up:: Quantum Computing MOC

The Two Qubit Questions

The two qubit questions are a two-part test to run on any qubit number put in front of you, in a headline, a board deck, or a vendor pitch: “Is that a physical qubit count or a logical one?” and “What year is the resource estimate you’re comparing it against?” The opening question checks the number’s units, because published counts are nearly always physical qubits, hardware components rather than attack capability, which is measured in error-corrected logical qubits. The follow-up checks the benchmark’s vintage, because the machine required to break RSA-2048 shrank from about 20 million noisy qubits in the 2019 estimate to under a million in the 2025 revision. Together the answers tell you whether the number means anything, in under a minute, without a physics degree.

The short version:

  • Question 1: “Is that a physical qubit count or a logical one?” The answer is nearly always physical, and physical counts measure hardware progress while logical qubits measure attack capability.
  • Question 2: “What year is the resource estimate you’re comparing it against?” A 20-million-qubit benchmark is the 2019 paper; the same author’s 2025 revision puts RSA-2048 at under a million noisy qubits, a 20-fold cut achieved on paper with no new hardware.
  • Put the questions to whoever put the number in the deck, the head of architecture or the vendor, and leave the security team out of it. The presenter owes you the number’s units.
  • The benchmark is also probably the wrong target: a 256-bit elliptic curve falls to a machine under half a million physical qubits, smaller than the RSA machine, and elliptic curves handle the key exchange in most TLS handshakes today.
  • The output is a read on whether the number matters at all, plus a defensible position anchored in the annual expert survey (28 to 49% odds of a break within 10 years, 2025 edition) rather than in anyone’s headline.

Picture a colleague telling you a used car costs “40,000” and calling it a steal. Before you agree, you’d ask two things: 40,000 in which currency, and a steal compared to which price guide, this year’s edition or one from 2019? A number with unstated units and a stale benchmark sounds precise while carrying no information, and every qubit headline has exactly those two failure points. The two qubit questions are the currency check and the edition check, applied to quantum hardware.

The framework

For any qubit number offered as evidence, of urgency or of safety, ask two questions, in these words:

  1. “Is that a physical qubit count or a logical one?” This is the units check. A physical qubit is a single noisy hardware component; a logical qubit is a reliable, error-corrected qubit assembled from hundreds to thousands of physical ones. Cryptanalysis runs on logical qubits, and vendor announcements count physical ones nearly every time, so most headline numbers describe hardware inventory rather than capability.
  2. “What year is the resource estimate you’re comparing it against?” This is the vintage check. Any qubit count only becomes a risk statement when it’s compared against how many qubits an attack needs, and that requirement is a moving research result. The 2019 estimate for RSA-2048 was about 20 million noisy qubits; the 2025 revision, by the same lead author under identical hardware assumptions, is under a million. An argument built on the 2019 figure is measuring you against a benchmark that’s already fallen more than 20-fold.

Direct the questions at whoever put the number in the deck: the head of architecture, the vendor, the author of the memo. The security team inherits numbers other people choose, so asking them produces a shrug, while asking the presenter produces either the units and the source, which is what you wanted, or the discovery that the number was decoration, which is also what you wanted.

The framework applies whenever a specific qubit count is doing persuasive work: a chip announcement framed as a countdown, a vendor slide framed as a margin of safety, a board member’s forwarded headline. It reads one number at a time and stops there. It produces a verdict on that number, and the timeline still comes from the expert survey and the resource-estimation literature, which is where the questions point you next. And on one class of machine, quantum annealers, the first question has no meaningful answer at all, which is covered below in where the questions break.

Why is the first question about physical versus logical qubits?

Because the two counts differ by a factor of hundreds to thousands, and only one of them appears in headlines. A physical qubit is one piece of quantum hardware, and it’s noisy: left alone it loses its state in a fraction of a second, and every operation on it carries a meaningful error chance. A logical qubit is built by spreading one qubit’s worth of information across a large block of physical qubits and running quantum error correction on top, so the group behaves like a single qubit that almost never errs. Under the leading surface-code scheme, one logical qubit reliable enough for a deep cryptographic computation costs on the order of a thousand or more physical qubits.

