
Increasing focus on quantum timelines demands a disciplined response
Q-Day – the estimated point at which quantum computers could break some of today’s most important cryptography standards – is no longer a distant concern.
According to a Global Risk Institute expert survey1, there’s now a 28-49% likelihood of Q-Day occurring by 2035, up markedly on a year ago.

With the timeline to cryptographically relevant quantum computers solidifying, regulator expectations and tech sector activities are accelerating.
This reinforces the message we’ve been making for several years – organisations must start planning and preparing now to support a quantum-safe future.
Moving migration targets
Resource estimates for what would be required to break current cryptography methods like Rivest-Shamir-Adleman (RSA) are falling sharply.
For example, when we started our quantum programme at HSBC four years ago, one widely cited estimate suggested that 20 million physical qubits would be required to break RSA-2048. Google’s latest estimate is below 1 million, and other research this year has suggested the number could fall further under different architectural assumptions.
In response to changing expert estimates, regulators and cyber agencies are accelerating the release of migration guidelines and timelines to quantum-safe cryptography standards.
In the UK, the National Cyber Security Centre has set out a three-phase roadmap –discovery and planning by 2028, migration of highest priority systems by 2031, and full migration by 2035. In the US, the latest post-quantum cryptography (PQC) executive order from June 2026 mandates that federal agencies migrate high-impact systems by 2030-31.
At the same time, major technology providers such as Google, Microsoft and Cloudflare have brought forward the targets for their own infrastructure migrations to 2029. These are vendor timelines, not Q-Day forecasts – but they set the pace for the ecosystem that every organisation depends on.
There’s a further reason the timeline matters today, not just at Q-Day. Encrypted data intercepted and stored now could be decrypted later, once a sufficiently capable quantum computer exists. This is especially relevant for any data with a confidentiality lifetime beyond the early 2030s – for example customer records or long-dated contracts.
By planning and taking action as soon as possible, this risk is reduced.
Taking a disciplined, risk-based approach
While the time to act is now, the right response is disciplined, risk-based planning – and this is the approach we’re taking at HSBC.
Global organisations and banks like us face additional complexity as quantum-safe standards and approaches are likely to differ across markets.
The PQC standards set by the National Institute of Standards and Technology (NIST) are likely to be an important reference point for many markets. Some jurisdictions may develop, or prefer, national standards.
Therefore, organisations will need to pay special attention to interoperability, vendor support, third-party assurance, and differing timelines to ensure an orderly migration.
Preparing for a quantum-safe future
At HSBC, we’re investing in frontier capabilities, helping to better serve our customers and clients.
We’ve mobilised a Group-wide quantum threat programme to build the visibility, governance and agility needed to complete migration safely – and we encourage other organisations to do the same.
Our approach involves identifying a representative set of critical-risk services to prioritise, developing a detailed view of their cryptographic assets and dependencies, and building the capabilities required to meet pre-requisites for quantum safety across the organisation.
The window to prepare is real, but it is narrowing – and the longer organisations wait, the more complex the migration becomes.
References
- Global Risk Institute’s Quantum Threat Timeline Report 2025 (opens in new window)

HSBC and Quantum
As one of the top global leaders in quantum finance, we’re at the forefront of developing new capabilities.

HSBC Patents and Research Papers
Our tech experts publish a wide range of research papers and register patents that help us deliver cutting-edge, digital-first banking solutions.