On 11 March 2026, Forrester's emerging-technology blog gave readers a specific piece of evidence for an alarming forecast. Quantum computers able to break mainstream public-key cryptography would likely arrive by 2030, the post argued, pointing to a demonstration that 1,399 logical qubits could factor RSA-2048 in under a week. The number is real and so is the research behind it. A reader who takes it at face value has been misled anyway.
IBM's Condor, the first superconducting processor past a thousand qubits, holds 1,121. Against that, 1,399 reads as a rounding error away from catastrophe. It is not. The two figures count different things, and the distance between them is the distance between a chip that exists and a machine nobody knows how to build.
That gap is close to the normal condition of public writing about quantum risk, which leaves a technology executive somewhere awkward. The published numbers will not survive checking, the experts appear to disagree by a decade, and a board still wants a position this quarter. The position turns out not to depend on any of it.
Forrester's underlying report, *The State Of Quantum Computing, 2026*, sits behind a paywall; every Forrester claim examined here comes from the free public post.
The word that was missing was “logical”
What 1,399 actually buys you
The figure is accurate and comes from serious work. Across the resource-estimate literature the RSA-2048 factoring program is put at roughly 1,399 logical qubits, and the April 2026 accounting of that circuit prices those logical qubits in physical ones. What the Forrester post left out is the price.
On a demonstrated grid-coupling topology they put the requirement at 381,000 physical qubits and 9.2 days, falling to 4.9 days at 439,000 qubits with a dedicated accelerator, or 190,000 qubits assuming a long-range coupling scheme that does not yet exist.
The phrase “under a week” attaches to none of those; the headline configuration takes 9.2 days. It belongs to a different paper: Craig Gidney's May 2025 estimate that RSA-2048 could be factored in under a week by a computer with fewer than a million noisy qubits, assuming a 0.1% gate error rate. Two papers, two units, one sentence.
Figure 1 sets both units on one axis, alongside the hardware that exists.

Why no two qubit numbers are comparable
A logical qubit is one error-corrected unit of computation, assembled from many physical ones so that hardware errors cancel rather than accumulate. The ratio between them is no constant: it is set by the code, the hardware, and the circuit depth.
The folk figure for surface codes is roughly a thousand physical qubits per logical one. IBM reports that its bivariate bicycle code, encoding 12 logical qubits into 144 data qubits, corrects errors as well as the surface code with ten times fewer qubits. Quantinuum's Helios, launched in November 2025, offers up to 48 error-corrected logical qubits from 98 physical ones.
That two-to-one encoding rate is the trap. It describes error-detection demonstrations at shallow depth, not the sustained billion-gate computation a factoring attack requires. Under the April 2026 accounting the effective ratio for RSA-2048 runs between roughly 136 and 314 physical qubits per logical one. A logical-qubit headline tells a buyer nothing without the code and the circuit depth beside it.
The rest of the post's numbers
One dropped word could be an editing accident. The post credits Quantinuum with logical qubits achieving 22 times lower failure rates, and the result is genuine. Microsoft and Quantinuum's error-correction paper records a 22-fold suppression factor for preparing a 12-qubit cat state, within a range running from 11-fold to 800-fold. The post lists it among key 2025 milestones; the paper was posted in April 2024.
A second claim attributes to IBM a commitment to machines with ten thousand physical qubits by 2029. IBM's published roadmap commits Quantum Starling, that year, to circuits of 100 million gates on 200 logical qubits, and states no physical count at all. The attributed figure could not be located in any IBM source.
The third claim is commercial. Forrester cites Procter and Gamble using SAS's quantum AI to cut optimization runtimes from hours to minutes. The collaboration exists, announced at SAS Innovate in May 2025, but the 97% figure appears only in material SAS produced itself. It also runs on quantum annealing, and an annealer cannot run Shor's algorithm, so the example belongs to a different technology from the one the forecast describes.
And the conservative number is stale too
None of this is partisan. In a talk written up by MIT Sloan on 9 December 2025, William Oliver, director of the MIT Center for Quantum Engineering, said breaking RSA would require a very large error-corrected quantum computer with millions of qubits. That was defensible against the 2019 literature, which put the requirement at 20 million noisy qubits, but Gidney's sub-million estimate had appeared six months before the write-up. Oliver was reported late rather than wrong.
The direction is what matters. In seven years the estimated physical-qubit cost of breaking RSA-2048 fell from 20 million to as low as 190,000, driven by algorithms rather than hardware. Anyone planning against a figure published more than a year ago is planning against one that has already moved.
They were never answering the same question
A decade to what, exactly?