Source: Austin G. Fowler, Matteo Mariantoni, John M. Martinis, Andrew N. Cleland, “Surface codes: Towards practical large-scale quantum computation,” Physical Review A 86, 032324, 2012, arXiv:1208.0928.

The overhead is a measured reality now rather than a projection. Google’s 2024 below-threshold demonstration used 101 physical qubits to protect a single logical one, and the milestone was that adding physical qubits lowered the logical error rate instead of raising it. That result produced exactly 1 logical qubit, and breaking RSA-2048 takes roughly 6,100 of them in the most-cited construction.

Source: Rajeev Acharya et al. (Google Quantum AI), “Quantum error correction below the surface code threshold,” Nature 638, 920-926, 2025, arXiv:2408.13687.

Source: Craig Gidney and Martin Ekerå, “How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits,” Quantum 5, 433, 2021, arXiv:1905.09749.

Now put a real headline through that arithmetic. The largest superconducting processors as of 2026 hold physical qubits in the low thousands, with IBM’s Condor at 1,121, and those are noisy and uncorrected. At today’s error rates, a machine that size holds zero cryptographically useful logical qubits, so a record-setting chip announcement is genuine hardware news that says almost nothing about your keys. That gap is the entire reason the first question exists: it forces the presenter to state which of the two units their number is in, and the answer is nearly always the one that measures inventory rather than capability. The full treatment of the distinction lives in Logical vs Physical Qubits.

Source: IEEE Spectrum, “An IBM Quantum Computer Will Soon Pass the 1,000-Qubit Mark,” spectrum.ieee.org.

Why does the year of the resource estimate matter?

Because the requirement side of the comparison has been falling fast, on paper, while everyone watches the hardware side climb. A qubit count only turns into a risk claim when someone compares it against how many qubits an attack needs, and that requirement is a live research result with a publication date. Citing the requirement without its year is like citing a price without saying which edition of the price guide it came from.

Here is the timeline the second question interrogates, as of mid-2026:

YearEstimateTargetLogical qubitsPhysical qubitsRuntime
2017Roetteler, Naehrig, Svore, Lauter (arXiv:1706.06752)256-bit elliptic curve~2,330millions after error correctiondays-scale
2019Gidney and Ekerå (arXiv:1905.09749, published Quantum, 2021)RSA-2048~6,100~20 million noisy8 hours
2025Gidney (arXiv:2505.15917)RSA-2048not statedunder 1 million noisyunder 1 week
2026Google Quantum AI, Ethereum Foundation, Stanford (whitepaper, 30 Mar 2026)256-bit elliptic curve (secp256k1)1,200 to 1,450fewer than half a million18 to 23 minutes

Three things in that table carry the whole argument:

  1. The 20-fold cut happened on paper. The 2025 RSA revision keeps every hardware assumption of the 2019 paper, a square grid of qubits with nearest-neighbor connections, a 0.1% gate error rate, a 1-microsecond surface-code cycle, and still cuts the machine by more than 20 times, crediting approximate residue arithmetic, yoked surface codes, and magic state cultivation. The requirement moved because the algorithms and the error correction got smarter, with no new hardware involved, and that class of improvement keeps arriving.
  2. RSA is probably the wrong target for the comparison anyway. Elliptic-curve keys are almost an order of magnitude smaller than RSA keys at a similar security level, which means a smaller quantum computer breaks them, and elliptic curves handle the key exchange in most TLS handshakes today (ECDH and its curves). The 2026 whitepaper puts a 256-bit curve at 1,200 to 1,450 logical qubits and fewer than half a million physical qubits running for minutes, against under a million for RSA-2048 running for days. The earliest-falling half of the estate is the elliptic-curve half, so a margin computed against RSA overstates the time you have even when the estimate is current.
  3. The falling requirement will never be a headline. It happens in papers rather than press releases, and the 2026 team even validated its circuit sizes with a zero-knowledge proof instead of publishing the attack, in the interest of responsible disclosure. So the number in the news is always the climbing one, and the number that sets the deadline is the quiet one. The second question is how you check which one you’re being shown, and the deeper literature lives in Quantum Resource Estimation and Shor’s Algorithm.

