Reading the bench
Reading the bench…Reading the bench
Reading the bench…standards
shorwatch-quantum 1.0.0 makes no claim that is not printed on this page. If a number moves the deadline, it is here, cited, and covered by a unit test.
Sum to exactly 1.000
quantumWeakness0.30publicExposure0.22retentionOverlap0.20leadTime0.16attackSurface0.12SP 800-57 Part 1 Rev. 5. Values between anchors are interpolated in log₂ modulus.
RSA modulus → strength
Curve → strength
Sizes in bytes, from FIPS 203 and FIPS 204.
| Set | Standard | Level | Public key | Secret key | Ciphertext | Signature |
|---|---|---|---|---|---|---|
| ML-KEM-512 | FIPS 203 | 1 | 800 | 1632 | 768 | — |
| ML-KEM-768 | FIPS 203 | 3 | 1184 | 2400 | 1088 | — |
| ML-KEM-1024 | FIPS 203 | 5 | 1568 | 3168 | 1568 | — |
| ML-DSA-44 | FIPS 204 | 2 | 1312 | 2560 | — | 2420 |
| ML-DSA-65 | FIPS 204 | 3 | 1952 | 4032 | — | 3309 |
| ML-DSA-87 | FIPS 204 | 5 | 2592 | 4896 | — | 4627 |
Read straight from the DER SubjectPublicKeyInfo.
1.2.840.113549.1.1.1Broken by Shor's algorithm.1.2.840.10045.2.1id-ecPublicKey; broken by the quantum discrete log.1.3.101.112Shor applies to the underlying curve.1.3.101.110Key agreement; Shor applies.2.16.840.1.101.3.4.3.18FIPS 204.2.16.840.1.101.3.4.3.19FIPS 204.2.16.840.1.101.3.4.3.20FIPS 204.2.16.840.1.101.3.4.2.1FIPS 203.2.16.840.1.101.3.4.2.2FIPS 203.2.16.840.1.101.3.4.2.3FIPS 203.1.3.6.1.4.1.62253.25722OpenSSL hybrid key agreement.1.3.6.1.4.1.62253.25723OpenSSL hybrid key agreement.Gidney & Eakerå, Quantum 5, 433 (2019)
Anchor. 4,098 logical qubits and roughly 20,000,000 physical qubits at p = 1e-3 (code distance 13) factor RSA-2048 in 8 hours.
L(n) = L(2048) · (n / 2048) · (log₂n / 11)
d(p) = round(13 · log₂(1/p) / log₂(1000)), minimum 3
P(n, p) = L(n) · (d / 13)² · (20,000,000 / 4,098)
Deadline. crqYear(n) = 2035 + 7.7 · log₂(n / 2048), clamped to 2028–2060. Elliptic-curve keys are converted to an equal-strength modulus and discounted by 0.75, because the quantum discrete-log attack is cheaper than factoring at the same claimed strength.
Lead time. 1,096 days (3 years) is reserved for a migration programme before a key is called overdue.
These are order-of-magnitude projections for planning, not forecasts. Quantum resource estimates for cryptography remain an active research area.
2 qubits, 5 gates (RY, RY, CNOT, RZ, CNOT), 2 measured observables
A 2-qubit variational circuit scoring a key against the Shor-broken / quantum-viable boundary. Simulated by exact statevector arithmetic, so there is no shot noise and the same inputs always yield the same signal.
signal = 0.62·<Z0> + 0.41·<Z0Z1> + -0.08
adjustment = 3.5 · tanh(signal)
Exact statevector arithmetic means there is no shot noise, so the engine, the REST endpoint and the agent tool all return byte-identical results for identical input.
RSA comparable security
1024→80, 2048→112, 3072→128, 4096→152 bits
NIST SP 800-57 Part 1 Rev. 5, Table 2Approved curve security
P-224/P-256→128, P-384→192, P-521→256 bits
NIST FIPS 186-5 and SP 800-57 Part 1 Rev. 5ML-KEM parameter sets
ML-KEM-512 / 768 / 1024 at NIST levels 1 / 3 / 5
NIST FIPS 203 (ML-KEM)ML-DSA parameter sets
ML-DSA-44 / 65 / 87 at NIST levels 2 / 3 / 5
NIST FIPS 204 (ML-DSA)RSA-2048 factoring anchor
4098 logical / ~20,000,000 physical qubits in 8 h
Gidney & Eakerå, Quantum 5, 433 (2019)CRQ projection basis
2035 for RSA-2048, 7.7 years per modulus doubling
Interpolation anchored on the published RSA-2048 estimate aboveMigration lead time assumption
3 years
Assumption published by Shorwatch; adjustable per watchDisclaimer
Shorwatch reports measured facts and an explicitly published model. The cryptographically-relevant-quantum date is an order-of-magnitude educational projection, not a forecast, and nothing here is security advice. Validate every migration decision with your own cryptographic review and current standards guidance.