HackMyIP
← Back to News
2026-08-14 SecurityWeek

Google Cloud Outlines Post-Quantum Cryptography Roadmap Targeting 2029

EncryptionCloud SecurityRegulation

Google Cloud has published an updated roadmap for migrating its infrastructure to post-quantum cryptography (PQC), targeting full readiness by 2029 with some work extending into the next decade. The announcement follows Google's March decision to accelerate its PQC transition after faster-than-expected advances in quantum hardware and error correction. The plan, built around Google's Quantum Threat Model, organizes work into three priority areas: mitigating Store Now Decrypt Later (SNDL) risk, strengthening digital signatures against forgery, and building the cryptographic agility needed to adopt new standards as they emerge.

Several milestones are already operational. Google Cloud's API endpoints, including google.com and googleapis.com, now use NIST-standardized ML-KEM key exchange in hybrid mode. Application and proxy load balancers support quantum-safe hybrid key exchange for TLS 1.3 on an opt-in basis, allowing customers to validate the change in their own environments. Organizations auditing their own TLS configurations can verify quantum-safe handshake support using an SSL/TLS checker. Cloud KMS has also reached general availability for NIST-standardized PQC algorithms covering both key exchange and digital signatures, with quantum-safe key import support slated for 2026.

The roadmap sets end-of-2027 as the target for mitigating SNDL risk across customer-facing workloads, administrative tooling such as Cloud VPN and Interconnect, and data transfer services including the BigQuery CLI and Storage Transfer Service. Signature integrity protections, including quantum-resistant software supply chain attestations, quantum-safe certificates, and hardening of identity mechanisms like Cloud IAM, carry a 2028 completion target. Hardware-backed protections such as confidential computing, Cloud HSM, and external key management options are also slated for 2028. On the silicon side, Google is anchoring trust in open source components including Caliptra and OpenTitan, the latter already supporting quantum-secure boot.

Google noted it anticipates continuing PQC efforts into the 2030s to align with broader industry guidance, including CNSA 2.0 and NIST IR 8547, which anticipate final deprecation of legacy quantum-vulnerable algorithms between 2030 and 2035. While Google frames infrastructure security as its own responsibility, customers remain accountable for updating client-side software, managing encryption key lifecycles, and reconfiguring services to use quantum-safe settings once available. Enterprises preparing for the transition can audit their current exposure with a broader privacy checkup and verify that authentication credentials tied to cloud services remain strong via a password checker.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →