Why Google’s Willow quantum chip impacts encryption timelines
Google's Willow chip achieves below threshold error correction, signaling progress toward quantum hardware capable of breaking RSA-2048. This advancement accelerates the need for global migration to NIST post-quantum standards like ML-KEM by the 2029 deadline.
Willow achieves below threshold error correction
Google’s Willow chip contains 105 superconducting qubits. It achieves below threshold error correction. As the team increases the number of physical qubits, the error rate decreases. Google tested arrays of physical qubits. They scaled from a 3×3 grid to 5×5 and then to 7×7. The error rate dropped by half during each scale-up. This achievement shows an exponential reduction in error. This is a beyond breakeven demonstration. The qubit arrays have longer lifetimes than the individual physical qubits. Willow provides a convincing prototype for a scalable logical qubit. The qubits maintain coherence for nearly 100 microseconds. This is five times longer than the previous generation. Willow performs a random circuit sampling benchmark in under five minutes. This task takes a modern supercomputer 10 septillion years. This benchmark is the classically hardest test. It checks if a quantum computer does something that a classical computer cannot. Google reported Sycamore results in 2019 and again in 2024. This computation lends credence to the idea that quantum computation occurs in many parallel universes.
The error rate drops.
Breaking RSA-2048 requires fewer qubits
Craig Gidney estimates that factoring a 2048-bit RSA encryption key requires fewer than one million physical qubits and less than a week of continuous computation using approximate residue arithmetic and compressed error-correction layouts. This is a 95% reduction from his 2019 estimate of 20 million qubits. The 2048-bit key is a 617-digit number. The attack requires five days of continuous operation. The system must maintain 1 microsecond surface code cycles and gate error rates below 0.1%. This performance is well beyond today’s systems. Such a machine needs a control system that reacts within 10 microseconds. It also needs a combination of hot and cold storage zones for active and idle qubits. The compute region handles logic operations. The hot storage region supports active qubit use. The cold storage region provides an area for idle logical qubits. The algorithm uses yoked surface codes for low-overhead logical qubit storage. This reduces the computational overhead. The computer must manage logical errors through more than 6.5 billion Toffoli gate operations. The threat remains. You already know the risks to RSA. Does the hardware arrive in time?
The threat remains.
Global migration schedules
Google targets 2029 for full post-quantum cryptography migration. This timeline reflects progress in hardware development, error correction, and factoring resource estimates. NIST recommends deprecating vulnerable algorithms after 2030 and disallowing them after 2035. Android 17 integrates ML-DSA for digital signature protection in alignment with NIST.
| NIST Standard | Name | Function |
|---|---|---|
| FIPS 203 | ML-KEM | Key Encapsulation |
| FIPS 204 | ML-DSA | Digital Signature |
| FIPS 205 | SLH-DSA | Digital Signature |
ML-KEM, formerly CRYSTALS-Kyber, allows two parties to establish a shared secret key over an insecure channel. ML-DSA, derived from CRYSTALS-Dilithium, provides the framework for authenticating digital identities. SLH-DSA, which is based on SPHINCS+, offers an alternative that does not rely on lattice mathematics. The transition to new standards requires crypto-agility. Organizations must update their systems to support new algorithms. The "harvest now, decrypt later" threat makes this an immediate concern. Adversaries capture encrypted data today to decrypt it when hardware matures. The Australian Signals Directorate advises that all classical public-key cryptography should be eliminated by 2030. The European Union expects critical infrastructures to transition to post-quantum cryptography for high-risk use cases by the end of 2030. The European Union also expects migration of medium-risk use cases to be completed by 2035. The U.S. National Security Agency requires national security systems to adopt quantum-resistant cryptography for new acquisitions starting in 2027. Software and firmware signing face exclusive-use requirements from January 1, 2027. The U.S. government must also achieve full quantum resistance across all National Security Systems by 2035.
The math changes.
The deadline nears.