“When will Y2Q happen?” remains one of the most asked — and most misunderstood — questions in post-quantum cryptography. A new scenario-based Monte Carlo assessment from SITG-Consulting‘s Strategic Forecasting Laboratory models a roughly 65% cumulative probability of an operational RSA-2048 compromise by 2028, rising to approximately 90% by 2029, with a non-trivial probability beginning as early as 2026–2027. Quantropi has anticipated a 2027–2029 window since 2022, based on research trajectories, investment patterns, and the convergence of enabling technologies. The SITG Consulting Monte Carlo assessment captures this convergence perfectly.
What does SITG Consulting’s Assessment Actually Show?
Most quantum timelines attempt to predict hardware delivery. SITG-Consulting instead reframes the question around operational capability: when an adversary can practically break public-key encryption.
By using a scenario-based, stochastic Monte Carlo architecture, the assessment changes the conversation.
From isolated milestones to the convergence of quantum engineering, artificial intelligence, cryptanalysis, semiconductor systems, and the strategic environment, the Monte Carlo simulation incorporates these convergence factors—not just theoretical qubit counts, but the real-world rate at which breakthroughs are occurring across these multiple domains.
The results are eye‑opening:
- 65% likelihood of Y2Q by 2028
- 90% likelihood by 2029
- A non‑trivial probability beginning as early as 2026–2027
The assessment concluded: “The convergence of artificial intelligence, optimized error correction, dynamic physical architectures, and algorithmic compression has significantly shortened the timeline to operational cryptographic compromise.”
This is not alarmism. It’s math. It’s modelling. It is the logical extrapolation of the current pace of innovation.
(Source: SITG-Consulting Strategic Forecasting Laboratory, “Forecasting the First Practical RSA Compromise: A Scenario-Based Monte Carlo Assessment,” 2026.)
What are the Implications?
For many organizations, quantum readiness has long been treated as a distant compliance obligation. Today, however, it is increasingly becoming a strategic modernization initiative—a way to gain competitive advantage and demonstrate leadership to customers, regulators, investors, and partners, rather than simply respond to emerging risks.
Organizations that recognize this shift and still delay their quantum-safe migration will be left behind. Those that have started but are moving slowly need to accelerate. And those that believe they can “wait and see” are not only gambling with their future attack surface; they are also risking the loss of competitive advantage and the opportunity to lead in their sectors.
So, should governments and enterprises accelerate their efforts toward quantum-safe migration? Yes. Significantly. (Unless they are in the top 1% and already far ahead.)
However, the real question—the one that matters now—is: How do you accelerate?
This is where many organizations get stuck. They know they need to move faster, but they don’t know how to do so without sacrificing governance, compliance, or architectural rigor.
The instinct is often to double down on planning:
- The instinct is often to double down on planning:
- Comprehensive Cryptographic Bill of Materials (CBOM) projects
- Multi‑year governance frameworks
- Endless inventories, audits, and re‑audits
- “Quantum readiness” committees that meet monthly but change little
Many of these are important. CBOM is essential. Governance is essential. Crypto agility is essential. But none of these alone will accelerate your timeline. In fact, if they become your only focus, they will slow you down.
The Acceleration Strategy: Prioritize and Parallelize
The organizations that will set the standard for their sectors — the ones that will avoid exposure —will follow a simple principle:
Don't sequence — parallelize. Don't boil the ocean — prioritize.
Yes, build your CBOM. Yes, establish governance. Yes, plan for crypto agile migrations. But do not wait for those projects to finish before mitigating the attack surfaces you already know are exposed.
You don’t need a CBOM to tell you that your site-to-site networks are vulnerable. You don’t need a governance committee to confirm that your IPsec and MACsec tunnels are prime HNDL targets. You don’t need a crypto inventory to know that your data-in-motion is at risk today.
These are the largest, most valuable, and most easily accessed attack surfaces in the enterprise — and they can be secured today, on existing infrastructure, without disrupting current operations, in parallel with your broader PQC program.
