Future Trends
Future Trends in Quantum Computing
& Cryptography
For years the honest answer to “when will a quantum computer break encryption?” was “not for decades, and probably not with anything we know how to build.” That answer changed in 2026 — not because someone built a bigger machine, but because researchers found much cheaper ways to run the attack. Two results published on the same day in March brought the estimated machine size down from millions of components to tens of thousands. In June, the White House responded with an executive order that put firm dates on the federal switch to new encryption. This page tracks what actually happened, what is still a projection, and what the calendar now looks like.
Where Things Stand — September 2026
Level 1, Level 2, Level 3: A Way to Read the Hardware News
Quantum computers make mistakes constantly. Almost every headline about progress is really a claim about mistakes — how many, and whether they can be caught and repaired while the machine runs. Microsoft's researchers, writing in IEEE Spectrum, sort progress into three levels, and the framework is a useful filter for press releases.
Level 1 is where machines have sat for a decade: around a thousand components, error-prone, with no sustained repair. They can demonstrate things but cannot be trusted for long calculations. Level 2 is a machine that repairs its own errors reliably enough for a customer to use it. Level 3 is the endgame — hundreds of thousands to millions of components, running millions of reliable operations. Only Level 3 threatens today's encryption.
The vocabulary: Level 1 machines are called NISQ (noisy intermediate-scale quantum). A physical qubit is one piece of hardware — an atom, or a superconducting circuit. A logical qubit is many physical qubits ganged together with an error-correcting code so that the group behaves like one reliable qubit. The ratio between them is the overhead, and it is the single number that decides whether an attack is affordable.
2026 is the year Level 2 ships. Microsoft and Atom Computing are building Magne for QuNorth in Denmark — about 1,200 atoms producing roughly 50 logical qubits, funded with €80 million from the Danish Export and Investment Fund and the Novo Nordisk Foundation. QuNorth expects it fully operational in early 2027. It will be the first error-corrected quantum computer working outside a research lab. That is a genuine milestone and it is also nowhere near cryptographically dangerous: 50 logical qubits is roughly one twenty-fifth of the 1,200 to 1,450 that the cheapest published attack on elliptic-curve encryption calls for.
Why atoms are ahead of circuits. Both of the first Level 2 machines use neutral atoms held in place by lasers rather than superconducting circuits etched on a chip. Atoms can be physically picked up and moved during a calculation, so any two of them can be brought together — which makes far more efficient error-correcting codes possible. The March preprint puts the overhead for its attack at roughly three atoms per logical qubit, against hundreds to a thousand physical qubits per logical qubit for the surface codes used on superconducting chips. A hundredfold saving on overhead is the reason a 10,000-atom machine is worth talking about at all.
Scale check: Manuel Endres's Caltech lab has already trapped and held about 6,000 atoms. Atom Computing has targeted a 10,000-atom third-generation system, and both Atom Computing and QuEra have said 100,000 atoms per vacuum chamber is reachable “within a few years.” Trapping atoms is not the same as computing reliably with them — but the raw counts are no longer the bottleneck.
AI as an Accelerant Nobody Had Modelled
The most consequential thing about early 2026 is not any single number. It is that these estimates fell because of better algorithms rather than better machines — and that the algorithms were found with help from AI. Dolev Bluvstein, who led the Caltech-linked work and has since founded the startup Oratomic to build the machine, told TIME: “There is no question that we used AI to accelerate this development.” The team ran an open-source, large-language-model-driven optimiser over candidate circuit designs, searching a space that human researchers had previously explored by hand over roughly thirty years.
This matters because every threat forecast in circulation assumed hardware was the limiting factor. If algorithmic improvement is now partly automated, resource estimates become a moving target that can shrink again without any new machine being built. Cloudflare's Bas Westerbaan called the results “a real shock.” IBM's quantum-safe leadership said it can no longer rule out a targeted attack on a high-value secret using hardware plausibly available by 2030.
Worth keeping in perspective: all of these estimates describe circuit designs, not working attacks. Every published figure assumes error rates and hardware connections that no existing machine delivers at scale. What the 2026 results narrow is the range of plausible dates — they say nothing about what a machine can do today.
Google Willow Crosses the Error Threshold
With 105 qubits, Willow was the first machine where adding more qubits made the overall error rate fall rather than rise — the precondition for all error correction. In October 2025 its Quantum Echoes result claimed the first verifiable advantage over classical supercomputers.
Two Papers Shrink the Attack
Google's whitepaper and the Caltech-linked preprint land the same day. Where estimates for breaking elliptic-curve encryption had run to millions of qubits, both papers put it in the tens of thousands to the hundreds of thousands. AI tooling helped find the improvements. Cloudflare moves its deadline to 2029; Oratomic launches to build the machine.
Executive Order 14412
The US puts dates in law: high-value federal systems must switch their key exchange by the end of 2030 and their digital signatures by the end of 2031. OMB memo M-26-15 adds a five-phase schedule running to 2035.
