Experts expect that a Cryptographically Relevant Quantum Computer (CRQC)—a quantum computer capable of breaking currently used public-key algorithms such as RSA or elliptic-curve cryptography (EC)—could become available sometime in the 2030s.
The continuously updated study by the German Federal Office for Information Security (BSI) on the state of quantum computing development names 2040 as a realistic date for this event.
In 2025, the EU’s NIS Cooperation Group published a PQC roadmap titled “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography.” It identifies 2030 and 2035 as key milestones for completing the migration of high-risk applications first, followed by medium- and low-risk applications, in line with the expected timeline for a CRQC. EU member states are expected to publish national PQC roadmaps by 2026 aligned with the EU roadmap.
A particularly concrete and immediate threat is the “Store Now, Decrypt Later” (SNDL) problem. Data encrypted today with RSA or EC could be recorded now and decrypted in the future using a quantum computer.
Furthermore, the transition of digital signatures and public-key infrastructures (PKIs) cannot be delayed. The reason lies in the long validity periods of root certificates and the long migration timelines for PKIs due to the complexity and diversity of the applications involved.
Similar timelines for PQC adoption are emerging in other parts of the world. In the United States, for example, the Commercial National Security Algorithm Suite 2.0 requires a complete and exclusive transition to PQC by 2033.