QUANTUM COMPUTING BASICS / ADVANCED

Reading Quantum Roadmaps: What Breaking Encryption Would Take

How to read vendor roadmaps, what a cryptographically relevant quantum computer would need, how far today's machines are from it and why security timetables do not wait.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Quantum companies now publish detailed roadmaps with named processors, target years and qubit counts. For security teams these documents are tempting to read as a countdown to the day RSA breaks. They are not designed for that, and reading them well takes some care.

This article explains what a quantum computer would need in order to break today’s public-key cryptography, sets that against what vendors have demonstrated and what they promise and shows why the migration dates proposed or recommended by government bodies do not depend on any single roadmap. It draws on the earlier articles on error correction and hardware.

What A Cryptographically Relevant Machine Needs

A cryptographically relevant quantum computer, often shortened to CRQC, is one that could run Shor’s algorithm against real key sizes such as 2048-bit RSA. A widely cited 2025 estimate comes from Craig Gidney of Google. In a May 2025 preprint he estimated that a machine built from a flat grid of qubits, each failing no more than 0.1 percent of the time, would need fewer than a million noisy physical qubits running continuously for less than a week.1 His 2019 estimate with Martin Ekerå had been 20 million qubits for eight hours.2

Preprints in 2026 went further by changing the architecture, and they trade fewer qubits for longer runs. Webster and colleagues’ Pinnacle design uses a different family of error-correcting codes, which needs qubits to interact beyond their nearest neighbours. Under the same error and speed assumptions as Gidney, it puts RSA-2048 at fewer than 100,000 physical qubits for a run of about a month, or about 139,000 for a run of a week.3 Cain and colleagues argue that a machine built from movable neutral atoms could run Shor’s algorithm at cryptographically relevant scale with as few as 10,000 of them, but that size suits slow runs. Their faster configurations need about 26,000 atoms for around 10 days on a 256-bit elliptic curve key, and about 102,000 atoms for around 97 days on RSA-2048.4 Neither design has been built. The dated history of these estimates is in How Many Qubits To Break RSA-2048?

From 2019 to 2026 the smallest published qubit count for RSA-2048 fell more than 200-fold, although the 2026 figures assume different hardware and much longer runs than the 2019 one. That downward trend is the most important point in this article. It came from better algorithms, codes and architectures, not from better hardware. The hardware still has to arrive, and it has to arrive as a complete system.

  1. AlgorithmA version of Shor’s algorithm for 2048-bit RSA, needing about 6.5 billion Toffoli gates in the 2025 estimate.
  2. Logical QubitsAbout 1,400 error-corrected logical qubits in the 2025 estimate (1,399 in its cost table), held stable for the whole run.
  3. Error Correction And DecodingSyndrome measurement and real-time classical decoding every microsecond or so, without falling behind.
  4. Physical QubitsAround a million physical qubits at about 0.1 percent error in the 2025 design; fewer in 2026 proposals that assume longer-range connections.
  5. Control, Cooling And EngineeringWiring, classical control systems and either lasers or cryogenics, all scaled to match.
The stack a cryptographically relevant quantum computer would need, using the 2025 surface code estimate as the example. Other designs trade qubits for time or connectivity, but every layer still has to work at once, throughout the computation.

Inside the 2025 estimate, the work is organised as about 1,400 logical qubits (1,399 in the paper’s Table 5, and fewer than 1,600 including idle qubits) carrying out about 6.5 billion Toffoli gates, a type of three-qubit logic operation, with each attempt taking roughly 12 hours.1 Every one of those figures sits far beyond what any machine has demonstrated.

Demonstrated Results Versus Targets

The error-corrected demonstrations covered in this series involve tens of logical qubits, run for short periods. Vendor roadmaps promise hundreds to tens of thousands of logical qubits by around 2030. The table separates the two.

OrganisationDemonstratedStated Target
GoogleBelow-threshold surface code memory up to distance 7 on Willow (Nature, published December 2024)Not covered here
QuantinuumUp to 48 error-corrected and up to 94 error-detected logical qubits on Helios (preprint, February 2026)Not covered here
IBMLoon experimental fault-tolerance chip announced November 2025Starling in 2029: 200 logical qubits running 100 million gates. Blue Jay later: 2,000 logical qubits, 1 billion operations
IonQNot covered here800 logical qubits in 2027; 80,000 logical qubits on 2 million physical qubits in 2030
Infleqtion30 entangled logical qubits on 80 physical qubits (company announcement, September 2026)100 logical qubits by 2028; 1,000 by 2030
Selected demonstrations and vendor targets as of October 2026. Targets are each company’s own statements, not results. Logical qubit definitions differ between vendors.

