eternaX Research · The Quantum Migration Risk Benchmark
QDI v1.0
Q3 2026

P(Q Doom)2035

34%
90% calibrated uncertainty interval: 22 – 48%

Probability critical cryptographic migration remains incomplete when CRQC capability arrives, by 2035.

2035 is the risk horizon. 2030 is a major migration milestone. 2026–2027 is the decision window.

The practical question is not only when Q-Day arrives. It is whether an institution still has enough time to discover, redesign, test, and deploy before its required transition milestones. UK guidance expects large organisations to spend 2–3 years on discovery, strategy, and an initial plan.[30] The EU calls for high-risk use cases to transition no later than end-2030,[11] while U.S. EO 14412 sets 2030/2031 milestones for federal high-value and high-impact systems.[24]

Quantum Clock
28 – 49% expert CRQC probability within 10 years[1]
Migration Clock
7% report deployed quantum-safe or hybrid cryptography[14]
Last updated
1 October 2026
Methodology
QDI v1.0 · View methodology & sources
Conflict disclosure. The P(Q Doom) Index is developed and published by EternaX Labs, which develops post-quantum blockchain infrastructure. The model uses published methodology, externally verifiable data, and documented update rules. Commercial considerations are not inputs to the index.
P(Q Doom)H = P(TQ < TM)
The probability that a cryptographically relevant quantum computer defeats widely deployed public-key cryptography before systemically important digital infrastructure completes its transition to post-quantum controls, within horizon H. TQ is the arrival time of quantum cryptanalytic capability. TM is the time at which critical migration reaches the defined safety threshold.

Model status. QDI v1.0 is a structured expert calibration informed by published quantum-risk and migration evidence. The full reproducibility package — distributional assumptions, weighting functions, sensitivity analysis, and machine-readable inputs — is the next methodology release. See Methodology.

Paarrthhh Birla, Dariia Porechna, Dr. Chen Feng. The P(Q Doom) Framework: A Probabilistic Model of Cryptographic Migration Risk. EternaX Research, September 2026. QDI v1.0.

The Race Between Two Clocks: Q-Day Probability vs. Migration Completion

P(Q Doom) is a race between two probability distributions. The Quantum Clock tracks when cryptographically relevant capability arrives. The Migration Clock tracks when critical infrastructure eliminates sole dependence on quantum-vulnerable cryptography. The overlap is P(Q Doom). This framework extends the Mosca inequality[21]: if an organization's data sensitivity lifetime plus its migration time exceeds the time to a CRQC, that organization is already exposed.

The Race: Quantum Arrival vs. Migration Completion

Stylized probability densities. The shaded overlap region is P(Q Doom).

P(Q Doom) CRQC Arrival (TQ) Migration Completion (TM) 2026 2029 2032 2035 2038
CRQC arrival Migration completion Overlap = P(Q Doom)

The Third Clock: Harvest Now, Decrypt Later

HNDL introduces a Data Clock. Data exfiltrated today can be compromised retroactively whenever TQ arrives. The Federal Reserve published a dedicated paper analyzing HNDL risks for distributed-ledger networks in September 2025.[18] Palo Alto Networks' Unit 42 reports that the fastest quartile of intrusions reached data exfiltration in 72 minutes in 2025, down from 285 minutes in 2024.[19] For data that must remain confidential for decades, Mosca's inequality can make HNDL exposure relevant today; the exact migration deadline depends on the data's required secrecy lifetime and the institution's migration duration.

Why Common Dismissals No Longer Hold

"Quantum computers are decades away."

Resource estimates for breaking RSA-2048 fell from 20 million physical qubits in the earlier Gidney–Ekerå estimate to below one million in Gidney's May 2025 update under substantially comparable surface-code assumptions.[5] Separate 2026 work using qLDPC and neutral-atom architectures models still lower physical-qubit requirements under materially different assumptions.[6][23] For secp256k1, Google reports circuits that map to fewer than 500,000 superconducting physical qubits and execute in minutes under stated hardware assumptions.[12] The GRI 2025 expert survey places CRQC probability within 10 years at 28–49%, its highest range in the series to date.[1]

"We will migrate when we need to."

Historical cryptographic transitions have taken years, and PQC adds discovery, vendor, interoperability, hardware, protocol, and governance dependencies.[20] In DigiCert's 2026 outlook, 87% of organizations report planning, testing, or implementing PQC initiatives, while only 7% report deployed quantum-safe or hybrid cryptography.[14] The UK NCSC separately expects large organizations to need roughly 2–3 years for discovery, strategy, and an initial migration plan before broader execution.[30]

"Our data is not that sensitive."

HNDL means sensitivity should be assessed against the data's required future secrecy lifetime, not only its current classification. The Federal Reserve describes HNDL as a present strategic risk for long-lived sensitive information.[18] In the Thales 2026 Data Threat Report, 61% of respondents cited future decryption of existing data—HNDL—as their top quantum concern.[17]

"Blockchain is a niche concern."

Google's 2026 analysis classified approximately 6.9 million BTC across script types as vulnerable to future at-rest or reused-key attacks because relevant public keys were already exposed at the time of analysis.[12] Ethereum relies on quantum-vulnerable primitives across account signatures, consensus signatures, KZG commitments, and some proof systems; the Ethereum Foundation now has a dedicated post-quantum program and targets core L1 post-quantum infrastructure by approximately 2029.[13]

If your institution's internal estimate of P(Q Doom) is 10%, the question is: would you accept a 10% probability of systemic cryptographic compromise in any other risk domain?

The Migration Runway: Why the Decision Window Is Now

P(Q Doom) measures the probability of losing the race. The Migration Runway asks a different question: how long can an institution delay before there is no longer enough implementation time to reach its target state? A 2035 risk horizon can therefore create a decision window years earlier.

