>_ Skip to main content
Menu
Search
Featured

Q-Day Isn’t a Single Morning. It’s Already Underway

Most people picture Q-Day as an event. One morning, a quantum computer wakes up, cracks the encryption holding the internet together, and everything protected by it spills open at once. That picture is wrong in an important way. Q-Day, the moment quantum machines get strong enough to break widely used encryption, is already unraveling, and the part that should worry business leaders started years ago.

The term you want anchored in your head is post-quantum cryptography, or PQC. That’s the set of encryption standards built to survive a quantum attack, and migrating to it is the whole conversation right now. On June 22, 2026, the Trump administration signed an executive order directing the federal government toward that migration and setting up support for critical infrastructure operators and the private sector. It’s a concrete signal and a first step, and the distance between a first step and a finished migration is where most companies are going to get hurt.

What happens on Q-Day

In simple terms, modern security rests on a bet. For decades we’ve secured infrastructure on the assumption that no computer could handle certain math, like factoring very large numbers, in any useful amount of time. That bet was placed with a classical mindset. A quantum computer changes the odds on exactly those problems, which means the foundation under standard encryption stops being load-bearing.

In an interview with The Washington Post published on July 2, IonQ president Jordan Shapiro, who runs the company’s quantum platform, called this a paradigm shift as opposed to an upgrade cycle. He’s right, and the distinction is worth slowing down on. Classical security is a back-and-forth. Attackers get better, defenders respond, attackers adjust, and the line moves in small increments nobody has to panic about. Quantum breaks that rhythm.

Shapiro describes it as a step-function change, a threat category that hasn’t existed before, and that framing is directionally correct because the defense can’t simply iterate its way out. You don’t patch your way past a broken assumption. You replace the assumption. In his words:

“This is a paradigm shift for security. The reality is that it is a type of technology becoming a threat that has never existed before. Rather than being a gradual evolution — like you might see in classical security, where the opponent gets better and then the defense gets better, and vice versa — this is a step-function change.

Harvest now, decrypt later is the part that’s already happening

Here’s the piece the overnight-apocalypse framing hides. Long before any quantum computer cracks anything, your encrypted data can be copied and stored by someone willing to wait. The industry calls it HNDL: harvest now, decrypt later. An adversary collects encrypted traffic today and reads it the day a capable quantum computer exists.

So the exposure clock isn’t ticking toward Q-Day. It’s already up for anything sensitive that traveled across a network in the last few years. Think about what has a long shelf life: health records, financial histories, state secrets, and tons of other sensitive documents. None of that expires on a two-year cycle. If it was harvested in its encrypted state in 2024, a break in 2029 still reads it clean. Let’s face it, most organizations have no inventory of what’s already been collected, which means they can’t even price the risk they’re carrying.

Shapiro’s sharper point is about Q-Day itself. He grants that the dramatic version is possible, a morning where a new quantum-powered hack gets announced out of nowhere, partly because plenty of companies publish quantum roadmaps when governments and others don’t, so the true capability frontier is partly invisible. But he expects something less cinematic and more corrosive. A gradual, systematic dismantling of security infrastructure, where algorithms and protocols we currently trust stop being safe, one after another, behind the scenes. Call it the quiet dismantling. It’s harder to plan around than a single deadline because there’s no alarm attached to it.

Why the timeline moved, and why that’s the real news

Not long ago the working expectation for Q-Day sat around 2035. Shapiro now puts the expectation before the end of this decade, and the reason is unglamorous compounding. Quantum hardware and software have all been improving faster than the field predicted, and when three curves bend at once, the combined timeline moves more than any single advance would suggest.

Jordan Shapiro's views on quantum risk.
Jordan Shapiro’s views on quantum risk. Source: IonQ/X

This is where blind optimism does the most damage. The comforting story goes: Q-Day is a decade-plus away, standards aren’t final, so migration can wait for a calmer quarter. Every clause in that story was reasonable a few years ago. It’s the timing that’s rotten now, and betting on 2035 as the consensus slides toward 2029 is exposure dressed as patience.

What the executive order does, and what it leaves on you

The June 22 order is a mandate, and mandates move procurement and set deadlines. It flags quantum security as a priority for critical infrastructure specifically, government systems, financial institutions, and health care among them, and it tells organizations to begin PQC migration, if they haven’t, with clear targets by the end of the decade. That’s a floor worth having.

But read Shapiro on what it doesn’t settle. PQC migration isn’t a one-time rollout. These quantum systems are new enough that nobody fully knows how they’ll interact with the algorithms meant to defend against them, so the standards themselves will keep moving. He expects the government to maintain and update them over time, which means any company treating migration as a single project with an end date has misread the assignment.

The refresh-cycle trap

So here’s the operational reason why “start now” isn’t a slogan. IT infrastructure refresh cycles typically run two to five years. That’s the trap. If your hardware updates aren’t already moving toward quantum-secure standards, the equipment you buy or renew this year could still be in service when the threat lands, and you won’t have a clean window to swap it out in time. The exposure gets baked into your stack on a timeline you set before you understood the risk.

At the very least, this reframes the decision. The question stops being “when is Q-Day” and becomes “when does my next refresh cycle lock in my exposure.” Those are different clocks, and the second one is the one you actually control.

What executives should do about it

Shapiro’s checklist is plain, and its plainness is the point. Understand the threat and learn what quantum actually does. Evaluate your own systems and ask whether they’d survive a quantum attack. Then move on quantum-secure solutions, in software or hardware, as you monitor for attacks in a landscape that keeps shifting.

Companies that are behind should start with inventory. Find what data is exposed today and where your infrastructure is soft. Know what’s at stake in concrete terms, including regulatory liability, since a framework like GDPR can make you financially answerable for exposure you failed to close. Then fix what you found. Shapiro’s blunt framing is that some of your data may already be sitting in someone’s archive waiting for HNDL, and you can’t undo that, but you can turn the faucet off and stop feeding the next breach.

His closing line is the one that’ll get quoted: if you’re not preparing now, you’re already too late. It means you’ve already absorbed some loss you can’t reverse, the harvested data you’ll never get back, and the job now is limiting how much more you hand over on a timeline you no longer fully control. The quiet dismantling doesn’t wait for your roadmap. Price that in.