What is the Mosca inequality?
The Mosca inequality is a simple risk formula, introduced by cryptographer Michele Mosca, that tells you whether your organization is already too late to protect its data from quantum computers. It compares three time spans: how long your data must stay secret (X), how long your quantum migration will take (Y), and how long until a quantum computer can break your encryption (Z). The rule is stark: if X + Y > Z, you are already too late.
What makes the formula powerful is that it reframes the entire quantum question. Instead of the unanswerable "when will quantum computers arrive?", it asks the answerable "does my data outlive my ability to protect it?", a question you can actually reason about using facts you already know about your own data and your own organization. It converts an intimidating, uncertain future into a concrete planning decision.
How does the formula work?
Break it into the three variables and the logic becomes intuitive. X is shelf-life: how long data must stay confidential, for example 10 years for medical, financial, or IP data. Y is migration time: how long it takes to become quantum-safe, often around 5 years across a large enterprise. And Z is the threat horizon: the time until a quantum computer breaks your cryptography, which is uncertain, perhaps 10 to 15 years.
Here is why X and Y add together. If your data must stay secret for 10 years (X), and your migration will take 5 years to complete (Y), then to have that data protected for its full confidentiality period you need to finish migrating 10 years before a quantum computer exists, which means you must start 15 years before. If a cryptographically relevant quantum computer might appear in 10 to 15 years (Z), the arithmetic already fails for your most sensitive data. You needed to have started already.
Why does data shelf-life change everything?
Because of the harvest-now-decrypt-later threat, the clock starts today: not when quantum computers arrive. Adversaries can capture encrypted data now, store it cheaply, and decrypt it the moment a capable quantum computer exists. So for any information that must remain confidential for years (health records, financial data, state secrets, trade secrets, intellectual property, long-term contracts) the exposure has already begun, even though the decryption is still in the future.
This is the insight that catches many leaders off guard. The instinct is to treat quantum as a distant problem to address when it gets closer. But the longer your X, the more urgent your migration, regardless of how far off Z might be. Data with a 25-year confidentiality requirement encrypted with today's algorithms is, in a real sense, already compromised the moment it is harvested: the decryption is just pending.
How do enterprises apply the Mosca inequality?
Turn it into a prioritization exercise rather than a single yes/no verdict. Estimate the shelf-life (X) of each major category of data you hold, and it will vary widely, which is the point. Estimate your realistic migration time (Y), which for a large organization is usually measured in years once you account for discovery, testing, and coordination. Use a conservative threat horizon (Z), erring toward "sooner" given the uncertainty. Then, for each data category, check whether X + Y approaches or exceeds Z. Wherever it does, that data is a migration priority now.
This calculation depends entirely on knowing what cryptography protects what data, which is exactly what a cryptographic bill of materials provides. Without that mapping, you can state the formula but not apply it. With it, the Mosca inequality becomes a practical triage tool that tells you where to spend your migration effort first.
What's the value of a formula built on an uncertain number?
It is fair to ask how a formula can be useful when Z (the arrival of a quantum computer) is genuinely unknown. The answer is that you do not need to predict Z precisely. You only need to see that, for your longest-lived data, the numbers already don't add up under any reasonable estimate. If X is 20 years and Y is 5, then even an optimistic Z of 15 years means you are late. The uncertainty in Z doesn't rescue you; it just widens the range of scenarios in which you are already behind.
That is the quiet power of Mosca's framing: it makes an uncertain future actionable by anchoring the decision to things you do know (your data's sensitivity and your organization's pace of change) rather than to a quantum timeline no one can pin down.
What should you do if X + Y > Z for your data?
Start migrating that data's cryptography now, in priority order, toward the NIST post-quantum standards. Being "too late" by the formula does not mean giving up: it means your highest-sensitivity data needs quantum-safe protection immediately, and every year of delay increases exposure. Focus first on the categories where X is longest and the data most valuable. The organizations that run this calculation honestly are the ones that start early enough for it to matter; the ones that avoid it are usually the ones the inequality was warning.