Last Safe Start Date = Target Completion Date − Expected Migration Duration − Implementation Buffer
The Last Safe Start Date is institution-specific. QDI does not assign one universal start date; it depends on the cryptographic estate, vendor dependencies, testing burden, and target milestone.
2026–2027

Decide + Discover

Establish ownership, inventory critical cryptographic dependencies, select priority control surfaces, and fund architecture/pilot work. This is a QDI planning inference, not a regulatory deadline.

2028

Know the Estate

UK NCSC target: complete discovery and assessment and create an initial migration plan, including supplier and infrastructure dependencies.[30]

2030–2031

Critical Milestones Mature

EU high-risk use cases: no later than end-2030.[11] U.S. federal HVAs/high-impact systems: PQ key establishment by end-2030 and signatures by end-2031.[24]

2035

Broad Completion Horizon

UK NCSC targets completion across systems, services, and products by 2035; U.S. transition guidance also points to broad deprecation of quantum-vulnerable public-key cryptography around this horizon.[30][10]

Q-Day may still be years away. Your last safe start date may not be.

Waiting for certainty about quantum capability is a poor decision rule when the remediation timeline is long. Every quarter of delay consumes implementation runway even if the estimated Q-Day itself does not move.

The Quantum Clock: When Will a CRQC Break Encryption?

The Quantum Clock tracks the composite distance to a CRQC across hardware scale, error correction maturity, and cryptanalytic algorithm efficiency. An improvement in any dimension moves Q-Day closer, including algorithmic advances that require no new hardware.

Expert CRQC Probability Estimates

HorizonEstimateSourceTrend
Within 10 years (~2035)28% to 49%GRI 2025[1]Highest in 7-year history
Within 15 years (~2040)51% to 70%GRI 2025[1]Rising

Quantum Hardware: State as of September 2026

No CRQC exists. Publicly demonstrated systems remain far from the fault-tolerant logical scale, circuit depth, sustained runtime, and end-to-end reliability required by published cryptanalytic workloads. Recent systems nevertheless show material progress in error correction and logical-qubit performance.

SystemQubitsMilestoneDate
Google Willow105 physicalBelow-threshold error correction; 0.143% logical error rate per cycle; logical qubit outlived physical constituents[2]Dec 2024
Quantinuum Helios98 physical48 fully error-corrected logical qubits at 2:1 encoding; 50 error-detected logical qubits also demonstrated[3]Nov 2025
Microsoft / Quantinuum H256 physical12 highly reliable logical qubits; GHZ circuit error 0.0011 vs. 0.024 for corresponding physical qubits[4]Sep 2024
IonQ Tempo development systemNot directly comparable#AQ 64 benchmark achieved; #AQ is a system-level algorithmic benchmark, not a count of error-corrected logical qubits[36]Sep 2025

Company roadmaps and demonstrated achievements are tracked separately throughout this model. Roadmap targets are planning indicators, not CRQC predictions.

A late-2020s planning signal, not a Q-Day forecast

In September 2026, IonQ published an end-to-end resource estimate of about 20,000 physical qubits and 26 days per attempt for attacking 256-bit elliptic-curve signatures. IonQ explicitly states that no machine capable of running the attack exists today, while noting that the estimate aligns with its public 2028 hardware roadmap.[31]

QDI treats this as a Grade C planning signal, not as proof that Bitcoin, Ethereum, or other ECC-secured systems will be breakable in 2028. Its relevance is the uncertainty it introduces into a migration program whose implementation timeline is measured in years.

AI as a Measured Quantum Accelerant

On Google's largest Sycamore experiments, AlphaQubit made 30% fewer decoding errors than correlated matching and 6% fewer than tensor-network methods.[22] Google also states that AlphaQubit is currently too slow for real-time decoding on fast superconducting processors. QDI therefore treats AI as an observed research accelerant in specific parts of the quantum stack—not as a universal multiplier on Q-Day.

Q-Day Moved Without Adding Qubits: The Collapsing Attack Requirement

The attacker is approaching from both directions. Quantum machines are improving. Simultaneously, the machine required to break deployed cryptography is becoming smaller.

RSA-2048: Modeled Physical Qubit Requirements Under Different Architectural Assumptions

~20M <1M <100K ~10K 2021 · Gidney & Ekera Surface code May 2025 · Gidney Surface code (~20x reduction) Feb 2026 · Pinnacle QLDPC codes (different arch.) Mar 2026 · Caltech Neutral-atom (different arch.)

These estimates use different hardware architectures, error-correction codes, and runtime assumptions. They are not a controlled longitudinal reduction from a single model. The first two (Gidney) use surface codes on superconducting architectures and represent a roughly 20-fold like-for-like improvement.[5] The Pinnacle[6] and Caltech/IQIM[23] estimates use fundamentally different architectures (QLDPC codes and reconfigurable neutral atoms) and have not completed full peer review. All four are included to illustrate the trajectory of modeled requirements across the research landscape.

ECC-256: A Lower-Resource Cryptanalytic Target

Recent secp256k1 resource estimates place attack circuits at either ≤1,200 logical qubits and ≤90 million Toffoli gates, or ≤1,450 logical qubits and ≤70 million Toffoli gates.[12] Google maps those circuits to fewer than 500,000 superconducting physical qubits executing in a few minutes under stated error-rate, connectivity, and clock assumptions. These are modeled resource estimates—not demonstrated attacks—and they should not be compared directly with RSA estimates built on different architectures, error-correction schemes, or runtime assumptions.

ResearchLogical qubitsPhysical qubits (modeled)Runtime
EUROCRYPT 2026[7]~1,193Varies by architectureNot disclosed
Google Quantum AI / PRX Quantum, 2026[12]≤1,200 or ≤1,450<500,000 (modeled superconducting)A few minutes

At the time of analysis, Google's 2026 study classified approximately 6.9 million BTC across script types as vulnerable to future at-rest or reused-key attacks because relevant public keys were already exposed.[12] Exposure is not the same as immediate exploitability: no CRQC capable of performing the attack exists today.

