A peer-reviewed critique in Nature has reopened the argument over when a quantum computer will actually break RSA. Henry Legg, a physicist at the University of St Andrews, argues that Microsoft's Majorana results do not hold up, and that a working machine is far further out than the company claims, on the order of centuries. Microsoft stands by its roadmap. The exchange is worth reading, and the security press is full of it this week.
It has no bearing on the date you have to migrate by.
Two different clocks
The quantum timeline is a hardware question. When will a cryptographically relevant quantum computer exist? Nobody knows, and the estimates now run from a few years to never. That uncertainty is real.
Your migration deadline is a different thing. Regulators set it, and they already picked the dates. CNSA 2.0 requires post-quantum key exchange by 2030 and signatures by 2035. Executive Order 14412 sets 2030 for civilian key exchange and 2031 for signatures. France's ANSSI expects post-quantum protection earlier still, from 2027. Germany's BSI mandates hybrid and ends support for classical-only systems in 2031. You can see the full stack on the [PQ]time page.
None of those dates were derived from a qubit count. They will not move if Legg is right, and they will not move if Microsoft ships on schedule. They are policy, and policy was written to be conservative precisely because the hardware date is unknown.
Harvest now, decrypt later does not wait for the hardware
There is a second clock, and it is already running. An adversary does not need a quantum computer today to attack your data today. It needs to copy the ciphertext today and decrypt it whenever the hardware arrives.
Ask one question about anything you send over the wire: how long does it need to stay confidential? If the answer runs past 2030, and the connection protecting it uses classical key exchange, that data is already exposed. The capture is happening now. The decryption happens later. Whether later is 2030 or 2040 changes nothing about whether you should have closed the gap.
The category error
A reader who follows the Majorana argument and concludes there is more runway has confused the hardware clock with the two clocks that actually bind. The compliance date is fixed by regulation. The exposure window opened the day the data started flowing. Neither is indexed to Microsoft's roadmap, and neither gets longer because a physicist and a vendor disagree in the pages of Nature.
The timeline debate feels decisive because it looks like the whole question. It is only the one input you cannot control and do not need to resolve.
The number that actually moves
Set the hardware timeline aside and measure what you can change. On most networks the picture holds regardless of when the quantum computer arrives: the edge negotiates post-quantum key exchange because a CDN turned it on, and the origin server behind it still negotiates classical. The published adoption figures describe the edge. Origin posture sits near zero, and the same pattern shows up every time you scan both sides of a proxy.
That is the number that responds to work. You configure a server, you rescan, and the grade moves. [PQ]probe measures origin key exchange per scan and tracks whether it is improving or degrading against each of the deadlines above, so the question in front of you stops being when the quantum computer arrives and becomes whether you are closing your own gap fast enough to make 2030.
The first clock is a physics argument that may run for years. The other two are already counting, and only one of the three is yours to answer.