Several things stand out. IBM’s 2029 target of 200 logical qubits and 100 million gates is well short of the roughly 1,400 logical qubits and billions of operations in the 2025 RSA-2048 estimate.56 IonQ’s 2030 target would, if met, be in the range a CRQC needs, but it is a company target, and an ambitious one compared with what any company has demonstrated.7 Infleqtion’s figures come from a press release that does not say whether its logical qubits are error corrected or only error detected.8

How To Read A Roadmap

A roadmap is a statement of intent written partly for customers and investors. Read it with five questions in mind.

First, are the targets in physical or logical qubits? Physical counts say little on their own. Second, how is a logical qubit defined, and at what error rate? IonQ, for example, attaches logical error rates to its targets; others do not.7 Third, how many operations can the machine run before an error, and for how long? The estimates cited here all need billions of operations under sustained fault-tolerant control, with runtimes that depend on the configuration. Fourth, which past milestones did this vendor hit on time? A roadmap’s track record is evidence. Fifth, does the target rest on peer-reviewed results, or on announcements and preprints?

Intermediate milestones are the best place to apply the track-record test. IBM’s roadmap, for instance, lists Loon for 2025, Kookaburra for 2026 and Cockatoo for 2027 before Starling in 2029, each meant to prove one part of the final architecture.5 IBM announced Loon in November 2025, in line with that plan.9 Whether the later steps arrive on schedule will say more about 2029 than the 2029 target itself.

Why Security Timetables Do Not Wait

Government bodies set out their migration timetables without relying on any single roadmap. NIST published its first three post-quantum standards, FIPS 203, 204 and 205, on 13 August 2024.10 In a draft report from November 2024, which as of October 2026 has not been finalised, NIST proposes treating RSA and elliptic curve algorithms at the 112-bit security level as deprecated after 2030 and disallowing them after 2035.11 The UK National Cyber Security Centre asks organisations to finish discovery and planning by 2028, migrate their highest-priority systems by 2031 and complete migration by 2035.12

  1. NIST Publishes FIPS 203, 204 And 205

    The first finalised post-quantum cryptography standards.

  2. UK NCSC: Discovery And PlanUpcoming

    Guidance: complete discovery and build an initial migration plan.

  3. NIST Draft: Deprecate 112-Bit RSA And ECCProposed

    Proposed in NIST IR 8547, still a draft.

  4. UK NCSC: Priority MigrationUpcoming

    Guidance: complete migration of the highest-priority systems.

  5. NIST Draft: Disallow Quantum-Vulnerable Public-Key AlgorithmsProposed

    Proposed in NIST IR 8547, still a draft.

  6. UK NCSC: Complete MigrationUpcoming

    Guidance: finish migrating to post-quantum cryptography.

Policy milestones that drive post-quantum migration, set independently of any vendor roadmap.

The logic is simple. Large organisations take many years to replace cryptography, and data stolen today can be decrypted later. The reasoning behind that risk is set out in The Quantum Threat, and the practical steps in Preparing For Migration. Roadmaps are worth tracking as a signal of pace. They should not set your timetable.

Footnotes

  1. C. Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits”, arXiv 2505.15917, 21 May 2025 (preprint). arxiv.org ↩ ↩2

  2. C. Gidney and M. Ekerå, “How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits”, arXiv 1905.09749, 2019. arxiv.org ↩

  3. P. Webster et al., “The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100 000 physical qubits using quantum LDPC codes”, arXiv 2602.11457, 12 February 2026, revised 5 May 2026 (preprint). arxiv.org ↩

  4. M. Cain et al., “Shor’s algorithm is possible with as few as 10,000 reconfigurable atomic qubits”, arXiv 2603.28627, 30 March 2026 (preprint). arxiv.org ↩

  5. IBM Quantum, “IBM lays out clear path to fault-tolerant quantum computing”, IBM Quantum Computing Blog, 10 June 2025. ibm.com ↩ ↩2

  6. IBM, “IBM Sets the Course to Build World’s First Large-Scale, Fault-Tolerant Quantum Computer at New IBM Quantum Data Center”, press release, 10 June 2025. newsroom.ibm.com ↩

  7. IonQ, “Roadmap”, company web page, accessed 7 October 2026. ionq.com ↩ ↩2

  8. Infleqtion, “Infleqtion Achieves 30 Entangled Logical Qubits on its Sqale Quantum Computer”, press release, 24 September 2026. infleqtion.com ↩

  9. IBM, “IBM Delivers New Quantum Processors, Software, and Algorithm Breakthroughs on Path to Advantage and Fault Tolerance”, press release, 12 November 2025. newsroom.ibm.com ↩

  10. NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards”, 13 August 2024. nist.gov ↩

  11. NIST, IR 8547 (initial public draft), “Transition to Post-Quantum Cryptography Standards”, 12 November 2024. csrc.nist.gov ↩

  12. UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, March 2025. ncsc.gov.uk ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.