# Q-Day is approaching. Most organizations aren’t ready

> Source: <https://siliconangle.com/2026/09/13/q-day-is-approaching-most-organizations-arent-ready/>
> Published: 2026-09-13 16:49:54+00:00

### Q-Day is approaching. Most organizations aren’t ready

“[Q-Day](https://www.harrisburgu.edu/events/q-day-what-it-means-and-why-we-need-to-prepare-now/),” the point at which quantum computers begin to break the encryption protecting most of the internet, lives in the same mental category as other far-off technology risks: real eventually, but not something requiring immediate action. That assumption is no longer safe.

In March, Google LLC [set 2029 as its own migration deadline](https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/) for post-quantum cryptography. This demonstrates how an organization with a genuine view into how quickly quantum hardware is advancing, and it’s years ahead of the National Security Agency’s 2031 target and the National Institute of Standards and Technology’s 2035 guideline for national security systems. Google said it accelerated its timeframe because of faster-than-expected progress in quantum hardware and error correction that has lowered the number of qubits needed to threaten current encryption.

The same month, a research team spanning the California Institute of Technology, the University of California at Berkeley, and quantum startup Oratomic Inc. [published a paper](https://www.caltech.edu/about/news/caltech-team-finds-useful-quantum-computers-could-be-built-with-as-few-as-10000-qubits) showing that a fault-tolerant quantum computer capable of running Shor’s algorithm, which breaks RSA and elliptic-curve encryption, may require as few as 10,000 to 26,000 qubits. That’s roughly two orders of magnitude below the millions once assumed necessary. Two independent lines of research thus concluded that the hardware bar is lower than the industry is planning for, and the timeline is compressing aggressively.

### Everywhere all at once

This isn’t a breach story where one company gets hit, and others watch from a safe distance. Public-key cryptography underpins everything: the Transport Layer Security handshake that secures web sessions, the digital signatures that authenticate software updates, the key exchanges banks use to move money, the certificates that let one server trust another. When these layers break, they break for everyone simultaneously because they’re all standing on the same mathematical foundation.

The closest historical parallel is the Year 2000 problem, but Y2K was a known, dated failure point, and it triggered roughly two years of coordinated, well-funded, all-hands remediation across the industry. Q-Day is shaping up to be a comparable failure with a similar or shorter runway, and it is getting a small fraction of the attention.

Furthermore, the “harvest now, decrypt later” strategy many adversaries are pursuing means the damage won’t wait for Q-Day. They can capture encrypted data today and hold onto it until decryption becomes possible. Some of what organizations consider secure right now is already compromised; they just don’t know it yet.

### Piecemeal patching won’t work

The instinctive response is to treat this like any other vulnerability: Inventory the systems, patch them and move on. But that approach breaks down at large scale. Modern organizations don’t run a handful of applications with clean ownership; instead, they run thousands of services, many built on third-party code that they can’t independently re-architect. Dependency chains run deep, and the whole chain is only as strong as its weakest cryptographic link.

Changing the landscape application by application before 2029 is not a realistic plan. There are too many control points, too many owners and too little visibility into where encryption actually lives.

The more immediate fix is to move to post-quantum readiness at the network layer itself, where a small number of control points can be upgraded instead of thousands of applications. A handful of infrastructure updates, rolled out once across the fabric that carries traffic between systems, can cover ground that would otherwise require perfect coordination across dozens of teams and vendors. That’s the difference between a migration that can realistically finish by 2029 and one that’s still in progress when the deadline arrives.

The network fabric that carries and secures traffic between applications can be updated once with new cryptographic standards and rolled out across the environment. Fewer control points means a faster rollout and far less dependence on dozens of teams executing correctly on deadline. It shifts post-quantum migration from an unmanageable, distributed project into a centralized one.

### Work is underway — slowly

My conversations with carriers, enterprises and governments indicate that quantum-readiness assessments are already happening. What they’re finding largely confirms that app-by-app progress is slow.

Independent research confirms this. DigiCert Inc.’s 2026 [Quantum Readiness Outlook](https://www.digicert.com/news/quantum-security-deployment-remains-stuck) found that 87% of organizations are planning, testing or implementing post-quantum initiatives, yet only 7% have deployed quantum-safe or hybrid cryptography across a meaningful share of their digital certificates.

Axiad IDS Inc. [found](https://www.axiad.ai/newsroom/axiad-research-finds-enterprises-more-confident-than-ready-for-post-quantum-cryptography) that 51% of enterprise security leaders have never formally tested their public-facing infrastructure for post-quantum key exchange, and nearly half lack a named leader responsible for the migration. A Ponemon Institute LLC [study](https://www.entrust.com/de/company/newsroom/entrust-global-report-finds-cryptographic-visibility-stagnant-as-quantum-threat-nears), sponsored by Entrust Corp., found that only 38% of organizations globally report actively transitioning to post-quantum cryptography.

Awareness is high, but execution is stalled, largely because organizations are trying to solve this problem at the wrong layer.

### What to do now

Most organizations aren’t acting with enough urgency. The practical starting point isn’t to wait for a regulatory mandate or a fully patched application stack, but to start an assessment at the infrastructure level now. That means understanding where encryption lives across the network, which systems can be upgraded centrally and which control points would give the fastest, broadest coverage if updated first.

Google didn’t set a 2029 deadline lightly, and additional research suggests that the timeline could move even earlier as quantum technology continues to improve faster than expected. Organizations that start building infrastructure-level crypto-agility today will be the ones still standing when that date arrives.

*Shaikh is chief executive of network-as-a-service company Graphiant Inc. He wrote this article for SiliconANGLE.*

##### Photo: [Unsplash](https://unsplash.com/photos/geometric-shape-digital-wallpaper-oyXis2kALVg)

# A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. **Join theCUBE’s Alumni Trust Network**, where technology leaders connect, share intelligence and create opportunities.

- **15M+ viewers of theCUBE videos** , powering conversations across AI, cloud, cybersecurity and more
- **11.4k+ theCUBE alumni** — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network

### Are you an AWS customer?  Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: [https://siliconangle.com/aws-marketplace/](https://siliconangle.com/aws-marketplace/)

##### **About SiliconANGLE Media**

[SiliconANGLE](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fsiliconangle.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=SiliconANGLE&index=9&md5=646b1b564e2259100a2b8638aab0a552),

[theCUBE Network](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecube.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Network&index=10&md5=7de2a85f95ab4a4a495cede20b8cb1da),

[theCUBE Research](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fthecuberesearch.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Research&index=11&md5=7bb33676722925eb57d588ec343e4f6f),

[CUBE365](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.cube365.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=CUBE365&index=12&md5=d310fb35919714e66ad8d42c9c0c1bc6),

[theCUBE AI](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecubeai.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+AI&index=13&md5=b8b98472f8071b23ebb10ab9a8dd0683)and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.
