Mosca’s Theorem: The One Equation That Decides When You Migrate

"Prevention is cheaper than a breach"

Mosca’s Theorem: The One Equation That Decides When You Migrate

Michele Mosca, one of the founding voices in post-quantum cryptography, condensed the entire migration decision into a single inequality:

If X + Y > Z, you are already too late.

Where:

  • X = how long your data must stay confidential
  • Y = how long your migration to quantum-safe cryptography will take
  • Z = how long until a cryptographically relevant quantum computer exists

The theorem is deceptively simple. What makes it powerful is that once you plug in real enterprise numbers, most organizations discover they crossed the line years ago.

Working Through Real Numbers

Let’s take a typical mid-sized enterprise — say, a financial services firm handling customer data, contracts, and internal communication.

X — Data confidentiality horizon. Customer PII under GDPR must be protectable for the duration it’s retained, often 10 years. Contracts, KYC records, and internal M&A discussions can require 15–20 years of confidentiality. Health-adjacent data (insurance underwriting, claims) can require 30+ years. A realistic X for this firm: 15 years.

Y — Migration time. Enterprise crypto migration is not a software update. It requires: discovery of all cryptographic assets (typically 6–12 months alone in a mid-sized org), prioritization, procurement, phased rollout across applications, protocols, HSMs, PKI, embedded systems, third-party dependencies, and validation. Historical precedent — the SHA-1 to SHA-256 migration took most enterprises 5–7 years, and that was a hash function swap, not an algorithm-family rebuild. Realistic Y: 5 years.

Z — Time until CRQC (cryptographically relevant quantum computer). This is the contested number. Expert surveys from the Global Risk Institute’s 2024 quantum threat report placed the median estimate for a CRQC capable of breaking RSA-2048 between 2035 and 2040, with meaningful probability mass before 2030 given recent qubit-count reductions. Realistic Z: 10–12 years.

Plug it in: X + Y = 15 + 5 = 20 years. Z ≈ 10–12 years.

20 > 12. Migration should already be in progress.

Why the Numbers Are Getting Worse, Not Better

Two of the three variables are moving in the wrong direction for defenders:

  • Z is shrinking. Recent 2026 papers from Caltech and Google Quantum AI (see our analysis of the qubit breakthrough) reduced qubit-count estimates for breaking ECC and RSA by more than an order of magnitude. That doesn’t mean Q-Day is next year — but the confidence intervals shifted meaningfully earlier.
  • Y is longer than most estimates. Enterprises discovering their crypto footprint for the first time regularly find 2–3x more RSA/ECC dependencies than they expected — buried in load balancers, IoT firmware, code-signing pipelines, VPN concentrators, and third-party libraries.
  • X is only fixed if data lifecycle policies are strict. Most organizations retain data far longer than policy suggests.

The Uncomfortable Corollary

Mosca’s Theorem also implies something most migration discussions gloss over: the day you start migration is not the day you’re safe. Any data encrypted with classical cryptography between now and the day your migration completes is exposed to Store Now, Decrypt Later (see our SNDL breakdown). The retrospective attack window is your entire Y — the duration of the migration itself.

This is why crypto agility — the ability to swap algorithms without re-architecting — is more important than picking the “right” post-quantum algorithm. The organizations that will migrate successfully aren’t the ones that guessed the best algorithm; they’re the ones whose systems can be updated with the next algorithm too, when NIST’s second wave arrives.

Where This Lands in Practice

The theorem is a diagnostic, not a solution. Turning “we’re behind” into “we have a plan” requires three concrete steps:

  1. Inventory. You cannot migrate what you cannot see. PQCryptoGuard performs automated discovery of cryptographic assets across your IT environment — certificates, key stores, TLS configurations, code-signing dependencies, embedded systems — and produces a prioritized migration backlog based on data sensitivity and exposure.
  2. Roadmap. Mosca’s inequality needs to be run per data class, not once for the whole organization. Our Consultancy & Migration Services apply the equation to your actual data lifecycle policies, retention obligations, and system topology to produce a defensible migration sequence aligned with regulatory deadlines (NIS2, DORA, upcoming NIST 2030/2035 milestones).
  3. Execute without a rebuild. Full application-by-application rewrites are what makes Y unrealistic. PQInfraProtect delivers quantum-resistant protection at the infrastructure layer, closing the biggest exposures without requiring individual applications to be refactored — which is what makes hitting a realistic Y possible at all.

Mosca’s Theorem doesn’t tell you when quantum computers arrive. It tells you when you should have started. For most enterprises, that answer is: three years ago. The next best time is now.


Want to run the equation against your actual data and systems? Request a migration assessment.

1
Mosca's Theorem
Mosca's Theorem states that migration to quantum-safe cryptography should begin before quantum computers can break current encryption.
2
What to Do Next
Crypto inventory is the first step toward post-quantum cryptography migration. Understand your cryptographic asset landscape.

Leave A Comment

Name*
Message*

Scroll to top