When someone says “quantum computer,” it still sounds like a problem from the future. Something that might eventually arrive, break RSA, and give us a reason to deal with it.
That is not how cryptographic migration works. The quantum problem does not start on the day someone builds a sufficiently powerful machine. It starts when data needs to stay secret for longer than the transition to new cryptography will take.
No quantum computer can practically break RSA or elliptic-curve cryptography today. I do not want to turn this into a countdown to disaster. It still makes sense to start now.
Data can outlive the system protecting it
Plenty of data loses its value quickly. A one-time code or a short-lived operational message may not be sensitive ten years from now.









