Executive summary — 'Q-Day' — the point at which a quantum computer can break the public-key cryptography protecting today's data — is the most consequential deadline in security that nobody can date precisely. That uncertainty gets used as an excuse to wait, which is exactly the wrong lesson. The honest position is that the arrival date is unknown and probably years away, while the date by which enterprises must have migrated is known, closer, and set by regulators rather than physicists. This separates the hype from the evidence and turns it into a planning position, building on the fundamentals of post-quantum cryptography. The quantum threat conversation is polarised between two unhelpful poses: the vendor pitch that Q-Day is imminent and terrifying, and the sceptic's shrug that it is decades away and not worth thinking about. Both dodge the actual planning problem, which does not depend on knowing the date. What matters is the gap between when adversaries can decrypt harvested data and when your data stops being sensitive — and for a great deal of enterprise data, that gap is already negative. What the Hardware Evidence Actually Shows Quantum hardware is advancing genuinely and fast, but breaking RSA-2048 requires something no one has yet built: a large fault-tolerant machine with thousands of stable logical qubits. Through 2025 and 2026, vendors including IBM, Google, Quantinuum, IonQ and others reported real progress on error correction and logical qubits, and IBM has publicly targeted demonstrating quantum advantage on a useful workload around the end of 2026. But a machine that shows advantage on a specialised problem is a long way from one that runs Shor's algorithm against real key sizes. The credible expert consensus places a cryptographically relevant quantum computer somewhere in the 2030s, with very few forecasters expecting it before 2030. One development did move the estimates in the wrong direction. Research published in 2025 suggested the physical-qubit count needed to break elliptic-curve cryptography could be roughly twenty times lower than earlier figures, and Google Quantum AI has set an internal target of completing its post-quantum migration by 2029. When the organisations building the machines start putting migration dates on the calendar, the 'decades away' framing looks complacent. The Deadlines That Are Actually Fixed While Q-Day floats, the migration deadlines do not. NIST finalised its post-quantum standards — FIPS 203, 204 and 205, covering ML-KEM, ML-DSA and SLH-DSA — in August 2024, and selected HQC in March 2025 as a code-based backup. NIST guidance now points to 2030 as the date after which RSA and ECC should not be used in new systems, and 2035 for existing deployments to complete migration. The NSA's CNSA 2.0 suite sets its own schedule for national security systems, with quantum-resistant algorithms required for new systems and a phased path to full compliance in the following years. These dates, not Q-Day, are what an enterprise plans against. Milestone Date What It Fixes NIST FIPS 203/204/205 finalised August 2024 Standard algorithms available to build and deploy against HQC selected as backup March 2025 Code-based alternative to the lattice primaries Google Quantum AI migration target 2029 A hardware builder's own planning date NIST: no RSA/ECC in new systems 2030 New builds must be quantum-safe NIST: legacy migration complete 2035 Existing systems must be migrated Forecasts summarise vendor roadmaps and standards-body guidance as of August 2026 and will evolve; treat specific dates as planning anchors rather than certainties. Turning the quantum timeline into a migration plan? eMudhra's post-quantum practice sequences discovery, hybrid certificates and cutover. Why the Planning Date Is Already Here The 'harvest now, decrypt later' threat collapses the timeline for a specific and important category of data. An adversary does not need a quantum computer today to attack data that must stay confidential for a decade; they only need to capture the encrypted traffic now and wait. For medical records, state secrets, long-lived financial instruments, intellectual property and anything with a multi-year confidentiality horizon, the effective deadline is not Q-Day but today. eMudhra's guide to the NIST PQC standards sets out which algorithms to adopt, and the migration itself is a certificate and inventory problem before it is a cryptography one — which is why it belongs in the same programme as certificate lifecycle management. A Defensible Position, Whatever the Date The organisations handling this well are not betting on a Q-Day date. They are building crypto-agility: the ability to inventory where cryptography is used, swap algorithms without re-architecting, and deploy hybrid certificates that combine classical and post-quantum protection during the transition. That posture is correct whether Q-Day lands in 2030 or 2040, because it hedges the uncertainty rather than gambling on it. PLAN AGAINST THE DEADLINE YOU CAN SEE, NOT THE ONE YOU CAN'T eMudhra will assess your cryptographic exposure and build a migration path aligned to the NIST and CNSA 2.0 timelines. Explore post-quantum cryptography or talk to an eMudhra expert. Tags: Post Quantum Cryptography About the Author eMudhra Limited eMudhra Editorial represents the collective voice of eMudhra, providing expert insights on the latest trends in digital security, cryptographic identities, and digital transformation. Our team of industry specialists curates and delivers thought-provoking content aimed at helping businesses navigate the evolving landscape of cybersecurity and trust services with confidence.