Google Cloud has published an updated roadmap for migrating its infrastructure to post-quantum cryptography (PQC), targeting full readiness by 2029, with some work expected to continue into the next decade.
In March, Google announced it was moving up its timeline for transitioning to PQC, setting a 2029 target after faster-than-expected advances in quantum hardware and error correction.
The tech giant announced this week that the plan, built around its own Quantum Threat Model, organizes work into three priority areas: mitigating Store Now Decrypt Later (SNDL) risk, strengthening digital signatures against forgery, and building the cryptographic agility needed to adopt new standards as they emerge.
Several milestones are already in place. Google Cloud’s API endpoints, including google.com and googleapis.com, now use NIST-standardized ML-KEM key exchange in hybrid mode. Application and proxy load balancers support quantum-safe hybrid key exchange for TLS 1.3 on an opt-in basis, allowing customers to validate the change in their own environments.
In addition, cloud KMS has also reached general availability for NIST-standardized PQC algorithms covering both key exchange and digital signatures.
The roadmap sets end-of-2027 as the target for mitigating SNDL risk across customer-facing workloads, administrative and developer tooling such as Cloud VPN and Interconnect, and data transfer services including the BigQuery CLI and Storage Transfer Service.
Signature integrity and identity protections carry a longer runway, targeted for completion by the end of 2028. This covers quantum-resistant software supply chain attestations, the rollout of quantum-safe certificates across Google’s infrastructure, and hardening of identity mechanisms such as Cloud IAM.
Foundational key management work carries the same end-of-2028 target overall, though individual pieces move at different speeds: Cloud KMS is set to support quantum-safe key import as early as 2026, while hardware-backed protections such as confidential computing and Cloud HSM, along with external key management and partner-enabled key sovereignty options, are slated for 2028.
On the hardware side, Google says it is anchoring trust in open source silicon components, including Caliptra and OpenTitan, the latter of which already supports quantum-secure boot.
“We anticipate continuing those efforts into the 2030s to support broader industry guidance and evolving global standards. These standards include CNSA 2.0 and the transition paths defined in NIST IR 8547, which anticipate the final deprecation of legacy, quantum-vulnerable algorithms between 2030 and 2035,” Google noted.
The company frames infrastructure security as its own responsibility, while customers remain responsible for updating client-side software, managing the lifecycle of their own encryption keys, and reconfiguring services to use quantum-safe settings once available.
For customers, Google recommends three initial steps: inventorying cryptographic assets such as keys and certificates, updating development and operations tooling to support PQC-capable libraries, and testing existing applications against the quantum-safe APIs and load balancers that are already available.
Related: Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security
Related: Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration
Related: Google Slashes Quantum Resource Requirements for Breaking Cryptocurrency Encryption
