Breaking
Tech NewsDeveloping Story

Google Cloud Sets 2027 Post-Quantum Deadline

Google Cloud's roadmap targets SNDL risk by 2027, with signatures and key management by 2028.

··2 hours ago·2 min read
padlock on laptop with light trails
Photo by FlyD on Unsplash

Google Cloud has laid out a phased plan to overhaul its encryption infrastructure, setting the end of 2027 as the target for eliminating its most urgent post-quantum risk. The roadmap, published on August 12, splits the migration into three risk domains, each with its own deadline, and signals a hard timeline for an industry that has struggled to move beyond pilot projects.

Three Risk Domains, Staggered Deadlines

The company’s approach is organized around a quantum threat model that breaks the problem into three parts. The first is store-now-decrypt-later (SNDL) risk, where an adversary collects encrypted data today in hopes of decrypting it once a quantum computer becomes available. Google aims to have this mitigated by the end of 2027.

The other two domains are more complex. Hardening digital signatures against forgery and rebuilding key management so systems can swap cryptographic algorithms quickly are both scheduled for completion by the end of 2028. That places these efforts ahead of the 2029 date Google has previously aligned with Cloudflare and Microsoft.

What Has Already Shipped

Several quantum-safe components are already live. Google Cloud API endpoints, including google.com and *.googleapis.com, now offer quantum-safe key exchange using ML-KEM in hybrid mode, following NIST standards. Application and proxy load balancers also support hybrid key exchange for TLS 1.3, though it is opt-in to let customers test it without breaking existing applications.

Cloud KMS has reached general availability for ML-KEM, ML-DSA, and SLH-DSA, and quantum-confidential ALTS, Google’s internal traffic protocol, was completed in 2025. Still to come are Cloud VPN and Interconnect in 2026 and 2027, Private CA in 2027, and Cloud IAM and a quantum-safe Cloud HSM in 2028.

The Certificate Problem

One technical hurdle is certificate size. Post-quantum signatures are large enough to slow down certificate chain validation, a performance issue Google is addressing with Merkle Tree Certificates. Jason Soroko, senior fellow at Sectigo, a certificate lifecycle management provider, said the approach replaces multiple large signatures with one compact inclusion proof, keeping overhead near current levels. He also noted that it integrates transparency logging into the issuance process.

"If a certificate is not in the tree, it simply does not exist."

— Jason Soroko, senior fellow at Sectigo

Customers Must Carry Part of the Load

Google was explicit that the migration is not solely on its side. Customers need to update client-side software to negotiate post-quantum handshakes and manage their own asymmetric key lifecycles. The company also cautioned that the timeline for some physical components may extend beyond 2029, since much of the transition hinges on natural equipment replacement cycles.

Why It Matters

The stakes here are concrete. Google warned in March that a cryptographically relevant quantum computer could arrive as early as 2029. That means a deadline of 2027 for the most sensitive data is not just a technical benchmark—it is a race against a clock that may be shorter than many organizations assume. For businesses relying on Google Cloud, the message is clear: planning for post-quantum security is no longer a future exercise, but a current operational requirement.

#post-quantum#google-cloud#encryption#ml-kem#sndl

Sources

Iliyas

Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories