Video companion
After Michele Mosca: Mosca inequality for your board
Michele Mosca co-founded the Institute for Quantum Computing and evolutionQ. His public lectures frame the quantum threat as a call to modernize how organizations manage cryptography.

What the video gets right
Mosca emphasizes that preparing for quantum computers makes infrastructure more agile — not just quantum-safe, but able to swap algorithms when any crypto threat emerges. The threat to RSA and ECC is real; the fix is a decade-plus process already underway through NIST PQC standardization.
His X + Y > Z framework (detailed in the Global Risk Institute report) turns HNDL into a planning formula:
- X = years data must stay confidential
- Y = years to migrate
- Z = years until a CRQC breaks your algorithms
When X + Y exceeds Z, you have exposure now. See also PostQuantum.com on HNDL.
What it does not cover
Boards need quantified exposure per data class, not just the inequality. Inventory must tag which assets protect long-shelf-life records.
This quarter
- Run Mosca inputs on the interactive calculator.
- Present X, Y, Z assumptions to your risk committee with explicit data retention policies.
- Start external TLS inventory with algorithm tags and re-scan cadence.
Continue on the Q-Day hub: Mosca inequality guide
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- Michele Mosca: As We Enter a New Quantum EraPerimeter Institute (YouTube) · 2015Michele Mosca on quantum threats to cryptography, crypto-agility, and preparing cyber infrastructure.
- Quantum Threat Timeline Report (Mosca inequality)Global Risk Institute · 2023Dr. Michele Mosca's X + Y > Z framework for harvest-now-decrypt-later exposure planning.
- What Is Harvest Now, Decrypt Later (HNDL)?PostQuantum.com · 2024Mosca theorem, HNDL urgency, and why migration must start before Q-Day headlines.
- What Is Post-Quantum Cryptography?NIST · 2024Official overview of NIST's PQC project, finalized standards, and the harvest-now-decrypt-later threat model.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.