Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal

Google Cloud has set a 2029 target to migrate its infrastructure to post-quantum cryptography (PQC), with some work expected to continue into the next decade. This accelerated timeline is in response to rapid advancements in quantum hardware and error correction, which have made it essential for tech giants like Google to prepare for the impending threat of quantum computers breaching current encryption methods.

The company’s plan to transition to PQC focuses on three key areas: mitigating the risk of Store Now Decrypt Later (SNDL), strengthening digital signatures against forgery, and building cryptographic agility to adopt new standards as they emerge. To this end, Google Cloud has already made significant strides in implementing post-quantum cryptography.

Several notable milestones have been reached, including the adoption of NIST-standardized ML-KEM key exchange in hybrid mode for API endpoints, such as google.com and googleapis.com. Additionally, application and proxy load balancers now support quantum-safe hybrid key exchange for TLS 1.3 on an opt-in basis, allowing customers to test the change in their own environments.

Cloud KMS has also reached general availability for NIST-standardized PQC algorithms covering both key exchange and digital signatures. This is a significant step towards ensuring that Google Cloud’s infrastructure remains secure against potential quantum attacks.

However, the company acknowledges that some aspects of its plan will require longer-term commitments. Mitigating SNDL risk across customer-facing workloads, administrative tooling, and data transfer services is targeted for completion by the end of 2027. Signature integrity and identity protections are expected to take a bit longer, with a target completion date set for the end of 2028.

Google’s decision to prioritize infrastructure security is in line with industry guidance and evolving global standards. The company has committed to anchoring trust in open source silicon components and will continue to support broader industry efforts into the 2030s. Customers are still responsible for updating client-side software, managing encryption key lifecycles, and reconfiguring services to use quantum-safe settings once available.

For customers, Google recommends a three-step approach: inventorying cryptographic assets, updating development and operations tooling, and testing existing applications against quantum-safe APIs and load balancers. By taking proactive measures to prepare for post-quantum cryptography, organizations can ensure the long-term security of their data and systems.

As the threat of quantum computers breaching current encryption methods becomes increasingly pressing, it’s essential that companies like Google take proactive steps to prepare for this new reality. The accelerated timeline set by Google Cloud serves as a model for other tech giants and organizations to follow suit in transitioning to post-quantum cryptography.


Source: SecurityWeek — 2026-08-14