← Back to Blog

CRQC Explained: When Does a Quantum Computer Actually Break Encryption?

CRQC Explained: When Does a Quantum Computer Actually Break Encryption? - QNSQY post-quantum encryption guide

The Definition That Matters

A Cryptographically Relevant Quantum Computer (CRQC) is a quantum computer capable of breaking real-world public-key cryptography. Specifically, a CRQC can run Shor's algorithm on parameters used today: RSA-2048, RSA-3072, ECDH P-256, ECDH P-384, and similar. NIST and NSA use this exact phrase in their post-quantum guidance to distinguish from lab demonstrations that break toy problems.

The single-number threshold most papers use: a CRQC can factor a 2048-bit RSA modulus (or solve the equivalent discrete log problem) in less than a year. Operationally, that is sufficient to harvest-now-decrypt-later any TLS session, any RSA-encrypted backup, or any ECDH key exchange.

Why the Distinction Is Not Pedantic

If you read a headline saying "1,121 qubits achieved" (IBM Condor, Dec 2023) and conclude cryptography is about to break, you are conflating qubit count with CRQC capability. They are different by four to five orders of magnitude.

A CRQC needs:

  1. Thousands of logical qubits, each error-corrected below a per-operation error rate of roughly 10^-10 or better for the core algorithm steps.
  2. Long coherence times across many hours of continuous computation.
  3. Connectivity sufficient to entangle thousands of logical qubits.
  4. Magic state distillation or equivalent resource-intensive non-Clifford gate infrastructure.

No quantum computer in April 2026 has any one of these at the required scale, let alone all four.

How NIST and NSA Use the Term

NSA CNSA 2.0 (Sept 2022) sets three deadlines for CRQC-resistant migration: new National Security Systems must ship quantum-safe by January 2027, application-layer traffic by 2030, and the full infrastructure by 2035. The "2035" is not a CRQC prediction; it is a planning target based on a conservative interpretation of expert surveys.

NIST IR 8547 (November 2024 draft) uses "CRQC" throughout and proposes deprecating quantum-vulnerable algorithms by 2035 and disallowing them entirely after.

Expert Timeline Estimates

The most cited source is the Global Risk Institute's annual Quantum Threat Timeline survey, conducted by Michele Mosca (IQC Waterloo) and collaborators. The 2025 report estimates a CRQC likelihood in the next 10 years between 28 percent (pessimistic) and 49 percent (optimistic), the highest 10-year range in the survey's seven-year history.

This does not mean a CRQC is definitely arriving in 10 years. It means a non-trivial fraction of expert opinion now places real probability on that window.

Three Misconceptions About CRQC

Myth 1: Quantum supremacy equals CRQC. Random circuit sampling and boson sampling prove exponential quantum advantage on contrived problems. They do not scale to Shor.

Myth 2: Bigger qubit count equals closer to CRQC. Quality matters as much as quantity. An error rate of 10^-3 on 1,121 qubits is millions of times worse than needed. Google Willow's 105 qubits below threshold is, in that sense, more important than Condor's 1,121 above threshold.

Myth 3: CRQC is decades away so we can relax. This misunderstands Mosca's theorem. If your data must remain confidential for 20 years, and CRQC arrives in 15 years, you are already too late.

What To Track

To know how close CRQC actually is, watch for:

  • Logical qubit count, not physical qubit count.
  • Logical error rate, with 10^-6 to 10^-10 being the relevant range.
  • Verified small-scale Shor, such as a credible quantum factoring of a 32+ bit integer (current verified demos are far below this).
  • Independent peer-reviewed results, not company press releases.
  • NIST, NSA, ENISA, NCSC public timeline updates.

Frequently Asked Questions

Does CRQC mean all cryptography is broken?

No. CRQC breaks public-key cryptography based on factoring and discrete logarithms (RSA, DH, ECDH, ECDSA, Ed25519). Symmetric ciphers like AES-256 and hash functions like SHA-384 remain secure against quantum computers given sufficient key sizes.

How close are we to a CRQC today?

Not close by physical qubit count. As of April 2026 the largest quantum computers have around 1,000 to 1,200 physical qubits at error rates far above what is needed for CRQC. The Global Risk Institute's 2025 survey estimates a 28 to 49 percent likelihood within 10 years.

Can we postpone PQC migration until CRQC is confirmed?

No. Adversaries can harvest encrypted traffic today and decrypt once CRQC arrives. If your data needs to remain confidential past the CRQC horizon, you have already lost the window to act reactively.

Is the 2022 Bao Yan Chinese paper claiming 372 qubits is enough a CRQC?

No. Scott Aaronson and Bruce Schneier both publicly criticized the paper. The approach relies on Schnorr's classical factoring heuristic which does not scale. The demo factored a 48-bit integer; real RSA is 2048 bits.

Sources

  1. NSA CNSA 2.0 FAQ
  2. NIST IR 8547 (draft)
  3. Global Risk Institute Quantum Threat Timeline 2025
  4. Gidney & Ekera (2021)

Questions people ask

What does CRQC stand for?

CRQC means Cryptographically Relevant Quantum Computer: a quantum computer powerful and stable enough to run Shor's algorithm against real-world key sizes such as RSA-2048 or 256-bit elliptic curves. It marks the point where today's public-key cryptography actually breaks, not merely in theory.

When will a CRQC exist?

Nobody knows. Public estimates from government agencies and researchers commonly fall in the 2030-2040 window, and required qubit counts keep dropping in published research. The operational answer is that harvest-now-decrypt-later collection makes long-lived data unsafe years before any CRQC boots.

What could a CRQC break?

RSA, elliptic-curve cryptography (ECDH, ECDSA, Ed25519), and finite-field Diffie-Hellman fall to Shor's algorithm. Symmetric ciphers and hashes survive: Grover's algorithm only halves their effective strength, which is why AES-256 and BLAKE3 remain safe while RSA-2048 does not.

Related Articles

Protect Your Data Before Q-Day Arrives

QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.

Try QNSQY

Originally published at quantumsequrity.com/blog/crqc-meaning-explained.