No — not in the long run. A large enough quantum computer running Shor's algorithm can break RSA, and the elliptic-curve cryptography (ECDSA, ECDH, Ed25519) used alongside it, in a practical amount of time. No quantum computer that can do this exists today, but the data you encrypt with RSA now may still need to be secret when one does.
Why does a quantum computer break RSA?
RSA is safe because factoring a very large number is hard for ordinary computers: the best known methods would take longer than the age of the universe for a 2048-bit key. Elliptic-curve cryptography rests on a similar hard problem, the discrete logarithm.
In 1994 Peter Shor showed that a quantum computer can solve both problems efficiently. Making keys bigger does not help much: Shor's algorithm scales gently with key size, so RSA-4096 buys years at most, not safety.
Can a quantum computer break RSA today?
No. Today's quantum computers are far too small and too error-prone. The estimates of what it would take keep falling, though: a 2019 estimate needed about 20 million physical qubits to break RSA-2048 in hours, and a 2025 estimate from Google researcher Craig Gidney put it under a million. Nobody can give a reliable date, which is exactly why standards bodies have stopped waiting for one.
What about AES and SHA-256?
Symmetric cryptography is in much better shape. The relevant quantum attack (Grover's algorithm) at best halves the effective key strength, so AES-256 and SHA-256 remain safe. AES-128 is usually recommended to move to AES-256 as a precaution.
When do I need to stop using RSA?
NIST's draft transition guidance (NIST IR 8547) proposes deprecating RSA and elliptic-curve algorithms at today's common strength after 2030 and disallowing them after 2035. US national security systems are being moved on a similar timeline under the NSA's CNSA 2.0. For most organisations, the practical deadline is sooner than the standard one, because migrating takes years and some data must stay secret for years after it is sent — see harvest now, decrypt later.
What replaces RSA?
NIST published the first post-quantum standards in August 2024:
- ML-KEM (FIPS 203) for key exchange and encryption — replacing RSA encryption and ECDH. See What is ML-KEM?
- ML-DSA (FIPS 204) for digital signatures — replacing RSA and ECDSA signatures.
- SLH-DSA (FIPS 205), a hash-based signature scheme, as a conservative alternative.
Most systems move through a hybrid stage first, combining a classical algorithm with a post-quantum one so that security never depends on the new algorithm alone.
How do I find the RSA in my systems?
That is usually the hard part: RSA and elliptic curves hide in dependencies, TLS settings, certificates, SSH keys and cloud services, not just in your own code. Qopanza scans your code, dependencies, TLS endpoints and cloud accounts, lists every quantum-vulnerable algorithm it finds, ranks them by exposure, and plans the migration to ML-KEM and ML-DSA. Start at qopanza.com, or read how to migrate.