A megaquop machine runs about a million quantum operations reliably. That is a smaller claim than most coverage of quantum computing makes, and it is a great deal harder than anything built so far. This guide sets out where the term came from, what the specification says, and the three things that have to keep working before one exists.
A megaquop runs a million operations, not a million qubits. The unit is quantum operations completed reliably, and Preskill was explicit that mega means roughly a million rather than exactly one.
The specification is concrete. One error in a million per logical gate, about a hundred logical qubits, circuits about ten thousand layers deep.
The gap to today is three to four orders of magnitude. Physical two-qubit gates are wrong about once in three hundred on Willow, and error correction rather than better gates is what closes it.
It would not break encryption. RSA-2048 is a gigaquop problem, a thousand times further up the scale.
Three things still have to hold. Error suppression as codes grow, a decoder that keeps up, and a floor of rare correlated errors nobody has cleared.
Nobody can name the first useful application. Preskill says so himself, and expects the early payoff to be scientific rather than commercial.
- Preskill named the next era in a keynote in December 2024
- He dropped the ISQ naming format on purpose
- A megaquop is not a NISQ machine with more qubits
- One error in a million, a hundred logical qubits, depth ten thousand
- Tens of thousands of physical qubits, and a guess about atoms
- Error suppression has to keep working as the codes grow
- The decoder has to keep up with the machine
- Rare correlated errors are the floor nobody has cleared
- Better algorithms have cut the target faster than better hardware
- Gigaquop and teraquop are the rungs above, and nobody has dated them
- Nobody can name the first useful application, including Preskill
- Frequently asked questions
Preskill named the next era in a keynote in December 2024
The person who named the noisy era also named what comes after it. John Preskill proposed the megaquop machine in a keynote at the Q2B conference in Silicon Valley on 11 December 2024, published the following March as Beyond NISQ: The Megaquop Machine (ACM Transactions on Quantum Computing, DOI 10.1145/3723153). He had coined NISQ, noisy intermediate-scale quantum, at a keynote in December 2017 and in arXiv:1801.00862 the January after.
A megaquop is a machine that can run roughly a million quantum operations reliably. The name is built from mega and quantum operation. Preskill was explicit that the prefix is approximate, writing that mega means not precisely a million but somewhere in the vicinity of a million. The vagueness is deliberate.
The reason a new word was needed is that the old one had stopped describing anything useful. NISQ named a machine by what it lacked, which was error correction. Once error correction starts working the interesting question is no longer how many qubits a machine has, but how many operations it can complete before the answer falls apart, and that is a question about time rather than size.
He dropped the ISQ naming format on purpose
Other people had proposed successors that kept the shape of the original acronym, adding a letter or changing the first word while keeping the ISQ ending. Preskill said plainly that he would rather leave ISQ behind as the field moves forward. The objection is not aesthetic.
Counting operations gives a scale that keeps going. A gigaquop machine runs a billion operations and a teraquop a trillion, and each is a factor of a thousand on from the last. Naming eras by what the hardware lacks produces a label that expires; naming them by what the machine can do produces a ruler.
At the far end of that ruler sits what Preskill calls a FASQ machine, for Fault-Tolerant Application-Scale Quantum, able to run a wide variety of useful applications. He credits the acronym to Andrew Landahl and calls the thing itself a rather distant goal. Everything between here and there is the megaquop era and its successors.
A megaquop is not a NISQ machine with more qubits
The most common way to misread the term is to treat it as the next size up. It is not a scale claim at all. What separates a megaquop machine from the best noisy machine ever built is not the number of qubits on the chip but the fact that error correction works on it, which is a difference of kind rather than of degree.
A NISQ machine has no error correction, so every extra gate eats into the chance of a usable answer and the circuit has to stay shallow enough to stay ahead of the noise. Adding qubits does not change that arithmetic. A bigger noisy machine is still a noisy machine, which is why the NISQ era ended in disappointment rather than in a gradual handover.
Error correction inverts the relationship. Once the correction buys more than it costs, spending more physical qubits on each logical one makes the logical qubit better, so scale starts working for you instead of against you. That inversion is the whole content of the below-threshold result, and it is what the megaquop target is counting on.
One error in a million, a hundred logical qubits, depth ten thousand
The specification is concrete enough to argue with, which is what makes it useful. Preskill puts the naive requirement at an error rate per logical gate of order one in a million, and says nobody expects to reach that without error correction and fault-tolerant operation. That is the headline number.
He immediately softens it, and the softening matters. The rate could be somewhat larger, he writes, because the field expects to keep leaning on error mitigation. That is not free. The sampling it needs grows exponentially with the size of the circuit, so mitigation moves the requirement rather than removing it.
The task he has in mind is a circuit of order a hundred logical qubits at a depth of order ten thousand. Those two numbers are what a million operations looks like when you lay it out as a computation. They also make the target checkable, because a machine either runs that circuit or it does not.
Tens of thousands of physical qubits, and a guess about atoms
What that costs in hardware is a rough guess even from him. Preskill writes that tens of thousands of high-quality physical qubits could suffice, and labels it a guess rather than an estimate. The number depends on the code, the physical error rate and how much of the machine goes on manufacturing the special states a fault-tolerant computer consumes.
The gap to today is easier to state. Two-qubit gates on Google’s Willow chip are wrong roughly once in three hundred, and the best superconducting gate reported so far, on an MIT fluxonium device, about once in 1,280. The megaquop target is one in a million per logical gate. That is three to four orders of magnitude, and error correction rather than better physical gates is what closes it. Our guide to quantum error correction sets out how.
On timing he says he does not know. He does offer a guess about hardware. If a megaquop machine arrives within a few years, he expects the modality to be Rydberg atoms held in optical tweezers, on the assumption they keep improving in both scale and performance. He notes that the more efficient codes now being discovered, the qLDPC family among them, suit tweezer arrays better than superconducting processors, at least for now.
Error suppression has to keep working as the codes grow
Three things have to hold before any of this happens, and each is less settled than the coverage suggests. The first was demonstrated in December 2024. Google reported (Nature 638, 920) that surface codes on its 105-qubit Willow processor suppressed the logical error rate by a factor of 2.14 each time the code distance rose by two, across distances three, five and seven.
That is the result the megaquop target rests on, because it is the first evidence that making a code bigger makes the encoded qubit better rather than worse. The largest version also outlived the best single physical qubit on the chip, by a factor of 2.4. Both numbers are real and both are narrower than they sound.
It has since been reproduced, which matters more than the original result. A USTC group reported below-threshold scaling on a different 107-qubit chip, at a smaller margin of 1.40 (Phys. Rev. Lett. 135, 260601). Two laboratories on two devices is a good deal more than one, and the quoted margins still measure the fit rather than what a production machine would hold.
The decoder has to keep up with the machine
The second condition is easy to overlook and hard to satisfy. A correction is worthless if it arrives after the calculation has moved on, so the classical computer working out what went wrong has to keep pace with the quantum computer producing errors.
The same Willow work decoded in real time only at code distance five. The decoder took 63 microseconds on average against an error-correction cycle of 1.1 microseconds. The distance-seven result, the one the headline rested on, was decoded after the fact rather than while the machine was running, and those are different kinds of claim that are easy to run together.
A megaquop machine runs circuits ten thousand layers deep. A decoder that falls behind by a factor of fifty every cycle does not get there, so decoding is a hardware problem in its own right rather than a detail of the analysis.
Rare correlated errors are the floor nobody has cleared
The third condition is the assumption the whole theory rests on. Error correction works because errors are supposed to arrive independently of one another, which lets a code outvote them and recover the right answer from a damaged one. Correlated errors do not merely worsen the numbers. They remove the guarantee.
The same team ran repetition codes out to distance 29 on a 72-qubit processor to find the floor. Performance there was limited by rare correlated error events happening about once an hour, and correlated errors from the two-qubit gates were the largest single item in the error budget. That finding is in the paper rather than in the coverage of it.
It is the one that would bite at megaquop scale. A machine running ten thousand layers on a hundred logical qubits is exposed to a rare event for far longer than a memory experiment is. Nothing about the below-threshold result addresses it.
Better algorithms have cut the target faster than better hardware
The clearest recent progress in this field used no new hardware at all, which is worth sitting with. Take the published estimate for factoring a 2,048-bit RSA key. It fell from 20 million noisy qubits running for eight hours (Quantum 5, 433) to under a million running for under a week (arXiv:2505.15917) in four years.
Both estimates assume the same machine. Gidney kept the square grid of qubits, the gate error rate of one in a thousand and the microsecond surface-code cycle from the earlier paper, and states so in his own abstract. The saving came from better arithmetic, from parking idle logical qubits in yoked surface codes, and from spending less area on manufacturing magic states.
That has a direct bearing on when a megaquop machine matters. If the operation count a useful problem needs keeps falling while the operation count a machine can deliver keeps rising, the two curves meet sooner than either one alone suggests. It also means a hardware roadmap is only half of any honest forecast. Our guide to post-quantum cryptography covers what defenders are doing about the other half.
Gigaquop and teraquop are the rungs above, and nobody has dated them
Preskill’s ladder is a ruler rather than a schedule. A megaquop runs a million operations, a gigaquop a billion, a teraquop a trillion, and he writes that experience with megaquop machines will guide the way to gigaquops, teraquops and beyond.
Cryptography sits well up that ladder. Factoring a 2,048-bit RSA key is estimated at roughly 2.7 billion Toffoli-equivalent operations, which is gigaquop territory rather than megaquop. A megaquop machine would not break anything. Saying otherwise is the commonest error made about the term, and our guide to the common myths takes apart at length.
He puts no year on any rung, and neither should anyone else. Anyone naming a date is offering a forecast rather than a finding, which is the same lesson the NISQ era taught the field the hard way.

Nobody can name the first useful application, including Preskill
The obvious question about a megaquop machine is what it would be for, and the honest answer is that nobody knows. Preskill puts the question to the community rather than answering it, and says so in as many words.
He does offer his own expectation. As a scientist he expects to learn valuable lessons by simulating the dynamics of many-qubit systems, particularly in two spatial dimensions and far from equilibrium. That is a scientific payoff, not a commercial one. He is careful about the difference and so should anyone quoting him.
Whether anything commercially valuable turns up at that scale he leaves open. The term marks a milestone worth aiming at, not a promise about what will be found there, and a guide that told you otherwise would be guessing.
Frequently asked questions
What is a megaquop machine?
A quantum computer able to run roughly a million quantum operations reliably, meaning with error correction working well enough that the answer survives. John Preskill proposed the term in a keynote in December 2024, and was explicit that mega means somewhere in the vicinity of a million rather than exactly a million.
Who coined the term megaquop?
John Preskill, the physicist who also coined NISQ, at a keynote in December 2017. He set out megaquop in a keynote at the Q2B conference in Silicon Valley on 11 December 2024, published the following March in ACM Transactions on Quantum Computing.
How many qubits does a megaquop machine need?
Preskill guesses that tens of thousands of high-quality physical qubits could suffice, and labels it a guess. The target he describes is a circuit of about a hundred logical qubits at a depth of about ten thousand. How many physical qubits that costs depends on the code and the physical error rate.
Would a megaquop machine break encryption?
No. Factoring a 2,048-bit RSA key is estimated at roughly 2.7 billion Toffoli-equivalent operations, which is a gigaquop machine rather than a megaquop one, a thousand times further up the scale. This is the most common misunderstanding about the term.
What comes after a megaquop?
A gigaquop machine runs a billion operations and a teraquop a trillion. At the far end Preskill describes a FASQ machine, for Fault-Tolerant Application-Scale Quantum, able to run a wide variety of useful applications, and calls that a rather distant goal.
How far is today’s hardware from a megaquop?
The best physical two-qubit gates on a superconducting chip are wrong about once in three hundred, and the megaquop target is one error in a million per logical gate. That gap is four orders of magnitude, and error correction rather than better physical gates is what closes it.




See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
