Mental model
In the previous two lessons you saw two separate pieces: Shor will break asymmetric cryptography once a CRQC arrives (a certainty), and HNDL makes today’s data vulnerable to that future break (the mechanism). Mosca’s inequality is a simple but powerful formula that reduces these two pieces to one decision rule.
In Michele Mosca’s own definition from his 2015 paper (source 1) there are three variables: X, how long the data must stay secret (your “shelf life”); Y, how long it will take to migrate your existing systems to PQC; Z, the time until a CRQC exists. The rule: if X + Y > Z, you should start worrying now.
Note: in some of this course’s early draft materials (and in some secondary sources) you may see the letters assigned the other way round (X = migration time, Y = secrecy period). Because order does not matter in addition, the math does not change, but if you cite Mosca’s own paper, match the letters to his definition: X = secrecy, Y = migration, Z = time until a CRQC.
Why the logic works
The intuition behind the formula is a simple timeline question: if you start migrating today (t=0), migration takes Y years and finishes at t=Y. But data produced today that must stay secret for X years has to be protected until t=X. If a CRQC arrives at t=Z, and the end of migration (Y) plus the last moment data is produced (roughly today, but in the worst case data produced just before migration finishes must be protected for X more years) falls after the CRQC arrives (Z), that data has been left exposed to HNDL. X+Y>Z is the simplest, rough (but useful) expression of that overlap.
Mosca himself presents the formula as a heuristic, not a rigorous mathematical proof: in the real world none of X, Y or Z is known precisely; all three are estimates. The value of the formula is not that it gives an exact answer, but that it reduces three separate uncertainties to one comparable frame.
Z: not a single date, but a range
This is the most important discipline point of this lesson. Giving a single date for Z, such as “a CRQC will arrive in 2035”, will not convince anyone who knows the subject, because nobody knows that for certain. Instead, the Global Risk Institute’s 2025 Quantum Threat Timeline report (source 2) aggregates the views of 26SOURCED experts into a probability range: a CRQC may exist within 10 years with probability 28-49%SOURCED, and within 15 years with probability 51-70%SOURCED. The range may look less precise than a single number, but it is actually more defensible: “between 28 and 49%, and here is the source” is more honest than “35%”, because the second claims false certainty.
Commercial stake note: Michele Mosca, one of this report’s authors and the author of the inequality, is also co-founder of evolutionQ, a quantum-risk consultancy. That does not invalidate the report (it is a survey of 26 independent experts, not one person’s view), but stating the relationship “the person who invented the inequality also founded a company that sells applying it” openly is part of this course’s own discipline.
How to apply it: a FOUNDATIONS example, an ADVISOR example
FOUNDATIONS (generic): you have personal data that must stay secret for 5 years (X = 5 years), and the organization’s migration capacity is 2 years (Y = 2 years). X+Y = 7 years. Even the lower bound of the Global Risk Institute’s 10-year range (28%) is a significant probability, and 7 years falls within the 10-year horizon. Result: it is reasonable to start migration planning for this data class; the urgency is moderate.
ADVISOR (a real bank data class): for a bank’s mortgage files you have to set X and Y with your own assumptions. This course deliberately does not give you a ready, universal number, because every bank’s secrecy requirements and migration capacity differ. An example frame, entirely ESTIMATED, with each assumption justified: for X, add the regulation’s minimum retention period (for example what KVKK requires) to the remaining term of the contract. If a 20-year mortgage has 15 years left and regulation requires keeping records for 10 more years after the contract ends, X ≈ 15+10 = 25 years. (This is the same magnitude as the corpus’s own pre-derived X=25yr figure, but here you see how it is computed rather than just copying it.) For Y, you need a realistic migration time estimate based on the size of the bank’s own PKI, HSM and application inventory (you will make this estimate methodical in M13); for a large Tier-1 bank 3-5 years can be a reasonable starting assumption, so say Y ≈ 4 years. X+Y ≈ 29 years, far beyond even the highest probability in the Global Risk Institute’s 15-year horizon (70%). The result is clear: migration for this data class should start now; there is nothing to debate. Using this formula without justifying your inputs in writing turns it into a black box; when a hostile architect asks “where did you get X”, your answer (step by step, as above) must be ready.
What we learned
Mosca’s inequality reduces three uncertain estimates (how long data must stay secret, how long migration takes, how much time we have) to one comparable decision. Its strength is not precision but discipline: keeping all three variables sourced and justified, and in particular carrying Z as an honest probability range rather than a single date.