Is RSA-4096 Quantum Safe?
No. RSA-4096 is not quantum safe. A larger modulus raises classical attack cost but does not remove Shor's polynomial-time quantum attack; exact fault-tolerant resources depend on the implementation assumptions.
Key Takeaway: RSA-4096 is NOT quantum safe. Do not rely on larger RSA keys as a quantum mitigation. Migrate to ML-KEM (FIPS 203) for key exchange and ML-DSA (FIPS 204) for signatures.
- Modality
- Encryption
- Key size
- 4096 bits
- Vulnerability
- Shor's polynomial-time factoring algorithm applies to RSA at every standardized modulus size; exact fault-tolerant resources are architecture-dependent.
- NIST status
- NIST IR 8547 is an initial public draft describing proposed federal transition horizons for affected RSA uses.
- Replaced by
- ML-KEM (FIPS 203) for key exchange, ML-DSA (FIPS 204) for signatures
- Deprecation
- No universal commercial date. NIST IR 8547 remains an initial public draft; CNSA 2.0 dates are scoped to NSS and related contexts.
Technical Analysis
RSA-4096 is NOT quantum safe.
How RSA-4096 Works
RSA-4096 uses the same algorithm as RSA-2048 with a larger modulus. It raises classical attack cost and typically increases key generation, signature, certificate, and handshake overhead; the performance delta is implementation- and workload-specific.
A larger RSA modulus provides greater classical security margin, but neither RSA-2048 nor RSA-4096 is a post-quantum construction. Calendar-time estimates for classical factoring are model-dependent and are not used here as evidence.
However, this classical security improvement creates a false sense of quantum security. Many compliance frameworks and security checklists recommend "use RSA-4096 for long-term security" without acknowledging that quantum computers invalidate this guidance entirely.
Quantum Vulnerability Explained
Shor's algorithm has polynomial complexity in RSA modulus length, so increasing the modulus does not create post-quantum resistance. Precise logical-qubit, gate-count, and runtime estimates vary across published architectures and error-correction assumptions.
A machine capable of attacking RSA-2048 would still require additional resources to attack RSA-4096, but the larger key changes the resource requirement rather than the underlying post-quantum verdict. No verified evidence supports assigning a calendar gap between those capabilities.
Furthermore, RSA-4096's larger key size introduces operational risks without quantum benefits: larger keys increase TLS handshake latency (critical for web performance), bloat certificate sizes (problematic for embedded devices and IoT), and consume more CPU cycles (higher cloud infrastructure costs). Organizations deploying RSA-4096 today as a "quantum mitigation" are paying performance penalties for no meaningful security gain against quantum adversaries.
Migration Path
Do not deploy RSA-4096 as a quantum security strategy — it is not quantum-safe. Instead, migrate directly to NIST-standardized post-quantum algorithms:
- ML-KEM (FIPS 203): Select a parameter set through the applicable key-establishment profile. NIST security categories are comparison targets, not direct bit-security or performance guarantees.
- ML-DSA (FIPS 204): Select a parameter set through the approved signature profile, then benchmark the final encoding, signer, verifier, hardware boundary, and workload.
- Transition constructions: Use only specified key-establishment or signature profiles with defined combiners, validation, negotiation, and failure behavior. Ad hoc algorithm pairing does not prove security or compatibility.
Avoid "upgrading" from RSA-2048 to RSA-4096 as a post-quantum strategy. The performance costs are real; the quantum security benefits are illusory.
Industries at Risk
CNSA 2.0 transition requirements apply to National Security Systems and associated acquisition or interoperability contexts. NSA's December 2024 FAQ calls for CNSA 2.0-compliant new NSS acquisitions in 2027, phaseout of non-supporting equipment and services by the end of 2030 unless otherwise noted, and CNSA 2.0 use by the end of 2031 unless otherwise noted.
Long-lived trust anchors and signing keys deserve early inventory because their replacement cycles can exceed those of leaf certificates. Their transition must follow the applicable certificate profile, relying-party support, and tested chain-validation behavior; validity dates alone do not predict a quantum break.
NIST IR 8547 is an initial public draft intended to inform transition planning. It does not supersede final standards merely by publication, and final or application-specific guidance governs each deployment context.
Timeline to Obsolescence
- 2025-2026: RSA-4096 offers no quantum security advantage over RSA-2048. Begin PQC migration planning.
- 2029: Treat as a readiness/control date for completing funded migration plans before external CRQC timing becomes operational risk.
- 2030: Within CNSA 2.0's NSS scope, equipment and services unable to support CNSA 2.0 are to be phased out unless otherwise noted.
- 2035: NIST IR 8547's initial public draft proposes a federal disallowance planning horizon for affected RSA uses; it is not a predicted break date.
Do not treat a larger RSA modulus as a post-quantum control. Classify the actual RSA use and migrate through the supported application profile selected for that key-establishment or signature path.
At a glance
| Full Name | RSA with 4096-bit keys |
| Category | encryption |
| Key Size | 4096 bits |
| Quantum Vulnerability | Shor's polynomial-time factoring algorithm applies to RSA at every standardized modulus size; exact fault-tolerant resources are architecture-dependent. |
| NIST Status | NIST IR 8547 is an initial public draft describing proposed federal transition horizons for affected RSA uses. |
| Deprecation Timeline | No universal commercial date. NIST IR 8547 remains an initial public draft; CNSA 2.0 dates are scoped to NSS and related contexts. |
| Replaced By | ML-KEM (FIPS 203) for key exchange, ML-DSA (FIPS 204) for signatures |
Evidence scope
Algorithm-level classification. Standards status and known cryptanalysis are separated from implementation, module-validation, protocol-composition, key-management, and policy evidence.
Evidence-scope review: 2026-07-10
- NIST finalized PQC standards (opens in new tab)Final standards · FIPS 203, 204, and 205
- NIST IR 8547 (opens in new tab)Initial public draft · proposed federal transition approach
- NSA CNSA 2.0 FAQ (opens in new tab)NSS scope · not a directive to entities outside NSS
- NIST SP 800-131A Rev. 2 (opens in new tab)Final guidance · transitioning cryptographic algorithms and key lengths
Migration Guidance
Do not rely on larger RSA keys as a quantum mitigation. Migrate to ML-KEM (FIPS 203) for key exchange and ML-DSA (FIPS 204) for signatures.
How Qtonic Quantum Can Help
Don’t Know Where RSA-4096 Lives in Your Stack?
QScout discovers instances of RSA-4096 across your infrastructure within the approved engagement window — designed to minimize operational disruption. First-findings timing is set during operator scoping.