Accelerating quantum deadlines have pushed global organisations to ready their systems by the turn of the decade, but as experts warn a quantum computer could soon cause internet-wide cryptography failures, is 2030 too late?
Defenders have spent the last several years quietly preparing for Q-Day: the theoretical date when quantum computing becomes capable of breaking modern encryption standards and decrypting sensitive data with ease.
With such an event threatening to upheave commonplace protections on bank transfers, private communications and broader critical systems, the US administration recently accelerated its deadlines for resilient, post-quantum encryption (PQC) across high-priority federal systems to December 2030.
Although estimates for Q-Day range from the 2030s to as far as the 2050s, private sector entities have narrowed their deadlines even further.
After observing significant “progress on quantum computing hardware development”, tech giant Google quickened its own PQC migration deadlines to 2029.
Apple has already bolstered iMessage with quantum-resistant encryption, while networking giant Cloudflare – which services roughly a fifth of all websites on the internet – mirrored Google’s 2029 deadline after calling out “rapid industry developments”.
Sharon Goldberg, Cloudflare’s senior director of product management, said there was a “non-negligible probability” we’ll soon have a quantum computer that can “break the public-key cryptography that is used all over the internet”.
“That’s an incredible failure mode,” Goldberg told Information Age.
“We’re used to vulnerabilities in a single product or a single system.
“But with this failure mode, all cryptography all over the internet fails at the same time.”
Goldberg added that even if it's unlikely a powerful-enough quantum computer exists before 2030, the damage it could cause is so great that “we need to take action now”.
It’s a ‘now’ problem
Goldberg told Information Age it was essential to consider the threat of “harvest now, decrypt later” attacks, where adversaries harvest encrypted traffic and data to later decrypt it once a powerful quantum computer arrives.
The threat vector is not just theoretical – cybercriminals explicitly sell and purchase stolen encrypted data based on the hope that its value explodes once quantum decryption becomes available.

Quantum computers could soon unlock all the cryptography on the internet. Photo: Shutterstock
“Any organisations with long-lived IP, defence, financial services, healthcare, and government should worry the most, because their data has a long shelf life,” said Goldberg.
Nalin Arachchilage, associate professor in cybersecurity at RMIT University, said this dynamic leads many organisations to mistakenly treat quantum computing as a “future problem”.
“Q-day is not far away from now,” said Arachchilage, echoing Goldberg’s sentiments.
“Data being intercepted and stored today can sit quietly for years and still be broken open the moment sufficiently powerful quantum computers arrive.
“It's a present problem, with a future trigger.”
Goldberg added there is an “even more significant threat of unauthorised access” to consider.
“All the technology we use to control access to sensitive digital systems is based on cryptography,” said Goldberg.
“If cryptography breaks, all these sensitive systems are no longer protected and are open to attackers.”
How is Australia’s government tracking?
Information Age understands the Australian public sector is still in a planning phase.
A Home Affairs spokesperson explained the latest annual Protective Security Policy Framework (PSPF) release mandates that entities “develop, implement and maintain” a PQC transition plan by July 2027.
Instead of explicitly mandating a timeframe for full PQC migration, the PSPF points to the Australian Signals Directorate’s (ASD) guidance for a 2030 implementation.
“ASD recommends organisations complete their transition to ASD-approved post-quantum cryptography by the end of 2030,” an ASD spokesperson told Information Age.
“A [cryptographically relevant] quantum computer does not currently exist, and the timeframe for its development remains uncertain.
“Organisations should act now because transitioning complex systems may take several years.”
It’s likely you’re behind
Arachchilage said those who haven’t already started laying out their cryptographic inventory are “behind schedule”.
"2030 was never meant to be treated as a start date – it's a deadline for having finished,” he said.
“We're seeing global peers moving their own internal deadlines earlier, and Google has publicly set 2029 – a full year ahead of where Australia's recommended cut-off sits.
“When the organisations building quantum computers are telling you to move faster than the regulator requires, that's a signal worth taking seriously.”
He added that large legacy systems, such as those common across government, take years to re-architect, and public entities should be treating 2030 as “their absolute latest date” accordingly.
The challenges ahead
Goldberg meanwhile supported a 2030 finish-line for most organisations because the global transition to PQC has “many dependencies” that will fall in place over the next couple of years.
“Standards need to be developed, vendors need to support these standards and solutions need to be tested and deployed by individual organisations,” she said.
She added that public entities need to “identify the critical systems that need to be upgraded”, rather than getting stuck cataloging each use of cryptography across their ecosystem.
“For each key system, figure out how you’ll either upgrade them, or put in compensating controls that will protect the system even if the system itself hasn’t been upgraded.”

Experts warn transitioning complex systems could take "several years". Photo: Shutterstock
During some early experiments in 2019, Cloudflare noticed older network equipment – such as firewalls and load balancers – was often “confused” by post-quantum encryption.
“When one of these devices sees something it doesn’t expect, it can drop or block the connection entirely,” Goldberg said.
Cloudflare said although the issue is now largely obsolete, it could resurface as different kinds of PQC are introduced across the internet.
“This is why gradual rollouts matter. Trying to flip a switch on the whole Internet at once is not the best idea.”
Sloppy AI coding among key bottlenecks
Arachchilage said his research with RMIT and industry collaborators had addressed three significant bottlenecks.
One such research initiative found quantum-safe cryptography needs to be usable enough that developers can adopt it correctly.
Another determined that organisations need realistic, staged roadmaps rather than a single, hard cut-off date.
The third finding identified an issue dubbed “secure coding drift”, and essentially offered a gamified training solution for developers and engineers to ensure the rapid uptake of AI-assisted coding doesn’t “reintroduce the very vulnerabilities PQC is meant to close.”
“Will the sector meet 2030?” asked Nalin.
“It's achievable, but only if organisations stop treating this as an IT upgrade and start treating it as a multi-year, board-level risk-management program.
“Just as we invest in skills and infrastructure for energy or transport security, Australia needs to invest in growing its quantum-safe workforce and capacity now, so that when the quantum era arrives, we're not scrambling to catch up but standing ready to lead.”