Many years away. A good guestimate is that you need 1M physical qubits factor numbers fast.
Also, there is classical public-key cryptography (i.e. encryption algorithms that run efficiently on today's classical computers) that is not susceptible to quantum computers. And symmetric cryptography has never been susceptible to quantum computers.
Also, there is classical public-key cryptography (i.e. encryption algorithms that run efficiently on today's classical computers) that is not susceptible to quantum computers. And symmetric cryptography has never been susceptible to quantum computers.