Magne, and the CNSA 2.0 Cliff
The first error-corrected machine outside a lab goes live in Denmark (~50 logical qubits). Separately, from January 1, 2027, newly purchased US national-security systems may no longer use RSA or elliptic-curve key exchange at all.
Impact on Global Cybersecurity
What It Would Actually Take to Break Today's Encryption
Two families of encryption protect nearly all internet traffic: RSA and elliptic-curve cryptography. Both rest on arithmetic that is easy to do and hard to undo, and a quantum computer running Shor's algorithm could undo either one — given a large enough machine. So the whole threat question reduces to a size estimate. Through 2025 the working assumption in most migration plans was that this needed millions of physical qubits and was more than a decade away. Three results in under a year dismantled that assumption from the software side. Craig Gidney of Google cut the RSA-2048 estimate from 20 million qubits to under a million in May 2025. Iceberg Quantum cut it again, to under 100,000, in February 2026 by swapping in a different family of error-correcting codes. Then in March 2026 Google's elliptic-curve whitepaper and the Caltech-linked neutral-atom preprint arrived together. None of the four required a hardware advance.
For readers who want the machinery: Gidney's and Iceberg's results concern integer factoring (Shor's algorithm applied to RSA); the March 2026 results concern the elliptic-curve discrete logarithm problem, which is the harder-sounding but computationally cheaper target. Google's figures are given as logical qubits and Toffoli-gate counts — roughly 1,200 to 1,450 logical qubits and 70 to 90 million Toffoli gates on the secp256k1 curve, which compiles to fewer than half a million physical superconducting qubits. Iceberg's reduction comes from quantum low-density parity-check (qLDPC) codes in place of surface codes.
The institutional reaction is the clearest evidence that these results were taken seriously. Cloudflare moved its completion target to 2029, ahead of any government requirement. Google publicly called for urgent preparation. The Boston Consulting Group has warned that an organisation starting migration in 2030 is already too late, because the average enterprise migration runs 42 to 54 months. Bitcoin, Ethereum, Tron, StarkWare and Ripple all announced quantum-resistance work in April 2026.
Harvest now, decrypt later is what makes the deadlines real. An adversary does not need a quantum computer today to profit from one later — it only needs to record encrypted traffic now and keep it. Any data that must stay confidential past roughly 2030 is already exposed if it is protected by RSA or elliptic-curve key exchange today. That is the argument that removes the option of waiting for the timeline to clarify.
How confident is the field? The Global Risk Institute's Quantum Threat Timeline Report 2025, released in early 2026, surveyed 26 specialists: depending on how their answers are aggregated, 28% to 49% put the odds of a cryptographically relevant machine within ten years — the highest ten-year figure in the report's seven-year history. Over fifteen years, 69% put the probability at 50% or better. Separately, the forecasting platform Metaculus moved its median prediction for an RSA break from 2052 to 2034 in late 2025.
| Algorithm | What Protects It Today | Quantum Outlook (as of September 2026) | Status |
|---|---|---|---|
| P-256 / secp256k1 (elliptic curve) |
Roughly 128-bit strength against classical attack | The cheapest target for a quantum attacker, and the one whose estimates have fallen fastest. Google (Mar 2026): under 500,000 superconducting qubits, 9–23 minutes. Caltech/Harvard/Berkeley (Mar 2026): a few days on ~26,000 neutral atoms; ~10,000 atoms is the floor, at much longer runtimes. This is what guards HTTPS key exchange, SSH and most cryptocurrency wallets. | Urgent |
| RSA-2048 | Roughly 112-bit strength against classical attack | Estimates for factoring one 2048-bit key: 20 million qubits (2019), under 1 million and a week of runtime (Gidney, May 2025), under 100,000 using qLDPC codes on hardware connections not yet demonstrated (Iceberg Quantum, Feb 2026). Harder than elliptic curve, and subject to the same algorithmic improvement. | Vulnerable |
| AES-128 | 128-bit symmetric key | Grover's algorithm searches keys quadratically faster, effectively halving the key length to about 64 bits of security. No structural break, but too thin a margin for new designs. | Weakened |
| AES-256 | 256-bit symmetric key | Same halving leaves about 128 bits — still comfortable. Doubling symmetric key length is a cheap and complete fix, which is why symmetric encryption is not the crisis. | Adequate |
| SHA-256 / SHA-3 | Hashing; 256-bit collision resistance | Grover reduces the effort to reverse a hash to about 128 bits; resistance to finding two inputs with the same hash is essentially unaffected. | Adequate |
| ML-KEM (FIPS 203) |
Hard lattice problems (Module-LWE) | The standard replacement for RSA and elliptic-curve key exchange. No known quantum speedup. Already carrying the majority of browser traffic through Cloudflare; required for US national-security key establishment under CNSA 2.0. | Quantum-Safe |
| ML-DSA (FIPS 204) |
Hard lattice problems (Module-LWE / SIS) | The standard replacement for digital signatures. No known quantum speedup. Signatures are the slower half of the migration — EO 14412 gives federal high-value systems until the end of 2031, a year later than key exchange. | Quantum-Safe |
| HQC (backup) |
Error-correcting-code problems (syndrome decoding) | Selected in March 2025 as a second key-exchange standard resting on completely different mathematics, so that a future break of lattice problems would not take everything with it. Draft standard expected 2026, final around 2027. | In Standardization |
Future Directions in Quantum-Safe Cryptography
The 2026 Rulebook: Dates That Now Exist in Writing
Executive Order 14412, signed June 22, 2026. “Securing the Nation Against Advanced Cryptographic Attacks” converted federal guidance into deadlines. High-value and high-impact government systems must move their key exchange to post-quantum algorithms by December 31, 2030, and their digital signatures by December 31, 2031. Agencies had 30 days to name a migration lead, NIST must run a pilot project to completion by the end of 2027, CISA must issue guidance on cryptographic inventories, and the FAR Council must propose procurement rules — which is the mechanism that pushes the requirement out to contractors and their suppliers.
