Google Cloud Unveils Quantum-Safe Roadmap, Full Readiness by 2029

2026-08-30 13:36
Favorite

en.Wedoany.com Reported - Google Cloud has set 2029 as its target for achieving full Post-Quantum Cryptography (PQC) readiness across its entire cloud infrastructure, releasing a multi-year migration roadmap on August 11 covering network connectivity, digital signatures, identity systems, certificates, key management, and hardware security. The company has already deployed some quantum-safe protections and plans to complete broader changes in 2027 and 2028.

The roadmap divides the migration effort into three areas: protecting encrypted data from future quantum decryption threats, preventing forgery of digital signatures and identities, and building infrastructure that can adapt to changes in cryptographic standards.

Some work is already in place. Google Cloud's API endpoints now support quantum-safe key exchange using the NIST-standardized ML-KEM hybrid mode; Application and Proxy Network Load Balancers support TLS 1.3 hybrid post-quantum key exchange; and Cloud KMS now generally offers the standardized ML-KEM, ML-DSA, and SLH-DSA algorithms. In August, Google also launched a preview of quantum-safe key import for Cloud KMS, making it easier for organizations using a bring-your-own-key model to migrate their encryption keys into Google Cloud.

This timeline is tied to the pace of regulation. In 2024, after finalizing three PQC standards, the U.S. National Institute of Standards and Technology (NIST) urged organizations to begin using these standards and plan their migration, rather than waiting for sufficiently powerful quantum computers to emerge.

Quantum hardware itself is also evolving. IBM is expanding its quantum infrastructure through large-scale interconnected cryogenic modules to advance research toward fault-tolerant computing, as reported by U.S. tech media outlet eWeek.

The most urgent part of Google's timeline targets "store now, decrypt later" attacks. In theory, attackers could collect and store encrypted traffic today, then decrypt vulnerable public-key encryption once future quantum systems become powerful enough. Google has therefore set the end of 2027 as the target for a set of protections covering customer workloads, administrator and developer connections, and data pipelines, involving Cloud VPN, Cloud Interconnect, Google Cloud SDK, GKE service mesh, Cloud Storage, BigQuery, and data transfer services.

The next phase targets 2028. Google plans to extend quantum-resistant protections to digital signatures, software attestation, certificates, identity and access systems, Confidential Computing, Cloud HSM, and external key management systems, with Cloud IAM included in that year's plan. A broader rollout of infrastructure-level quantum-safe certification spans 2027 and 2028.

Meanwhile, quantum readiness efforts are also advancing at the U.S. federal level. An executive order in June requires federal high-value assets and high-impact systems to adopt post-quantum cryptography for digital signatures by the end of 2031.

The roadmap does not promise to complete all the work on behalf of customers. Google draws a clear distinction between "security of the cloud" and "security in the cloud": the underlying infrastructure—such as networks, transport encryption, servers, and operating systems—is Google's responsibility to migrate, but customers must still address their own applications, client software, asymmetric key lifecycles, and cloud configurations. Some physical hardware transitions may extend beyond 2029, depending on normal device replacement cycles; engineering requirements, third-party dependencies, and standard changes may also alter timelines for individual products.

Google advises enterprises to begin three efforts immediately: inventory where encryption keys, certificates, and vulnerable algorithms are used; update software and development tools to support PQC; and test applications against quantum-safe APIs and load balancers before migration enters production systems.

NIST's migration guidance provides a longer horizon for the timeline: cybersecurity products, services, and protocols need updating, and organizations must inventory quantum-vulnerable algorithm locations before replacement; the relevant algorithms will be deprecated and removed from NIST standards by 2035, with high-risk systems required to act sooner.

For enterprise security teams, 2029 is more of a planning marker than an endpoint. Cloud providers have begun replacing the cryptographic mechanisms underlying their platforms, and customers need to assess whether the cryptographic assets in their own environments can keep pace.

This bulletin is compiled and reposted from information of global Internet and strategic partners, aiming to provide communication for readers. If there is any infringement or other issues, please inform us in time. We will make modifications or deletions accordingly. Unauthorized reproduction of this article is strictly prohibited. Email: news@wedoany.com