The Migration Clock: Post-Quantum Cryptography Readiness in Financial Systems

NIST finalized three PQC standards in August 2024 (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA), concluding an 8-year process.[8]

Global Regulatory Migration Deadlines

AuthorityKey deadlineScope
NSA CNSA 2.0 / CSfC[9]CSfC transition targets 2030 for registered solutions; NSS transition completes by 2035U.S. National Security Systems; program timelines vary by component
NIST IR 8547 Initial Public Draft[10]Draft transition: deprecate selected quantum-vulnerable algorithms after 2030; disallow by 2035Proposed U.S. federal / standards transition; not final guidance
EO 14412[24]High-value/high-impact key-establishment milestone by 2030; digital signatures by 2031U.S. federal systems; contractor requirements follow rulemaking
EU NIS Cooperation Group[11]Member States should start transitioning by end-2026; high-risk use cases no later than end-2030EU member states / high-risk use cases
UK NCSC[30]Discovery + initial plan by 2028; highest-priority migration by 2031; completion target 2035Large organisations / critical infrastructure
G7 Cyber Expert Group Non-prescriptive[25]Illustrative roadmap includes prioritising critical systems around 2030–32G7 financial sector planning reference, not regulatory requirement
Singapore MAS[35]Aim for financial institutions to achieve quantum resilience before end of the decadeSingapore financial institutions; supervisory expectations forthcoming
Institutional signal — U.S. Treasury, August 2026. Treasury launched a public-private Quantum-Readiness Task Force specifically to accelerate the U.S. financial sector's transition to quantum-safe technology in an orderly and operationally resilient manner.[34]

Enterprise Deployment: The Planning-Deployment Gap

Planning, testing, or implementing PQC[14]87%
Actively preparing / transitioning globally[15]38%
Quantum-safe or hybrid cryptography deployed[14]7%
No single person leading PQC migration[16]46%

Quantum Migration Is Not One Migration

Different cryptographic surfaces migrate at radically different speeds. Cloudflare reports that over 65% of human traffic to its network is already post-quantum encrypted, while post-quantum authentication remains a later-stage deployment problem.[26] Where comparable global penetration data do not exist, QDI uses qualitative maturity labels rather than pseudo-precise percentages.

SurfaceObservable statusEvidence / caveat
TLS key establishmentScalingCloudflare reports >65% of human traffic to its network is PQ-encrypted; this is provider-specific telemetry, not a global Internet share.[26]
Authentication / PKITransitioningPQ signature deployment and standards support are expanding, but comparable global production penetration is not yet measured. Cloudflare explicitly identifies authentication as unfinished work.[26]
HSM / custodyEmergingVendor and institutional projects exist, but there is no single comparable global deployment share. Inventory, hardware lifecycle, certification, and key-management dependencies matter.
Public blockchainsActive R&D / early deploymentEthereum has a structured PQ roadmap with core infrastructure targeted for approximately 2029; no major public L1 has completed a full end-to-end PQ transition.[13]
Legacy OT / IoTDependency-constrainedThe UK NCSC flags ICS protocols and long-lived roots of trust as migration challenges; upgradeability and supplier dependencies can dominate timing.[30]

These labels are evidence summaries, not measurements on a common numerical scale. QDI will replace qualitative labels with comparable deployment statistics only where defensible datasets exist.

The 2029 Convergence: Five Distinct Engineering Timelines Cluster Around One Planning Horizon

2029 is not a Q-Day prediction. Five organizations publicly target 2029 for distinct engineering milestones spanning defensive PQ migration, protocol-level quantum resistance, and fault-tolerant/scalable quantum-computing roadmaps. The clustering is noteworthy as a planning horizon, but it does not imply a shared threat forecast, common methodology, or predicted Q-Day.

Google[32]
2029
Cloudflare[26]
2029
Ethereum[13]
2029
IBM Starling[28]
2029
Microsoft[33]
2029

Navy/Green: PQ migration or defense target. Amber: Fault-tolerant quantum system target. These are planning targets, not CRQC predictions.

Migration Is Multi-Dimensional

DimensionWhat must changeCurrent state
McustodyKey management, HSMs, signingCoinbase building PQ-CoreKMS; most custodians pre-planning
MchainConsensus, transaction validation, state proofsEthereum targets Dec 2029[13]; Bitcoin BIP-360 proposed Feb 2026
MwalletUser-facing signatures, account abstractionEthereum EIP-8141 under consideration
MnetworkTLS, VPN, SSH, API encryption~65% of Cloudflare traffic PQ-encrypted[26]
MsettlementPayment systems, clearing, FMIBIS Project Leap Phase 2 demonstrated PQC in payments[29]

BIS Project Leap Phase 2 tested post-quantum signatures in an operational payment system while sending liquidity transfers, in a controlled experiment involving the BIS Innovation Hub Eurosystem Centre, Bank of Italy, Bank of France, Deutsche Bundesbank, Nexi-Colt, and Swift.[29] It demonstrates technical feasibility in a real payment-system setting; it does not demonstrate system-wide production migration.

Probability Decomposition, QVaR, and Quantum Migration Debt

Q3 2026 Driver Attribution

QDI v1.0 shows direction and relative contribution rather than exact percentage-point attribution. Exact marginal contributions will be published only with the reproducibility package; this avoids implying precision that the current structured calibration cannot yet independently reproduce.

