Quantum computers capable of breaking today's widely used encryption are still a future threat. Google Cloud does not want its security migration to become a problem in the future.
Google has set 2029 as its target for full post-quantum cryptography readiness across Google Cloud, laying out a multi-year migration covering network connections, digital signatures, identity systems, certificates, key management, and hardware-backed security. The company has already deployed some protections and plans major additional changes through 2027 and 2028.
For enterprise IT and security teams, Google's roadmap carries a less comfortable message: cloud providers can quantum-proof their own infrastructure, but customers will still have applications, keys, certificates, software, and configurations to migrate.
Google has already started the quantum-security transition
Google's post-quantum roadmap, released on Aug. 11, divides the migration into three broad areas: protecting encrypted data from future decryption, protecting digital signatures and identities from forgery, and building cryptographic infrastructure that can adapt as standards change.
Some of that work is already complete.
Google says its Cloud API endpoints now support quantum-safe key exchange using NIST-standardized ML-KEM in hybrid mode. Application and proxy load balancers also support hybrid post-quantum key exchange for TLS 1.3, while Cloud KMS has made the standardized ML-KEM, ML-DSA, and SLH-DSA algorithms generally available.
Google expanded that effort in August by introducing quantum-safe key import in preview for Cloud KMS, aimed at organizations using bring-your-own-key models to move cryptographic keys into Google Cloud.
The timing matters because security agencies are no longer treating post-quantum cryptography as theoretical preparation. After finalizing three PQC standards in 2024, NIST urged organizations to begin using them and to plan migrations rather than waiting for a sufficiently powerful quantum computer to emerge.
The security preparations are unfolding as quantum hardware itself continues to advance. eWeek recently reported how IBM's quantum infrastructure is scaling through massive interconnected cryogenic modules designed to support its pursuit of fault-tolerant computing.
Google's roadmap gets more aggressive through 2028
The most immediate part of Google's plan focuses on what security researchers call “store now, decrypt later” attacks.
An adversary does not need a cryptographically relevant quantum computer today to create a future problem. Encrypted traffic can theoretically be collected now and stored until sufficiently powerful quantum systems exist to attack vulnerable public-key encryption.
Google is therefore targeting the end of 2027 for a group of protections covering customer workloads, administrator and developer connections, and data pipelines. Its roadmap lists technologies including Cloud VPN, Cloud Interconnect, Google Cloud SDKs, GKE service mesh, Cloud Storage, BigQuery, and data transfer services.
The next phase targets 2028.
Google plans to expand quantum-resistant protection across digital signatures, software attestations, certificates, identity and access systems, Confidential Computing, Cloud HSM, and external key management systems. Cloud IAM is among the products listed for 2028, while Google's broader infrastructure-wide quantum-safe authentication rollout spans 2027 and 2028.
That timetable sits alongside a much broader U.S. push toward quantum readiness. A June executive order requires federal high-value assets and high-impact systems to use post-quantum cryptography for digital signatures by the end of 2031. eWeek examined that deadline and the broader federal push in its coverage of the government's new quantum initiative.
What eWeek found: Google's target does not eliminate the customer's migration
The most important detail in Google's roadmap may be buried beneath all those product timelines: 2029 is Google's target, not necessarily the customer's finish line.
Google explicitly divides responsibility between security “of the cloud” and security “in the cloud.”
The company says it will handle the transition of its underlying infrastructure, including networking, encryption in transit, servers, operating systems, and other cloud foundations. But customers remain responsible for their own applications, client-side software, asymmetric-key lifecycles, and Google Cloud configurations.
Google even warns that some physical hardware transitions may continue beyond 2029 because upgrades can depend on normal equipment-replacement cycles. Individual product schedules may also move as engineering requirements, third-party dependencies, and standards evolve.
That distinction keeps the 2029 date from becoming a misleading "problem solved" milestone.
The migration challenge extends well beyond Google Cloud. eWeek's examination of IBM's quantum security strategy similarly highlighted the need for organizations to identify cryptographic vulnerabilities and prepare their systems before large-scale quantum machines become practical threats.
What enterprises should start doing now
Google recommends three immediate steps: inventory, update, and validate.
Organizations should identify where cryptographic keys, certificates, and vulnerable algorithms are being used; update software and development tooling to support PQC; and test applications against quantum-safe APIs and load balancers before the transition reaches production systems.
NIST's PQC migration guidance points in the same direction. The agency says cybersecurity products, services, and protocols will require updates and that organizations need to identify where quantum-vulnerable algorithms are used before replacing them. Its current transition guidance calls for those algorithms to be deprecated and ultimately removed from NIST standards by 2035, with higher-risk systems moving earlier.
For enterprise security teams, that makes Google's 2029 target less a distant countdown and more a planning marker.
The cloud provider is already changing the cryptography underneath its platform. The harder question for customers is whether they know enough about the cryptography inside their own environments to keep pace.
Also read: eWeek previously explored why post-quantum cryptography needs to be deployed before quantum computers become powerful enough to threaten today's public-key encryption.


