Why 2029 Matters
Some preparatory work is already complete. Other targets stretch into the early 2030s, timed to align with evolving industry standards and the gradual retirement of older cryptographic algorithms. The goal is straightforward: protect data and authentication systems against computing power that doesn’t exist yet, but will.
Three Core Protection Priorities
Google Cloud’s approach centers on three areas:
- Stopping “Store Now, Decrypt Later” attacks, where adversaries capture encrypted data today with plans to decrypt it once quantum computers mature
- Strengthening digital signatures against forgery, since quantum computing could eventually crack current signature schemes
- Building adaptable systems that can quickly adopt new cryptographic standards as they emerge
As an immediate step, Google Cloud’s API endpoints, including google.com and googleapis.com, now offer quantum-safe key exchange for incoming traffic using the NIST-standardized ML-KEM algorithm in hybrid mode. Application and proxy load balancers also support hybrid key exchange for TLS 1.3 on an opt-in basis, letting customers test post-quantum handshakes before they become mandatory.
The Three-Phase Rollout
| Phase | Target Date | Focus Area | Key Systems |
|---|---|---|---|
| Phase 1 | Late 2027 | Store Now, Decrypt Later protection | Cloud VPN, Cloud Interconnect, Cloud SDK, BigQuery CLI |
| Phase 2 | End of 2028 | Integrity and non-repudiation | Binary Authorization, Access Approval, Cloud IAM |
| Phase 3 | Late 2028 | Foundational infrastructure | Key management, confidential computing, HSMs |
The second phase strengthens software supply chain controls, certificate systems, and identity services, crucial for robust data protection. The third phase covers key management libraries, confidential computing, hardware security modules (HSMs), and external key management solutions. Quantum-safe key import arrives in 2026, with quantum-safe Cloud HSMs scheduled for 2028.
Built on Industry Standards
Google Cloud’s roadmap connects to broader industry efforts. Certificate migration will follow developments at the Internet Engineering Task Force (IETF). The company is also experimenting with Merkle Tree Certificates to manage the larger signature sizes that come with some PQC schemes. Chrome and Cloudflare have already started similar experiments, suggesting this isn’t a solo effort but an industry-wide shift.
Google Cloud frames this as a shared responsibility. The company handles underlying cloud security, including networks, server infrastructure, and transport protocols. Customers remain responsible for their applications, client software, key lifecycle management, and service configurations.
What This Means for Customers Now
Hardware replacement timelines may extend beyond 2029 simply due to normal refresh cycles. For customers looking to prepare today, Google Cloud recommends three immediate steps:
- Inventory your cryptographic assets across all systems
- Update software for development and site reliability teams
- Validate application behavior against quantum-safe APIs and load balancers
These actions help surface older dependencies and compatibility issues before they become emergencies. The roadmap also extends to sovereign cloud initiatives and AI-related services, which will need similar protections as PQC migration spreads. As Google Cloud put it: “We plan to achieve full PQC readiness by 2029, when our efforts converge.”
Hashlytics Take: What stands out here isn’t the timeline itself, it’s the admission that hardware replacement could stretch well past 2029. That’s a rare moment of honesty from a major cloud provider. Most companies sell certainty. Google is telling enterprise customers the quantum transition will be messy, multi-year, and dependent on standards bodies still finalizing their work. For CISOs planning budgets now, that’s more useful than a clean deadline that later slips.
Follow Hashlytics on Bluesky, Facebook, LinkedIn, Telegram and X to Get Instant Updates



