Google Cloud has published a post-quantum cryptography (PQC) roadmap aimed at migrating its infrastructure to protect against future quantum computer threats. The tech giant is targeting full readiness by 2029, with some work expected to continue into the next decade.
The rapid advancement of quantum hardware and error correction has forced Google to accelerate its timeline for transitioning to PQC. In March, the company announced it was moving up its deadline to adopt post-quantum cryptography, and this week’s updated roadmap outlines the scope of the effort. The plan is built around Google’s Quantum Threat Model, which organizes work into three priority areas: mitigating Store Now Decrypt Later (SNDL) risk, strengthening digital signatures against forgery, and building cryptographic agility to adopt new standards as they emerge.
Several key milestones are already in place. For example, Google Cloud’s API endpoints now use NIST-standardized ML-KEM key exchange in hybrid mode, while application and proxy load balancers support quantum-safe hybrid key exchange for TLS 1.3 on an opt-in basis. Additionally, cloud KMS has reached general availability for NIST-standardized PQC algorithms covering both key exchange and digital signatures.
The roadmap sets specific targets for various components of the infrastructure. By the end of 2027, Google Cloud aims to mitigate SNDL risk across customer-facing workloads, administrative and developer tooling, as well as data transfer services. Signature integrity and identity protections are expected to be completed by the end of 2028, covering quantum-resistant software supply chain attestations, the rollout of quantum-safe certificates across Google’s infrastructure, and hardening of identity mechanisms such as Cloud IAM.
On the hardware side, Google is anchoring trust in open source silicon components, including Caliptra and OpenTitan. The company notes that it will continue efforts into the 2030s to support broader industry guidance and evolving global standards, which include CNSA 2.0 and the transition paths defined in NIST IR 8547.
Google emphasizes that infrastructure security is its own responsibility, while customers remain responsible for updating client-side software, managing the lifecycle of their own encryption keys, and reconfiguring services to use quantum-safe settings once available. For customers, Google recommends three initial steps: inventorying cryptographic assets such as keys and certificates, updating development and operations tooling to support PQC-capable libraries, and testing existing applications against the quantum-safe APIs and load balancers that are already available.
In practical terms, this means that users of Google Cloud services should start preparing for post-quantum cryptography by assessing their current cryptographic assets, updating their tools and software to support PQC, and testing their applications against the new standards. By taking proactive steps now, organizations can ensure a smooth transition to post-quantum cryptography and maintain the security of their data in the face of emerging quantum threats.
Source: SecurityWeek — 2026-08-14