
No quantum computer can break your encryption today. None is close. The reason to pay attention anyway is that NIST has put dates on the calendar, and they'll reach you through contracts and audits long before they reach you through a broken key.
NIST's draft transition report lists 112-bit-strength RSA and elliptic-curve cryptography as deprecated after 2030, with all RSA and ECC disallowed after 2035. For most small businesses the work this year is small: an inventory, a few upgrades, and better questions for your vendors.
The short version
- Nothing you use is breakable today, and the expert consensus agrees.
- NIST deprecates 112-bit RSA and ECC after 2030. Everything classical is disallowed after 2035.
- Your browsers already moved. Your VPN, your backups, and your old line-of-business app probably didn't.
- The 2026 job is an inventory, not a purchase.
Do you need to care about quantum computers yet?
Not the machines. The deadlines. The Global Risk Institute's 2025 expert survey put the odds of a cryptographically relevant quantum computer appearing at 28-49% within ten years and 51-70% within fifteen, drawn from 26 specialists.
Read those numbers before reacting to them. Roughly a coin flip in fifteen years is not a reason to panic, and it's not a reason to ignore this either. It's a reason to know what you'd have to change.
The practical question isn't "when will quantum break my encryption." It's "when does my bank, my insurer, or my auditor start asking whether I've moved." That's a 2027-2030 question, and the answer is cheaper if you start the inventory now.
What "harvest now, decrypt later" actually means
An attacker copies your encrypted traffic today and stores it until they can decrypt it. They don't need to break anything now. They need patience and disk space.
This matters for data with a long shelf life. Medical records, legal files, M&A documents, trade secrets, client financials. Anything still sensitive in 2035. It doesn't matter much for a Teams message about lunch.
Be honest about which of your data is which. Most small businesses have a thin slice of genuinely long-lived secrets and a large pile of things nobody will care about in five years. The thin slice is what the planning is for.
NIST already finished the hard part
In August 2024, NIST released three finalized post-quantum encryption standards: FIPS 203 (ML-KEM) for general encryption, FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures.
The replacement algorithms exist. They're standardized. Vendors are shipping them. That's why this is now a project-management problem instead of a research problem.
The dates that follow from it, per NIST IR 8547:
- RSA-2048 and ECC P-256 (112-bit strength): deprecated after 2030, disallowed after 2035.
- RSA-3072 and above, ECC at 128-bit strength or higher: no deprecation step, disallowed after 2035.
- Status of the document: still an initial public draft, published November 2024. Treat the dates as direction, not law.
You're already using post-quantum crypto and didn't notice
Cloudflare reported in April 2026 that over 65% of human traffic to Cloudflare is post-quantum encrypted, and set 2029 as its target for full post-quantum security. Its earlier write-up notes that recent versions of all major browsers, OpenSSL, Go, and recent Apple operating systems enable the hybrid X25519MLKEM768 key exchange by default.
Two-thirds of the human traffic hitting one of the largest networks on the internet already moved, and nobody sent you a memo. If your staff run current Chrome or Edge against a modern site, the key exchange protecting that session is already quantum-resistant.
The gap is everything that isn't a browser. VPN appliances. Site-to-site tunnels. File transfer tools. Old line-of-business apps with hardcoded TLS libraries. Backup software. That's where the real work sits.
What a small business should actually do this year
Five things, none of them expensive.
- Build a cryptographic inventory. List every place you encrypt something: VPN, email, backups, file shares, website certificates, any app that talks to a partner's API. You can't migrate what you haven't written down. If you already keep an IT asset inventory, add a column.
- Patch and stay current. Post-quantum key exchange arrives in browser, OS, and TLS library updates. A fleet that's two years behind on patching gets none of it for free.
- Ask vendors one question in writing. "What is your timeline for supporting the NIST post-quantum standards?" File the answers. A vendor with no answer in 2026 is a vendor to watch.
- Fix certificate management first. Certificate lifetimes are already shrinking toward automated renewal, and the post-quantum transition means another mass certificate swap. Both problems have the same fix. We covered it in shrinking SSL certificate lifetimes.
- Know where your long-lived secrets live. Tie this to your data retention policy. Data you deleted on schedule can't be harvested.
If you already run a framework like NIST CSF 2.0, the inventory slots into asset management and the vendor question slots into supply chain risk. You're not starting a new program.
What this costs
Close to nothing in 2026, if you're already patching. The algorithms ship inside software you're paying for. The cost is an afternoon of inventory work and a slightly more annoying vendor review.
It gets expensive in one scenario: you're running unsupported hardware or an application nobody maintains. Then the post-quantum deadline becomes a replacement deadline, and you'd rather find that out in 2026 than in 2031 during an audit. That's the real value of doing the inventory early. It surfaces the things that can't be upgraded at all.
Who should ignore this for now
If you're a ten-person firm with no regulated data, no long-lived secrets, and everything in Microsoft 365, your post-quantum plan is "keep patching." The platform vendors are shipping this inside browser and OS updates, and you inherit it by staying current.
Take it seriously if you're a law firm holding deal documents, a medical practice, a defense contractor, or a registered investment adviser under Reg S-P. Anyone whose contracts already name encryption standards will hear about this from a client first.
Frequently asked questions
When will quantum computers actually break RSA?
Nobody knows, and anyone giving you a confident date is selling something. The Global Risk Institute's 2025 survey of 26 experts puts the odds of a cryptographically relevant quantum computer at 28-49% within ten years and 51-70% within fifteen. Plan around NIST's transition dates instead, since those are scheduled regardless of what the hardware does.
Is post-quantum cryptography required by law?
Not for private businesses today. NIST IR 8547 is a draft transition report, and federal systems move first. Expect the requirement to reach you indirectly, through cyber insurance questionnaires, client security reviews, and framework updates, well before any law names it.
Do I need to buy new hardware?
Usually no. The new algorithms are software. The exception is network gear and appliances already past end of support, which won't get post-quantum firmware because they aren't getting firmware at all.
What about my backups?
Backups are the clearest harvest-now target you have, because they hold the most long-lived data in one place. Ask your backup vendor about their post-quantum roadmap and confirm your encryption keys are managed somewhere you control.
Does a VPN protect me from this?
Only if the VPN itself uses post-quantum key exchange, and many small-business VPN appliances still don't. That's precisely the gap worth checking. Your browser traffic is likely further along than your VPN.
Where to start
Start with the inventory. It takes an afternoon, it costs nothing, and it tells you whether you have a five-year project or a non-issue.
The NetSys Group runs cryptographic inventories as part of our security assessments, and our vCISO team builds the vendor questions into annual reviews. Book a complimentary risk assessment and we'll tell you where you actually stand.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



