Skip to content

This blog was first published in 2024 and has been updated.

Can quantum computers break RSA encryption? Not in any practical, real-world sense today. Quantum computing does pose a future risk to public-key cryptography, but claims that today’s quantum computers can break modern RSA encryption need important context.

First, it’s important to clarify that RSA encryption is a public cryptographic standard, not an RSA Security product. The algorithm is associated with our founders and shares its name with our company, but it is a public standard (FIPS 186-5) and not owned by, or affiliated with, RSA Security.

Because RSA encryption helps secure digital communications across the web, quantum risk deserves serious planning. But security leaders also need to keep today’s risks in focus, including credential theft, weak MFA coverage, social engineering, unmanaged access, and the growing threat posed by AI..

What is RSA encryption?

RSA encryption is a public-key cryptography method used to help secure digital communications. RSA stands for Rivest, Shamir, and Adleman, the three researchers who introduced the algorithm in 1977.

The RSA algorithm uses a public key to encrypt information or verify a digital signature, and a private key to decrypt information or create that signature. This model helps two systems establish trust without first sharing a secret key.

That makes RSA encryption important for secure web connections, digital certificates, authentication protocols, software signatures, and other cybersecurity functions that depend on trusted communication.

Can quantum computers break RSA encryption?

Quantum computers could eventually threaten some widely used public-key cryptography systems, including RSA encryption. But that does not mean today’s quantum computers can break modern RSA encryption in practical cybersecurity environments.

The basis of many recent concerns  is a May 2024 paper published by researchers at Shanghai University that demonstrates a method for factoring integers up to 50 bits in length using an innovative combination of quantum and classical algorithms and techniques. Since RSA encryption is based, in part, on the computational difficulty of factoring large prime numbers, some have speculated that these techniques could be extrapolated to eventually break the algorithm.

After some alarmist early headlines about the story, a few outlets corrected  the record. In Forbes, Craig Smith wrote that the process outlined by Shanghai University “represents incremental steps rather than a paradigm-shifting breakthrough that renders current cryptographic standards obsolete.” In The Quantum Insider,  Matt Swayne noted that while the process “represents a technical milestone, it is far removed from cracking the highly secure encryption algorithms commonly used in military and financial systems today.”

That distinction matters. Research progress is important, but factoring a small integer in an academic setting is not the same as breaking the 2048-bit RSA encryption used in real-world systems.

Why 2048-bit RSA encryption is not the same as a 50-bit factoring test

The problem with the claims described above  is that factoring a 50-bit integer is a far cry from breaking the 2048-bit encryption used in modern implementations of the RSA algorithm. But just how far is difficult for the human brain to fathom since encryption strength increases exponentially with key length.

For illustrative purposes, imagine a suitcase with a three-digit lock and 1,000 possible combinations. Add just one more dial and complexity increases tenfold to 10,000 combinations. Now imagine a suitcase with 2,048 dials. Even with binary bits, the number becomes so large that the methods demonstrated in this paper would take many times the age of our universe to find a solution. Threat actors tend to have shorter deadlines.

That exponential growth is why 2048-bit encryption cannot be compared directly to a 50-bit factoring demonstration. The research may show that quantum and classical techniques are advancing, but it does not show that current RSA encryption has been broken.

Is quantum computing a near-term cybersecurity threat?

Although the field continues to make steady advances, it’s important to note that quantum computing is still limited by major engineering challenges  and faces many daunting technical challenges before practical application of the technology will be possible. Researchers have estimated that breaking a single 2048-bit RSA key would require a large-scale, fault-tolerant quantum computer with millions of physical qubits. Current quantum systems are not close to that level of practical cryptographic capability. 

Moreover, the latest methods documented by Shanghai University researchers involve a combination of quantum and classical computing techniques. Until this dependency on classical techniques is eliminated, this method will reach its physical limits long before it can scale to 2048 bits.

For security leaders, the takeaway is straightforward: quantum computing is worth planning for, but it should not be treated as an immediate crisis. The quantum computers available today do not have the practical cryptographic capability needed to break 2048-bit RSA encryption in real-world use.

What organizations should do about quantum computing now

While quantum computing may not represent a near-term threat, organizations should not ignore it. The National Institute of Standards and Technology (NIST) first asked the public for strategies to create post-quantum cryptography standards in 2016 and finalized its first three post-quantum cryptography standards in 2024: FIPS 203, FIPS 204, and FIPS 205. NIST is also continuing work on additional post-quantum standards, including FIPS 206.

