What Is Quantum Computing and How Will It Affect Encryption?

Cybersecurity October 05, 2026
What Is Quantum Computing and How Will It Affect Encryption?

Quantum computing has moved from physics papers to engineering roadmaps. It is not a faster laptop. It is a different way of processing information, one that uses the counterintuitive rules of quantum mechanics. For most everyday tasks, a quantum computer would be no better than the device in your pocket. For a few specific problems, however, it could be dramatically better — and one of those problems sits underneath almost every secure connection we rely on.

What a quantum computer actually does

Classical computers store data as bits. Each bit is either 0 or 1. Quantum computers use qubits. A qubit can be in a superposition: a weighted combination of 0 and 1 at the same time. When multiple qubits are entangled, their states become linked, so measuring one tells you something about the others.

This does not mean a quantum computer tries every answer at once. That is a common shorthand, and it is misleading. Quantum algorithms are carefully designed to amplify the probability of correct answers and cancel out wrong ones. The result is a machine that can tackle certain mathematical structures — factoring, discrete logarithms, simulating molecules — far more efficiently than any classical computer.

Building one is hard. Qubits are fragile. They lose their quantum state through noise and interference, a process called decoherence. Today's machines are noisy and small. Useful, fault-tolerant quantum computers are still an engineering challenge, but progress is steady.

Why encryption is worried

Modern encryption comes in two main flavours. Symmetric encryption, such as AES, uses the same key to lock and unlock data. Asymmetric encryption, such as RSA and elliptic-curve cryptography (ECC), uses a public key to encrypt and a private key to decrypt. Asymmetric cryptography also underpins digital signatures and key exchanges in TLS, the protocol that secures websites.

RSA and ECC rely on mathematical problems that are easy to set up but very hard to reverse. RSA depends on the difficulty of factoring large numbers. ECC depends on the discrete logarithm problem over elliptic curves. A classical computer would need an impractical amount of time to solve these problems for well-chosen keys.

A large, fault-tolerant quantum computer running Shor's algorithm could solve them. That is the core risk. It would not break every cipher, but it would break the public-key cryptography that protects most internet traffic, software updates, banking sessions, and encrypted messages.

Symmetric keys, hashes and the Grover effect

Symmetric encryption is less exposed. Grover's algorithm gives a quadratic speed-up for searching unstructured data. In practice, that means a 128-bit symmetric key could offer roughly the security of a 64-bit key against a quantum attack. A 256-bit key would still be strong. This is why security experts generally recommend moving to AES-256 where feasible, and why hash functions with longer outputs remain useful.

But the big problem is asymmetric cryptography. It is used everywhere, often invisibly. Every time you see a padlock in a browser, a key exchange is happening. Every time a software update is signed, a digital signature is checked. Replace RSA and ECC, and you need to replace a lot of plumbing.

Harvest now, decrypt later

You might think this is a problem for the 2030s or beyond. For some data, that is true. For other data, the clock is already running.

An attacker can record encrypted traffic today and store it. If that data still matters in ten or fifteen years — medical records, financial details, state secrets, long-lived intellectual property — then a future quantum computer could decrypt it. This is known as "harvest now, decrypt later". It turns a future threat into a present-day risk.

If a secret needs to stay secret for longer than it takes to build a cryptographically relevant quantum computer, the migration to post-quantum cryptography has already started.

Post-quantum cryptography: the replacement

Post-quantum cryptography (PQC) is the name for algorithms designed to run on classical computers but resist attacks from both classical and quantum machines. They are not quantum algorithms. They are ordinary software that uses different mathematical hard problems.

The main families include:

  • Lattice-based: based on the difficulty of finding shortest vectors in high-dimensional lattices. Used for key encapsulation and signatures.
  • Hash-based: builds signatures from secure hash functions. Conservative and well understood, but with larger keys and signatures.
  • Code-based: relies on error-correcting codes. Long-established, with large key sizes.
  • Multivariate: uses systems of multivariate polynomial equations. Smaller signatures, but a more recent area of scrutiny.

Standards bodies have been running a multi-year selection process. The US National Institute of Standards and Technology (NIST) published its first post-quantum standards in 2024, covering key encapsulation and digital signatures. More standards are expected. The UK's National Cyber Security Centre (NCSC) has advised organisations to plan their migration by 2028 and complete it by 2035.

That timeline is not about a known quantum break date. It is about the time needed to inventory cryptography, test new algorithms, update protocols, and replace hardware and software that may not be upgradeable. Migration is slow. Starting early is cheaper than panicking later.

What to do now

For individuals, there is no button to switch to post-quantum encryption. Your browser and messaging apps will adopt it as vendors update their software. Keep your devices and apps up to date. Use strong, unique passwords and a password manager. Turn on multi-factor authentication. Prefer services that publish clear security information and update promptly. These habits protect you against today's threats, which remain far more likely than a quantum attack.

For organisations, the work is more structured. A practical first pass looks like this:

  1. Inventory cryptography. Find where RSA, ECC, and other public-key algorithms are used — in TLS, VPNs, code signing, email, databases, IoT devices, and third-party services.
  2. Classify data lifetimes. Identify what must stay confidential for five, ten, or twenty years. That tells you where "harvest now, decrypt later" matters most.
  3. Talk to vendors. Ask when they will support post-quantum key exchange and signatures. Put it in contracts and renewal discussions.
  4. Test hybrid modes. Many implementations combine classical and post-quantum algorithms during transition. This gives protection if one algorithm is later broken.
  5. Plan for crypto-agility. Design systems so algorithms can be swapped without rewriting everything. Avoid hard-coded cryptography.
  6. Follow national guidance. Bodies such as the NCSC and NIST publish detailed migration advice. Use it rather than inventing your own timeline.

Quantum computing will not arrive as a single switch. It will creep in through research milestones, cloud access, and specialised hardware. Encryption will not disappear; it will be upgraded. The organisations that treat that upgrade as a long-term maintenance project, rather than a last-minute emergency, will be the ones that keep their data safe.

Photo: Ludovic Delot / Pexels