惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
I
InfoQ
The Register - Security
The Register - Security
L
LangChain Blog
H
Help Net Security
The GitHub Blog
The GitHub Blog
S
Schneier on Security
博客园 - 【当耐特】
W
WeLiveSecurity
Attack and Defense Labs
Attack and Defense Labs
IT之家
IT之家
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Google DeepMind News
Google DeepMind News
The Cloudflare Blog
H
Heimdal Security Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Y
Y Combinator Blog
雷峰网
雷峰网
N
Netflix TechBlog - Medium
Security Archives - TechRepublic
Security Archives - TechRepublic
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
L
Lohrmann on Cybersecurity
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
The Exploit Database - CXSecurity.com
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
V
Visual Studio Blog
博客园 - 聂微东
PCI Perspectives
PCI Perspectives
Last Week in AI
Last Week in AI
A
Arctic Wolf
宝玉的分享
宝玉的分享
T
The Blog of Author Tim Ferriss
S
Secure Thoughts
T
Threat Research - Cisco Blogs
GbyAI
GbyAI
云风的 BLOG
云风的 BLOG
D
Darknet – Hacking Tools, Hacker News & Cyber Security
S
SegmentFault 最新的问题
SecWiki News
SecWiki News
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏
Schneier on Security
Schneier on Security
P
Proofpoint News Feed
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
AI
AI
Engineering at Meta
Engineering at Meta

