Skip to main content

What To Do If Q-Day Happens Years Early?

0
Medium
Published: 09/16/2026 (09/16/2026, 11:54:14 UTC)
Source: Reddit Cybersecurity

Description

This content discusses the potential early arrival of 'Q-Day,' the point when quantum computers could break traditional asymmetric cryptography, possibly as early as 2028. It highlights that most governments and organizations plan to be post-quantum prepared by 2030-2035, but recent statements from IonQ suggest that breaking 256-bit elliptic curve cryptography might be feasible sooner. The post emphasizes the need for organizations to accelerate their post-quantum cryptography projects, conduct rapid cryptographic inventories, and implement emergency response plans if Q-Day occurs earlier than expected. It also advises prioritizing mitigation of authentication threats and updating incident response policies to address quantum-related attacks. The content serves as a strategic warning rather than a report of an active vulnerability or exploit.

Reddit Discussion

r/cybersecurity·posted by u/rogeragrimes
00

Most of the world’s governments tell you that you need to be post-quantum prepared by 2030-2035. For example, the US government says critical infrastructure should be key-exchange-prepared by the end of 2030 and authentication-prepared by the end of 2031 (ignore for now that they have the threats exactly backward). Non-critical infrastructure has until the end of 2035. There are a few governments saying critical infrastructure should be prepared by 2029, and many large tech companies, such as Google, Cloudflare, and Microsoft, say they plan to be prepared by 2029.

But what happens if Q-Day happens in 2028?

I cover this topic in my latest post-quantum books, Becoming Post-Quantum: Your Guide to Post-Quantum Success (https://www.amazon.com/dp/B0HHTBDZ7T) and Becoming Post-Quantum: Your Post-Quantum Project Plan (Companion Book) (https://www.amazon.com/dp/B0HJJJ675G).

This isn’t a rhetorical question. IonQ has recently stated (https://www.ionq.com/news/ionq-publishes-worlds-first-fully-compiled-end-to-end-blueprint-for-breaking-256-bit-elliptic-curve-signatures) that it is realistic that its quantum computers could break traditional asymmetric cryptography used by everyone by 2028.

To be clear, a paper is not a working cryptographically-relevant quantum computer. But it is a clear sign that IonQ thinks that it is not out of the realm of possibility.

I wrote about this last week: https://www.linkedin.com/pulse/should-you-post-quantum-prepared-2028-roger-grimes-vo9le.

Note: It takes a lot more than just stable, logical working qubits to make a cryptographically-relevant quantum computer. Marin Ivezic’s analysis is the best I’ve seen on the subject: https://postquantum.com/crqc-capability-framework/. But getting lots of stable, usable error-corrected qubits is one of the biggest challenges, if not the most challenging part.

Most organizations haven’t even started an official post-quantum project yet. They are late. They need to start now! ASAP!!

But even if your organization has started an official post-quantum project, it’s likely that the estimated “Q-Day” (i.e., the day when the first quantum computer breaks traditional asymmetric encryption) that the entire project is running on is probably 2030-2035.

What happens if Q-Day happens in 2028 or 2029?

Well, you’ve got to accelerate your post-quantum project, of course. All of it. It would be a massive immediate refocusing of resources. It would likely result in your organization being less efficient and productive (unless you are a vendor in the post-quantum space).

You would have to reach out to your immediate boss, executive management, and the board of directors, if you have one, and tell them what just happened. Then you would gather all the necessary resources for an emergency meeting. You would immediately start your cryptographic inventory. Instead of having a year plus to conduct it on all critical systems, you would start conducting it focused first and best on your top critical systems. Ultimately, you would want your cryptographic inventory finished as fast as possible (e.g., a week, a month, a quarter) on your most critical assets.

You would then make emergency decisions regarding what can be reconfigured, what needs to be upgraded, what needs to be replaced, what needs to be decommissioned, and what needs to be physically isolated. You would be making these decisions quickly.

You might need to hire extra resources well beyond what you have today to conduct the post-quantum project superfast. Do you have those post-quantum vendors selected today? Do you know any? If not, start figuring out whom to call when. What cryptographic inventory software will you use? None are perfect. None inventory everything. But you need to use one (or more) to help you collect your cryptographic inventory as quickly as you can. You should do your research and make these two selections now, so you'll have them when you need them. [Hint: You need them now, regardless of Q-Day dates.]

