THE QUANTUM THREAT / INTERMEDIATE

Myths And Facts About The Quantum Threat

Six common beliefs about quantum computers and encryption, checked against what NIST, the UK NCSC and European security agencies actually say.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Discussion of quantum computing and security swings between two poles. One camp says all encryption is about to collapse. The other says the whole issue is decades off and safe to ignore. Both positions lead to poor decisions, and both contain claims that public guidance from security agencies contradicts.

This article takes six beliefs that come up often in boardrooms and project meetings and checks each against primary sources. The table gives the short version; the sections below explain the reasoning.

MythWhat The Evidence SaysMain Source
Quantum computers will break AESAES with 128-bit or longer keys stays usable; NIST does not plan to replace itNIST IR 8547 (draft)
Longer RSA keys will keep us safeShor’s algorithm scales gently with key size, so the algorithms must be replacedShor (1995); NIST IR 8547
Quantum key distribution is the answerUK, French, German, Dutch and Swedish agencies all prioritise post-quantum cryptographyNCSC (2025); joint position paper (2024)
The threat is certainly decades awayExpert odds of a CRQC within 10 years are 28 to 49 percent, and hardware estimates keep fallingGlobal Risk Institute (2026)
Nothing needs doing until a quantum computer existsRecorded data is already exposed, and agencies have set dates from 2028 onwardNIST IR 8547; NCSC (2025)
Signatures face the same harvest risk as encryptionA finished login cannot be forged later; the risk is forgery once a quantum computer exists, so long-lived keys still need early migrationNIST IR 8547
Six myths at a glance. Positions dated as of October 2026.

Myth 1: Quantum Computers Will Break AES

Grover’s search algorithm gives a quantum computer at most a square-root speed-up against brute-force key search.1 That weakens symmetric ciphers but does not break them. NIST’s draft transition guidance says its symmetric standards are significantly less exposed to quantum attack than public-key ones, and that it does not expect to move away from them as part of this transition. Only a few 112-bit options will be disallowed, in 2030.2 The Shor And Grover article explains why.

Myth 2: Longer RSA Keys Will Keep Us Safe

This is the mirror image of the first myth. Doubling a symmetric key restores its margin, so it is tempting to assume the same for RSA. It does not work. Shor’s algorithm solves factoring and discrete logarithms in polynomial time, so the cost grows modestly as keys grow.3 NIST’s plan treats every RSA, Diffie-Hellman and elliptic curve key size as quantum-vulnerable, with all of them proposed for disallowance after 2035 regardless of strength.2

Myth 3: Quantum Key Distribution Is The Answer

Quantum key distribution (QKD) uses quantum physics, sent over special equipment and dedicated links, to share keys in a way that can reveal an eavesdropper.4 It is real and it works over suitable links. The question is whether it is the right defence against quantum computers, and the agencies that have published positions say no.

The UK National Cyber Security Centre, in a paper published in August 2025, points out that QKD provides no authentication on its own, says it will not support QKD for government or military use, and names post-quantum cryptography as the best mitigation.5 In January 2024 France’s ANSSI, Germany’s BSI, the Netherlands’ NLNCSA and Sweden’s National Communications Security Authority published a joint position paper. The four agencies judge that QKD is too restricted and too immature for general use. In their view it fits only a few specialised cases, it cannot run without its own physical network, and its security has not yet been proven to the level they would want, so organisations should put post-quantum cryptography first.6

Myth 4: The Threat Is Certainly Decades Away

Nobody can give a date, and claiming certainty in either direction is the mistake. The most recent Global Risk Institute survey, published in March 2026, found experts rate a cryptographically relevant quantum computer within 10 years as quite possible, at 28 to 49 percent, and within 15 years as likely, at 51 to 70 percent. The report says expert timelines have accelerated compared with earlier editions.7

Engineering estimates point the same way. In 2019 Gidney and Ekerå estimated that RSA-2048 could be factored in eight hours with 20 million noisy qubits. In 2025 Gidney cut that to under one million qubits in under a week.8 Neither figure describes a machine that exists, but the trend is downward. The Q-Day article shows how to plan under this uncertainty.

Myth 5: Nothing Needs Doing Until A Quantum Computer Exists

Two facts undercut this. The first is harvest now, decrypt later: data recorded today can be read once a quantum computer exists, so long-lived secrets are exposed already.2 The second is time. NIST notes that past cryptographic migrations took more than a decade.2 Governments have set dates accordingly. NIST proposes deprecating 112-bit public-key algorithms after 2030 and disallowing all quantum-vulnerable ones after 2035,2 and the NCSC asks organisations to finish discovery and planning by 2028.9 Details are in What Governments Expect.

Myth 6: Signatures Face The Same Harvest Risk As Encryption

Signatures and encryption face different risks. A forged signature only helps if it is produced and accepted while it still matters, which needs a quantum computer at that moment. NIST notes that, unlike encryption, authentication stays secure as long as the algorithms are secure when the check happens.2 A login that finished years ago cannot be forged after the event. Signed documents and software that must still be trusted years from now are different: once their signing algorithm can be broken, new forgeries become possible, so they need a plan before that point.

That is not a reason to delay. Some signing keys sit at the root of trust for many years: certificate authority roots, and keys built into devices to check firmware. NIST says devices that cannot update their verification code should be designed to require quantum-resistant signatures if they may still be in use when such a computer arrives.2

Footnotes

  1. L. K. Grover, “A fast quantum mechanical algorithm for database search”, arXiv quant-ph/9605043, 29 May 1996. arxiv.org ↩

  2. NIST, IR 8547 (initial public draft), “Transition to Post-Quantum Cryptography Standards”, November 2024. nvlpubs.nist.gov ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7

  3. P. W. Shor, “Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer”, arXiv quant-ph/9508027, submitted 30 August 1995. arxiv.org ↩

  4. NSA, “Quantum Key Distribution (QKD) and Quantum Cryptography (QC)”. nsa.gov ↩

  5. UK National Cyber Security Centre, “Quantum networking technologies”, published 5 August 2025. ncsc.gov.uk ↩

  6. ANSSI, BSI, NLNCSA and Swedish National Communications Security Authority, “Position Paper on Quantum Key Distribution”, 25 January 2024. cyber.gouv.fr ↩

  7. Global Risk Institute and evolutionQ, “Quantum Threat Timeline Report 2025”, published 9 March 2026. globalriskinstitute.org ↩

  8. C. Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits”, arXiv 2505.15917, 21 May 2025. arxiv.org ↩

  9. UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.