Here is an uncomfortable fact about the encryption protecting your data right now. A large enough quantum computer will break it, and while that machine does not exist yet, the attack has already started. Adversaries are recording encrypted traffic today, sitting on it, and waiting for the hardware that decrypts it. It is called "harvest now, decrypt later", and it means that any data with a shelf life longer than a few years, medical records, contracts, trade secrets, personal data you are legally required to protect, is arguably already exposed.
That reframes post-quantum cryptography from a research-lab curiosity into a planning problem for 2026. You do not need a quantum physicist on staff. You need to know what standards exist, what your obligations are, and why "we will deal with it when quantum computers arrive" is the one answer that is definitely wrong.
Why "someday" is already a problem
The threat model is the confusing part, so it is worth being precise. Two things are true at once: no quantum computer today can break RSA-2048, and your long-lived secrets are already at risk. Both, together.
The bridge between them is time. Harvest-now-decrypt-later attacks capture ciphertext now and decrypt it whenever the capability lands. If a piece of data still needs to be confidential in 2035, and a capable quantum computer plausibly arrives before then, that data is effectively at risk from the moment it crosses a network today. The clock that matters is not "when does quantum break encryption", it is "how long does this data need to stay secret", and for a lot of business data the honest answer is a decade or more.






