
Quantum computing is emerging as one of the most consequential frontier technologies of the 21st century. Using quantum-mechanical principles, quantum computers are primed to solve specific classes of computational problems exponentially faster than classical machines. For G20 economies, accounting for the bulk of global GDP and home to the world's most advanced digital infrastructure, financial systems, critical data flows, and defence networks, this represents both a transformational opportunity and a systemic cybersecurity risk.
While quantum computing promises breakthroughs in materials science, pharmaceuticals, logistics, and artificial intelligence, it also threatens to render widely used cryptographic systems obsolete. This "quantum threat horizon" is accelerating global efforts toward post-quantum cryptography, quantum-safe infrastructure, and new cybersecurity governance frameworks.
The central dilemma lies in the risks posed by quantum computing to existing encryption systems. Every bank transfer, encrypted email, or government login, presently relies on cryptographic systems that are secure only because classical computers cannot feasibly solve the underlying mathematical problems. Quantum computing fundamentally alters this.
Quantum machines, once they become sufficiently mature, could break widely used encryption schemes by solving mathematical problems used in such encryption, at dramatically accelerated speeds. The result would be a structural breakdown of current digital security architectures. As global digital systems deepen their reliance on cryptography, the emergence of cryptographically relevant quantum computers (CRQCs) would reshape the foundations of digital trust.
The term "Q-Day" refers to the moment a quantum computer becomes powerful enough to break today's encryption at scale. Until recently, most experts placed it comfortably beyond 2035, but that consensus is rapidly being revised.
The Global Risk Institute's 2025 Quantum Threat Timeline Report1 found that the timeline for a quantum computer capable of breaking today's encryption has accelerated compared to previous estimates. Earlier assessments by the Global Risk Institute suggested a 17 to 34 per cent probability of such a machine emerging by 2034.2
However, in December 2024 the unveiling of Google's Willow quantum chip demonstrated a significant leap in error correction.3 Error correction has been one of the main engineering obstacles to building a useful quantum computer in the past. Following this breakthrough, subsequent research has revised calculations shortening the expected timeline of the arrival of Q-Day, making a breakthrough in the 2030-2032 timeframe a credible planning horizon.4 Experts have also reduced estimates of how many quantum building blocks, known as qubits, would be needed to break the most widely used encryption standards.5 Future quantum computers are assessed to be capable of breaking the cryptography protecting digital systems with far fewer qubits than previously thought.
The White House has set 2035 as the target year for full adoption of quantum-resistant encryption.6 However, the convergence of faster hardware, smarter algorithms, and better error correction means that businesses and governments planning for Q-Day after 2035 may be dangerously complacent. A 2030-2032 horizon is now a scenario that prudent organisations must plan for. For G20 governments, this arithmetic points to one conclusion: preparation must begin immediately.
There is a particularly unsettling dimension to the quantum cybersecurity challenge that is not widely understood. A sufficiently powerful quantum computer does not yet exist. However, the risk is already extant since the 'harvest now, decrypt later' threat means that adversaries are already collecting and storing encrypted data today with the explicit intention of decrypting it once quantum capability becomes available.
This means the quantum threat is not purely prospective. It is cumulative and retrospective. Data being transmitted today across G20 networks, like diplomatic cables, corporate trade secrets, intellectual property, healthcare records, and long-term financial contracts, may already be compromised.
This changes the nature of the problem. Encryption no longer becomes only about protecting real-time communications, but about ensuring long-term confidentiality over decades. For infrastructure with long lifecycles such as power grids, transportation systems, and healthcare networks, it means that systems deployed today must already be made quantum resilient. For the G20, whose economies collectively underpin the world's critical digital infrastructure, this has important implications.
The international response to new and emerging threats is accelerating. A major milestone came in August 2024 when the United States National Institute of Standards and Technology (NIST) published the first internationally recognised set of post-quantum cryptography (PQC) standards.7 These algorithms are designed to resist quantum attacks and are now forming the backbone of global migration strategies.
NIST's roadmap calls for current quantum-vulnerable encryption to be phased out after 2030 and prohibited entirely after 2035, with widely used systems such as RSA-2048 explicitly targeted for replacement. This has become the de facto global benchmark. In the US, the Quantum Computing Cybersecurity Preparedness Act additionally requires all federal agencies to audit their vulnerable systems and report on migration progress every year — a model of government accountability that other G20 members would do well to adopt.
Investment in quantum technology across G20 economies has also accelerated dramatically.
However, the distribution of investment in quantum technologies across G20 countries is uneven. The United States leads in private quantum investment, commanding 44 per cent of global funding, followed by the United Kingdom, Canada, and Australia collectively at around 20 per cent, and China at 17 per cent, with Europe and other countries trailing.11 This skewed distribution leads to asymmetry in risk across G20 countries.
Certain sectors face a more acute migration urgency to quantum-resilient systems, as compared to others, mostly due to long asset lifecycles and high systemic dependency on encryption. Some of these sectors which cannot afford to take a wait-and-see approach are as follows:
Cryptography is so deeply embedded in modern organisations that many businesses are often not fully sure about where exactly encryption is embedded across all their systems. This could range from database connections to authentication processes, background software jobs, among other. Before any migration can begin, organisations first need to know what it is that they need to be protecting.
The following priorities stand out for the B20 community:
The quantum computing transition is not a distant technological scenario; it is an unfolding systemic shift in digital security architecture. The G20 now faces a binary choice. They can coordinate by aligning on common post-quantum standards, migrating critical infrastructure in parallel, and building shared capacity across all G20 members — arriving at Q-Day with a resilient global digital architecture intact. Or they can allow migration to proceed unevenly, along existing geopolitical and economic fault lines, leaving gaps that can be exploited.
The B20 community has a distinctive role in making the first outcome more likely: through advocacy for common standards, private sector leadership on risk assessment, and a genuine commitment to building quantum resilience across the full G20 membership. Decisions taken between now and 2030 will determine whether the global digital system transitions smoothly into the post-quantum era or experiences a destabilizing rupture in its foundational trust layer.
1.Global Risk Institute (GRI), Quantum Threat Timeline Report 2025, March 2026, https://globalriskinstitute.org/publication/quantum-threat-timeline-report-2025b/
2.Global Risk Institute (GRI), Quantum Threat Timeline Report 2024, December 2024, https://globalriskinstitute.org/publication/2024-quantum-threat-timeline-report/
3.Google unveils 'mindboggling' quantum computing chip, The Guardian, 9 December 2024, https://www.theguardian.com/technology/2024/dec/09/google-unveils-mindboggling-quantum-computing-chip
4.Quantum Computing Report, Q-Day: Accelerated Timeline Across Wider Attack Surface, April 2026, https://quantumcomputingreport.com/q-day-accelerated-timeline-across-wider-attack-surface-executive-summary/
5.The Quantum Insider. Q-Day Just Got Closer: Three Papers in Three Months Are Rewriting the Quantum Threat Timeline. March 2026, https://thequantuminsider.com/2026/03/31/q-day-just-got-closer-three-papers-in-three-months-are-rewriting-the-quantum-threat-timeline/
6.US Executive Office of the President, Memorandum on "Promoting United States Leadership in Quantum Computing While Mitigating Risk to Vulnerable Cryptographic Systems", November 2022, https://www.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf
7.National Institute of Standards and Technology (NIST). Announcing Approval of Three FIPS for Post-Quantum Cryptography, August 2024, https://www.nist.gov/news-events/news/2024/08/announcing-approval-three-federal-information-processing-standards-fips
8.National Quantum Initiative Reauthorization Act, Congressional Budget Office, 1 November 2024, https://www.cbo.gov/system/files/2024-11/hr6213.pdf
9.UK unveils £2.5bn AI Sovereign Fund and quantum scale-up, 18 March 2026, https://www.techjournal.uk/p/uk-unveils-25bn-ai-sovereign-fund
10.OECD Digital Economy Papers, "An Overview of National Strategies and Policies for Quantum Technologies", December 2025, https://www.oecd.org/content/dam/oecd/en/publications/reports/2025/12/an-overview-of-national-strategies-and-policies-for-quantum-technologies_33a0b249/5e55e7ab-en.pdf
11.European Centre for International Political Economy, "Benchmarking Quantum Technology Performance: Governments, Industry, Academia and their Role in Shaping our Technological Future", March 2025, https://ecipe.org/publications/benchmarking-quantum-technology-performance/
