Enter a key size. See the quantum resources Shor's algorithm needs to break it — and the year quantum-hardware roadmaps are projected to get there.
RSA secures most of today's internet — banking, email, software updates, government records. Its safety rests on one assumption: factoring large integers is computationally infeasible.
Peter Shor showed in 1994 that a large enough quantum computer factors integers in polynomial time, breaking RSA outright. Today's hardware is far from that scale — but the requirement is falling and the hardware is rising. The only real question is when. The estimator below puts a number on it.
Nothing is sent anywhere — analysis runs entirely in your browser. Generate a real RSA pair locally with OpenSSH, then paste rsa_demo.pub into the box above:
ssh-keygen -t rsa -b 2048 -f rsa_demo -N ""
Bump -b to 4096 and watch the break-year move out.
Resource model anchored to Gidney & Ekerå 2019 (arXiv:1905.09749, ~3n logical qubits, ~0.3 n³ Toffoli gates, ~20M physical for RSA-2048) and the qLDPC «Pinnacle» architecture (Webster, Berent et al. 2026, arXiv:2602.11457, <100k physical for RSA-2048 — an Iceberg Quantum blueprint, frequently miscredited to IonQ, whose own 2026 factoring result is a 30-bit number). Surface code and qLDPC bracket a continuum of estimates that has fallen ~200× in six years — the chart below traces it.
The break-year reads the requirement against the dated milestones of the public vendor roadmaps, interpolated on a log axis; where a requirement sits above the last of them — 1,000,000 physical qubits, Google Quantum AI, 2029 — the estimate is a trend extrapolation and the terminal says so. The runtime and the qubit count are one point on a space–time tradeoff, not two independent facts: the same architecture buys fewer qubits by running longer, so neither figure means anything quoted without the other.
The requirement is falling as the hardware rises. Plot both on one log axis and the picture is a convergence — the open question is only when, not whether.
A qubit count without a runtime is a number without a unit. The same neutral-atom architecture (Cain et al. 2026, on the chart twice) is 11,000 qubits or 102,000 qubits depending only on how long you are willing to wait — and the cheap end takes years. Each label therefore names both, and configurations that miss the 100-day bound are drawn hollow and kept out of the fit.
A straight line on a log axis keeps falling without limit and reaches fewer physical qubits than the algorithm has logical ones. The curve instead bends toward 4,667 — 1,400 logical qubits at a 30 % code rate. That is a floor for the current state of two fields, not a law: it moves down if someone publishes a leaner compilation or a better code.
A qLDPC estimate is never crossed against a planar superconducting roadmap. Per modality: superconducting reaches the 100,000-qubit requirement in 2028; ion trap tops out at 50,000 by 2035 and neutral atom at 1,180, so neither crosses. And the headline window rests on a single dated claim — Google’s 2029 million-qubit target. Drop it and the crossing moves to 2030.
The figure is compiled, never drawn: every mark, curve, band and label is generated from the estimate corpus and the dated vendor-milestone data, so a new paper or a slipped roadmap reaches the picture by re-running the command rather than by editing a file.
Shor breaks RSA and elliptic-curve cryptography — both reduce to the same hidden-subgroup problem a quantum computer solves efficiently. The mitigation is already standardised: cryptography built on problems Shor cannot touch.
| Standard | Algorithm | Use | Hard problem | Status |
|---|---|---|---|---|
| FIPS 203 | ML-KEM (Kyber) | Key encapsulation | Module lattice (MLWE) | Final · 2024 |
| FIPS 204 | ML-DSA (Dilithium) | Signatures | Module lattice (MLWE) | Final · 2024 |
| FIPS 205 | SLH-DSA (SPHINCS+) | Signatures | Hash functions | Final · 2024 |
| FIPS 206 | FN-DSA (Falcon) | Signatures | NTRU lattice | Draft · 2025/26 |
Shor solves the abelian hidden-subgroup problem — exactly what factoring (RSA) and discrete log (ECC) reduce to. Lattice and hash problems do not, so Shor gives no exponential speedup; only Grover's quadratic speedup applies, defeated by modestly larger parameters.
An adversary can record encrypted traffic today and decrypt it once a quantum computer arrives. Any secret that must stay confidential into the 2030s should migrate to post-quantum algorithms now — the deadline is set by your data's lifetime, not the computer's arrival date.
JoS QUANTUM works the defensive side of this story: quantum key distribution and ML-based security proofs for quantum communication protocols. See our patent portfolio and QKD as a Quantum Machine Learning task (npj Quantum Information, 2025).