Why PQC Alone Is Not Enough for HNDL
Many organizations assume that simply upgrading to PQC‑based Key Encapsulation Mechanisms (KEMs) over a Public Key Infrastructure (PKI) will solve HNDL. It won’t. If you have an extended data protection requirement — months, years, decades — then relying solely on in-band PQC means you are betting that:
- The current PQC standards will never be compromised
- Future quantum advancements will never weaken lattice‑based schemes
- Crypto‑agility will always keep you ahead of adversaries
But if that were true, why is NIST already approving new additional standards? Why are we building crypto‑agile architectures? Why are we preparing for future migrations?
Because we fully expect today’s PQC to eventually weaken. When it does, any data harvested today — even if encrypted with PQC-over-PKI — becomes vulnerable again. That is why HNDL is uniquely dangerous, and why solving it requires more than PQC.
Why PQC Alone Is Not Enough for HNDL
To truly mitigate HNDL, you must remove the in-band KEM from the data channel entirely. That means out-of-band key delivery.
Out-of-band key delivery means keys never traverse the harvested channel. It eliminates the cryptographic handshake that adversaries can harvest today and decrypt tomorrow. It breaks the HNDL attack chain at its root. Even if today’s PQC algorithms weaken, your data remains protected because the keys were never exposed in band.
This is the “fix it once, fix it right” approach. And this is where Quantropi’s QiSpace™ platform delivers a fundamentally different — and fundamentally stronger — solution. It delivers software-defined, out-of-band quantum-safe key delivery, enabling organizations to strengthen protection for critical network environments while continuing broader PQC migration programs.
The Path Forward: Accelerate Smartly
To accelerate your quantum‑safe journey:
- Parallelize your PQC migration with immediate HNDL mitigation
- Prioritize the attack surfaces that matter most — site-to-site networks and data-in-motion
- Adopt out‑of‑band key delivery to eliminate future HNDL exposure
- Continue CBOM and governance work, but don’t let them stall action
- Build crypto‑agility, because PQC will weaken over time and will keep evolving
Frequently asked questions (FAQ)
Y2Q (“Years to Quantum”) is the point at which a quantum-capable adversary can practically break today’s public-key encryption, such as RSA-2048. SITG-Consulting’s Monte Carlo assessment models a ~65% cumulative probability by 2028 and ~90% by 2029. This creates a need for quantum-safe security technologies and migration strategies.
HNDL is the practice of capturing encrypted traffic today for decryption once quantum capability arrives. It makes the migration timeline concrete: data with long protection requirements harvested now is already in scope.
PQC migration is essential, but in-band PQC key exchange can still be harvested today and attacked if algorithms weaken in the future. For long-lived data, out-of-band key delivery removes that exposure entirely.
With the highest-value, most readily protected surfaces: site-to-site networks and data-in-motion over IPsec, MACsec, and OTNsec. These can be quantum-secured now, in parallel with CBOM and governance programs, on existing infrastructure.
Quantropi’s QiSpace™ platform enables organizations to accelerate quantum-safe adoption through software-based cryptographic solutions, including out-of-band quantum-safe key delivery, while supporting broader crypto-agile modernization strategies alongside standards-based post-quantum cryptography.
No. Quantropi’s QiSpace™ platform is software-based and hardware-agnostic, deployable across fibre, copper, wireless, cloud, and IoT, and integrates with existing network infrastructure from vendors including Cisco, Nokia, Palo Alto Networks, Fortinet, and Ciena
Lead the Timeline, Don’t Chase It
Y2Q is not a distant theoretical milestone. It is a rapidly approaching operational reality, and the organizations acting now — decisively, intelligently, and in parallel — will set the pace their sectors will follow by remaining secure when the timeline compresses further.
Quantropi anticipated this window in 2022 and built QiSpace™ so that enterprises, governments, and defence organizations can secure their most valuable channels today and on the infrastructure they already own. The timeline is compressing. Leadership means being ready before it does.
Innovation finds a way. Quantum finds a way. Your security strategy must find a way too. And it starts with accelerating. A lot.
Connect with us at sales@quantropi.com to start accelerating toward a quantum-safe security posture. Contact us today!