ECC-256 resource reductions[7]↑ HIGH
Below-threshold QEC[2],[3]↑ HIGH
RSA-2048 resource reductions[6]↑ MEDIUM
AI-assisted error correction[22]↑ EMERGING
EO 14412 + EU roadmap + G7 actions[24],[11],[25]↓ HIGH
Ethereum PQ program[13]↓ MEDIUM
NIST FIPS availability[8]↓ MEDIUM
BIS Project Leap Phase 2[29]↓ EMERGING
QDI v1.0 calibrated estimate34%

Calibrated P(Q Doom) Estimates Across Horizons

HorizonEstimateIntervalInterpretation
P(Q Doom)203011%4 – 21%Low but non-negligible; HNDL exposure active
P(Q Doom)203534%22 – 48%Canonical benchmark
P(Q Doom)204052%38 – 67%More likely than not

Three Metrics, One Taxonomy

MetricQuestion
P(Q Doom)What is the probability we lose the migration race?
QVaRHow much economic value is secured by quantum-vulnerable cryptography?
Quantum Migration DebtHow much time/cost has accumulated because infrastructure cannot transition fast enough?

Conceptual decomposition: Quantum Systemic Risk ∝ P(Q Doom) × QVaR × Migration Friction. This is a risk taxonomy, not yet a standardized monetary formula.

Quantum Migration Debt: The Stock and the Flow

Migration debt has two components. Institutions inherit a stock of existing systems that depend on quantum-vulnerable cryptography, and they can create a continuing flow of new debt when long-lived systems are launched today with a known future classical-to-PQ retrofit requirement.

Reduce existing debt

Prioritize the highest-value authorization and control surfaces in existing wallets, custody, tokenization, settlement, identity, and signing workflows. The objective is staged risk reduction, not a one-time replacement of the entire estate.

Create no new quantum debt

For new long-lived infrastructure, design PQ-capable or PQ-native controls from inception where practical, so the protected layer does not begin life with an avoidable classical-to-PQ retrofit already embedded in its roadmap.

Reduce existing debt. Create no new quantum debt.

This is an operational principle, not a claim that every dependency becomes quantum-safe on day one. External networks, endpoints, identity systems, counterparties, and legacy integrations may still require migration.

Monitor

Lower P(Q Doom), lower QVaR

Protect

Lower P(Q Doom), higher QVaR

Accelerate

Higher P(Q Doom), lower QVaR

Systemic Priority

Higher P(Q Doom), higher QVaR

Vertical axis: P(Q Doom). Horizontal axis: QVaR.

Two Ways to Act Now — Without Replacing Everything

The existence of a multi-year migration problem does not mean an institution must execute an enterprise-wide cutover before it can reduce risk. The practical first step depends on whether the infrastructure already exists or is being built now.

Existing infrastructure

Protect What Exists

Preserve the current wallet, custodian, chain, tokenization platform, or settlement workflow and add PQ protection at the highest-value authorization and control surfaces where architecture permits.

  • Start with one critical asset-movement or authorization path.
  • Measure integration, latency, operational controls, reversibility, and auditability.
  • Expand protection incrementally instead of waiting for the entire ecosystem to migrate.
New infrastructure

Build What Comes Next PQ-Native

If a new tokenization, wallet, custody, or settlement system is expected to operate into the 2030s, avoid introducing a preventable future retrofit requirement across the protected control layer.

  • Design PQ authorization and crypto-agility into the architecture from inception.
  • Avoid creating new legacy cryptographic migration debt where PQ-native controls are practical.
  • Test the new path before production scale, while architectural choices are still flexible.
You do not need to solve the entire PQ migration today.
You need to stop making the problem larger and begin reducing the most consequential exposure. A scoped pilot can answer the immediate engineering question: can one critical path be protected now without waiting for every surrounding system to migrate?

Methodology, Data Availability, and What Comes Next

Model Architecture

QDI is defined as P(TQ < TM). In a fully specified implementation, this probability is computed by integrating the quantum-arrival distribution against the probability that migration remains incomplete at each point in time. QDI v1.0 uses a structured calibration across six factor families while the complete public parameterization and calculation package is being prepared:

FactorMeaningUpdates via
QHQuantum hardwareDemonstrated logical qubits, error rates
QACryptanalytic efficiencyPublished resource estimates
QECError correctionDemonstrated suppression factors
MAMigration adoptionDeployment surveys, protocol data
MSStandards maturityNIST standards, HSM/library support
GEGovernance coordinationRegulatory mandates, BIS/G7 actions

Source hierarchy: Grade A (peer-reviewed research and primary public-sector sources such as NIST, NSA, BIS); Grade B (preprints by established researchers); Grade C (company roadmaps and first-party engineering disclosures); Grade D (expert and enterprise surveys); Grade E (secondary media/analysis). No model input is based solely on Grade E. Where a primary or peer-reviewed source is available, it supersedes a secondary summary; company roadmaps are evidence of planning, not proof of achieved capability.

Calibration and Reproducibility Status

The 34% point estimate is calibrated against two principal evidence streams: a quantum-side distribution anchored to the GRI 2025 expert survey[1] and a migration-side distribution informed by deployment evidence including DigiCert's 2026 readiness data[14], Entrust/Ponemon's global preparation data[15], and historical migration-duration research.[20] The 90% calibrated uncertainty interval (22–48%) expresses parameter uncertainty across both sides of the race. It is not presented as a formal Bayesian posterior credible interval in v1.0.

Important: v1.0 should be read as a structured expert calibration informed by primary evidence, not yet as a fully independently reproducible statistical package. The next methodology release will publish the distributional assumptions, weighting functions, sensitivity analysis, source register, and machine-readable inputs required to reproduce the estimate. Until then, QDI reports qualitative driver attribution rather than exact marginal percentage-point contributions.

What Changes the Number Next

EventDirectionExpected sensitivity
Demonstrated fault-tolerant logical-qubit scale materially exceeds current recordsIncreasesHigh
New ECC/RSA resource estimate reduces requirements by an order of magnitudeIncreasesHigh
Major fault-tolerant hardware roadmap delay or demonstrated technical setbackDecreasesHigh
G-SIB or major custodian completes material PQ migration in productionDecreasesMedium
Major FMI deploys PQ-protected production authorization or settlement controlsDecreasesHigh

Quantitative percentage-point impact ranges will be added only after the reproducibility package fixes the update function and sensitivity rules.

From Risk Measurement to Action

The two action paths above are vendor-independent: protect existing critical control surfaces, and avoid creating new migration debt in new infrastructure. They reduce the migration side of P(Q Doom) without requiring an institution to wait for the entire ecosystem to transition at once.

EternaX Labs supports both paths. For existing infrastructure, EternaX provides post-quantum authorization and control layers designed to work with existing wallets, custody, tokenization, and settlement workflows. For new infrastructure, EternaX provides PQ-native, crypto-agile blockchain infrastructure designed so the protected control layer can use post-quantum authorization from inception.

The EternaX product suite uses NIST FIPS 205 (SLH-DSA / SPHINCS+) as its primary PQ signature primitive and supports cryptographic agility as standards evolve. Pluto is EternaX's PQ-native EVM-compatible public testnet.

Vendor disclosure. Descriptions of EternaX products in this section are company claims and are not inputs to QDI. The benchmark, action categories, and methodology are intended to remain independently challengeable regardless of vendor choice.

Start With One Critical Path

Existing infrastructure? Select one high-value wallet, custody, tokenization, authorization, or settlement workflow and test PQ protection without replacing the surrounding stack.

Building something new? Design one new deployment PQ-native from day one and avoid introducing a future classical-to-PQ retrofit across the protected control layer.

The objective is not a multi-year transformation on day one. It is a scoped technical proof that gives the institution evidence to act.

P(Q Doom) FAQs: Quantum Risk, Q-Day, Post-Quantum Migration, Bitcoin, Ethereum, and Institutional Action

Direct answers to the questions most likely to be asked by boards, CISOs, CTOs, risk teams, researchers, journalists, and AI systems. These answers use the same definitions, evidence hierarchy, and caveats as the main report; where a short FAQ conflicts with the detailed methodology, the methodology governs.

Benchmark, Definition, and Timeline

What is P(Q Doom)?

P(Q Doom) is the probability that cryptographically relevant quantum capability arrives before systemically important digital infrastructure completes its transition away from sole dependence on quantum-vulnerable public-key cryptography. The benchmark is written as P(TQ < TM), where TQ is the quantum-arrival clock and TM is the migration-completion clock.

What is the current P(Q Doom) estimate?

QDI v1.0 estimates P(Q Doom)2035 at 34%, with a 90% calibrated uncertainty interval of 22–48%. The estimate is a structured calibration informed by expert CRQC timelines, migration-adoption evidence, standards maturity, and observed engineering progress. The interval is not presented as a formal Bayesian posterior credible interval in v1.0, and 34% is not a claim that Q-Day is certain by 2035. [1] [14]

Does 34% mean there is a 34% chance that Q-Day happens by 2035?

No. P(Q Doom) is a race probability, not a standalone Q-Day forecast. It measures the probability that quantum cryptanalytic capability arrives before migration is sufficiently complete, so it depends on both the quantum timeline and the migration timeline.

What is Q-Day?

Q-Day is the point at which a quantum computer can practically defeat widely deployed public-key cryptography at a scale and cost relevant to real systems. Different systems can face different effective Q-Days because algorithms, key types, exposed public keys, implementation choices, and attack economics differ.

What is a cryptographically relevant quantum computer or CRQC?

A CRQC is a fault-tolerant quantum computer capable of running cryptanalytic algorithms, such as Shor's algorithm, at the scale needed to compromise widely deployed public-key cryptography. A large physical-qubit count alone does not make a machine cryptographically relevant; error correction, logical qubits, gate fidelity, runtime, and architecture matter.

Does a cryptographically relevant quantum computer exist today?

No. No publicly demonstrated quantum computer can currently execute the full fault-tolerant workloads required to break widely deployed RSA or elliptic-curve cryptography. Current research instead measures how hardware, error correction, logical-qubit performance, and attack-resource estimates are converging. [31]

Why is 2035 the canonical P(Q Doom) horizon?

2035 is long enough to capture material CRQC probability while still overlapping with major government and industry migration horizons. It also provides enough probability mass for the benchmark to measure the race between technology progress and migration progress rather than only near-term tail risk.

Why does 2030 matter if the canonical benchmark is 2035?

Because 2030 is becoming a major institutional migration milestone, not because QDI claims Q-Day occurs in 2030. U.S., EU, and UK transition roadmaps create material milestones around 2028–2031, while large institutions can require years for discovery, architecture, vendor coordination, testing, and deployment. [24] [11] [30]

What is the Migration Runway?

Migration Runway is the time remaining between today and the date by which an institution needs a target cryptographic state, after accounting for how long discovery, redesign, testing, procurement, vendor coordination, and deployment are likely to take. It converts a distant risk horizon into a present-day implementation question.

What is the Last Safe Start Date?

The Last Safe Start Date is the latest date at which a migration program can begin and still reach its target state with an appropriate implementation buffer. Conceptually: Last Safe Start Date = target completion date − expected migration duration − safety buffer.

Quantum Threat and Cryptographic Exposure

What is Quantum Migration Debt?

Quantum Migration Debt is the accumulated time, cost, dependency, and retrofit burden created when systems remain dependent on quantum-vulnerable cryptography while the migration window shrinks. It has both a stock and a flow: legacy systems represent existing debt, while new systems built today with avoidable future retrofit requirements create new debt.

Why should institutions start discovery and architecture work in 2026–2027?

Because planning is itself part of the migration. The UK NCSC says large organizations may need roughly 2–3 years for discovery, strategy, and an initial plan, while U.S. and EU frameworks place important migration milestones around 2030–2031. Delaying discovery consumes the same runway needed for implementation. [30] [24] [11]

What post-quantum migration milestones matter between 2028 and 2035?