To commercial products, not to broken encryption. Oliver's “decade or more” attaches to commercialized quantum computers and applications, a different proposition from a machine that can factor an RSA key. On cryptography he says something narrower: such a machine is not yet available, and organizations should move to post-quantum cryptosystems now regardless.
Forrester's 2030 date covers both propositions at once. Separate them and most of the apparent decade-wide gap goes too, leaving a difference of emphasis between two people who agree on the recommendation.
Breaking RSA is a solved algorithm; making money is not
The two questions have genuinely different answers. Breaking RSA needs one algorithm that has been published for decades and enough error-corrected hardware to run it. Commercial advantage needs algorithms nobody has written. Oliver put it more bluntly than most vendors would: there are problems he cannot solve on a classical computer and does not yet know how to solve on a quantum one either.
The strongest advantage claim on record reflects that. On 22 October 2025 Google announced that its Willow chip had run an algorithm it calls Quantum Echoes roughly 13,000 times faster than the Frontier supercomputer could. Its credibility rests on verifiability rather than speed: the output reproduces across machines, and the team checked its predictions against nuclear magnetic resonance spectroscopy. It is a physics result, not a business one.
A 2026 preprint titled “The NISQ Trap” argues that eight years of quantum-advantage demonstrations have systematically selected problems classical hardware was positioned to lose. The strongest business example in current coverage is a vendor-reported annealing proof of concept. Commercial advantage is not here, and the cryptographic timeline never depended on it.
So when? Nobody can tell you, and that is the finding
Two experts are an anecdote; here is the distribution
Two named positions are not a disagreement among experts. They are two samples from one, and the distribution has been measured for seven consecutive years. The Quantum Threat Timeline Report 2025, published 9 March 2026 by Michele Mosca and Marco Piani of evolutionQ, asks 26 specialists one question: how likely is a machine able to factor RSA-2048 in under 24 hours, within a given horizon.
The averaged answers put it at 28% to 49% within ten years, the highest in the survey's history, and 51% to 70% within fifteen, with medians clustering between 2029 and 2032. Figure 2 places both sources against that spread. Forrester sits near the mainstream center rather than the alarmist edge, and Oliver at the conservative end of the same distribution.

Two qualifications travel with it. Its authors are principals of a company selling post-quantum security services, and 26 respondents is a small sample. Its 24-hour threshold is also stricter than the resource papers use, which produces a result worth noticing: a machine matching Gidney's estimate would break RSA-2048 in under a week and still fail the survey's definition of a relevant computer.
The estimate has moved a hundredfold, and it can move back
The reduction came from approximate residue arithmetic, yoked surface codes, and magic state cultivation rather than better hardware, and nothing guarantees that continues. Every such estimate is built on an assumed gate error rate no hardware has delivered at scale, which makes it a projection rather than a measurement. Falling fast is not the same as falling predictably.
The machines make the distance concrete. Condor reached 1,121 physical qubits, and the best-documented error correction is Google's below-threshold demonstration published in *Nature* in December 2024: a 101-qubit distance-7 surface code, the logical error rate suppressed 2.14-fold for each increase of two in code distance. Between a thousand physical qubits today and 190,000 in the most optimistic estimate sit two to three orders of magnitude.
The case that it never happens at all
The strongest skeptical position is not that quantum computing is overhyped. It is that a cryptographically relevant machine is physically impossible. Tim Palmer of Oxford argues in the *Proceedings of the National Academy of Sciences*, published 16 March 2026, that information capacity grows linearly rather than exponentially with qubit count, and that a hard ceiling follows. His own department puts it at a few hundred error-corrected qubits; the most generous published reading is 200 to 400 today and never more than about a thousand.
The position has real weaknesses. Rational Quantum Mechanics is a minority interpretation, indistinguishable from standard quantum mechanics at the qubit counts anyone can currently reach, which leaves it untestable where it matters. But take it seriously and the consequence is stark. The RSA-2048 circuit needs about 1,399 logical qubits, the elliptic-curve circuit at 256 bits about 1,193. Both sit above Palmer's ceiling on any reading. If he is right, neither attack is ever built.
Two further skeptical points survive scrutiny. Capability of this kind will show up in error-correction results and gate fidelities long before any working attack, so the image of waking one morning to broken encryption is the wrong model. And the exposure is to public-key cryptography specifically; symmetric algorithms such as AES are not comparably threatened. And if Palmer is right after all, one thing still holds, for reasons the published standards settle rather than the physics.
