Quantum computing's most immediate real-world impact is not on chemistry or optimisation — it's on cybersecurity. A fault-tolerant quantum computer running Shor's algorithm could break RSA-2048 and elliptic-curve cryptography, the foundations of today's internet security. In response, governments worldwide are spending tens of billions on quantum technology programmes and mandating a transition to post-quantum cryptography.
"The threat is not hypothetical and it is not distant. 'Harvest-now, decrypt-later' attacks are happening today. Nation-state adversaries are collecting encrypted internet traffic now, betting they can decrypt it in 10–15 years when quantum computers mature. Sensitive communications encrypted today with RSA or ECC are already at risk."
The Cryptographic Threat
Shor's algorithm, running on a fault-tolerant quantum computer, can factor large integers in polynomial time — breaking RSA. A 4,000-logical-qubit machine (requiring ~4 million physical qubits with current surface code overheads) could crack RSA-2048 in approximately 8 hours. Current quantum computers have nowhere near this capability, but the development trajectory is clear.
| Algorithm | Classical Security | Quantum Attack | Status |
|---|---|---|---|
| RSA-2048 | 112-bit | Shor's algorithm | Vulnerable |
| ECC-256 | 128-bit | Shor's algorithm | Vulnerable |
| AES-256 | 256-bit | Grover's (halved) | Acceptable with key doubling |
| CRYSTALS-Kyber | 128-bit | None known | NIST PQC Standard |
| CRYSTALS-Dilithium | 128-bit | None known | NIST PQC Standard |
NIST Post-Quantum Cryptography Standards
In August 2024, NIST published its first three post-quantum cryptography (PQC) standards: ML-KEM (Kyber) for key encapsulation, ML-DSA (Dilithium) for digital signatures, and SLH-DSA (SPHINCS+) as a hash-based signature backup. US federal agencies are required to begin migration by 2030.
Government Quantum Investment (2026)
| Country / Bloc | Committed Investment | Key Programme |
|---|---|---|
| United States | $3B+ (CHIPS Act, NQI) | NSF Quantum Leap, DARPA ONISQ |
| European Union | €7B (Quantum Flagship) | EuroHPC quantum integration |
| China | $15B+ (est.) | National Laboratory for Quantum Info Sciences |
| United Kingdom | £2.5B | National Quantum Strategy |
| India | ₹6,000 Cr (~$720M) | National Quantum Mission |
Key Takeaways
- Harvest-now-decrypt-later attacks mean the quantum cryptographic threat exists today, not in the future.
- NIST has finalised the first post-quantum cryptography standards — migration should begin immediately for high-value systems.
- Quantum sensing and quantum communication (QKD) are also major national security investments alongside quantum computing.
- The geopolitical race for quantum supremacy is intensifying — quantum capability is now considered a strategic national asset.
