Google Cloud has published an updated roadmap for migrating its infrastructure to post-quantum cryptography (PQC), targeting full readiness by 2029, with some work expected to continue into the next decade.
In March, Google announced it was speeding up its schedule for moving to PQC, setting a target of 2029 following faster-than-expected progress in quantum hardware and bug fixes.
The tech giant announced this week that the plan, built around its proprietary Quantum Threat Model, organizes work into three priority areas: mitigating Store Now Decrypt Later (SNDL) risk, strengthening digital signatures against forgery, and building the cryptographic flexibility needed to adopt new standards as they emerge.
Several important milestones have already been set. Google Cloud API endpoints, including google.com and googleapis.com, now use NIST-standardized ML-KEM key exchange in hybrid mode. Application load balancers and proxies support quantum-safe TLS 1.3 hybrid key exchange on an opt-in basis, allowing clients to validate the change in their own environment.
In addition, cloud KMS has also reached general availability for the NIST-standardized PQC algorithms covering both key exchange and digital signatures.
The roadmap sets the end of 2027 as the target for reducing SNDL risk in client-facing workloads, administration and developer tools such as Cloud VPN and Interconnect, and data transfer services including BigQuery CLI and Storage Transfer Service.
Signature integrity and identity protection have a longer path, scheduled for completion by the end of 2028. This includes quantum-resistant software supply chain attestations, implementation of quantum-safe certificates in Google’s infrastructure, and strengthening of identity mechanisms such as Cloud IAM.
Work on core key management has broadly the same goal through the end of 2028, although individual pieces are moving at different speeds: Cloud KMS is set to support quantum-safe key import as early as 2026, while hardware-backed protections such as confidential computing and Cloud HSM, along with external key management and partner-enabled key sovereignty options, are slated for 2028.
On the hardware side, Google says it’s relying on open-source silicon components, including Caliptra and OpenTitan, the latter of which already supports quantum-secure charging.
“We plan to continue these efforts into 2030 to support broader industry guidelines and evolving global standards. These standards include CNSA 2.0 and the transition paths defined in NIST IR 8547, which provide for the final retirement of legacy, quantum-vulnerable algorithms between 2030 and 2035.” Google noted.
The company makes infrastructure security its own responsibility, while customers remain responsible for updating client software, managing the lifecycle of their own encryption keys, and reconfiguring services to use quantum-safe settings as they become available.
For customers, Google recommends three initial steps: inventorying cryptographic assets such as keys and certificates, updating development and operations tools to support PQC-compliant libraries, and testing existing applications against the quantum-safe APIs and load balancers already available.
Connected: Keyfactor marks $1B+ investment for AI, post-quantum security
Connected: Trump signs executive order to accelerate migration of post-quantum cryptography
Connected: Google Reduces Quantum Resource Requirements to Crack Cryptocurrency Encryption