What Willow Actually Did, and Why You Should Take It Seriously
In December 2024, Google DeepMind announced the Willow quantum chip, and the internet promptly split into two camps: those who panicked and those who dismissed it as academic theater. Neither response is quite right, but understanding what Willow actually accomplished matters if you’re responsible for any system that needs to remain secure past 2030.
Here’s what happened in technical terms. Willow solved a specific benchmark computation in under five minutes. The same problem would take today’s most powerful classical supercomputers approximately 10 septillion years to complete. That’s a number so large it stops meaning anything to human intuition, but the ratio itself is what matters. This wasn’t a theoretical exercise. The chip physically ran and completed a task in microseconds that represents exponential centuries of serial computation.
But the real story isn’t the speed result. Any sufficiently powerful quantum system solving a carefully chosen problem will eventually outrun classical hardware. What made Willow worth paying attention to was something more fundamental: it demonstrated what quantum engineers call below-threshold error correction. Willow achieved this with 105 qubits by proving that adding more qubits actually reduced errors rather than amplifying them. This is the milestone everyone in the field has been chasing for fifteen years. It means Willow didn’t just solve a hard problem faster. It proved that the path to building quantum computers that won’t destroy themselves with noise is physically real.
Why Quantum Speed Threatens Everything You’ve Built
Let’s talk about RSA encryption, which protects most internet traffic today and locks down the majority of sensitive data at rest in enterprise systems. RSA’s security depends on a mathematical truth: multiplying two large prime numbers together is easy, but factoring the result back into those primes is so computationally hard that no classical computer, given any reasonable amount of time, could do it. This asymmetry has been the bedrock of digital trust for decades.
A sufficiently powerful quantum computer, running Shor’s algorithm, breaks that asymmetry. It can factor those large numbers efficiently. Not eventually. Not in a thousand years. Efficiently, within hours or days, on hardware that might exist in five to ten years. The implications reach every layer of infrastructure: your HTTPS handshakes, your certificate authorities, your SSH keys, your VPN tunnels, your code signing, your database encryption, your regulatory compliance.
This is not a distant threat. The timeline has teeth. Adversaries with nation-state resources are believed to be harvesting encrypted traffic right now, storing it in bulk, waiting for quantum computers powerful enough to decrypt it retroactively. That data might be proprietary source code, customer databases, security audit findings, or strategic communications. The year someone harvests it is the year it all becomes readable. Willow doesn’t make that year next week, but it moves the needle. It proves the path works.
The Migration Hasn’t Started, But the Deadline is Real
In August 2024, the National Institute of Standards and Technology finalized its first three post-quantum cryptography standards: ML-KEM (built on CRYSTALS-Kyber), ML-DSA (built on CRYSTALS-Dilithium), and SLH-DSA (built on SPHINCS+). These are concrete, vetted alternatives to RSA and elliptic-curve cryptography. They’re not theoretical. They’re not proposals. They’re federal standards, which means they’re the reference frame for every government contractor and, eventually, for anyone who wants to sell systems to the government. You can review the NIST post-quantum cryptography standards announcement directly.
The NSA hardened the deadline further in 2022 when it released Commercial National Security Algorithm Suite 2.0, requiring migration to post-quantum algorithms by 2030 for all national security systems. That’s six years from now. For contractors working on defense, intelligence, or critical infrastructure projects, that’s not a suggestion. It’s a compliance mandate with teeth. Miss it and you lose contracts. Worse, your systems might lose certification entirely.
Yet here’s what the January 2025 Ponemon Institute survey found: only 18% of enterprise security teams had begun a formal inventory of their cryptographic assets. That’s the bare minimum prerequisite for migration. You cannot move to post-quantum encryption if you don’t know where your encryption lives. Eighteen percent means 82% of enterprises have done essentially nothing.
What “Migration” Actually Means in Your Infrastructure
This is where the conversation gets uncomfortable, because migration isn’t a software patch you install on a Tuesday and move forward. It’s a systematic replacement of cryptographic foundations across systems that were often built a decade ago and have been reinforced by a thousand dependencies since.
Start with the inventory problem. Where does encryption happen in your environment? Load balancers terminating TLS. APIs issuing JWT tokens. Databases using transparent data encryption. Code signing pipelines. Certificate authorities. Hardware security modules. Message queues. The list sprawls. Each one uses cryptographic primitives. Each one will need to be evaluated, tested with post-quantum algorithms, and replaced or updated.
Then there’s the interoperability problem. You can’t unilaterally migrate everything. You have suppliers. You have partners. You have legacy systems running on hardware that might not support the computational overhead of post-quantum algorithms efficiently. Some embedded systems, older IoT devices, or specialized appliances might be cryptographically locked in. You’ll need hybrid approaches, running classical and post-quantum algorithms in parallel for years. That’s cost. That’s complexity. That’s surface area for mistakes.
The timeline gets compressed further by supply chain dynamics. If your organization is competing for resources and expertise with thousands of other enterprises all trying to migrate simultaneously, prices go up. Talent gets scarce. Projects slip. This is already happening in the compliance consulting space.
What You Should Do Monday Morning
Willow is real, but it’s not an emergency. It’s a signal that the timeline is contracting faster than most organizations realize. The quantum threat isn’t imminent, but the migration work is.
Start with the inventory. Work with your security team, your infrastructure teams, your application owners. Map where cryptography actually lives. Document everything. Prioritize assets that protect the most sensitive data or have the longest operational lifespans. Get it organized somewhere you can actually act on it.
Then run a pilot with post-quantum algorithms. Take a non-critical system. Test ML-KEM or ML-DSA. Measure performance. Document integration challenges. Gather real data about whether post-quantum cryptography introduces operational friction your organization needs to solve for before you’re doing this under deadline pressure.
Budget for this work. The compliance deadline of 2030 for national security systems is six years away, but the practical deadline for large-scale migration is closer. If you’re starting from zero now, you’re already behind. If you’ve been moving incrementally, you’re in a reasonable position to accelerate.
The Willow announcement mattered because it proved quantum computing’s path is real, not because it broke your encryption tomorrow. But it removed one layer of speculation from the timeline. The work of replacing that encryption is yours to do today. What’s the current state of your cryptographic inventory? And more importantly, what’s stopped you from making it a priority until now?