migration plan from them. Most organisations can’t answer that today, and that is where the risk sits.”

— Antonio García, Senior Operations Coordinator (GPC), ACK3® · Due Diligence

 

Quantum risk as corporate risk

For senior management, quantum computing should enter the risk map as a set of concrete vectors with different probabilities and time horizons, rather than as a single future event.

Factor Exposure Why it matters
Quantum attack today Low No cryptographically relevant quantum computer is publicly known to exist. However, that does not reduce the other vectors.
Reputational and trust impact Medium Retroactive exposure of historical data would affect customers, partners and regulators all at once.
Regulatory and contractual compliance Medium It is rising quickly. Tenders, audits and major clients will start requiring evidence of a migration plan.
Long-lived confidential data High Harvest now, decrypt later makes the exposure real today, even though the damage materialises later.
Supply chain and third parties High An organisation’s security depends on the least prepared supplier handling its data.
Legacy and OT systems High Cryptography embedded in hardware cannot be updated with a patch. It has to be replaced, and that has a cost and a schedule.

NIST has published the first three finalised post-quantum cryptography standards, FIPS 203, FIPS 204 and FIPS 205, and encourages organisations to begin transitioning to them without waiting for further standards.

NIST — Post-Quantum Cryptography Project

European and British authorities have set a shared horizon: critical systems must be protected by 2030–2031, and the migration must be completed by 2035. Discovery and planning should begin now.

European Commission — PQC Coordinated Roadmap · NCSC — PQC Migration Timelines

Research published in 2025 estimates that a 2048-bit RSA key could be factored with fewer than one million noisy qubits in under a week, well below earlier estimates of around twenty million.

Gidney (2025) — How to factor 2048 bit RSA integers with less than a million noisy qubits · arXiv

The most common framing error

Treating quantum computing as a future event, when it is a present exposure. As long as no one can break current encryption, the risk seems theoretical. But the data being stolen today does not expire, suppliers are not migrating at the same pace, and regulators have already set the deadline. The organisation that waits for “Q-Day” to act will discover that its problem did not start that day. It started years earlier, in every encrypted communication that someone decided to keep.

 

Before the migration: what management should do now

The transition to post-quantum cryptography is a multi-year programme. Its first phase is not technical but one of intelligence and governance. It starts with identifying which information assets must remain confidential beyond 2030, and for how long. The next step is a cryptographic inventory: which algorithms, certificates and protocols are in use, in which systems, and under whose control. The third step is the supply chain. Critical suppliers need to be mapped, their migration plans requested, and post-quantum requirements built into new contracts and tenders. Once that picture is in place, priorities can be set by risk, a budget can be defined, and the board can decide whether to proceed with crypto-agility and hybrid schemes during the transition.

For companies operating in sectors or regions with a higher exposure to state-level cyber espionage, this analysis also has a geopolitical dimension. Who is interested in your information, and what capacity do they have to intercept it? For that framework, see our analysis of hybrid threats and strategic impact.

 

Frequently asked questions about quantum computing and security

When will quantum computers be able to break current encryption?

There is no consensus on the date. Regulators are planning around a 2030–2035 horizon. Because of harvest now, decrypt later, sensitive long-lived data should be treated as exposed already.

What is post-quantum cryptography?

Post-quantum cryptography is a set of algorithms that run on today’s classical computers and are designed to resist attacks from both classical and quantum computers. NIST standardised the first of them in 2024.

Which companies should start preparing first?

The first to prepare should be companies that handle data with a long confidentiality period, operate critical infrastructure, fall under NIS2 or DORA, or supply the defence and financial sectors.

Does your organisation know how exposed it is to the quantum threat?

ACK3® helps organisations turn quantum risk into strategic decisions. We assess exposure, verify third parties, plan continuity scenarios and monitor the threat environment, and we coordinate with specialised partners for the technical migration.

ACK3® Service What it delivers against quantum risk
Strategic risk consulting Board-level quantum exposure assessment, identification of critical information assets and their confidentiality horizon, and integration into the corporate risk map.
Due Diligence and economic intelligence Assessment of the cryptographic readiness of suppliers, technology partners and acquisition targets, plus the contractual requirements to demand from them.
Crisis management and business continuity Cryptographic compromise scenarios, escalation protocols and continuity plans in the event of retroactive exposure of sensitive information.
Intelligence and monitoring · Global Hybrid SOC 24/7 monitoring from Madrid of state-level cyber espionage campaigns, technological developments and regulatory changes that affect your exposure.
Specialised training Executive briefings for management and risk committees on quantum threats, regulatory deadlines and decision-making.

The quantum threat does not begin the day the machine exists. It began the day your data was captured.