Quantum Threat 101: Why RSA and ECC Won’t Last

Home >> TECHNOLOGY >> Quantum Threat 101: Why RSA and ECC Won’t Last
Share

Last updated on September 21st, 2026 at 08:07 am

A silent countdown is occurring in the background of all the encrypted connections you are making today – in the process of each login, each bank transfer, each secure message. Most people don’t know it exists. And the ones that know are in a great hurry to put it back on before it gets late.

This article dissects the reasons why both RSA and ECC, which are the most widely used encryption systems globally, are on borrowed time, what they are being replaced by, and why organizations that fail to adhere to the clock already have a real cause to worry. Camp is the kind of background information every developer, security professional, business owner, or even bored individual who cares about keeping their data confidential should have.

What RSA and ECC Actually Do

Before we get to why they’re vulnerable, it helps to understand what these systems protect.

Both RSA (Rivest-Shamir-Adleman) and ECC (Elliptic Curve Cryptography) are cryptographic systems, which are a form of cryptography, and in particular public-key cryptography. They support HTTPS, VPNs, secure email, digital signatures, and most internet authentication systems. If your browser displays a padlock, RSA or ECC is very likely working behind the scenes.

Both systems use math problems that are incredibly difficult to solve on classical computers in any reasonable time.

The security of RSA lies in integer factorization: It is simple to multiply two large primes, and extremely hard to undo the process – to factor the product and compute the two original primes. An RSA key of 2048 bits implies that the underlying semiprime is so large that a classical computer would take millions of years to factor it by brute force.

ECC follows a different path, based on the elliptic curve discrete logarithm problem. The mathematics are different, though the principle is the same: computationally asymmetric. Easy to calculate in one direction, but almost impossible without the secret key.

This assumption has held for decades. The thing is, it only holds for classical computers.

How Quantum Computing Breaks the Assumption

Shor’s Algorithm: The Core Threat

Everything changed in 1994 when mathematician Peter Shor published an algorithm that changed everything. Shor’s algorithm, which can run on a quantum computer, can factor large integers and solve discrete logarithms in polynomial time rather than exponential time.

That difference is a big difference. Attempts to use classical computers to solve RSA-2048 require exponential time – the problem becomes so exponentially difficult as to become virtually impossible in practice. Shor’s algorithm flips that. With a sufficiently large quantum computer, it becomes feasible to factor the RSA semiprime or solve the discrete log problem in ECC.

What that would mean in practice: it might have a powerful enough quantum machine that it can generate a private key using a public key. It may masquerade as servers, break signatures, and decrypt communications it has overheard—any supposition on which the security of RSA and ECC is based falls.

I read a few technical explainers in the post-quantum documentation and NIST security research papers while preparing this. It should be a regular pattern: erased by a patch that there is no patch to Shor’s algorithm. The only way to make RSA or ECC quantum-resistant is to increase the size of the keys, at least to a useful degree. The algorithm breaks the mathematical structure.

What About Symmetric Encryption?

Nothing breaks under equal measure. Symmetric keys such as AES and hash cryptography functions such as SHA-256 are a little more threatened by quantum computing: Grover’s algorithm.

Grover’s algorithm offers a quadratic speedup in searching unsorted data. This is applied to brute-forcing a symmetric key, and as a consequence, effectively reducing AES-128 to around 64-bit protection against a quantum attacker – weak. But AES-256? That becomes about 128-bit quantum security, which is still thought to be sufficient in the predictable future.

This means the quantum threat 101 story is more precisely concerned with public-key cryptography: RSA, ECC, Diffie-Hellman, ECDH, ECDSA, Ed25519, and their derivatives. Symmetric encryption and hashing are not affected, but their security level decreases.

The following graph illustrates how Shor’s algorithm achieves the goal of breaking public-key systems, but Grover’s algorithm only weakens symmetric ones:

Quantum Threat 101: Why RSA and ECC Won't Last

The Harvest Now, Decrypt Later Problem

Why the Threat Is Already Active

This is where it stings: organizations need not wait until they are on the verge of losing a working quantum computer to be in jeopardy. It is another type of attack already in progress.

This technique is called harvest now, decrypt later (HNDL). Encrypted network traffic capture, storage, and manipulation by nation-state actors and advanced adversaries is already a reality today -SSL/TLS sessions, VPN tunnels, encrypted file e-mails.

They can’t read it now. The presumption, though, is that once a cryptographically relevant quantum computer (CRQC) is built, they will be able to reverse everything they have stored.

