Google put concrete dates on their post-quantum migration. Worth a read if you’re advising customers on crypto agility.
Already shipped (2026):
- Quantum-safe key exchange on google.com and *.googleapis.com (hybrid ML-KEM / FIPS 203)
- Hybrid X25519MLKEM768 for TLS 1.3 on app and proxy load balancers, opt-in
- ML-KEM, ML-DSA and SLH-DSA generally available in Cloud KMS
The three-domain structure:
- Store Now Decrypt Later mitigation — target end of 2027. Ingress, admin/dev paths (VPN, Interconnect, SDKs), data pipelines.
- Integrity & non-repudiation — end of 2028. Supply chain attestation, PQC certificates, IAM. They’re leaning on Merkle Tree Certificates to work around PQC signature sizes in WebPKI.
- Foundations & key management — end of 2028. KMS, HSM, Confidential Compute, EKM, hardware roots of trust (OpenTitan, Caliptra).
Why it matters for us: the 2029 target sits well ahead of the NIST IR 8547 and CNSA 2.0 deprecation window (2030–2035). Expect customers to start asking their other providers the same question: where’s your dated roadmap? Crypto inventory and agility are becoming procurement criteria, not nice-to-haves.
Their recommended first steps are the same three we’ve been putting in front of clients: inventory your crypto assets, update libraries and SDKs, validate against PQC-enabled endpoints before it hits production.
Link in comments. Happy to discuss where this lands vs. the Microsoft side.
#PostQuantum #PQC #CloudSecurity #CryptoAgility
Source:
Google Blog