Skip to main content
Home/Topics/Mosca's inequality

Topic · Quantum risk planning

Mosca's inequality: is your data already at quantum risk?

The one-line test that turns the Q-Day debate into a planning decision, with a calculator you can run on your own systems.

By Shujaatali Badami, IEEE and ISA Senior Member · Last reviewed

Mosca's inequality says that if x + y > z, your data is at risk, where x is how long the data must stay secret, y is how long migration to post-quantum cryptography will take, and z is the time until a quantum computer can break today's public-key encryption.

Mosca's inequality calculator

Pick a preset or move the sliders. The figures are planning assumptions, not predictions. Set z to your own view of when a cryptographically relevant quantum computer arrives.

7 y
8 y
10 y

What Mosca's inequality says

Michele Mosca, co-founder of the Institute for Quantum Computing at the University of Waterloo, framed quantum risk as a simple comparison of three durations:

  • x, how long your data or keys must stay secret (the security shelf life),
  • y, how long it will take you to migrate to quantum-safe cryptography,
  • z, how long until a quantum computer can break today's public-key cryptography.

If x + y > z, you have a problem: the data you are protecting today will still matter after an adversary can decrypt it. Mosca set this out in IEEE Security & Privacy in 2018, in "Cybersecurity in an Era with Quantum Computers: Will We Be Ready?".

Why it matters more than the date of Q-Day

Public debate fixates on z, the date. Mosca's point is that z is the one term you cannot control and the one term you do not need to know precisely. If x plus y is already larger than any credible z, the planning answer is the same whether Q-Day is 2030 or 2040: start now.

That is also why harvest now, decrypt later is the right threat model. Adversaries do not need a quantum computer today. They only need to record traffic today and wait.

A worked example from industrial control

Take a water utility. Its SCADA telemetry is stale within hours, so x is close to zero and Mosca's inequality is comfortable even with a slow migration. Its engineering drawings, network topology and the keys that sign PLC firmware are different. They stay sensitive for 15 to 25 years, and OT migration cycles run 8 to 12 years because controllers are replaced on capital schedules, not software schedules. With x = 25 and y = 10, the inequality fails for any z under 35 years, and no serious estimate puts z anywhere near that.

The practical move is to rank data flows by x, not by system. That is step two of the five-step OT migration plan.

My take

For any information that has to stay confidential for a decade or more, the point of no return under Mosca's inequality has already passed. The only variable left to argue about is y, and y is the one organisations consistently underestimate.

Shujaatali Badami, quantum-IoT research engineer, Chicago

Frequently asked

What is Mosca's inequality?

Mosca's inequality is a planning rule from quantum computing researcher Michele Mosca. If x, how long data must stay secret, plus y, how long migration to quantum-safe cryptography takes, is greater than z, the time until a quantum computer can break current public-key cryptography, the data is at risk.

Is Mosca's inequality the same as Mosca's theorem?

Yes. The rule x + y > z is widely called Mosca's theorem, although it is a risk-management inequality rather than a mathematical theorem.

What value should I use for z?

Nobody knows z precisely. Use a range. Public estimates of when a cryptographically relevant quantum computer could exist mostly sit in the 2030s, with some vendors claiming earlier. The useful exercise is to check whether x plus y is larger than every credible value of z.

How long does post-quantum migration take?

For enterprise IT, several years. For industrial control systems and operational technology, 8 to 15 years is common, because controllers, HSMs and gateways are replaced on capital cycles and firmware often cannot be updated in the field.

Why does Mosca's inequality matter for harvest now, decrypt later?

Because an adversary can record encrypted traffic today and decrypt it once a quantum computer exists. If data must stay secret beyond that point, it is already exposed the moment it is captured, regardless of when Q-Day happens.

Related