PostQuantum – Quantum Computing, Quantum Security, PQC

Lightning Network's Quantum Problem Ethereum's Five Quantum Vulnerabilities Bitcoin's Quantum Vulnerability — Anatomy How Close Is the Quantum Threat? Resource Estimates The Quantum Threat to Cryptocurrencies: What's Real Lattice-Based PQC "Limitations" Paper — A Reality Check China's Hanyuan-2 Dual-Core Quantum Computer Pick One Layer First for Your Post-Quantum Migration Cisco Quantum Switch: Room-Temperature Qubit Routing IonQ Claims Q-Day by 2029 — Here's What They Actually Said Project Eleven's 110-Page Quantum Blockchains Report QuantWare Raises $178M Series B Q-CTRL Claims Practical Quantum Advantage Quantum Computing Simulates 12,635-Atom Protein How Quantum Snake Oil Vendors Respond to Hard Questions Simulated Quantum Entanglement | PostQuantum.com Quantum Snake Oil: Guide to Misleading Quantum Terms Quantum AI Trading — Quantum Snake Oil Dictionary Quantum-Proof — Quantum Snake Oil Dictionary Quantum-Grade Encryption — Quantum Snake Oil Dictionary Quantum-Safe Certified — Quantum Snake Oil Dictionary Military-Grade Quantum Encryption | PostQuantum.com What Is a QBOM? Quantum Bill of Materials vs CBOM Explained Quantum-Inspired Encryption — Quantum Snake Oil Dictionary What Is Trust Now, Forge Later (TNFL)? Quantum Blockchain — Quantum Snake Oil Dictionary What Is PQC Migration? The Largest Cryptographic Overhaul Quantum Financial System (QFS) | PostQuantum.com What Is QKD (Quantum Key Distribution)? What Is Quantum Error Correction (QEC)? Unhackable Quantum Encryption | PostQuantum.com Unconditionally Secure — Quantum Snake Oil Dictionary Perfect Secrecy — Quantum Snake Oil Dictionary Information-Theoretic Security | PostQuantum.com Quantum Encryption / Quantum Cryptography Quantum-Enhanced — Quantum Snake Oil Dictionary Quantum-Safe vs Quantum-Resistant vs Post-Quantum Anatomy of Quantum Denial: Bitcoin's Example What Is a Logical Qubit? The Metric That Actually Matters What Is Q-Day? When Quantum Computers Break Encryption What Is Harvest Now, Decrypt Later (HNDL)? What Is Grover's Algorithm? What Is Shor's Algorithm? The Quantum Threat Explained What Is Quantum Safe? What the Label Means for CISOs What Is Quantum Computing Security? What Is Quantum Cyber Security? What Is Quantum Cryptography? QKD, PQC, and related? Quantum Security: A Complete Guide for Security Leaders What Is Post-Quantum Cryptography (PQC)? Crypto-Agility Is an Architecture Problem, Not a Library Swap IBM Quantum Advantage 2026: Heron + Fugaku Analyzed Aaronson Warns: CRQC by 2029 Is Plausible U.S. Quantum Policy: NQI Reauthorization and PQC Bills The Narrow Advantage: Why Quantum Computing Will Transform Five Industries and Disappoint Twenty The Error Correction Revolution Rewriting Quantum Timelines The Signature Supply Chain: How Deep Does Digital Trust Go? Quantum Chemistry's Honest Ledger: What the Resource Estimates Actually Say About Drug Discovery, Catalysis, and Materials Design Why Quantum Won't Save Wall Street (Yet): An Honest Assessment of Quantum Computing in Finance PQC Standards Fragmentation Quantum Sovereignty and the Utility Trap The Decoder Bottleneck: The CRQC Challenge Nobody Is Talking About IonQ Publishes Complete Fault-Tolerant Blueprint for Trapped Ions — The Walking Cat Architecture Quantum Computing by 2033: Which Industries Win, Which Wait, and Why Nature Reviews Publishes the Definitive CMOS–Spin Qubit Compatibility Assessment IonQ Photonic Interconnect: First Networked Commercial Quantum Computers QuEra Achieves 2:1 Physical-to-Logical Qubit Ratio With Ultra-High-Rate qLDPC Codes Grover's Algorithm vs AES - Why "Ignore It" Is Almost Right McKinsey Quantum Monitor 2026: Tipping Point? Meta PQC Migration Playbook: Lessons for CISOs NVIDIA Ising: Open AI Models for Quantum Calibration and Error Correction Harvard's Cascade Neural Decoder PQC Signature Migration Before Encryption Architecture Matters as Much as the Algorithm: Q-CTRL's Heterogeneous Quantum Computer Design Cuts RSA-2048 to 190k-381k Qubits China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Anthropic's Mythos Preview and the End of a Twenty-Year Cybersecurity Equilibrium China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Cloudflare Joins Google: Two Internet Giants Now Say 2029 for Post-Quantum Migration China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging QuiX Quantum Achieves First Below-Threshold Error Mitigation in Photonic Quantum Computing China's Quantum Talent Ecosystem: Building a Superpower's Workforce Quantum Threat Timeline Report 2025: Record Predictions, But Can the Survey Keep Up? China's Quantum Talent Ecosystem: Building a Superpower's Workforce China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower Gauge Theory Meets Quantum Computing China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority QuantumShield360 AI Achieves World's First Complete Post-Quantum Cryptography Migration — Full Quantum Resilience Across All Enterprise Systems 10,000 Qubits to Run Shor's Algorithm Google Quantum AI Achieves 10x Reduction in Resources to Break Bitcoin's Cryptography The U.S. Intelligence Community Just Put Quantum on Equal Footing with AI. And Expanded the Threat Definition Google Just Drew a Line in the Sand: PQC Migration by 2029 Silicon Crosses the Logical Threshold: First Universal Logical Operations Demonstrated in a Silicon Quantum Processor The 1,000-Qubit Ceiling That Probably Isn't Science Confirms What Large Corporate Survivors Already Knew - Organizational Bullshit Makes You Worse at Your Job A New Algorithm Shrinks the Quantum Attack Surface for ECC Quantinuum Squeezes 94 Logical Qubits from 98 Physical — But What Does It Actually Mean?
What Is a CRQC? Quantum Computer That Breaks Encryption
Marin Ivezic · 2026-05-04 · via PostQuantum – Quantum Computing, Quantum Security, PQC

This is part of the Quantum Security Reference Deep Dive series. For the full landscape overview, see the capstone article on quantum security.

Introduction

A Cryptographically Relevant Quantum Computer (CRQC) is a quantum computer powerful and reliable enough to run Shor’s algorithm against real-world cryptographic systems, breaking RSA, ECC, and Diffie-Hellman at the key sizes used in production. No CRQC exists today. Building one requires simultaneous advances across at least ten distinct engineering capabilities. The question is when one will be built, not whether.

How a CRQC Differs from Today’s Machines

Today’s quantum computers are often described as NISQ devices: Noisy Intermediate-Scale Quantum machines. They operate with hundreds to a few thousand physical qubits, error rates that accumulate rapidly over sequential operations, and coherence times measured in microseconds to milliseconds. They are useful for certain research and optimization problems but cannot sustain the long, deep computations that Shor’s algorithm requires.

A CRQC must operate in a fundamentally different regime. Breaking RSA-2048 requires maintaining roughly 1,400 error-corrected logical qubits through millions of sequential gate operations over hours or days without accumulating fatal errors. Each logical qubit is itself constructed from hundreds or thousands of physical qubits through quantum error correction, meaning the total physical qubit count runs into the hundreds of thousands or millions.

