Q-Day Is Coming: The Encryption Race Against Time
Quantum computers powerful enough to break widely used public-key cryptography — a threshold commonly called “Q-Day” — could arrive before 2030, according to projections cited by Singapore’s defence officials. For a digital economy that runs on financial services, ports, and pharmaceutical manufacturing, the implications are existential. Every encrypted transaction, every secured communication, every protected database depends on cryptographic foundations that quantum computing threatens to demolish.
Military Expert 7 Guo Jinghua of Singapore’s Digital and Intelligence Service framed it bluntly: “It’s a case of fighting fire with fire,” noting that defence organisations are turning to quantum communications even as they explore the technology’s computational potential.
The SIT-IBM Quantum-Safe Centre
In August 2026, the Singapore Institute of Technology and IBM announced plans to establish the Quantum-Safe Centre at SIT’s Punggol Campus, targeted for launch by the end of 2026. The centre will serve as a dedicated hub to accelerate Singapore’s transition to quantum-safe cybersecurity, assessing cybersecurity risks posed by future quantum computing threats.
Beyond risk assessment, the partnership addresses the skills gap in post-quantum cryptography through two Continuing Education and Training programs. These cover post-quantum cryptography fundamentals, enterprise migration planning, cryptographic risk discovery, governance, and security architecture modernization.
CSA’s National Quantum-Safe Architecture
The Cyber Security Agency of Singapore (CSA) has taken a regulatory approach to the quantum threat. CSA released a Quantum-Safe Migration Handbook and a Quantum Readiness Index — first for public consultation from October to December 2025, then as a finalized version in July 2026. Critical Information Infrastructure (CII) providers must submit comprehensive plans for migrating to quantum-safe cryptography by March 2027, with full system migration required by the end of 2031.
This timeline is among the most aggressive national quantum-safe migration deadlines globally, reflecting Singapore’s assessment that the “harvest now, decrypt later” threat — where adversaries collect encrypted data today for future decryption — demands immediate action.
The Financial Sector’s Quantum Risk
The Monetary Authority of Singapore has been particularly proactive. MAS has flagged the “harvest now, decrypt later” threat as directly relevant to Singapore’s financial services sector, where long-lived data confidentiality is essential. Financial institutions are being urged to inventory their cryptographic dependencies, assess quantum vulnerability, and begin migration planning well before Q-Day arrives.
A Broader Ecosystem Response
The quantum-safe push extends beyond government mandates. Quantinuum’s first wave of partners in Singapore includes Squareroot8, a homegrown startup formed in 2020 that develops quantum cryptography technology. The two firms signed a memorandum of understanding in March 2026 to co-develop quantum communications solutions. This partnership exemplifies how Singapore’s quantum ecosystem is developing defensively as well as computationally — building capabilities to protect the very digital infrastructure that quantum computing could undermine.