Reviews of enterprise security assessments suggest this threat is often treated as hypothetical. It isn’t. Storage costs for bulk traffic have dropped to almost zero. Nation-states have strong motivation to collect now. Government
market records, medical records, legal agreements, proprietary studies, intelligence records – any data of sensitivity that has long survival is within the scope.

The vital variable is the data lifetime. Suppose the information you are protecting must stay confidential for only two years; NDL isisn’tour biggest threat. However, when it must remain confidential for at least ten years and longer, as most sensitive enterprise and government information does, the clock has already started ticking on harvesting.

What Data Is Actually at Risk

Encrypted data is not equally risky. The most exposed categories of HNDL:

  • The greatest motivators for collecting information are government and military communications; foreign intelligence services are the most motivated.
  • Personal identifiers (permanent) and healthcare historical records (long retention): permanent and long-retention data.
  • Intellectual property and trade secrets – competitive advantage is decades old.
  • Contracts, compliance documentation, and audit trails: long-term financial and legal duty agreements.
  • PKI infrastructure and root certificates – failure in this case is contagious throughout the chain. The exposure of the HNDL is low in the case of most consumer data – a login session, a short-lived API call. However, organizations dealing with any of the above categories are well advised to consider this a risk today, not in the future.

Timelines and the Road to Q-Day

Where Quantum Hardware Actually Stands

Among the transparent disadvantages in this area is that no one knows when a cryptographically significant quantum computer (CRQC) will be implemented, that is, one that is capable of successfully executing Shor’s algorithm against practical-sized RSA-2048 or ECC-256 keys.

Studies show the trend has increased. Recent generalizations have lowered the simulation cost in qubits and gates needed to break RSA, shrinking previous margins of comfort.

Current estimates indicate that RSA-1024 may be compromised as early as 2028-2030, with RSA-2048 and other possible future standards challenged as early as the early-to-mid 2030s, under realistic research-lab conditions.

The utility-scale quantum computing program of DARPA (and similar government-evenly funded programs of other nations) is an indication of a planned effort towards useful quantum machines in (approximately) the same international timeline of either the early- or mid-2030s.

Why Migration Timelines Start Now

Even if “Q-day” occurs in 2033, organizations may still have time to prepare, but that doesn’t mean they have until 2032 to start.

Upgrading cryptographic infrastructure is traditionally slow. The cryptography in a large enterprise or government agency – among PKI, TLS settings, VPN stacks, firmware, IoT agents, code-signing systems, and other protocols of their own – can usually require five to ten years or more to update.

The regulatory calculus is simple: when full migration to post-quantum cryptography must take place by 2030-2035, it must begin now. Standards bodies are already treating this as an urgent need, not a future option.

NIST has completed three post-quantum crypto standards: FIPS 203 (ML-KEM, which uses CRYSTALS-Kyber), FIPS 204 (ML-DSA, which uses CRYSTALS-Dilithium), and FIPS 205 (SLH-DSA, which uses SPHINCS+).

The NSA introduced the CNSA 2.0 model, which requires adopting PQC in national security systems by approximately 2030. RSA-2048 and ECC-256 are estimated to be deprecated around 2030-2035.

Post-Quantum Cryptography: What’s Replacing RSA and ECC

The New Math Behind PQC

Post-quantum cryptography does not use quantum computers; it is classical cryptography resistant to quantum attacks. The biggest shift is moving away from problems that Shor’s algorithm can solve(factoring, discrete logs) to math problems that quantum machines are thought to keep hard.

The final standards that are adopted in NIST are based on:

  • Here is lattice-based cryptography: ML-KEM (Kyber) and ML-DSA (Dilithium). Its security is based on the hardness of problems such as Learning With Errors (LWE) in high-dimensional mathematical lattices. No known quantum algorithm provides a useful speedup.
  • Hash-based signatures SLH-DSA (SPHINCS+) rely only on the security of cryptographic hash functions, which the Grover algorithm only weakens.
  • Code-based schemes and multivariate schemes – another family under study to reduce redundancy, as no one individual PQC family has so far had decades of cryptanalytic pressure cash in on it.

The Trade-offs Worth Knowing

PQC isn’t a straight swap. Security architects and developers should understand the real practical costs.

Lattice-based schemes have much larger public keys and ciphertexts than their RSA or ECT counterparts. ML-KEM key sizes are specified in kilobytes rather than hundreds of bytes. PQC-enabled TLS pilot programs report about 20-35% handshake overhead compared with current ECDH-based systems.

