top of page

Mosca’s Theorem: The Equation That Tells You When to Start Post-Quantum Migration

Writer: Brian Couzens
Brian Couzens
2 minutes ago
4 min read
Mosca’s Theorem explaining the X plus Y greater than Z post-quantum cryptography risk equation

Post-quantum cryptography is often discussed as a future technical programme. That framing is too comfortable.

The question for boards, security leaders and technology executives is not whether a cryptographically relevant quantum computer will arrive on a particular date. The question is whether the organisation’s sensitive data will remain protected for as long as it needs to be, given the time required to change the cryptography that protects it.

Michele Mosca’s risk inequality provides a direct way to assess that question.

X + Y > Z

It is simple enough to fit on a slide. Its implications are not.

If the equation holds, an organisation may be unable to protect data for the period it requires. The post-quantum migration programme is already late, even if the quantum computer capable of breaking current public-key cryptography does not yet exist.

What do X, Y and Z mean?

Mosca’s framework uses three time horizons.

X: Security shelf-life

X is the period for which information must remain confidential.

For some data, this could be weeks or months. For other data, it may be years or decades. Think of personal data subject to regulatory obligations, long-term commercial contracts, merger and acquisition material, sensitive government information, healthcare records, source code, intellectual property and strategic research.

The question is not simply whether the data matters today. It is whether disclosure in the future would still cause harm.

Y: Migration time

Y is the time required to migrate cryptographic systems to quantum-safe alternatives.

This is not a software update. Migration can involve discovering where public-key cryptography is used; identifying dependencies in applications, infrastructure, protocols, cloud platforms and third-party products; engaging suppliers; testing interoperability; updating certificates and key-management processes; deploying new configurations; and validating that security controls still operate as intended.

NIST highlights both cryptographic inventory and crypto-agility as central foundations for post-quantum migration. An organisation cannot effectively prioritise what it has not identified, and it cannot adapt quickly where cryptography is hard-coded into applications and infrastructure.

For a complex enterprise, Y can be a multi-year programme.

Z: Collapse time

Z is the estimated time until a quantum computer, or another cryptanalytic advance, can break the public-key cryptography on which current systems depend.

This includes widely deployed approaches based on RSA, elliptic curve cryptography and Diffie-Hellman. A cryptographically relevant quantum computer could use Shor’s algorithm to undermine the mathematical assumptions that protect these systems.

Z is not a known date. It is an uncertain planning horizon. That uncertainty is precisely why organisations should avoid treating it as a reason to wait.

The inequality that changes the conversation

When:

X + Y > Z

the time required to protect information and complete the migration is longer than the estimated time remaining before the current cryptography becomes vulnerable.

The organisation has a problem.

Consider a simple example:

  • Sensitive records must remain confidential for 10 years. X = 10

  • The organisation estimates that discovery, planning, supplier engagement, testing and deployment will take 4 years. Y = 4

  • The estimated point at which quantum capability could threaten current public-key cryptography is 7 years away. Z = 7

The calculation is:

10 + 4 > 7

The organisation needs 14 years of protection and transition time but has only 7 years before the projected cryptographic risk materialises.

Waiting for certainty does not improve the calculation. It worsens Y and shortens the available margin.

Why “harvest now, decrypt later” matters

Mosca’s Theorem matters because quantum risk is not confined to the day a quantum computer becomes capable of breaking RSA or ECC.

An adversary can collect encrypted traffic, files and records today, retain them, and attempt decryption later when the necessary capability becomes available. This is known as harvest now, decrypt later.

For data with a long confidentiality requirement, the threat therefore exists now. The encrypted material may be secure against current adversaries while still being exposed to future compromise.

The relevant decision is not whether a quantum computer can decrypt the information today. It is whether the information would still have value when it can be decrypted.


What leaders should do now

Mosca’s Theorem does not provide a precise Q-Day prediction. It provides a decision framework for dealing with uncertainty.

A credible response starts with five actions:

  1. Classify long-lived data. Identify information that must remain confidential beyond the organisation’s plausible migration horizon.

  2. Build and maintain a cryptographic inventory. Map where public-key cryptography is used across applications, services, devices, data flows, certificates, protocols, libraries and third-party dependencies. NIST describes this visibility as a basis for managing cryptographic risk and preparing for PQC migration.

  3. Estimate migration time honestly. Include discovery, remediation, procurement, supplier roadmaps, technical testing, operational deployment and assurance. Do not assume an algorithm change is a simple upgrade.

  4. Prioritise by business and exposure risk. Start with sensitive long-life data, externally exposed services, critical trust relationships, systems with weak crypto-agility and dependencies that may be difficult to replace.

  5. Build cryptographic agility. Design systems, governance and supplier requirements so that cryptographic algorithms, keys, libraries and protocols can be changed without a complete redesign. NIST notes that many existing systems were not built to support rapid cryptographic adaptation.


The strategic point

The value of Mosca’s Theorem is not the arithmetic. It is the discipline it imposes.

It forces leaders to replace vague questions about when quantum computing will arrive with a more practical question:

Given the confidentiality life of our data and the time needed to migrate, are we already behind?

For organisations holding data with long-term sensitivity, the answer may be uncomfortable.

The move to post-quantum cryptography is not a one-off replacement project. It is an enterprise risk, architecture, supplier-management and governance challenge. The organisations that begin by understanding X, Y and Z will have options. Those that postpone the work until Z becomes clear may discover that their available time has already disappeared.


Closing line

Quantum risk is often framed as a problem for tomorrow. Mosca’s Theorem explains why, for long-lived data and complex technology estates, the migration decision belongs to today.








 
 
 

Comments


bottom of page