The exact timeline varies by jurisdiction and system, but several major roadmaps cluster in this period. The UK NCSC targets discovery and an initial plan by 2028, highest-priority migration by 2031, and completion by 2035; U.S. Executive Order 14412 sets key-establishment and signature milestones around 2030–2031; the EU roadmap targets high-risk use cases by end-2030. [30] [24] [11]

What is Harvest Now, Decrypt Later or HNDL?

HNDL is the strategy of collecting encrypted data today and storing it until a future quantum computer can decrypt it. That means long-lived confidential data can be exposed before a CRQC exists, because the relevant deadline is the data's secrecy lifetime plus migration time, not only the date of a future quantum break. [18]

Which cryptographic systems are most exposed to quantum attacks?

Public-key systems based on integer factorization or discrete logarithms are the core concern, including RSA and widely used elliptic-curve systems. In digital assets, this includes signature and consensus components that rely on ECDSA, BLS, and related public-key assumptions; the exact risk depends on how and when public keys become exposed and what the protocol verifies. [7] [12] [13]

Are Bitcoin and Ethereum quantum-vulnerable?

Yes, important parts of both ecosystems rely on quantum-vulnerable public-key cryptography. Bitcoin uses secp256k1 signatures, while Ethereum currently relies on quantum-vulnerable cryptographic components across accounts, consensus, commitments, and proofs; both ecosystems are actively studying migration paths. [12] [13]

Does IonQ's 2028 roadmap mean Bitcoin will be broken in 2028?

No. IonQ's 2026 work is a modeled resource estimate, and its 2028 hardware target is a company roadmap; neither proves that a cryptographically relevant machine will exist in 2028. The planning signal is that a published ECC attack resource estimate and a commercial hardware roadmap have moved into a similar order of magnitude, which reduces the comfort of assuming late-2020s capability is irrelevant. [31]

Why does the 2029 convergence matter?

Several organizations publicly target 2029 for different engineering milestones, including defensive PQ migration, protocol-level quantum resistance, and fault-tolerant hardware roadmaps. This is not a shared Q-Day forecast; it is a useful planning signal that leading ecosystems are allocating engineering effort around a similar late-2020s horizon. [26] [13] [28]

Is AI accelerating quantum computing?

AI is already contributing to measurable parts of the quantum stack, including error decoding and research workflows. QDI therefore tracks demonstrated AI-enabled improvements through hardware, error-correction, and algorithm-efficiency evidence rather than applying an arbitrary 'AI acceleration' multiplier. [22]

Migration, Architecture, and Immediate Action

What post-quantum cryptography standards has NIST finalized?

NIST finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) in August 2024. These standards provide standardized post-quantum primitives for key establishment and digital signatures, giving institutions a concrete technical destination for migration. [8]

What is post-quantum cryptography or PQC?

Post-quantum cryptography is cryptography designed to remain secure against both classical and quantum adversaries while running on conventional computing hardware. It is different from quantum cryptography: PQC is deployed through software, protocols, hardware security modules, applications, and infrastructure that institutions already use. [8]

What is crypto-agility?

Crypto-agility is the ability to change cryptographic algorithms, keys, parameters, and policies without rebuilding an entire system. It matters because post-quantum standards and implementation preferences will continue to evolve, so institutions should avoid hard-wiring a single cryptographic assumption into long-lived infrastructure.

Do institutions need to replace their entire technology estate to start post-quantum migration?

No. Institutions can begin with the highest-value cryptographic control surfaces and migrate incrementally. A practical program can protect selected authorization, custody, wallet, tokenization, PKI, network, or settlement workflows while broader infrastructure transitions over time. [29]

Can existing wallets, custody, tokenization, or settlement workflows be protected before the whole ecosystem migrates?

In many architectures, yes. Post-quantum controls can be introduced at selected authorization or control layers before every underlying protocol, vendor, or base network becomes fully PQ-native; however, that does not make every dependency in the end-to-end system quantum-safe, so scope and residual classical dependencies must be explicit.

Does MPC or an HSM alone make ECDSA quantum-safe?

No. MPC and HSMs can improve how classical private keys are generated, stored, and used, but they do not change the quantum vulnerability of the underlying ECDSA signature scheme. If a system ultimately authorizes value using a quantum-vulnerable public-key primitive, the cryptographic assumption itself still needs a migration path. [12]

What does PQ-native mean?

PQ-native means post-quantum security is designed into the protected architecture from inception rather than added later as a retrofit. A PQ-native system should still be explicit about external dependencies—identity, networks, devices, counterparties, bridges, and other classical components—so 'PQ-native' is not the same as claiming every surrounding dependency is quantum-safe.

Why build new infrastructure PQ-native from day one?

Because a new long-lived system built today on avoidable quantum-vulnerable controls can create a known future retrofit requirement before the system reaches the end of its intended life. Designing the protected control layer PQ-native from inception can avoid substantial classical-to-PQ migration debt later.

What should an institution pilot first?

Start with one critical path where authorization matters and the boundary can be measured clearly: for example a wallet, custody workflow, tokenization control, asset-transfer authorization, or settlement instruction. The objective of the first pilot is not to replace everything; it is to prove integration, performance, policy, auditability, and operational control on a bounded workflow.

Should institutions wait for cloud, custody, chain, HSM, or core-platform vendors to finish migrating?

No. Vendor readiness can constrain execution, but institutions can begin cryptographic discovery, dependency mapping, architecture decisions, procurement requirements, crypto-agility work, testing, and bounded pilots before every supplier is ready. The UK NCSC explicitly tells organizations to identify supplier and physical-infrastructure dependencies and communicate migration needs to suppliers; waiting for the whole ecosystem can consume the same runway needed for implementation.[30]

Should new tokenization and digital-asset infrastructure be built PQ-native now?

