@filippo Quote from a paper that you cite: ", our most time-efficient architectures can potentially enable run- times of 10 days for ECC–256 with ≈ 26,000 qubits, and 97 days for RSA–2048 with ≈ 102,000 qubits" This is for one key! If all "substantial engineering challenges" are solved. It was not the scope of your post, but a broader assessment at Confidentiality, Integrity, Availability risks with some concrete estimations would help (which is maybe more a job for a IT Security Risk Manager).