The gap between a NISQ machine and a CRQC is not a matter of adding more qubits to an existing design. It requires qualitative engineering breakthroughs in error correction, control systems, fabrication, and sustained operation. I cover the progression from NISQ through fault-tolerant quantum computing in my analysis of the NISQ to FTQC to FASQ trajectory.

The Ten Capabilities a CRQC Requires

My CRQC Quantum Capability Framework identifies ten engineering capabilities that must converge before a quantum computer can threaten cryptography. The framework exists because single metrics (qubit count, gate fidelity, quantum volume) fail to capture the full picture. A machine with a million physical qubits but inadequate error correction cannot run Shor’s. A machine with perfect error correction but insufficient qubit connectivity cannot execute the algorithm efficiently.

The ten capabilities span four layers. The foundation layer covers quantum error correction, syndrome extraction, below-threshold operation, and qubit connectivity. The computation layer addresses high-fidelity logical gates and magic state production. The integration layer requires full algorithm integration, real-time decoder performance, and continuous long-duration operation. The engineering layer demands manufacturing at scale.

No quantum computing platform has demonstrated all ten simultaneously. Several have made significant progress on individual capabilities. The CRQC Scorecard assesses how close each quantum computing modality (superconducting, trapped ion, neutral atom, photonic, silicon) is to meeting the full set.

Tracking Progress

Two tools on PostQuantum.com are designed to help security leaders track CRQC progress without needing to evaluate individual research papers.

The CRQC Quantum Capability Framework provides the analytical structure. When a new result is published (a new error correction threshold demonstrated, a new qubit connectivity record, a new logical gate fidelity), the framework shows where that result fits in the overall picture and whether it moves the needle toward a CRQC.

The CRQC Readiness Benchmark translates capability progress into timeline estimates. It allows readers to adjust assumptions (error rates, algorithmic improvements, engineering pace) and see how those assumptions affect the estimated arrival date. The methodology behind it is documented in the benchmark methodology paper.

The Resource Estimates

The most concrete way to think about CRQC proximity is through published resource estimates for specific cryptographic attacks.

For RSA-2048, the current best estimate (Gidney, 2025) requires fewer than one million physical qubits and under one week of runtime, assuming surface code error correction with physical error rates of 10⁻³. The Pinnacle architecture using qLDPC codes pushes the theoretical floor below 100,000 physical qubits under optimistic assumptions that have not been validated at scale.

For ECC, the estimates are lower. The Chevignard et al. EUROCRYPT 2026 paper places the P-256 ECDLP at 1,193 logical qubits. Google’s March 2026 analysis estimates fewer than 500,000 superconducting physical qubits could break ECC-256.

These numbers should be interpreted carefully. They assume physical error rates and hardware parameters that no current machine achieves. They also represent a trajectory: five years ago, the RSA-2048 estimate was 20 million physical qubits. The direction is consistent even if the destination date is uncertain.

Why “When” Matters Less Than You Think

My detailed prediction points toward RSA-2048 falling by 2030. Other credible estimates range from the early 2030s to the 2040s. The uncertainty is real and irreducible at this stage of the technology’s development.

For security planning, however, the exact date is secondary. As I have argued at length, the deadlines for PQC migration are already set by regulators and industry. CNSA 2.0, NIST IR 8547, Google, Cloudflare, and the EU have all established quantum security timelines independent of CRQC predictions. The HNDL threat means that data captured today is already at risk regardless of when a CRQC arrives.

A CRQC will be built. The engineering challenges are immense but finite. The appropriate response is to prepare on the timelines that are certain rather than gamble on the one that is not.

Go Deeper

What Is Q-Day? — the day a CRQC arrives

Cryptographically Relevant Quantum Computers (CRQCs) — full explainer

CRQC Quantum Capability Framework — the ten capabilities a CRQC requires

CRQC Readiness Benchmark — methodology and interactive timeline estimator

CRQC Scorecard by Modality — how close each quantum platform is

From NISQ to FTQC to FASQ — the technology progression

Quantum Breakthrough for RSA-2048 (Gidney 2025) — the latest resource estimate

Quantum Upside & Quantum Risk - Handled

My company - Applied Quantum - helps governments, enterprises, and investors prepare for both the upside and the risk of quantum technologies. We deliver concise board and investor briefings; demystify quantum computing, sensing, and communications; craft national and corporate strategies to capture advantage; and turn plans into delivery. We help you mitigate the quantum risk by executing crypto‑inventory, crypto‑agility implementation, PQC migration, and broader defenses against the quantum threat. We run vendor due diligence, proof‑of‑value pilots, standards and policy alignment, workforce training, and procurement support, then oversee implementation across your organization. Contact me if you want help.

Talk to me Contact Applied Quantum