Skip to content
Calcrivo

Quantum Threat Readiness Calculator

Apply Mosca's inequality to post-quantum risk: secrecy lifetime, migration time and years to a quantum-capable adversary.

Inputs

years
years
years

Expert estimates cluster around 10–20 years

%
%
%
%

Mosca's Inequality Verdict

Act now — data encrypted today will still be sensitive when it can be broken

Exposure Gap (x + y − z)

10.0years

Latest Safe Start

0.0years from now

Migration Readiness

27.0/ 100

Effective Symmetric Strength Against Grover

128bits

Harvest-Now-Decrypt-Later Exposure

85.0%

Next Step

Build the cryptographic inventory — you cannot migrate algorithms you cannot find

Step by step

  1. Values used

    Years the data must stay secret (x) = 15 years; Years to complete migration (y) = 7 years; Years until a cryptographically relevant quantum computer (z) = 12 years; Traffic and data still protected by RSA or ECC = 85 %; Symmetric key length in use = AES-256; Cryptographic inventory completeness = 40 %; Ability to swap algorithms without redesign = 30 %; Systems piloting post-quantum or hybrid key exchange = 5 %

  2. Quantum Threat Readiness

    Mosca's inequality: act now if x + y > z, where x is the years data must stay secret, y the years the migration takes and z the years until a cryptographically relevant quantum computer.

  3. Grover and Shor

    Grover's algorithm halves effective symmetric strength (AES-256 → 128 bits), while Shor's algorithm breaks RSA and ECC outright, so asymmetric algorithms must be replaced rather than lengthened.

  4. Mosca's Inequality Verdict

    = Act now — data encrypted today will still be sensitive when it can be broken

  5. Exposure Gap (x + y − z)

    = 10.0 years

  6. Latest Safe Start

    = 0.0 years from now

  7. Migration Readiness

    = 27.0 / 100

  8. Effective Symmetric Strength Against Grover

    = 128 bits

  9. Harvest-Now-Decrypt-Later Exposure

    = 85.0

How it works

Mosca's inequality is the only planning tool that matters here: if the secrecy lifetime plus the migration duration exceeds the time until a capable quantum computer, then data you encrypt today is already exposed, because an adversary can record it now and decrypt it later. Grover only halves symmetric strength, so AES-256 remains sound; Shor breaks RSA and ECC completely, which is why every asymmetric use must be inventoried and replaced. Harvest-now-decrypt-later means the deadline is not when quantum computers arrive — it is now, for anything that must stay secret for a decade.

Formulas

Quantum Threat Readiness

Mosca's inequality: act now if x + y > z, where x is the years data must stay secret, y the years the migration takes and z the years until a cryptographically relevant quantum computer.

x
Required secrecy lifetime of the data
y
Time to complete the migration
z
Time until the threat is real
x + y − z
Years of exposure — positive means you are already late

Grover and Shor

Grover's algorithm halves effective symmetric strength (AES-256 → 128 bits), while Shor's algorithm breaks RSA and ECC outright, so asymmetric algorithms must be replaced rather than lengthened.

Grover
Quadratic speed-up against symmetric search
Shor
Polynomial-time factoring and discrete logarithms

Frequently Asked Questions

How is Quantum Threat Readiness calculated?

Mosca's inequality: act now if x + y > z, where x is the years data must stay secret, y the years the migration takes and z the years until a cryptographically relevant quantum computer. Mosca's inequality is the only planning tool that matters here: if the secrecy lifetime plus the migration duration exceeds the time until a capable quantum computer, then data you encrypt today is already exposed, because an adversary can record it now and decrypt it later. Grover only halves symmetric strength, so AES-256 remains sound; Shor breaks RSA and ECC completely, which is why every asymmetric use must be inventoried and replaced.

Why does Quantum Threat Readiness matter?

Harvest-now-decrypt-later means the deadline is not when quantum computers arrive — it is now, for anything that must stay secret for a decade.

What values do I need to enter?

This calculator takes 8 inputs: Years the data must stay secret (x), Years to complete migration (y), Years until a cryptographically relevant quantum computer (z), Traffic and data still protected by RSA or ECC, Symmetric key length in use, Cryptographic inventory completeness, Ability to swap algorithms without redesign, Systems piloting post-quantum or hybrid key exchange. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Why does crypto-agility carry as much weight as the inventory?

Because most of the migration cost is architectural. Systems with hard-coded algorithms, fixed-size key fields or certificate assumptions have to be redesigned, and that is what makes y large enough to fail the inequality.

Is AES-256 enough after quantum?

Yes, for confidentiality. Grover reduces it to roughly 128 bits of effective strength, which remains infeasible. The urgent work is key exchange and signatures — RSA and ECC — not bulk encryption.

You might also need