Source: Craig Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits,” 2025, arXiv:2505.15917.

Source: Ryan Babbush, Adam Zalcman, Craig Gidney, Michael Broughton, Tanuj Khattar, Hartmut Neven (Google Quantum AI), Thiago Bergamaschi, Justin Drake (Ethereum Foundation), Dan Boneh (Stanford), “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations,” 30 March 2026, quantumai.google.

Who do you put the questions to?

The person who put the number in the deck: the head of architecture if it’s an internal memo, the vendor if it’s a pitch, the author if it’s a forwarded article. Whoever chose to present a qubit count as evidence owes you its units and its benchmark, and both questions are answerable by anyone who actually understood the number they used. Keep the security team out of the exchange, because they didn’t pick the number and asking them to defend it just relocates the confusion.

Delivered plainly, the questions are a units check rather than a gotcha. A presenter who knows the material answers both in a sentence and the conversation gets sharper. A presenter who can’t answer either has told you the number was rhetorical, which quietly ends that number’s role in the decision.

What do the questions look like on a real number?

Run them end to end on a realistic vendor slide, the kind that shows up in a quarterly briefing: “Leading processors have passed 1,100 qubits and roadmaps point to 10,000 within a few years. With 20 million qubits needed to break RSA, the quantum threat remains decades out, and our platform will keep you ahead of it.”

Question 1: “Is that a physical qubit count or a logical one?” Both of the slide’s hardware numbers are physical. The 1,100-qubit figure is IBM’s Condor class of processor, and those qubits are noisy and uncorrected, so the machine holds zero logical qubits of the kind Shor’s algorithm needs. The 10,000-qubit roadmap is also physical, and at hundreds to thousands of physical qubits per logical one, 10,000 physical qubits buys perhaps a handful of logical qubits against the roughly 6,100 that RSA-2048 requires. So the left half of the slide is real hardware progress that carries no attack capability.

Question 2: “What year is the resource estimate you’re comparing it against?” The slide’s 20-million figure is the 2019 Gidney and Ekerå estimate. The current figure from the same lead author is under a million noisy qubits (arXiv:2505.15917), so the slide’s margin of safety is inflated by a factor of 20. And the benchmark targets the wrong algorithm besides: the 2026 Google Quantum AI estimate puts a 256-bit elliptic curve, the cryptography negotiating most TLS key exchange, at fewer than half a million physical qubits running for minutes. The “decades out” conclusion was computed from a stale requirement against the slower-falling target.

The output, in under a minute: the slide’s qubit numbers are real and its risk conclusion doesn’t follow from them. Hardware sits at thousands of noisy physical qubits, the requirement has fallen to under a million for RSA and under half a million for ECC, and the planning input is the expert survey: the 2025 Quantum Threat Timeline puts the odds of a machine breaking RSA-2048 within 10 years at 28 to 49%, up sharply from 19 to 34% one edition earlier. You walk out with a sourced probability and its direction instead of a vendor’s adjective.

Source: Mosca, M. and Piani, M., Quantum Threat Timeline Report 2025 (26 experts, published 9 March 2026), Global Risk Institute / evolutionQ, globalriskinstitute.org.

Common misconceptions

  • “The qubit count is a countdown, and every record is a step closer to broken keys.” The record counts physical qubits, and capability is gated by error rates and demonstrated error correction rather than by raw width. A wider chip with the same noisy gates moves the cryptographic clock very little, which is why reading quantum progress starts with quality rather than quantity.

  • “RSA-2048 is the benchmark to watch.” The smaller machine arrives first, and the smaller machine breaks elliptic curves: 1,200 to 1,450 logical qubits and under half a million physical, against roughly 6,100 logical for RSA. ECC carries most TLS key exchange, so the earliest-falling cryptography is the half doing the most work.

