PQC in Plaintext: Google Cloud’s post-quantum cryptography roadmap

Google Cloud has published a detailed roadmap for migrating its infrastructure and customer-facing services to post-quantum cryptography (PQC) by 2029. The strategy is based on the Google Quantum Threat Model and prioritizes three domains: mitigating Store Now, Decrypt Later (SNDL) risks, ensuring integrity against forgery through strengthened digital signatures, and building cryptographic agility to adapt to evolving standards. The roadmap aligns with CNSA 2.0 and NIST IR 8547 transition timelines, which anticipate deprecating quantum-vulnerable algorithms between 2030 and 2035.

Immediate progress for 2026 includes several milestones. Google Cloud API endpoints (google.com and *.googleapis.com) now support quantum-safe key exchange using ML-KEM (FIPS 203) in hybrid mode. Application and proxy load balancers support X25519MLKEM768 for TLS 1.3 on an opt-in basis. The company is collaborating with the IETF PLANTS Working Group on Merkle Tree Certificates to address PQC signature size challenges in WebPKI. Cloud KMS now offers general availability for NIST-standardized PQC algorithms: ML-KEM, ML-DSA, and SLH-DSA.

Domain 1 (SNDL mitigation) targets completion by end of 2027. Key journeys include securing customer workloads via quantum-safe ingress on load balancers (already completed in 2026), securing admin and developer flows (Cloud VPN, Interconnect, OS Login, SDKs, client libraries, GKE service mesh targeted for 2026–2027), and securing data pipelines (Cloud Storage SDK, BigQuery CLI, Data Transfer Service targeted for 2026–2027).

Domain 2 (integrity and non-repudiation) targets completion by end of 2028. This covers securing the software supply chain (Binary Authorization, Access Approval in 2026; Assured OSS in 2027), issuing quantum-safe certificates (private CA, Google Trust Service with Merkle Tree Certificates, rollout across Google Cloud products by 2027–2028, following IETF standards), and protecting identity and access (Cloud IAM in 2028, infrastructure-wide quantum-safe authentication by 2027–2028).

Domain 3 (foundations and key management) also targets completion by end of 2028. Foundational key management and libraries (Cloud KMS with ML-DSA, SLH-DSA, and ML-KEM hybrids already completed in 2025; quantum-safe key import BYOK in 2026). Hardware-backed services (Confidential Compute including attestation and vTPM, and Quantum-Safe Cloud HSM FIPS 140-3 L3) targeted for 2028. Key sovereignty and partner solutions (External Key Management, partner enablement) targeted for 2028.

Google Cloud outlines a shared responsibility model: Google handles security of the cloud (network, ALTS protocol, hardware integrity via open-source silicon roots like Caliptra v2.1, TPM 2.0 v185, and OpenTitan), while customers manage security in the cloud (updating client software, managing asymmetric keys, configuring quantum-safe settings). The timeline for some physical hardware components may extend beyond 2029, using natural replacement cycles.

Recommended immediate customer actions: inventory cryptographic resources using Cloud Asset Inventory, update development and SRE teams to use PQC-supporting software (BoringSSL, Chrome, SDKs), and validate existing applications using quantum-safe APIs and load balancers. Google Cloud emphasizes that PQC readiness is a collaborative effort and that their roadmap will continue to evolve with industry standards.

PQC in Plaintext: Google Cloud’s post-quantum cryptography roadmap

View Original