Although the rapid acceleration of artificial intelligence has understandably sucked the oxygen out of the room in the security community, there is another technological shake-up marching steadily toward us that will reshape our digital world: quantum computing.
Quantum computers leverage the laws of quantum physics to perform difficult simulations and solve complex mathematical problems. A sufficiently powerful and stable quantum computer, also known as a Cryptographically Relevant Quantum Computer (CRQC), will do what today’s most powerful supercomputers cannot, breaking the public-key encryption and authentication that secures online banking, communications, and other vital networks and systems. Key public institutions and private companies are ill prepared for the moment when advanced quantum computing becomes a reality.
That’s why Aspen Digital is launching Preparing for Q-Day, a project intended to address the security challenges of accelerated quantum computing.
What is Q-Day?
In the next five to ten years we face the possibility of a quantum computer that can bypass public-key cryptographic algorithms, the security foundation of our modern digital economy. Cryptographic systems protect our data, identities, and communications, securing critical information across sectors, from financial transactions to private messaging.
Aware of this looming technological breakthrough, adversaries have used the strategy of “harvest now, decrypt later” to store encrypted data today in the hopes of accessing it once a CRQC arrives. This milestone, termed Q-Day by security experts, is projected to arrive as soon as the next 5 years, though timelines vary.
By breaking quantum-vulnerable encryption, adversaries would have the capacity to read confidential content, pose as an authorized user, modify communications content, and insert fraudulent information into digital systems. These critical vulnerabilities risk jeopardizing continuity of operations and the integrity of the information we share online, eroding the public’s trust in our core institutions.
In addition to Q-Day, we must have a plan for a potential future in which a CRQC is not only developed, but arrives much sooner than anticipated and becomes widely available and cheap to deploy. In this hypothetical emergency, or “break glass,” scenario, powerful quantum computing could be leveraged by adversaries at scale, rather than a single nation-state actor.
What is being done now to prepare for the quantum era?
Cryptographers and researchers have responded by developing algorithms designed to withstand cyberattacks from a quantum computer, or post-quantum cryptography (PQC) algorithms. In 2024, the National Institute for Standards and Technology (NIST) released the first three finalized PQC standards to facilitate the beginning of this necessary digital transition.
This June, the Trump Administration released two Executive Orders to accelerate the government’s plan for quantum computing and post-quantum preparedness. In Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, the Administration sets a 2030 timeline for federal agencies to migrate their digital systems to post-quantum encryption, five years earlier than the timeline set under the Biden Administration in 2022.
Within industry, over the last few months, major technology companies including Microsoft, Google, and Cloudflare, have announced that they will expedite their quantum-safe deadline to 2029.
Even amidst these efforts to plan for Q-Day, much of the broader government and business communities remain unprepared for the PQC transition. Through discussions with security experts, we have identified a set of questions that strike at the core of our gap in readiness:
- How should we respond if a CRQC not only arrives sooner than anticipated but is relatively cheap to produce on a commercial scale?
- How do we communicate with business leaders the need to prepare for a CRQC in the next 5-10 years?
- What strategies can industry and government implement in the PQC era to preserve trust in our institutions?
Our plans to prepare for Q-Day
To address these questions, Aspen Digital is partnering with experts with decades of experience in cryptography, security protocols, digital identity, and internet standards. We will collect insights from critical industry and government stakeholders, map vulnerabilities and dependencies, and synthesize migration plans into a pragmatic and useful resource for leaders, technical staff, and the public. In parallel, we will create a first-of-its-kind guide for stakeholders to understand and respond to an emergency “break glass” scenario.
Over the next eight months, our work will unfold in four phases:
Understanding PQC Risk
We will begin by mapping out the opportunities and challenges identified by critical organizations who face meaningful risks in the quantum era. This phase will include background interviews with cross-sector experts in business, technology, policy, and civil society who are responsible for executing the PQC transition. Hidden risks may exist in particular sectors or industries, so we seek to unearth these critical dependencies and tailor our recommendations accordingly.
Drafting Migration Recommendations
Based on the conclusions from our experts’ research and interviews, we will draft recommendations along two tracks, accounting for separate and distinct scenarios in the development of quantum computing.
The first track will synthesize resources from the field into consolidated, digestible recommendations tailored to private and public sector stakeholders. These recommendations will identify how leaders can make the case for a strong PQC migration plan within their organizations.
The second track will plan for unlikely, but potentially momentous, emergency “break glass” scenarios in quantum innovation that may override the set of typical recommendations. Our draft plans will unpack steps that stakeholders can take to minimize risk to intellectual property, trade secrets, and confidential information.
There are many existing trustworthy handbooks, factsheets, checklists, and templates including from NIST, the Cybersecurity and Infrastructure Security Agency (CISA), and industry and civil society leaders, and Aspen Digital’s recommendations will build on and amplify these resources as part of our work.
Validating Recommendations
Once we draft migration resources to account for distinct scenarios in the quantum era, we will move into the validation phase. The Aspen Digital team will consult with business representatives and finalize guidance to operationalize our recommendations.
Building Consensus
In early 2027, we will convene and align cross-sector groups from the public and private sectors to drive awareness, promote adoption of proposed guidance, amplify messaging, and generate a shared sense of ownership and urgency about addressing PQC timelines.
Next steps
As we embark on conducting field interviews, drafting recommendations, and socializing frameworks with industry experts, Aspen Digital will continue to align and build consensus across sectors on the need to prepare for the PQC era. Our team of experts will seek to communicate to leaders in government and business what we might risk with inaction and promote steps required to preserve public trust in our economy, digital systems, and institutions.
Like major technological transitions of the past, a complete migration to PQC will require sustained coordination across groups of stakeholders with disparate, and often competing, priorities. We are committed to creating a forum to convene and share our findings, ensuring that we are collectively prepared to securely interoperate in the global economy of the 2030s and beyond.
We are grateful to the William and Flora Hewlett Foundation for making this work possible.
Interested in getting involved with Preparing for Q-Day? Reach out to aspendigital@aspeninstitute.org if you would like to contribute your expertise.


