Methodology
Last updated: September 14, 2026
How this site estimates when major cryptographic systems become vulnerable.
1. How we estimate
- We baseline to IonQ’s public roadmap as it is the most aggressive in terms of hardware with large quantities of logical qubits. We accept that roadmaps can change, in either direction, and we will make updates when appropriate. We accept that not all logical qubits are equal, and as new information or an industry standard metric becomes accepted we will update our methodology. Every change is recorded in the Update Log.
- We estimate a midpoint for 2028 and have selected June 10th. This is somewhat arbitrary, but so is the concept of Q‑Day being an actual day that can be verified independently (we assume a government may not reveal the arrival of Q‑Day for security reasons).
- No first‑breaker claims — several protocols share a year.
2. What would move the date
- Vendor milestones or revised roadmaps that change logical‑qubit availability, fidelities, or gate depths.
- Peer‑reviewed advances that reduce attack resources or alter cost models.
3. Sources
- NIST PQC Standards: FIPS 203/204/205 (Aug 2024).
- IonQ: hardware roadmap.
- IonQ (Sept 2026): 256‑bit ECDLP architecture (paper).
- Chevignard, Fouque & Schrottenloher (CRYPTO 2025): Reducing qubits in factoring.
- Gidney (2025): RSA‑2048 factoring with < 1M noisy qubits.