Google Cloud outlines PQC roadmap, targets full quantum readiness by 2029
Google Cloud has updated its post-quantum cryptography (PQC) roadmap, aiming for full PQC readiness across its services by 2029 to protect against future quantum computing threats. The strategy focuses on mitigating 'Store Now, Decrypt Later' risks, ensuring integrity against forgery, and enhancing cryptographic agility. Immediate milestones include quantum-safe key exchange for API endpoints and load balancers, and GA availability of NIST-standardized PQC algorithms in Cloud KMS. The roadmap details plans for securing customer workloads, admin flows, data pipelines, and the software supply chain through 2027 and beyond.
- →Immediate PQC Milestones Achieved (2026)
- →Google Cloud's Post-Quantum Cryptography Roadmap
- →PQC Migration Strategy and Key Domains
- →Roadmap to 2027: Store Now Decrypt Later (SNDL) Mitigation
- →Integrity and Non-Repudiation Initiatives
Features (1) ›
- Immediate PQC Milestones Achieved (2026)
Google Cloud API endpoints (google.com, *.googleapis.com) now offer quantum-safe key exchange using NIST-standardized ML-KEM in hybrid mode. Application and proxy load balancers support quantum-safe hybrid key exchange (X25519MLKEM768) for TLS 1.3 on an opt-in basis, and NIST standardized PQC algorithms (ML-KEM, ML-DSA, SLH-DSA) for encryption and signing keys are now generally available in Cloud KMS.
Notes (4) ›
- Google Cloud's Post-Quantum Cryptography Roadmap
Google Cloud has shared its updated roadmap to migrate all services to post-quantum cryptography (PQC) by 2029. This initiative aims to protect cloud infrastructure and customer data against potential decryption by future cryptographically-relevant quantum computers.
- PQC Migration Strategy and Key Domains
The PQC migration strategy is based on the Google Quantum Threat Model, prioritizing protection across three key domains: mitigating Store Now, Decrypt Later (SNDL) risks, ensuring integrity against forgery, and enhancing foundational capabilities for cryptographic agility. This strategy also extends to Sovereign Cloud initiatives and AI services.
- Roadmap to 2027: Store Now Decrypt Later (SNDL) Mitigation
Google Cloud is targeting 2027 to implement changes for SNDL mitigation across customer workloads, administrator and developer flows, and data pipelines. This includes securing customer workloads with quantum-confidential TLS 1.3 handshakes, protecting admin pathways like Cloud VPN and Interconnect, and safeguarding data transfers for analytics and storage platforms.
- Integrity and Non-Repudiation Initiatives
Plans are underway to quantum-proof digital signatures and attestations to prevent forgery, focusing on securing the software supply chain with quantum-resistant attestations for services like Binary Authorization and Cloud Build. Google Cloud is also transitioning its public key infrastructure (PKI), including internal and external certificate authorities, to support ML-DSA and SLH-DSA certificates.
https://cloud.google.com/blog/products/identity-security/pqc-in-plaintext-google-clouds-post-quantum-cryptography-roadmap/
Related releases
- VPC Service Controls Recommender Enters Public Preview Google Cloud release notes ·
- BigQuery Table Explorer Deprecated; Features Move to Reference Panel Google Cloud release notes ·
- Terraform Google Provider v7.44.0 Adds New Resources and GCP Enhancements Terraform Google Provider Releases ·
- BigQuery GA for Query Templates in Data Clean Rooms and TVF Table Parameters Google Cloud release notes ·
- Cortex Framework 7.0.2 Addresses Security Vulnerabilities in Google Cloud Dependencies Google Cloud release notes ·
- Looker's Semantic Layer Integrates with Gemini Enterprise for Governed AI Analytics Google Cloud Blog ·