That is the right model for organizations to follow: prepare deliberately, without treating quantum computing as an immediate crisis. Security teams should monitor NIST guidance, understand where quantum-vulnerable cryptography exists in their environments, and plan for future migration to post-quantum cryptography.

In the meantime, NIST has also said that 2048-bit RSA keys should continue to offer sufficient protection through at least 2030. Organizations should continue following best practices for key length and key rotation to keep their encryption secure.

Beyond that, the RSA algorithm already provides a built-in solution through extended key lengths. While 2048-bit keys are in common use today, modern web browsers already support larger 4096-bit keys should the need arise.

For most organizations, the practical next steps are clear:

  • Inventory where public-key cryptography is used across applications, infrastructure, cloud services, certificates, and third-party systems.
  • Track NIST post-quantum cryptography standards and vendor migration guidance.
  • Maintain strong key management, rotation, and certificate lifecycle practices.
  • Avoid rushing into untested cryptographic changes without a clear risk model.
  • Prioritize security controls that reduce active risk today, especially identity-based attacks.
Why identity security is the more immediate cybersecurity risk

Quantum computing deserves long-term attention, but most organizations face more immediate cybersecurity risks from identity-based attacks. Cybercriminals do not need quantum computers to compromise users, bypass weak controls, or exploit unmanaged access.

Change Healthcare was compromised by stolen credentials and didn’t have MFA enabled on some of its accounts. Scattered Spider convinced IT help desk staff to disable or reset MFA credentials in order to launch a ransomware attack. And Colonial Pipeline was breached in part due to an orphaned VPN account.

Quantum computing requires massive funding and resources. These data breaches did not. Instead, they relied on classic exploits like social engineering, password-based authentication, and organizations not keeping track of who has access to what. Those are the risks that demand organizations’ attention and action, not quantum computing.

That is why identity security remains central to enterprise cybersecurity. Strong MFA, passwordless authentication, access governance, lifecycle controls, and zero trust IAM help organizations reduce the risks attackers are actively exploiting now.

Encryption helps protect digital trust. Identity security helps determine who gets access, under what conditions, and whether that access remains appropriate over time. Organizations need both, but identity is where many attackers are finding success today.

Prepare for quantum risk, but prioritize today’s threats

Quantum computing may eventually change how organizations protect encrypted communications, digital signatures, and other cryptographic systems. That’s why security leaders should follow post-quantum cryptography standards and start planning for long-term migration.

But there’s no need to borrow trouble. RSA encryption has not been broken by today’s quantum computers, and the most urgent cybersecurity risks are already here. Organizations should prepare for quantum risk while strengthening the identity controls that protect users, applications, data, and critical systems now.

RSA ID Plus helps organizations strengthen secure access with MFA, passwordless authentication, and resilient authentication capabilities across cloud, hybrid, and on-premises environments, And RSA ID Plus Sovereign Deployment enables them to incorporate full-stack identity and access management capabilities across private cloud, on-premises, and air-gapped environments. .Explore these RSA solutions to see how stronger identity controls can help reduce the risks attackers are exploiting today.

RSA encryption and quantum computing frequently asked questions
Can quantum computers break RSA encryption?

Quantum computers cannot break RSA encryption in any practical, real-world sense today. Future quantum computers may threaten RSA encryption, but current quantum systems cannot break modern RSA encryption.

How many qubits would it take to break RSA encryption?

Breaking RSA encryption would likely require millions of physical qubits. The exact number depends on error correction, hardware quality, algorithm design, and implementation details.

Is 2048-bit RSA encryption still secure?

2048-bit RSA encryption is still considered secure for current real-world use. Organizations should continue following key management, key rotation, and cryptographic planning best practices.

Is RSA encryption the same as RSA Security?

RSA encryption is not the same as RSA Security. RSA encryption is a public cryptographic standard named after Rivest, Shamir, and Adleman, while RSA Security is a cybersecurity company.

What should organizations do about quantum computing now?

Organizations should prepare for quantum computing by inventorying cryptography, monitoring NIST post-quantum standards, and prioritizing today’s identity-based risks. The right approach is planning, not panic.

Never Trust, Always Verify

Zero Trust starts with identity. See how RSA helps you verify every user and every access request, without slowing your business down.
Explore Zero Trust Solutions