Photo: Ramaz Bluashvili / Pexels
EU warns Q-Day could arrive before quantum computers are commercially viable
Member states have until the end of 2026 to plan their transition to post-quantum cryptography, with high-risk infrastructure migration due by 2030
The European Union is preparing for a cybersecurity threat that sounds like a paradox: quantum computers might break modern encryption before they’re actually useful for anything else. The bloc’s NIS Cooperation Group has published a roadmap requiring all 27 member states to begin planning their transition to post-quantum cryptography by December 31, 2026.
The core concern is what researchers call “Q-Day,” the moment a quantum computer becomes powerful enough to crack the asymmetric encryption that secures everything from banking systems to blockchain networks.
The “store now, decrypt later” problem
The most unsettling part of the EU’s warning isn’t about future attacks. It’s about attacks happening right now.
The concept is straightforward: adversaries can harvest encrypted data today and simply wait until quantum hardware matures enough to decrypt it. By the time Q-Day actually arrives, years of sensitive communications, financial records, and government secrets could be cracked open retroactively.
Recent technical advancements, including research from Google, have pushed some estimates for viable quantum attacks forward to as early as 2029. That’s notably ahead of when most experts expect quantum computers to become commercially useful for general-purpose tasks.
The EU’s three-phase timeline
The roadmap lays out a structured migration plan with three key milestones.
First, member states must complete their initial planning by the end of 2026. This phase includes stakeholder mapping, risk assessments, and building cryptographic inventories, essentially figuring out where all the vulnerable encryption lives across government and critical infrastructure.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Second, high-risk infrastructure must complete its migration to post-quantum cryptography by the end of 2030. This covers the systems where a breach would be most catastrophic: energy grids, financial networks, defense communications, and similar targets.
Third, broader systems across the EU are targeted for full PQC conversion by 2035.
The EU has publicly invested over €11 billion in quantum technologies in recent years but still trails both the US and China in private sector investment. Europe leads in scientific publications on quantum technology.
What this means for crypto
Most major blockchains, including Bitcoin and Ethereum, rely on elliptic curve cryptography for securing wallets and validating transactions. This is precisely the type of asymmetric encryption that quantum computers would target. A sufficiently powerful quantum machine could theoretically derive private keys from public keys, making any wallet with an exposed public key vulnerable.
Bitcoin’s case is particularly interesting. Addresses that have never been used to send a transaction (only to receive) keep their public key hidden behind an additional hash layer. But any address that has broadcast a transaction has its public key sitting on the blockchain forever.
The EU’s roadmap aligns with standards already established by NIST, which finalized its first set of post-quantum cryptographic algorithms in 2024. Several blockchain projects have begun exploring quantum-resistant signature schemes, though none of the major Layer 1 networks have implemented them at the protocol level yet.
The “store now, decrypt later” threat applies to blockchain data as well. Every transaction ever recorded on a public ledger is, by definition, permanently available for future analysis.
The EU’s initiative also connects to its broader EuroQCI project, which aims to build quantum-safe communication infrastructure across the bloc.
The gap between 2029 (when some quantum attacks may become feasible) and 2035 (when the EU wants full migration completed) creates a window of vulnerability that both regulators and market participants will need to navigate.