Google Cloud Blog
Follow
PQC in Plaintext: Google Cloud’s post-quantum cryptography roadmap
Google is updating its Google Cloud roadmap to fully migrate to post-quantum cryptography by 2029. Their strategy focuses on three key areas: mitigating store now, decrypt later risks, ensuring integrity against forgery, and enhancing cryptographic agility. Google is already transitioning internal and customer-facing services to PQC algorithms. They are also deploying PQC solutions across their Sovereign Cloud initiatives and integrating them into AI services.The company aims for full PQC readiness by 2029, with efforts extending into the 2030s to align with evolving global standards. Key milestones for 2026 include quantum-safe API endpoints and load balancers, along with experimentation in quantum-safe certificates. Cloud Key Management Service (KMS) now supports NIST-standardized PQC algorithms for encryption and signing keys.The roadmap to 2029 is structured around customer-centered journeys, prioritizing areas most vulnerable to quantum computing impacts. Domain 1 targets store now, decrypt later mitigation by 2027, securing customer workloads, administrator flows, and data pipelines. Domain 2 focuses on integrity and non-repudiation, aiming for completion by 2028 by securing the software supply chain, issuing quantum-safe certificates, and protecting identity and access. Domain 3 addresses foundations and key management, targeting completion also by 2028 with standardized quantum-safe keys, hardware-backed services, and partner solutions. Google emphasizes a shared responsibility for quantum safety, managing the transition of cloud infrastructure while customers manage their own applications and data.