Google Cloud publishes post-quantum roadmap for 2029

Google Cloud released an updated roadmap to migrate infrastructure to post-quantum cryptography, targeting full readiness by 2029 and noting some work may extend into the 2030s.

Google Cloud published an updated roadmap to migrate its infrastructure to post-quantum cryptography, targeting full readiness by 2029 while acknowledging some work will continue into the next decade. The plan is organized around the company’s Quantum Threat Model and follows an accelerated timeline set in March.

The roadmap focuses on three priorities: reducing Store Now Decrypt Later (SNDL) risk, strengthening digital signatures against forgery, and building cryptographic agility to adopt new standards as they emerge. Google said faster-than-expected advances in quantum hardware and error correction prompted the earlier deadline.

Several milestones are already in place. Google’s API endpoints, including google.com and googleapis.com, now use the NIST-standardized ML-KEM key exchange in a hybrid configuration that pairs classical and quantum-resistant algorithms. Application and proxy load balancers support quantum-safe hybrid key exchange for TLS 1.3 on an opt-in basis so customers can validate changes in their environments. Cloud Key Management Service reached general availability for NIST-approved post-quantum algorithms covering both key exchange and digital signatures.

The roadmap sets specific timelines. Google plans to mitigate SNDL risk across customer-facing workloads, administrative and developer tooling such as Cloud VPN and Interconnect, and data transfer services including the BigQuery CLI and Storage Transfer Service by the end of 2027. Signature integrity, software supply chain attestations and identity protections, including rollout of quantum-resistant certificates and hardening of Cloud IAM, are targeted for completion by the end of 2028.

Foundational key management work carries an end-of-2028 target overall but is phased. Cloud KMS is expected to support quantum-safe key import as early as 2026. Hardware-backed protections such as confidential computing and Cloud HSM, along with external key management and partner-enabled key sovereignty options, are planned for 2028.

On hardware trust, Google is anchoring work to open-source silicon components such as Caliptra and OpenTitan; OpenTitan already supports quantum-secure boot. Google noted, “We anticipate continuing those efforts into the 2030s to support broader industry guidance and evolving global standards. These standards include CNSA 2.0 and the transition paths defined in NIST IR 8547, which anticipate the final deprecation of legacy, quantum-vulnerable algorithms between 2030 and 2035.”

Google framed infrastructure protections as its responsibility while saying customers must update client-side software, manage the lifecycle of their own encryption keys, and reconfigure services to use quantum-safe settings once available. The company recommended customers inventory cryptographic assets such as keys and certificates, update development and operations tooling to support post-quantum-capable libraries, and test applications against the quantum-safe APIs and load balancers already offered.

The roadmap follows broader government and industry actions to accelerate post-quantum migration and provides timelines and hybrid options designed to address data that could be harvested now for later decryption.

Articles by this author