OMB memorandum M-26-15, June 24, 2026. The implementation schedule: agency migration plans were due within 120 days (late October 2026), all agencies must support TLS 1.3 or later by January 2, 2030, and the work is divided into five phases — inventory and governance in 2026–27, pilots in 2027–28, key exchange for priority systems by 2030, signatures in 2031, and everything remaining by 2035.
CNSA 2.0 — January 1, 2027. Every newly acquired US national-security system must be quantum-safe. RSA and elliptic-curve key establishment become impermissible in new classified procurement, not merely discouraged. Defence contractors are directly in scope and supply-chain pressure extends it well beyond them.
FIPS 140-2 sunset — September 21, 2026. All remaining FIPS 140-2 certificates move to historical status, so only FIPS 140-3 validated modules may be used in new federal procurement. This is the practical bottleneck few plans account for: not every hardware security module supports the new algorithms yet, and validation queues are long.
The rest of the standards picture: NIST IR 8547 (draft) deprecates RSA and elliptic curve for new federal use in 2030 and disallows them entirely in 2035. NIST CSWP 39, finalised December 19, 2025, treats cryptographic agility as an architectural requirement with a formal maturity model; CSWP 48 maps migration onto the Cybersecurity Framework 2.0 and SP 800-53 so progress can be audited as a risk outcome. Standardisation continues too: NIST advanced nine additional signature candidates to a third evaluation round in May 2026, hedging against a break in the lattice family.
Agility is the design lesson. A system built in 2026 with an elliptic-curve algorithm hardcoded into its logic will need a rewrite to migrate. One where the algorithm and key configuration live outside the business logic migrates by changing a setting. Given migrations that average three and a half to four and a half years, the difference between those two designs is the difference between meeting the 2030 deadline and missing it.
First Three Post-Quantum Standards Finalised
NIST publishes FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA). The migration clock starts here.
HQC Selected as a Backup Key-Exchange Standard
Built on different mathematics from ML-KEM, so one broken assumption cannot compromise both. Draft expected 2026.
NIST CSWP 39: Cryptographic Agility
Swapping algorithms without rearchitecting becomes a stated design requirement, with a maturity model to measure it.
⚠ Elliptic-Curve Attack Priced at ~26,000 Atoms
Google and a Caltech-linked team publish on the same day: under 500,000 superconducting qubits, or roughly 26,000 neutral atoms, against earlier estimates in the millions. Cloudflare moves its deadline to 2029.
⚠ Executive Order 14412 and OMB M-26-15
Federal deadlines become binding: key exchange for high-value systems by end of 2030, signatures by end of 2031, everything else by 2035.
FIPS 140-2 Certificates Expire
September 21. New federal procurement requires FIPS 140-3 validated modules only — a hardware constraint on everyone else's schedule.
Agency Migration Plans Due to OMB
120 days after M-26-15. The first checkpoint at which federal readiness becomes visible rather than asserted.
CNSA 2.0 Takes Effect for New Acquisitions
RSA and elliptic-curve key establishment no longer permissible in newly procured national-security systems. Defence supply chain in scope.
Magne Operational at QuNorth, Denmark
~50 logical qubits from ~1,200 atoms. First error-corrected quantum computer running outside a research lab.
IBM Starling Targeted; Cloudflare Aims to Finish
IBM targets its first large-scale fault-tolerant machine — 200 logical qubits, 100 million operations. Cloudflare targets full post-quantum security including authentication. The commonly cited risk window opens.
Federal Deadlines Bite
Key exchange for high-value systems by December 31, 2030; signatures by December 31, 2031. RSA and elliptic curve deprecated for new federal use per NIST IR 8547.
RSA and Elliptic Curve Disallowed Outright
Full deprecation across federal systems. The UK's NCSC, the EU's ENISA and partner nations have aligned to the same horizon.
Resources & Further Reading