02.1

The short version

Not a faster classical computer

Quantum computers don't outrun classical machines at everyday tasks like spreadsheets or web browsing. They exploit superposition and entanglement to explore many possible solutions simultaneously, which only pays off for specific problem shapes: simulating molecules and materials, certain optimization problems, and integer factorization.

Extremely fragile by nature

Qubits lose their quantum state ("decohere") from stray heat, vibration, or electromagnetic noise in microseconds to milliseconds. Quantum error correction spreads one logical qubit across many physical qubits to survive that noise — and building enough reliable logical qubits is the central engineering problem of the field.

02.2

Benefits, drawbacks, and risks

Benefits
  • Molecular and materials simulation. Quantum computers are natively good at modeling quantum systems — new catalysts, battery chemistries, and drug candidates could be screened computationally instead of only in the lab.
  • Optimization at scale. Logistics routing, portfolio construction, and scheduling problems with combinatorial complexity are natural candidates for quantum or hybrid quantum-classical approaches.
  • Stronger cryptographic primitives. Quantum key distribution and quantum random number generation offer security properties that are difficult or impossible to replicate classically.
  • A forcing function for better security hygiene. The migration to post-quantum cryptography is pushing organizations to finally inventory and modernize decades-old cryptographic infrastructure, quantum threat or not.
Drawbacks
  • Cost and access. Dilution refrigerators, cryogenic control electronics, and ultra-high vacuum systems put hardware access almost entirely in the hands of a few national labs, well-funded startups, and hyperscalers.
  • Narrow near-term utility. As of 2026, no quantum computer has demonstrated a clear, verified advantage on a genuinely useful workload — advantage claims to date are on constructed benchmark problems.
  • Hype outrunning hardware. Marketing timelines routinely outpace peer-reviewed results; treat vendor roadmaps as directional, not committed, especially multi-year-out claims.
  • Talent scarcity. The field needs people fluent in both quantum physics and software engineering — a small and slow-growing pool that constrains how fast progress can translate into products.
Risks
  • "Harvest now, decrypt later." Adversaries can record encrypted traffic today and decrypt it once a cryptographically relevant quantum computer exists — making long-lived secrets (state, medical, financial) vulnerable even before the hardware arrives.
  • Breaking current public-key cryptography. RSA and elliptic-curve cryptography, which secure most of the internet today, are theoretically breakable by a sufficiently large fault-tolerant quantum computer. Current resource estimates put that at roughly a million high-quality logical qubits for RSA-2048 — down sharply from earlier estimates, but still far beyond anything built to date.
  • Geopolitical concentration. Quantum advantage, especially in cryptanalysis, has obvious military and intelligence value, which is driving state-level investment and secrecy that could outpace civilian oversight.
  • Migration risk, not just quantum risk. The post-quantum cryptography transition itself is a major undertaking with its own failure modes: legacy systems that can't be patched, new algorithms with less real-world scrutiny, and interoperability gaps during the changeover.
02.3

How we got here — and the cryptographic clock

Aug 2024

NIST finalizes the first PQC standards

FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) were published after an eight-year evaluation process, giving organizations quantum-resistant algorithms they can implement today.

2025

Error correction starts working on real hardware

Google's Willow processor demonstrated that adding more physical qubits to a surface code reduces the logical error rate rather than increasing it — the long-sought "below threshold" result that makes scaling a matter of engineering, not just theory.

Early-mid 2026

Logical qubit counts climb into the double and triple digits

Multiple vendors — including Quantinuum and IBM — reported dozens to around 100 logical qubits, alongside falling physical-to-logical qubit overhead. Meaningful progress, still orders of magnitude short of the roughly one million logical qubits current estimates say cryptographically relevant factoring would require.

2026

Post-quantum migration crosses the halfway mark

Cloudflare reported that more than half of the human web traffic it observes is now protected by quantum-resistant key agreement, while the EU, US federal agencies, and major cloud providers set migration deadlines running from 2026 out to 2029.

2029–early 2030s

Where the roadmaps point next

IBM's public roadmap targets a large-scale fault-tolerant system by 2029; most independent risk estimates put meaningful probability of a cryptographically relevant quantum computer within the following decade, not this one. Roadmaps have historically slipped — treat these as directional.