On a practical note, if your adversaries can use quantum computers against you (you’d have to calculate the risk of them actually doing so), you would need to implement monitoring tools, processes, and policies to be able to detect a quantum compromise. Is there a way to detect a successful quantum attack? For key exchange breaks, probably not. Other than you learn that previously protected information seems to be known by unauthorized entities. For authentication breaks, you would look out for fake digital certificates and use, and other related artifacts, such as fraudulent successful logons, fraudulent websites with fraudulent “valid” digital certificates. You would need to threat model the various quantum threats against your environment and then create and implement the appropriate protective and detective controls.

You would need to update your SOC (if you have one) and potentially your incident response policies and procedures. How do you respond to a quantum attack if you actually detect one? How do you respond to stolen data? How do you respond to a fraudulently used “valid” digital certificate and its use? In the latter case, you would certainly get the fraudulently used digital certificate revoked, warn stakeholders of the use, and get other related fraudulent assets removed and/or taken down. Ultimately, you need to threat model the various quantum attacks that would be possible against your company and take the appropriate preventative, detective, and incident response controls, like you would against any threat. Only this threat is quantum and new.

I would also recommend that you focus on mitigating authentication threats first (https://www.linkedin.com/pulse/us-government-gets-pqc-threats-exactly-backward-you-should-grimes-sx7ee) over key exchange threats, if you can’t do them both at the same time. This goes counter to every other post-quantum expert telling you what to do first. I’m right. They are wrong.

Regardless of whether Q-Day comes early or not, it’s cheaper and better to do it sooner than later. I wrote about that here: https://www.linkedin.com/pulse/why-become-post-quantum-now-versus-later-roger-grimes-wiboe.

With this post, I just want you to consider what you and the world are going to look like if Q-Day happens years earlier than most governments are telling you to be prepared for. There is at least one quantum computer vendor that is saying it’s not insane to think it might happen in 2028 or soon thereafter.

The possibility is non-zero. You need to make that part of your post-quantum plans. It would be irresponsible not to.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/16/2026, 16:31:34 UTC

Technical Analysis

The post outlines concerns about the possibility that quantum computing capabilities could compromise current asymmetric cryptographic systems earlier than widely anticipated, potentially by 2028. IonQ's publication of a blueprint for breaking 256-bit elliptic curve signatures is cited as an indicator that such advances are plausible, though a fully operational cryptographically relevant quantum computer is not yet realized. The author stresses that most organizations have not yet begun adequate post-quantum preparedness and recommends immediate acceleration of cryptographic inventory and mitigation efforts. The discussion includes strategic steps for emergency response, prioritization of authentication threat mitigation, and the necessity of threat modeling for quantum attacks. The content is advisory and forward-looking, focusing on preparedness rather than describing a specific vulnerability or exploit.

Potential Impact

If quantum computers capable of breaking current asymmetric cryptography become operational earlier than expected, the confidentiality and integrity of encrypted communications and authentication mechanisms could be compromised. This would affect critical infrastructure and organizations relying on traditional cryptographic protections. The impact includes potential unauthorized data access, fraudulent digital certificates, and compromised authentication systems. However, no active exploit or vulnerability is reported; the impact is a future risk requiring proactive mitigation.

Defensive Guidance

No immediate patch or fix is applicable as this is a strategic threat related to future quantum computing capabilities. Organizations should accelerate their post-quantum cryptography projects, conduct rapid cryptographic inventories focusing on critical systems, and prioritize mitigation of authentication threats. They should also update incident response and security operations center (SOC) procedures to address potential quantum attacks, including detection and response to fraudulent digital certificates and unauthorized access. Selecting post-quantum cryptography vendors and cryptographic inventory tools in advance is recommended to enable rapid response if Q-Day occurs early. Continuous threat modeling and implementation of appropriate preventive, detective, and incident response controls specific to quantum threats are advised.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6aaac46255bf5e2cf5dd1ce1

Added to database: 09/16/2026, 16:31:30 UTC

Last enriched: 09/16/2026, 16:31:34 UTC

Last updated: 09/17/2026, 03:31:32 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses