Mosca’s Theorem shows when to start quantum-safe crypto

Dr. Michele Mosca’s inequality, developed to assess the timeline for quantum-safe cryptography, is now guiding organizations in their migration to post-quantum security. Mosca’s Theorem calculates when the time needed to protect data plus the time to migrate systems will exceed the arrival of a quantum computer capable of breaking current encryption.

He explained the theorem arose from recognizing a pattern: “risk mitigation moves far slower than risk creation.” On September 18, 2026, the Quantum Computing Society of the Philippines partnered with the Quantum Ecosystems & Technology Council of India to host a joint event with Mosca, signaling a growing international focus on proactive quantum security measures.

Mosca’s Theorem Defines Urgency for Quantum-Safe Transition

The event featured Dr. Michele Mosca, whose work is increasingly guiding organizations’ timelines for adopting post-quantum cryptography, and provided a platform to discuss practical applications of his theorem. Mosca, currently a professor at the University of Waterloo and CEO of evolutionQ, has spent over three decades bridging the communication gap between cryptography and quantum computing experts.

The theorem frames the challenge as a race against time, comparing the lifespan of data needing protection (X) with the time required for system upgrades (Y) against the estimated arrival of a cryptographically relevant quantum computer (Z). Mosca explained that if the sum of X and Y exceeds Z, an organization is already vulnerable, highlighting a critical need for proactive planning.

Questions from the audience during the live Q&A session explored the theorem’s connection to Q-Day preparedness, the role of frameworks like OWASP in quantum security testing, and the potential of technologies beyond post-quantum cryptography and quantum key distribution, such as multi-party computation and homomorphic encryption. QCSP is also taking a long-term approach, moving “upstream” to introduce quantum and computing concepts in high school and elementary school curricula, expanding beyond university-level programs and train-the-trainer initiatives.

From Classical Cryptanalysis to Quantum Security Translation

Michele Mosca marked the first international partnership for QETCI and extended its Quantum Pulse series beyond India’s borders. This collaboration, held on September 18, 2026, connected audiences in both countries via Zoom and YouTube, demonstrating a growing effort to share quantum security expertise globally. Mosca’s participation highlighted a shift in his own perspective, evolving from initial skepticism towards quantum computing to a decades-long role bridging the cryptography and quantum computing fields.

Mosca’s experience reveals a recurring pattern in security, where emerging threats are often overlooked until they begin to materialize, as security professionals focus on immediate concerns while technology developers prioritize innovation. He explained that this dynamic highlights the urgency of proactive measures in quantum security, particularly given the substantial investments currently flowing into quantum networking technologies.

Mosca noted that entanglement-based protocols offer a potentially more straightforward path to validation against physical security assumptions, even as prepare-and-measure quantum key distribution methods continue to advance. Mosca described his work as translating the complexities of quantum computing for the cryptographic community, a role he has fulfilled for over 30 years. This proactive approach aims to cultivate a future workforce prepared for the challenges and opportunities presented by quantum technologies, ensuring a more robust and adaptable quantum ecosystem.

Four Organizational Postures Facing Quantum Cybersecurity Threats

Five years ago, many organizations adopted a posture, but Mosca now cautions against complacency given the accelerating development of quantum computing capabilities. He also describes encompassing activities like proofs of concept and cryptographic inventories that, while appearing diligent, often fail to translate into effective risk reduction. Mosca specifically warned against using these inventories as justification for delay, noting organizations are already aware of their most critical dependencies, such as firmware signing processes.

Conversely, Mosca stated there is no evidence suggesting quantum computing will universally enhance artificial intelligence, though he anticipates benefits in specific computational components. Regarding the potential for AI-assisted quantum attacks, he asserted that preparedness on the defensive side is paramount, and the necessary solutions are already known. To improve security, Mosca advocates for stronger vendor disclosure requirements and collaborative exercises between penetration testers and cryptographers, repeating realistic attack simulations until consistent scenarios emerge.

He draws a parallel to the evolution of other technologies, predicting a progression where attackers first replicate existing methods before innovating new playbooks. Mosca also highlighted that much of the work required for quantum security does not necessitate deep expertise in quantum physics, but rather focuses on effectively communicating risk to leadership and managing organizational change, stating, “Cybersecurity or quantum first?” He believes translating risk for executives and boards is often the most challenging aspect of the transition. “Because broken cryptography is invisible to the victim,” Mosca called for increased accountability and proactive testing to ensure robust defenses.

AI’s Asymmetrical Role in Advancing Quantum Computing & Attacks

This collaboration signals a growing international focus on coordinating quantum security strategies, particularly as the timelines for transitioning to cryptography become clearer. Mosca’s Theorem puts the problem in terms of timing: if the time your data must stay confidential (X) plus the time your systems need to migrate (Y) exceeds the time until a cryptographically relevant quantum computer arrives (Z), you are already in trouble.

He said he came up with it as a way to reach a small group of people who protect long-lived, high-impact assets, and that he never expected it to be so widely adopted. In a Q&An answer he added that the shelf life and migration time are largely within an organization’s control, while the likelihood and impact of an attack feed into a normal risk assessment. Organizations with low risk tolerance and very high impact should act first.

Mosca described four postures that governments and organizations take: Wait and see, where nearly everyone was five years ago, and quantum readiness theater, which is many activities, such as proofs of concept and a cryptographic inventory, that never become a serious mitigation program.

Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of The Quant

The Quant

The Quant possesses over two decades of experience in start-up ventures and financial arenas, brings a unique and insightful perspective to the quantum computing sector. This extensive background combines the agility and innovation typical of start-up environments with the rigor and analytical depth required in finance. Such a blend of skills is particularly valuable in understanding and navigating the complex, rapidly evolving landscape of quantum computing and quantum technology marketplaces. The quantum technology marketplace is burgeoning, with immense growth potential. This expansion is not just limited to the technology itself but extends to a wide array of applications in different industries, including finance, healthcare, logistics, and more.

Latest Posts by The Quant: