Key Takeaways
- Researchers propose QLOPS (Quantum Logical Operations Per Second) as the first unified benchmarking metric for fault-tolerant quantum computing (FTQC) hardware, integrating error-correction code rates, decoder accuracy, decoder throughput, and decoder latency into a single comparable score.
- RSA-2048 factoring serves as the validation benchmark in the framework (arXiv:2507.12024v2), meaning QLOPS is explicitly calibrated against the encryption standard protecting the majority of enterprise TLS, VPN, and PKI infrastructure today.
- Organizations that wait for a “definitive” quantum threat timeline before beginning PQC migration are making a strategic error — QLOPS is the instrument that will shorten that warning window, and it is being built now.
Last updated: July 2025
The Measurement Problem That Keeps Your RSA Keys Alive — For Now
Picture your security architecture team in a procurement meeting, evaluating two quantum computing platforms from competing vendors. Both claim fault-tolerant operation. Both publish qubit counts. Neither provides a number that tells you how close either machine is to breaking RSA-2048.
That gap — the absence of a standardized, cryptographically meaningful performance metric for fault-tolerant quantum hardware — is precisely what a research team addressed in a paper published on arXiv in July 2025 (arXiv:2507.12024v2). Their proposed solution is QLOPS: Quantum Logical Operations Per Second.
For enterprise security leaders, QLOPS matters not because it signals imminent danger, but because it closes the information asymmetry that currently makes quantum risk planning feel like guesswork. When QLOPS benchmarks become available for real hardware platforms, CISOs will have, for the first time, a vendor-neutral number they can track quarter over quarter — the same way they track CVE severity scores or patch compliance rates.
[IMAGE: A fault-tolerant quantum processor array with entangled photon beams connecting logic gate nodes, rendered in deep black with cyan and teal light traces, macro lens perspective, 8K cinematic quality]
What QLOPS Actually Measures — and Why the Components Matter
QLOPS (Quantum Logical Operations Per Second) is a proposed benchmarking metric for fault-tolerant quantum computing hardware that integrates four interdependent performance dimensions into a single comparable figure: the code rate of the quantum error-correcting code in use, the accuracy of the classical decoder processing error syndromes, the throughput of that decoder, and its latency. The metric is designed to reflect the practical execution requirements of real quantum algorithms — not idealized laboratory conditions.
The distinction from existing metrics is significant. Physical qubit counts, which dominate vendor marketing, measure raw hardware scale but say nothing about whether those qubits can sustain the logical operations required to run Shor’s algorithm against a 2048-bit RSA key. Gate fidelity percentages, similarly, describe individual operation quality without capturing system-level throughput under error-correction overhead.
QLOPS collapses these separate dimensions into a single operational figure. As the authors state:
“Through a resource analysis of factoring RSA-2048, we demonstrate that QLOPS reflects the practical requirements of quantum algorithm execution.”
For a CISO, the translation is direct: QLOPS is the metric that connects quantum hardware progress to your specific cryptographic attack surface.
The Four Pillars of the QLOPS Framework
Code rate determines how many physical qubits are required per logical qubit. Lower code rates mean more physical overhead — a machine with 10,000 physical qubits but a poor code rate may support far fewer logical operations than a 5,000-qubit machine with an efficient error-correcting code.
Decoder accuracy measures how reliably the classical processing layer identifies and corrects quantum errors. An inaccurate decoder compounds errors rather than suppressing them, making fault-tolerant computation impossible regardless of qubit count.
Decoder throughput captures how many error syndromes the classical system can process per second. A quantum processor that generates errors faster than its decoder can process them creates a backlog that halts computation — a bottleneck invisible to qubit-count metrics.
Decoder latency measures the delay between error occurrence and correction. High latency allows errors to propagate across logical qubits before correction, degrading the effective logical error rate of the entire system.
The QLOPS framework integrates all four. A hardware platform that scores well on qubit count but poorly on decoder throughput will produce a low QLOPS figure — accurately reflecting its inability to execute cryptographically relevant algorithms at scale.
QLOPS vs. Current Quantum Benchmarking Approaches
| Metric | What It Measures | Cryptographic Relevance | Bottleneck Visibility |
|---|---|---|---|
| Physical Qubit Count | Raw hardware scale | Low — ignores error correction overhead | None |
| Gate Fidelity (%) | Individual operation accuracy | Partial — single-gate, not system-level | Partial |
| Quantum Volume | Circuit depth × width under noise | Moderate — hardware-agnostic but limited scope | Low |
| Circuit Layer Operations Per Second (CLOPS) | Sampling throughput for variational circuits | Low for FTQC — targets NISQ workloads | Low |
| QLOPS (Proposed) | Logical operations per second under full error correction | High — calibrated against RSA-2048 factoring | High — exposes decoder bottlenecks explicitly |
The research team explicitly identifies the absence of a comprehensive FTQC evaluation framework as a gap in the field at the time of publication. QLOPS is designed to fill that gap by enabling comparative evaluation across different FTQC schemes running on different hardware platforms — something no existing metric supports at the logical operation level.
Why RSA-2048 Is the Right Benchmark — and What That Signals
The choice to validate QLOPS against RSA-2048 factoring is not arbitrary. RSA-2048 is the encryption standard underpinning the majority of enterprise PKI infrastructure, TLS certificate chains, code-signing pipelines, and VPN authentication systems. It is the specific target that makes a quantum computer cryptographically relevant rather than merely scientifically interesting.
By anchoring QLOPS to RSA-2048 resource requirements, the framework produces benchmarks that map directly to the question security leaders actually need answered: how far is current hardware from the capability threshold that threatens our encryption?
The research does not provide a specific timeline for when any existing platform will reach that threshold — the paper’s abstract does not include numerical QLOPS scores for specific hardware, and no qubit counts, error rates, or decoder specifications for evaluated platforms are disclosed. This is a meaningful data gap. The framework’s value at this stage is structural: it establishes the measurement methodology before the race accelerates, not after.
The absence of QLOPS scores for named hardware platforms in the current publication means the metric’s immediate utility is in procurement evaluation criteria and internal risk modeling — not in declaring a specific threat date. That changes as vendors adopt the framework.
Regulatory and Market Context: The Compliance Clock Is Already Running
NIST finalized its first three post-quantum cryptographic standards in August 2024 — ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205). Federal agencies operating under OMB memoranda face migration mandates with active deadlines. The financial sector is receiving parallel guidance from regulators in the EU under DORA and from the UK’s FCA, both of which reference quantum risk in their operational resilience frameworks.
The compliance burden is not theoretical. Organizations that have not begun cryptographic inventory — cataloguing which systems use RSA-2048, elliptic curve Diffie-Hellman, or other quantum-vulnerable algorithms — are already behind the remediation curve that regulators expect.
QLOPS accelerates this urgency in a specific way: it gives the threat a measurable velocity. When hardware vendors begin publishing QLOPS scores, the question shifts from “will quantum computers break RSA?” (answered: yes, eventually) to “at what rate is QLOPS improving, and does that rate outpace our migration timeline?” That is a question security teams can model, budget against, and escalate to boards.
Organizations currently treating PQC migration as a 5-to-10-year horizon project face a structural risk: QLOPS-driven hardware benchmarking may compress that timeline without warning, and “harvest now, decrypt later” attacks — where adversaries collect encrypted data today for decryption once quantum capability arrives — are already a documented threat vector requiring no future hardware at all.
The BeQuantum Perspective: Benchmarks Without Migration Plans Are Just Numbers
At BeQuantum, we track FTQC progress precisely because our Digital Notary and PQC Layer infrastructure must be calibrated against realistic threat timelines, not worst-case speculation or vendor optimism.
The QLOPS framework represents the kind of standardization that makes our work — and our clients’ security planning — more rigorous. Here is what that means in practice:
When a CISO uses BeQuantum’s PQC Layer to negotiate ML-KEM key exchanges alongside legacy RSA sessions during a hybrid migration period, the question they are implicitly answering is: “How long do I need this hybrid mode to run before I can deprecate RSA entirely?” QLOPS, once populated with real hardware data, feeds directly into that calculation.
Our IceCase hardware security module architecture is designed around the assumption that cryptographic agility — the ability to swap algorithms without re-engineering the surrounding infrastructure — is non-negotiable. QLOPS benchmarks will eventually tell organizations exactly which algorithm families need to rotate first, based on which are most efficiently attacked by the highest-scoring hardware platforms.
The organizations that will navigate this transition with the least disruption are those building cryptographic agility into their infrastructure now, before QLOPS scores for named platforms start appearing in vendor datasheets and threat intelligence feeds.
What Your Security Team Should Do in the Next 90 Days
Step 1: Complete a cryptographic asset inventory (Days 1–30) Audit every system in your environment that uses RSA-2048, ECDH, or ECDSA for key exchange or digital signatures. Prioritize systems with data retention periods exceeding five years — these are your highest harvest-now-decrypt-later exposure. Tools like network traffic analysis and certificate transparency log queries can accelerate discovery.
Step 2: Establish a QLOPS monitoring brief (Days 30–60) Assign a member of your security architecture team to track QLOPS-related publications and hardware vendor announcements. Set a threshold: if any publicly benchmarked hardware platform reaches a QLOPS score that the research community associates with RSA-2048 factoring feasibility, your migration timeline compresses immediately. You need a pre-defined response plan before that data exists, not after.
Step 3: Begin hybrid PQC deployment on your highest-risk TLS endpoints (Days 60–90) NIST-standardized ML-KEM is available in OpenSSL 3.x and is supported in current versions of BoringSSL (used by Chrome and Android). Deploy hybrid key exchange — ML-KEM + ECDH — on external-facing endpoints handling sensitive data. This provides quantum resistance without breaking compatibility with clients that have not yet migrated, and it satisfies the “crypto-agility” requirement appearing in emerging regulatory guidance.
FAQ
Q: Does QLOPS mean quantum computers can already break RSA-2048? A: No. QLOPS is a proposed benchmarking framework, not a capability announcement. The research uses RSA-2048 factoring as a validation target to ensure the metric reflects cryptographically meaningful workloads — not to report that any existing hardware has achieved that capability. No specific QLOPS scores for named hardware platforms are published in the current paper.
Q: How is QLOPS different from quantum volume, which vendors already publish? A: Quantum volume measures the largest random circuit a device can execute with greater than 2/3 probability of success — a useful NISQ-era metric that does not account for fault-tolerant error correction overhead. QLOPS specifically targets fault-tolerant quantum computing performance, integrating error-correcting code rates and decoder performance into the benchmark. For cryptographic threat modeling, QLOPS is the more relevant metric because Shor’s algorithm requires fault-tolerant, not NISQ, hardware.
Q: Should we wait for QLOPS scores before starting PQC migration? A: No. Harvest-now-decrypt-later attacks require no quantum hardware on the attacker’s side today — adversaries collect ciphertext now and decrypt it when capability arrives. Any data encrypted with RSA-2048 today that must remain confidential for more than three to five years is already at risk under this threat model. NIST standards are finalized and implementation libraries are production-ready. Migration should begin immediately, independent of QLOPS timeline data.
Sources: “Benchmarking fault-tolerant quantum computing hardware via QLOPS” — arXiv:2507.12024v2