Quantum Threat Readiness Calculator
Apply Mosca's inequality to post-quantum risk: secrecy lifetime, migration time and years to a quantum-capable adversary.
Inputs
Expert estimates cluster around 10–20 years
Mosca's Inequality Verdict
Act now — data encrypted today will still be sensitive when it can be broken
Exposure Gap (x + y − z)
10.0years
Latest Safe Start
0.0years from now
Migration Readiness
27.0/ 100
Effective Symmetric Strength Against Grover
128bits
Harvest-Now-Decrypt-Later Exposure
85.0%
Next Step
Build the cryptographic inventory — you cannot migrate algorithms you cannot find
Step by step
Values used
Years the data must stay secret (x) = 15 years; Years to complete migration (y) = 7 years; Years until a cryptographically relevant quantum computer (z) = 12 years; Traffic and data still protected by RSA or ECC = 85 %; Symmetric key length in use = AES-256; Cryptographic inventory completeness = 40 %; Ability to swap algorithms without redesign = 30 %; Systems piloting post-quantum or hybrid key exchange = 5 %
Quantum Threat Readiness
Mosca's inequality: act now if x + y > z, where x is the years data must stay secret, y the years the migration takes and z the years until a cryptographically relevant quantum computer.
Grover and Shor
Grover's algorithm halves effective symmetric strength (AES-256 → 128 bits), while Shor's algorithm breaks RSA and ECC outright, so asymmetric algorithms must be replaced rather than lengthened.
Mosca's Inequality Verdict
= Act now — data encrypted today will still be sensitive when it can be broken
Exposure Gap (x + y − z)
= 10.0 years
Latest Safe Start
= 0.0 years from now
Migration Readiness
= 27.0 / 100
Effective Symmetric Strength Against Grover
= 128 bits
Harvest-Now-Decrypt-Later Exposure
= 85.0
How it works
Mosca's inequality is the only planning tool that matters here: if the secrecy lifetime plus the migration duration exceeds the time until a capable quantum computer, then data you encrypt today is already exposed, because an adversary can record it now and decrypt it later. Grover only halves symmetric strength, so AES-256 remains sound; Shor breaks RSA and ECC completely, which is why every asymmetric use must be inventoried and replaced. Harvest-now-decrypt-later means the deadline is not when quantum computers arrive — it is now, for anything that must stay secret for a decade.
Formulas
Quantum Threat Readiness
Mosca's inequality: act now if x + y > z, where x is the years data must stay secret, y the years the migration takes and z the years until a cryptographically relevant quantum computer.
- x
- Required secrecy lifetime of the data
- y
- Time to complete the migration
- z
- Time until the threat is real
- x + y − z
- Years of exposure — positive means you are already late
Grover and Shor
Grover's algorithm halves effective symmetric strength (AES-256 → 128 bits), while Shor's algorithm breaks RSA and ECC outright, so asymmetric algorithms must be replaced rather than lengthened.
- Grover
- Quadratic speed-up against symmetric search
- Shor
- Polynomial-time factoring and discrete logarithms
Frequently Asked Questions
How is Quantum Threat Readiness calculated?
Mosca's inequality: act now if x + y > z, where x is the years data must stay secret, y the years the migration takes and z the years until a cryptographically relevant quantum computer. Mosca's inequality is the only planning tool that matters here: if the secrecy lifetime plus the migration duration exceeds the time until a capable quantum computer, then data you encrypt today is already exposed, because an adversary can record it now and decrypt it later. Grover only halves symmetric strength, so AES-256 remains sound; Shor breaks RSA and ECC completely, which is why every asymmetric use must be inventoried and replaced.
Why does Quantum Threat Readiness matter?
Harvest-now-decrypt-later means the deadline is not when quantum computers arrive — it is now, for anything that must stay secret for a decade.
What values do I need to enter?
This calculator takes 8 inputs: Years the data must stay secret (x), Years to complete migration (y), Years until a cryptographically relevant quantum computer (z), Traffic and data still protected by RSA or ECC, Symmetric key length in use, Cryptographic inventory completeness, Ability to swap algorithms without redesign, Systems piloting post-quantum or hybrid key exchange. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why does crypto-agility carry as much weight as the inventory?
Because most of the migration cost is architectural. Systems with hard-coded algorithms, fixed-size key fields or certificate assumptions have to be redesigned, and that is what makes y large enough to fail the inequality.
Is AES-256 enough after quantum?
Yes, for confidentiality. Grover reduces it to roughly 128 bits of effective strength, which remains infeasible. The urgent work is key exchange and signatures — RSA and ECC — not bulk encryption.
You might also need
- Enterprise Security Readiness CalculatorCommonly used together
- AI Model Security Risk CalculatorCommonly used together
- Data Retention Compliance CalculatorCommonly used together
- Ransomware Impact CalculatorAlso in Forensics & Emerging Threats
- Enterprise Cybersecurity Health Score CalculatorAlso in Forensics & Emerging Threats
- Kill Chain Coverage CalculatorAlso in Forensics & Emerging Threats