That impacts bandwidth, storage, and latency – especially in limited-resource systems, such as IoT devices, embedded hardware, and high-throughput financial infrastructure. It is not impossible without planning.

It is one of the first challenges anyone undertaking Post-Quantum Cryptography Migration will hit; it is not a simple configuration change. It may involve revising libraries, protocols, hardware security modules (HSMs), and the machinery supporting key generation, distribution, and storage.

What’s Already Deployed and What’s Just Starting

Quantum Threat 101: Why RSA and ECC Won't Last

What Exists in 2026

The migration process is underway in locations well positioned to relocate quickly.
Major browsers and hyperscalers have been testing or implementing hybrid key exchange in TLS – executing ML-KEM and classical ECDH simultaneously, preventing connection security from being compromised even if one of the two algorithms is subsequently broken.

Before the final assignment of the NIST standards, Google, Cloudflare, and others began experimenting with hybrid PQC-TLS designs in production.

NIST ultimately published three stable standards (FIPS 203, 204, 205). VPN heavyweight vendors, certificate vendors, and enterprise security vendors have started releasing products or previewing PQC-enabled products.

The IETF, ETSI, and ENISA have published profiles, hybrid patterns, and transport-layer guidelines to help architects implement these changes.

Open-source tooling exists. The liboqs project provides reference implementations of PQC algorithms. Vendor SDKs are starting to support ML-KEM and ML-DSA.

What’s Just Beginning

The harder, slower part is the organizational side. Top-down inventory: Most enterprises have not yet done a crypto inventory, an organized audit of where RSA and ECC live across their infrastructure. Migration planning is impossible without such an inventory.

A growing idea is crypto-agility: building systems so cryptographic code is modular and swappable across algorithms. The RSA-2048 + SHA-256-based application developed today will need code modification to port.

In a crypto-agile system, you can update algorithms through configuration. Today’s agile design significantly lowers the cost of the transition in the end.

Even the regulatory pressure is formalizing. The US national security systems deadlines are hard on CNSA 2.0. National cybersecurity agencies in Europe, such as ENISA, and other countries are releasing statements on mobile and network migration with specific deadlines. Government contracts and regulated industries are starting to publish PQC readiness as procurement and compliance requirements, although this is still limited to enterprises.

The Road Ahead and How to Start

A Practical Starting Point

Migration to post-quantum cryptography should be a project of significant magnitude, and it will take years before a large organization is fully migrated. But these are the definite first steps that will be really noticed:

1. Cryptographic exposure: inventory. Determine the location of RSA and ECC – TLS certificates, VPN setups, S/MIME, code-signing pipelines, IoT, HSM, and firm-to-firm connectivity. You can’t migrate what you can’t find.

2. Determine your lifetime risk of data. What information in your organization should be confidential for ten or more years? That’s your HNDL exposure. Protect those data flows first.

3. Follow the NIST standards. The final baselines are stable: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). Use vendor solutions that do not meet these requirements with caution.

4. Test hybrid deployments. The suggested intermediate solution is to run ML-KEM and ECDH in TLS setups and VPN setups. It offers quantum resistance without forsaking classical standards and years of real-world experience.

5. Plan for crypto-agility. Where new systems are being constructed, or old ones are refactored, we should construct layers of abstraction. It is less expensive to build this today than to retrofit it later.

To further support the technical background, my experience led me to two specific, more useful external materials: the ENISA Post-Quantum Cryptography Migration report to get the migration strategy and organizational advice, and the ETSI Quantum Safe Cryptography white paper to give a clear technical explanation of why, at the time, the existing cryptography is vulnerable and how quantum-safe alternatives compare.

Trust Booster External links: Anchor text:

Wrapping Up

RSA and ECC won’t last is not the main point of Quantum Threat 101: Why RSA and ECC Won’t Last. The quantum computers that can implement Shor’s algorithm at scale aren’t available yet.

But the direction is clear: harvest-now-decrypt-later is already operational for long-lived sensitive data, and it will take years to move about, not months.

RSA and ECC aren’t retiring with the flip of a coin. However, organizations beginning their Post-Quantum Cryptography Migration planning today will build inventory, risk assessments, hybrid deployments, and crypto-agility options that will exist in 2030. The ones that wait won’t.

The mathematical problem that underpins your current security is not faulty. It is simply weak in a very particular way, and its weakness has a timeline that is coming into view. That’s enough to act on.

Leave a Reply

Your email address will not be published. Required fields are marked *