Google Cloud has published a detailed migration roadmap for post-quantum cryptography, setting 2029 as the deadline for full readiness across its infrastructure. The plan, unveiled on August 11, 2026, lays out a phased approach to replacing the cryptographic foundations that protect virtually everything online, from banking transactions to medical records to blockchain networks.
The three-phase plan
Google Cloud’s roadmap breaks the quantum threat into distinct risk categories, each with its own deadline.
The first priority, targeted for the end of 2027, focuses on what cryptographers call “store now, decrypt later” attacks. This is the scenario where adversaries, whether nation-states or sophisticated criminal organizations, are already harvesting encrypted data today with the expectation that future quantum computers will crack the encryption.
The second phase, due by end of 2028, tackles integrity and non-repudiation risks through quantum-safe digital signatures and certificates. These are the mechanisms that verify identity and prove that data hasn’t been tampered with.
That same 2028 deadline also covers foundational key management and cryptographic agility, which is the ability to swap out cryptographic algorithms as threats evolve without rebuilding entire systems from scratch.
The final milestone, full post-quantum cryptography readiness, lands in 2029. Google first announced this company-wide target on March 25, 2026.
What’s already shipping
Quantum-safe key exchange protocols are now live on Google Cloud API endpoints and load balancers, using a hybrid ML-KEM/X25519 approach. The hybrid model is deliberate: it layers the new quantum-resistant algorithm on top of a proven classical one, so security doesn’t degrade even if researchers discover a flaw in the newer standard.
NIST-standardized algorithms, specifically ML-KEM, ML-DSA, and SLH-DSA, are being integrated into Google’s Cloud Key Management Service. NIST finalized these standards in 2024 after years of evaluation.
Google has also begun advancing quantum-safe certificates, the digital credentials that underpin secure connections across the internet.
The broader industry scramble
Both Cloudflare and Microsoft have set their own 2029 targets for post-quantum readiness, creating something close to an industry-wide consensus on timing.
Google’s work on post-quantum cryptography stretches back roughly a decade, predating the current urgency. The company contributed to the research that ultimately became the finalized NIST standards.
Why this matters beyond cloud computing
For the cryptocurrency and blockchain ecosystem, the stakes are particularly acute. Bitcoin, Ethereum, and virtually every major blockchain protocol depend on elliptic curve cryptography for wallet security and transaction signing. A quantum computer capable of running Shor’s algorithm at scale could theoretically derive private keys from public keys, potentially compromising any wallet whose public key has been exposed on-chain.
Enterprises that delay their own post-quantum transitions face a compounding risk. Every day of inaction increases the volume of encrypted data that adversaries can harvest for future decryption. The 2027 deadline Google set for addressing this specific threat suggests the company views the “harvest now, decrypt later” window as already open and narrowing.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

2 hours ago
21









English (US) ·