Google Cloud has published a detailed roadmap for transitioning its extensive infrastructure to post-quantum cryptography (PQC), with a strategic target for full readiness by 2029. This accelerated timeline, initially moved up in March, is a direct response to faster-than-anticipated advancements in quantum hardware and error correction capabilities, which pose a long-term threat to current cryptographic standards. The company’s plan is structured around its proprietary Quantum Threat Model, focusing on three critical areas: mitigating Store Now Decrypt Later (SNDL) risk, bolstering digital signatures against potential forgery, and cultivating the cryptographic agility necessary to swiftly adopt emerging PQC standards, as reported by SecurityWeek.
Google Cloud’s Strategic Shift to Post-Quantum Cryptography
Google Cloud has already implemented several key milestones on its journey to quantum-safe operations. Its core API endpoints, including google.com and googleapis.com, now leverage NIST-standardized ML-KEM key exchange in a hybrid mode. Furthermore, application and proxy load balancers support quantum-safe hybrid key exchange for TLS 1.3 on an opt-in basis, enabling customers to validate these changes within their environments. Cloud Key Management Service (KMS) has also reached general availability for NIST-standardized PQC algorithms, covering both key exchange and digital signatures.
Mitigating Store Now Decrypt Later (SNDL) Risk
One of the primary concerns addressed by Google Cloud’s post-quantum roadmap is the Store Now Decrypt Later (SNDL) risk. This refers to the threat where adversaries can record encrypted data today, intending to decrypt it later using a sufficiently powerful quantum computer. Google Cloud aims to mitigate SNDL risk across customer-facing workloads, administrative tools like Cloud VPN and Interconnect, and data transfer services such as the BigQuery CLI and Storage Transfer Service by the end of 2027. This proactive measure is crucial for protecting sensitive data against future quantum decryption capabilities.
Signature integrity and identity protections, including quantum-resistant software supply chain attestations, the rollout of quantum-safe certificates across Google’s infrastructure, and the hardening of identity mechanisms like Cloud IAM, are targeted for completion by the end of 2028. Foundational key management work also shares this 2028 target, with quantum-safe key import in Cloud KMS expected by 2026. Hardware-backed protections, such as confidential computing and Cloud HSM, alongside external key management and partner-enabled key sovereignty options, are slated for 2028. Google is also anchoring trust in open-source silicon components like Caliptra and OpenTitan, the latter already supporting quantum-secure boot.
Actionable Steps for Post-Quantum Readiness
While Google Cloud assumes responsibility for securing its infrastructure, customers retain accountability for updating client-side software, managing their own encryption key lifecycles, and reconfiguring services to utilize quantum-safe settings once available. To prepare for this transition, Google recommends three initial steps for customers:
- Inventory Cryptographic Assets: Identify and catalog all existing cryptographic keys, certificates, and their associated algorithms and usage.
- Update Tooling: Ensure development and operations tooling support PQC-capable libraries. This is a vital step for
implementing PQC-capable libraries in Google Cloud environmentsefficiently. - Test Applications: Validate existing applications against the quantum-safe APIs and load balancers that are already available. This early testing can help identify potential compatibility issues and ensure a smooth transition.
Google anticipates these efforts will continue into the 2030s to align with broader industry guidance and evolving global standards, including CNSA 2.0 and NIST IR 8547. These standards foresee the final deprecation of legacy, quantum-vulnerable algorithms between 2030 and 2035, underscoring the long-term importance of this strategic shift.
Related: Quantum-Resistant Cryptography Migration: Challenges & Strategy, Microsoft’s Post-Quantum Cryptography Acceleration: A 2029 Shift