The deadline does not care when the machine arrives
RSA already has an expiry date, and it is published
The decision left the forecasting business in 2024. NIST Internal Report 8547 sets the transition schedule for quantum-vulnerable public-key algorithms, and it is specific: RSA, ECDSA, ECDH, and finite-field Diffie-Hellman at roughly 112 bits of security are deprecated after 2030 and disallowed after 2035. That document remains an initial public draft. The replacement algorithms are not: they have been final since 13 August 2024, when NIST published FIPS 203, FIPS 204, and FIPS 205, issued through the Federal Register the same day.
The draft status matters less than it did, because the deadline has since been made binding elsewhere. Executive Order 14412, signed 22 June 2026, requires federal agencies to move their most sensitive systems to post-quantum encryption by 31 December 2030, and OMB Memorandum M-26-15 sets out the phased migration running to 2035. For any organization inside a federal supply chain this is already a compliance project with a date on it, and the timeline debate reduces to whether it will also be enforced by physics. Hybrid modes combining an approved post-quantum algorithm with a classical one escape the 2035 disallowance, which is what makes phasing viable.
This is also where the two sources that opened this piece agree. Oliver's guidance is to implement post-quantum cryptosystems now; Forrester's is to start quantum-safe implementation immediately. The recommendation was never in dispute. Only the reasoning offered for it was.
The arithmetic that needs no date
There is a formal reason the recommendation holds without a date, and it belongs to Michele Mosca of the Institute for Quantum Computing at the University of Waterloo, the researcher behind the survey above. His inequality reduces the question to three quantities.
**X, the shelf life:** how many years the data must remain confidential. A statutory retention period or the working life of a trade secret will usually supply it.
**Y, the migration:** how many years the organization needs to move its systems to post-quantum cryptography. This is the only one it controls, and it shrinks by starting.
**Z, the arrival:** how many years until a machine exists that can break the encryption. Nobody can supply this one; the survey above is the closest available substitute.
If X plus Y exceeds Z, the data protected today will still be sensitive when the machine that breaks it arrives. Figure 3 is a worksheet rather than a chart for that reason: only Z comes from research. What the inequality changes is the order of operations. Ranking data stores by how long they must stay confidential, rather than by how sensitive they feel, produces a defensible migration sequence.

The mechanism that makes X matter is harvest now, decrypt later. In August 2023 CISA, the NSA, and NIST jointly warned that threat actors could be targeting data today that will still require protection in future.pdf), a risk since taken up outside the quantum industry. That is a recognized threat model stated in conditional language, not a documented finding that mass harvesting is under way. The distinction is worth preserving.
What survives if the skeptics are right
Grant Palmer his ceiling and the cryptanalytic case goes away entirely. No machine, no factoring, and in time no harvested traffic worth decrypting either. That is a real concession and it should be made plainly rather than argued around.
One thing survives it. The migration schedule was written against a compliance calendar, not a physics forecast, so it binds whether or not the machine is built. An organization that migrates and turns out to have been wrong about the physics has still met a federal deadline. One that waits and turns out to have been wrong has missed it. That asymmetry, not the physics, settles the decision.
What to do on Monday
**Start a cryptographic inventory.** It is the first recommendation in the CISA, NSA and NIST factsheet.pdf) and the precondition for the rest. An organization that cannot list where it uses RSA and elliptic-curve cryptography cannot sequence a migration.
**Rank data stores by required confidentiality lifetime, not by sensitivity.** That ranking is Mosca's X, and it converts a general warning into an order of work. Financial records, health data, government archives, and intellectual property sort differently on the two.
**Prioritize against 2030 and 2035 rather than against a Q-Day forecast.** The dates in Executive Order 14412 and the NIST schedule do not move with the physics.
**Put post-quantum readiness into vendor diligence.** Replace questions about qubit counts with questions about logical qubits, the error-correcting code, and measured error rates. A supplier quoting a bare qubit number is either misunderstanding the field or counting on the buyer to.
One number is deliberately absent. No credible general figure for how long such a migration takes could be established, and inventing one would repeat the failure this piece has been auditing. Y comes from the inventory.
The forecast is not the deadline
Return to the sentence that opened this piece. It carried a real figure from a real paper, and its author was arguing for what the standards already require. What it lost in transmission was one word, and with it the difference between a machine nearly here and one two orders of magnitude away.
That error is not a reason to dismiss the risk, nor to wait for better numbers. The numbers are unstable because the research is moving quickly, and they will still be unstable in 2028. The deadline will not be. RSA-2048 has a published expiry date, its replacements have been standardized since August 2024, and today's traffic is collected whichever forecast proves right. Act on the deadline. The forecast will keep moving without you.