Map
โ†‘Post-Quantum Cryptography

Cryptographically Relevant Quantum Computer (CRQC)

Wiki conceptcryptographyquantum-computing โ†ณ show in map Markdown
title
Cryptographically Relevant Quantum Computer (CRQC)
type
concept
summary
Cryptographically relevant quantum computer: what it is, threshold, April 2026 timeline collapse
tags
cryptography, quantum-computing
created
2026-04-07
updated
2026-04-10

A quantum computer powerful enough to break real-world public-key cryptography โ€” specifically, to run Shor's algorithm against RSA and elliptic curve keys at the sizes used in production systems (2048-bit RSA, 256-bit ECC).

The term distinguishes between quantum computers that exist today (which can't break production cryptography) and the threshold machine that would. Current quantum computers have hundreds to low thousands of noisy physical qubits. Breaking production cryptography requires either millions of noisy physical qubits with extensive error correction, or โ€” per recent 2026 research โ€” potentially as few as 10,000 physical qubits with better architectures (neutral atoms with non-local connectivity).

Timeline as of April 2026

Two papers published in April 2026 collapsed estimates:

  • Google: revised downward the logical qubits needed to break P-256/secp256k1, making minute-scale attacks feasible on superconducting architectures
  • Oratomic: showed 10,000 physical qubits sufficient on neutral atom platforms

Google's cryptography team set 2029 as the migration deadline. Filippo Valsorda calls this a "1939โ€“1940 moment" โ€” public research may be lagging classified work. See crqc-timeline for the full analysis.

Separately, ETH Zurich demonstrated (Nature, April 8, 2026) neutral-atom swap gates using geometric phases at 99.91% fidelity across 17,000 qubit pairs simultaneously. This crosses the surface-code error correction threshold (~99%) and shows massive parallelism on the neutral-atom platform Oratomic's paper depends on. Swap gates alone don't threaten cryptography, but the fidelity and scale are prerequisites for the neutral-atom CRQC path.

Why the threshold matters

Below the CRQC threshold, quantum computers are scientifically interesting but don't threaten deployed cryptography. Above it, every RSA key, ECDSA signature, and ECDH key exchange in existence becomes breakable. There's no gradual degradation โ€” classical public-key cryptography either holds or it doesn't.

The store-now-decrypt-later threat means the practical impact starts before CRQCs exist: adversaries can archive encrypted traffic now and decrypt it once they have a CRQC.