Apply Mosca's inequality to post-quantum risk: secrecy lifetime, migration time and years to a quantum-capable adversary.
Mosca's inequality is the only planning tool that matters here: if the secrecy lifetime plus the migration duration exceeds the time until a capable quantum computer, then data you encrypt today is already exposed, because an adversary can record it now and decrypt it later. Grover only halves symmetric strength, so AES-256 remains sound; Shor breaks RSA and ECC completely, which is why every asymmetric use must be inventoried and replaced. Harvest-now-decrypt-later means the deadline is not when quantum computers arrive — it is now, for anything that must stay secret for a decade.
Quantum Threat Readiness
Mosca's inequality: act now if x + y > z, where x is the years data must stay secret, y the years the migration takes and z the years until a cryptographically relevant quantum computer.
Grover and Shor
Grover's algorithm halves effective symmetric strength (AES-256 → 128 bits), while Shor's algorithm breaks RSA and ECC outright, so asymmetric algorithms must be replaced rather than lengthened.
Mosca's inequality: act now if x + y > z, where x is the years data must stay secret, y the years the migration takes and z the years until a cryptographically relevant quantum computer. Mosca's inequality is the only planning tool that matters here: if the secrecy lifetime plus the migration duration exceeds the time until a capable quantum computer, then data you encrypt today is already exposed, because an adversary can record it now and decrypt it later. Grover only halves symmetric strength, so AES-256 remains sound; Shor breaks RSA and ECC completely, which is why every asymmetric use must be inventoried and replaced.
Harvest-now-decrypt-later means the deadline is not when quantum computers arrive — it is now, for anything that must stay secret for a decade.
This calculator takes 8 inputs: Years the data must stay secret (x), Years to complete migration (y), Years until a cryptographically relevant quantum computer (z), Traffic and data still protected by RSA or ECC, Symmetric key length in use, Cryptographic inventory completeness, Ability to swap algorithms without redesign, Systems piloting post-quantum or hybrid key exchange. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Because most of the migration cost is architectural. Systems with hard-coded algorithms, fixed-size key fields or certificate assumptions have to be redesigned, and that is what makes y large enough to fail the inequality.
Yes, for confidentiality. Grover reduces it to roughly 128 bits of effective strength, which remains infeasible. The urgent work is key exchange and signatures — RSA and ECC — not bulk encryption.