Not as a universal mandate. But where an institution controls the architecture, expects the system to be long-lived, and can use standards-aligned implementations without unacceptable operational trade-offs, it should evaluate PQ-native or crypto-agile controls at inception. That can avoid creating a preventable classical-to-PQ retrofit across the protected control layer while preserving algorithm flexibility as standards evolve.[27]

What does “quantum-safe” mean in this report?

It is a scoped engineering claim, not a blanket guarantee. A component or control is quantum-safe only with respect to the cryptographic function, algorithm, implementation, and threat model being described. External dependencies—endpoints, identity systems, networks, HSMs, counterparties, bridges, legacy integrations, or other classical cryptography—may remain outside that protection. The report therefore prefers claims such as “PQ-protected authorization layer” over saying an entire institution or ecosystem is quantum-safe.

Governance, Reproducibility, and Institutional Use

Can P(Q Doom) rise or fall?

Yes. The index should rise when credible evidence moves quantum capability closer or migration completion further away, and fall when hardware progress slows, attack-resource estimates worsen, or real production migration accelerates. A useful benchmark must be capable of moving in both directions.

How is the 34% P(Q Doom) estimate calculated?

QDI is defined as P(TQ < TM). In a fully specified implementation, that is computed by integrating the quantum-arrival distribution against the probability that migration remains incomplete over time. QDI v1.0 is a structured calibration across six factor families; until the public parameterization, data, code, and sensitivity package is released, the 34% should not be treated as an independently reproducible closed-form statistic.

What is QVaR and how is it different from P(Q Doom)?

P(Q Doom) measures the probability of losing the migration race. QVaR, or Quantum Value-at-Risk, measures the economic value or flow exposed to quantum-vulnerable cryptographic control. The two answer different questions: probability versus exposure.

What is Quantum Systemic Risk in this framework?

The report uses Quantum Systemic Risk as a conceptual combination of probability, exposure, and migration friction: P(Q Doom) × QVaR × migration friction. It is a taxonomy for reasoning about systemic risk, not yet a single standardized monetary formula.

How often will the P(Q Doom) Index be updated?

QDI is designed as a quarterly benchmark. Each edition should publish the current estimate and interval, evidence that moved the index, methodology version, source register, change log, and—once available—version-frozen data and code so changes can be audited over time.

How can researchers reproduce or challenge P(Q Doom)?

The report is designed for external challenge, but full reproduction requires the planned methodology and data package: the TQ and TM distributions, source-to-variable mapping, weighting rules, correlation assumptions, sensitivity analysis, update rules, and calculation code. Until that package is published, the 34% should be treated as a transparent structured calibration rather than a fully reproducible public model.

Does EternaX benefit commercially from a higher P(Q Doom) score?

EternaX develops post-quantum infrastructure, so the report discloses an unavoidable commercial conflict of interest. The safeguard is methodological: commercial considerations are not model inputs, sources and assumptions are published, roadmap evidence is separated from demonstrated achievement, and the index must be capable of falling when evidence improves.

What does EternaX provide in relation to this framework?

EternaX supports two action paths defined independently in the report: protecting selected high-value control surfaces in existing infrastructure, and designing new protected infrastructure PQ-native from inception. The report's risk taxonomy is broader than any one vendor, and EternaX appears only after the vendor-independent action categories are established.

How should boards, CISOs, CTOs, and risk committees use P(Q Doom)?

Use it as a forcing function for an internal estimate and a migration-runway discussion, not as a prediction to outsource judgment to. The practical questions are: what cryptography protects our critical assets and data, how long would migration really take, what external dependencies control that timeline, and what is our last safe start date?

What is the single most important action institutions can take now?

Do not wait for certainty about Q-Day. Identify one critical cryptographic path, measure its migration runway and dependencies, and either begin reducing existing quantum migration debt or avoid creating new debt in the next system you build.

Decision rule: You do not need certainty about Q-Day to justify action. If migration takes years and uncertainty can move faster than implementation, the rational first step is to measure the runway, reduce the highest-value existing exposure, and avoid creating preventable new migration debt.

References

[1] Mosca, M.; Piani, M. "Quantum Threat Timeline Report 2025." Global Risk Institute / evolutionQ, 9 March 2026. globalriskinstitute.org

[2] Google Quantum AI. "Quantum error correction below the surface code threshold." Nature 638, 920-926 (2025). nature.com

[3] Quantinuum. "Introducing Helios: The Most Accurate Quantum Computer in the World" and Helios launch specifications. November 2025. quantinuum.com

[4] Microsoft / Quantinuum. "Microsoft and Quantinuum create 12 logical qubits and demonstrate a hybrid, end-to-end chemistry simulation." 10 September 2024. azure.microsoft.com

[5] Gidney, C. "How to factor 2048 bit RSA integers with less than a million noisy qubits." arXiv:2505.15917, 21 May 2025; compares against the earlier ~20M-qubit Gidney–Ekerå estimate under the same core hardware assumptions. arxiv.org

[6] "Pinnacle Architecture: On reducing the cost of breaking RSA-2048 to 100,000 physical qubits." February 2026. arxiv.org

[7] Chevignard, C.; Fouque, P.-A.; Schrottenloher, A. ECC resource-estimation work presented in the EUROCRYPT 2026 proceedings. Springer EUROCRYPT 2026 proceedings

[8] NIST. "Post-Quantum Cryptography FIPS Approved: FIPS 203, 204, 205." August 13, 2024. csrc.nist.gov

[9] U.S. National Security Agency. "CNSA 2.0 / CSfC Post-Quantum Cryptography Guidance." Updated guidance. nsa.gov

[10] NIST. "IR 8547: Transition to Post-Quantum Cryptography Standards." Initial Public Draft, November 2024. csrc.nist.gov