  • “Quoting the low end of the expert range is the conservative move.” It’s the opposite. The 2025 survey’s 28% floor comes from reading every expert’s likelihood bin at its bottom edge, and the 49% ceiling from the top edge, so carrying 28% into a board deck is the rosiest available reading. Prudent planning prices the top of the range, because that’s where the cost of being wrong sits.

  • “A verified quantum advantage will be the starting gun.” Cryptanalysis needs one specific algorithm at sufficient scale rather than a general advantage certificate, and the two milestones are independent. The first hardware key recovery against Even-Mansour constructions ran on an IBM processor in 2026, at 3- and 4-bit toy scale, while no fully verified quantum advantage claim stood anywhere. Waiting for the advantage announcement means watching the wrong track.

    Source: Anina Köhler, Jakob Murauer, Tim Heine, Stefan Rosemann, Tobias Hemmert, “Simon’s Algorithm for the Even-Mansour Cipher on Quantum Hardware,” 2026, arXiv:2604.25509.

  • “The estimate dropped 20-fold, so the machine got 20 times closer.” The drop happened on paper, under fixed hardware assumptions, and it shrank the machine an attacker must eventually build rather than the machine anyone has. The two curves move separately, hardware climbing and the requirement falling, and the questions exist precisely to keep them from being conflated in either direction.

  • “If the vendor answers ‘logical qubits,’ the conversation is over.” A logical-qubit claim has its own units problem: the logical error rate achieved and the physical-per-logical overhead paid. One logical qubit demonstrated at modest depth is a milestone; thousands of them at cryptographic depth is the threat. The follow-up below handles it.

Pro tips

  1. Pull the survey yourself, annually. The Quantum Threat Timeline is public, annual, and free from the Global Risk Institute, and reading the range plus its direction takes 10 minutes. A vendor summarizing it for you is a translation layer you don’t need, and the year-over-year movement, 19-to-34% jumping to 28-to-49% in a single edition, is more informative than any single number in it.
  2. When the answer to question 1 is “logical,” ask the overhead. The follow-up, in one sentence: “How many physical qubits per logical qubit, and at what logical error rate?” A genuine logical-qubit result quotes both, the way Google’s below-threshold paper quotes 101 physical per logical. An evasive answer converts the claim back into a physical count wearing better branding.
  3. Ask which target the estimate is for. RSA-2048 and 256-bit ECC are different machines with different arrival orders, and the smaller one, the ECC machine, sets the earlier date. An estimate that never names its target algorithm hasn’t finished being a number yet.
  4. Date-stamp every benchmark in your risk register. Record the estimate the current risk position was computed against, by author and year (“Gidney 2025, under 1M physical, RSA-2048”), so next year’s review can see at a glance whether the benchmark went stale underneath the register.
  5. When there’s no benchmark at all, the number carries no risk content. A raw count compared against nothing is an inventory fact about someone’s lab. The burden of turning it into a risk statement belongs to whoever presented it, and question 2 is how you hand that burden back politely.
  6. Track the falling curve deliberately. The papers that move the deadline publish on arXiv without press cycles, so pair the annual survey pull with a look at the current resource-estimation state of the art. The 2019-to-2025 revision is the proof that the quiet track is the one that moves.

Where do the two questions break?

The framework’s honest limits, stated up front:

  1. Quantum annealers run on different qubit semantics entirely. A D-Wave machine advertises thousands of qubits, and the first question has no meaningful answer there, because annealing qubits are analog optimization elements rather than gate-model physical qubits on the road to logical ones. An annealer can’t run Shor’s algorithm at any count, so the right question for that machine is architectural, gate-model or annealer, and the full story lives in Quantum Annealing and the D-Wave Question.
  2. The questions read one number; they don’t produce a timeline. They tell you whether a specific count means anything, and the planning inputs still come from the expert survey and the resource-estimation literature. A clean pass through both questions leaves you with a calibrated number, and what to do about it is a separate decision.
  3. A well-formed logical claim passes instantly, and the work moves to the follow-ups. As logical-qubit demonstrations mature, more announcements will answer question 1 correctly, and the discriminating questions become the overhead, the logical error rate, and the sustained circuit depth. The framework stays useful there as the opener rather than the whole conversation.
  4. Exotic architectures blur the physical count itself. Photonic and other measurement-based designs can quote qubit numbers that count time-multiplexed or networked modes, which stretches what “physical qubit” means. The invariant that survives every architecture is error-corrected logical capacity at depth, which is where question 1’s follow-ups land you anyway.

