{
  "id": 7134548,
  "title": "Q-Day is approaching. Most organizations aren’t ready",
  "url": "https://urgent.news/2026/09/13/q-day-is-approaching-most-organizations-arent-ready",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-13T16:49:54.000Z",
  "source": {
    "name": "SiliconANGLE",
    "slug": "siliconangle",
    "url": "https://siliconangle.com/2026/09/13/q-day-is-approaching-most-organizations-arent-ready/"
  },
  "original_language": "en",
  "account": "Q-Day, the moment when quantum computers could potentially break the encryption protecting most of the internet, remains a distant threat for many organizations. However, recent developments suggest this realization is changing. In March, Google announced its own migration deadline for post-quantum cryptography, targeting 2029. This is ahead of the National Security Agency's 2031 target and the National Institute of Standards and Technology's 2035 guideline for national security systems. Google's accelerated timeline is due to advances in quantum hardware and error correction, which have reduced the number of qubits needed to threaten current encryption. A recent study by researchers from Caltech, UC Berkeley, and quantum startup Oratomic Inc. found that a fault-tolerant quantum computer capable of running Shor's algorithm - which breaks RSA and elliptic-curve encryption - may require as few as 10,000 to 26,000 qubits. This is significantly fewer than the millions previously thought necessary. The implications of this are profound, as public-key cryptography underpins many critical systems, including web security, software updates, banking transactions, and server authentication. When these layers of security break, they fail for everyone simultaneously because they all depend on the same mathematical foundations. The analogy to the Year 2000 problem is apt, but unlike that crisis, Q-Day has far less attention and a far shorter time frame. Moreover, adversaries are actively \"harvesting now, decrypting later,\" meaning sensitive data can be stolen today and decrypted later when quantum computers become powerful enough. The instinct to treat this like any other vulnerability - by inventorying systems and patching them - doesn't scale. Modern organizations run thousands of services with complex dependency chains, making a piecemeal approach impractical. Instead, the more immediate solution is to focus on post-quantum readiness at the network layer. Upgrading a handful of control points in the infrastructure that carries and secures traffic between applications can provide broader protection than upgrading thousands of individual applications. This centralized approach is far more manageable and realistic, with the potential for completion by 2029. Many organizations are now assessing their quantum-readiness, but findings indicate that progress at the application level is slow. The real urgency lies in infrastructure-level assessments, which can identify which systems can be centrally upgraded and which control points would offer the broadest coverage if updated first. The path forward is clear: organizations must start building infrastructure-level crypto-agility now to remain secure when Q-Day arrives.",
  "summary": "“Q-Day,” the point at which quantum computers begin to break the encryption protecting most of the internet, lives in the same mental category as other far-off technology risks: real eventually, but not something requiring immediate action. That assumption is no longer safe. In March, Google LLC set 2029 as its own migration deadline for post-quantum […] The post Q-Day is approaching. Most…",
  "key_points": [
    "Q-Day, when quantum computers could break internet encryption, is approaching",
    "Google aims to migrate to post-quantum cryptography by 2029, earlier than NSA's 2031 deadline"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}