Video companion
After Q-Day Explained: what mid-market CISOs should do this quarter
Popular explainers get the threat right — quantum computers will eventually break RSA and ECC. The gap for most enterprises is turning that awareness into an inventory program with evidence auditors can check.
The core claim in plain language
Q-Day is not a calendar date on anyone's wall. It is the capability milestone when a cryptographically relevant quantum computer can break the public-key cryptography your TLS, VPNs, and code signing depend on today. Most expert estimates still place that milestone in the 2030s — but harvest-now-decrypt-later means adversaries can copy ciphertext now and decrypt it later.
What the video gets right
- Shor's algorithm breaks RSA and ECC — symmetric crypto like AES needs larger keys (Grover), but public-key infrastructure is the urgent migration target.
- HNDL is real today — storage is cheap; breaking crypto today is not required to threaten long-lived secrets.
- PQC standards exist — NIST finalized ML-KEM, ML-DSA, and SLH-DSA in 2024; migration can start now.
What it does not cover (where Qtangl fits)
Explainers rarely answer operational questions: which endpoints still use RSA-2048, which third-party SaaS dependencies embed legacy crypto, and who owns remediation. A one-time spreadsheet exercise decays within weeks.
Qtangl Assess produces a prioritized backlog with algorithm tags, framework crosswalks, and signed scan artifacts your board can reference — an inventory aid, not a formal attestation.
90-day action checklist
- Run a baseline cryptographic inventory on external TLS and critical dependencies.
- Export a CycloneDX CBOM and map findings to NSM-10, CNSA 2.0, or NIST IR 8547 tiers.
- Quantify HNDL exposure for your longest-lived data classes using Mosca's inequality.
- Schedule re-scans aligned to your change cadence — one scan satisfies this quarter's slide, not next year's audit.
Continue on the Q-Day hub: What is Q-Day? guide
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-03
- What Is Post-Quantum Cryptography?NIST · 2024Official overview of NIST's PQC project, finalized standards, and the harvest-now-decrypt-later threat model.
- What Is Q-Day? Quantum Computing and Cyber RiskPalo Alto Networks · 2026CRQC definition, HNDL threat model, and migration guidance for enterprise security teams.
- Q-Day Explained: The Quantum Threat to EncryptionYouTube · 2025Beginner-friendly explainer covering Shor's algorithm, HNDL, and PQC basics.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.