How do you use the two questions in a boardroom?

Deploy them upward, in the meeting where the number appears. When a director forwards a headline or a vendor’s slide claims a margin of safety, ask the two questions of the person presenting, in those words, and frame them as a units check on the evidence rather than a challenge to the presenter. The exchange takes under a minute, and it repositions you as the person in the room who knows what the numbers are denominated in, which is a durable kind of authority in a topic full of adjectives.

Carry two lines in for the follow-through. For question 1: “physical counts measure hardware progress, and attack capability is measured in logical qubits, which today’s machines hold approximately none of.” For question 2: “if the benchmark is 20 million qubits, we’re being measured against a 2019 paper whose figure has since fallen 20-fold.” Then close with the defensible position: the current expert survey puts a 10-year break at 28 to 49% and rising, so the plan prices lead time against our own data’s shelf life instead of anyone’s forecast date, which is the reasoning Mosca’s theorem formalizes. Every piece of that is checkable from public sources, which is what makes it survive a skeptical room.

Questions people ask

Do I need a physics background to use the two questions? No. The first question is a units check and the second is a publication-date check, and both are answerable, or conspicuously unanswerable, by whoever presented the number. The physics behind them lives in Logical vs Physical Qubits if you want it, and the framework works without it.

What answer should I expect to the first question? “Physical,” nearly every time, and vendors mean physical unless they explicitly claim otherwise. The interesting outcomes are the rare “logical” answer, which earns the overhead follow-up, and a blank stare, which tells you the number was decoration.

What’s the current best answer to the second question? As of mid-2026, RSA-2048 stands at under a million noisy physical qubits running under a week (Gidney 2025, arXiv:2505.15917), and a 256-bit elliptic curve at fewer than half a million physical qubits running for minutes (Google Quantum AI, Ethereum Foundation, and Stanford, March 2026). Any comparison quoting 20 million qubits is running on the superseded 2019 figure.

Why do the questions go to the head of architecture or the vendor instead of the security team? Because accountability follows authorship. The presenter chose the number and owes you its units and benchmark, while the security team inherits whatever number the deck carries. Asking the author also creates the right incentive: numbers stop appearing in decks unless someone can defend them.

What if the presenter can’t answer either question? That result is the finding. A qubit count whose own presenter can’t state its units or benchmark was persuasion rather than evidence, and it exits the decision without anyone needing to argue about quantum physics.

Does a big qubit number ever matter? Yes, when it arrives with the things that make it capability: a gate error rate below the error-correction threshold, demonstrated logical qubits whose error rate falls as the code grows, and sustained depth. A number wearing those credentials deserves attention, and the questions are how you find out whether it has them.

Do the questions work on a D-Wave announcement? No, and that’s by design. Annealer qubits are a different object doing a different job, and no count of them moves the cryptographic clock, so the questions would flatter the number by taking its units seriously. The one question that matters there is whether the machine is gate-model at all.

Where do I pull the sources myself? The Quantum Threat Timeline from the Global Risk Institute (globalriskinstitute.org), the RSA estimates from arXiv (1905.09749 and 2505.15917), and the ECC estimate from the Google Quantum AI whitepaper (quantumai.google). All public, all citable in a deck without anyone’s interpretation in between.


Everything here is the map, given freely, and the two questions are yours to run on the next number that reaches your desk. The version quantified against your own estate, which algorithms guard which of your systems, and which falling estimate governs each of them, is the work I do. Request the workshop.

Last verified 2026-08-02 · Updated 2026-08-25 · Maintained by Addie LaMarr, LaMarr Labs.