[11] EU NIS Cooperation Group / European Commission. "Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography." June 2025. digital-strategy.ec.europa.eu

[12] Babbush, R. et al. "Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations." PRX Quantum 7 (2026), 031001. research.google

[13] Ethereum Foundation. "Post-quantum cryptography on Ethereum." Strawmap, February 2026. ethereum.org

[14] DigiCert. "Quantum Readiness Outlook 2026" deployment findings, cited in DigiCert Quantum Central launch materials. 2026. digicert.com

[15] Entrust / Ponemon Institute. "2026 Global State of Post-Quantum and Cryptographic Security Trends." Survey of 4,149 IT and security practitioners; 38% reported their organizations were preparing for the post-quantum threat. entrust.com

[16] Axiad Research. "The PQC Confidence Gap." 2026 survey of 315 U.S. enterprise security and IT leaders; 46% reported no single named individual responsible for leading PQC migration. axiad.com

[17] Thales. "2026 Data Threat Report." 61% of respondents cited future decryption of existing data (HNDL) as their top quantum concern. thalesgroup.com

[18] Mascelli, J., Rodden, M. "Harvest Now Decrypt Later: Examining Post-Quantum Cryptography." Federal Reserve FEDS 2025-093, September 2025. federalreserve.gov

[19] Palo Alto Networks Unit 42. "2026 Global Incident Response Report." Fastest quartile of intrusions reached exfiltration in 72 minutes in 2025 versus 285 minutes in 2024. paloaltonetworks.com

[20] Campbell, R. "Enterprise Migration to Post-Quantum Cryptography: Timeline Analysis." Computers 15(1):9, 2026. doi.org

[21] Mosca, M. "Cybersecurity in an era with quantum computers." 2018. Mosca inequality formalizes HNDL exposure timing.

[22] Google DeepMind. "AlphaQubit: AI-based quantum error correction decoder." Nature, November 2024. blog.google

[23] Caltech/IQIM. "Shor's algorithm with as few as 10,000 reconfigurable atomic qubits." March 2026. arxiv.org

[24] Executive Order 14412. "Securing the Nation Against Advanced Cryptographic Attacks." White House, 22 June 2026. whitehouse.gov

[25] G7 Cyber Expert Group. "Statement on Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector." January 2026. The roadmap is explicitly non-prescriptive. gov.uk

[26] Cloudflare. "Cloudflare targets 2029 for full post-quantum security." 7 April 2026. blog.cloudflare.com

[27] NIST. "Considerations for Achieving Crypto Agility: Strategies and Practices," CSWP 39upd1, Final, updated 29 June 2026. csrc.nist.gov

[28] IBM. "Quantum Roadmap." IBM states Starling is targeted for 2029 with 200 qubits and 100 million gates; roadmap targets are goals and may change. ibm.com

[29] BIS Innovation Hub. "Project Leap phase 2: quantum-proofing payment systems." 11 December 2025. Tested PQC in an operational payment system while sending liquidity transfers. bis.org

[30] UK National Cyber Security Centre. "Timelines for migration to post-quantum cryptography." Targets: discovery and initial plan by 2028; highest-priority migration by 2031; completion by 2035. ncsc.gov.uk

[31] IonQ. "We Just Published the First Full-Stack Blueprint for Breaking 256-Bit Elliptic-Curve Signatures." 8 September 2026. Reports ~20,000 physical qubits and ~26 days per attempt; explicitly states no capable machine exists today. ionq.com

[32] Google Cloud. "PQC in Plaintext: Google Cloud’s post-quantum cryptography roadmap." 11 August 2026. Google Cloud targets full PQC readiness by 2029. cloud.google.com

[33] Microsoft Quantum. "Majorana 2 – Microsoft’s Scalable Quantum Processor With Reliable, Long-Lasting Qubits." Microsoft states a roadmap target for a scalable, practical quantum computer by 2029. quantum.microsoft.com

[34] U.S. Department of the Treasury. "Treasury Announces the Quantum-Readiness Task Force." 24 August 2026. home.treasury.gov

[35] Monetary Authority of Singapore, remarks by Managing Director Chia Der Jiun, MAS Annual Report 2025/2026 Media Conference. MAS states its aim for financial institutions to achieve quantum resilience before the end of the decade. Reproduced by BIS, 17 August 2026. bis.org

[36] IonQ. "IonQ Achieves Record Breaking Quantum Performance Milestone of #AQ 64." 25 September 2025. ionq.com

Citation: Paarrthhh Birla, Dariia Porechna, Dr. Chen Feng. The P(Q Doom) Framework: A Probabilistic Model of Cryptographic Migration Risk. EternaX Research, September 2026. QDI v1.0.

Contact: research@eternax.ai · Web: eternax.ai/quantum-doom-index.html
@EternaXlabs (X) · EternaX Labs (LinkedIn) · eternax-ai (GitHub)

© 2026 EternaX Labs. The P(Q Doom) Index methodology is published for transparency and external review.

Founding Team

10+ years at the intersection of blockchain infrastructure, institutional finance, and post-quantum cryptography

Paarrthhh Birla
Paarrthhh Birla
Co-Founder
Ex-Polygon (VP Growth Office); Head of Partnerships, Subspace Protocol; Digital assets strategy at EYP, Advised Visa and State Street; MBA, CPA.
Dariia Porechna
Dariia Porechna
Co-Founder
Cryptographer and distributed systems architect; Head of Protocol, Subspace; Research Engineer, Wolfram|Alpha. Co-author, SILMARILS.
Dr. Chen Feng
Dr. Chen Feng
Chief Scientist
Assoc. Prof. at University of British Columbia; PhD (Toronto); 100+ peer-reviewed papers; Quantum communications, blockchain, TEE privacy. Co-author, SILMARILS.