Google Cloud Advances 2029 PQC Deadline After Quantum Hardware Gains
Google Cloud moved its post-quantum target to 2029 citing hardware progress. The plan emphasizes infrastructure changes while leaving client-side and key-lifecycle tasks to customers. Overlap with federal CNSA 2.0 timelines creates an untested hybrid period through 2028.
Google Cloud endpoints now run NIST ML-KEM hybrid key exchange by default while load balancers offer opt-in quantum-safe TLS 1.3. Cloud KMS reached general availability for standardized PQC algorithms. The plan splits work into SNDL risk reduction by end-2027, signature and identity hardening by end-2028, and continued foundational key-management work through 2028 with hardware elements such as Cloud HSM following in the same window. Google explicitly assigns client-side updates and key-lifecycle management to customers.
The roadmap references CNSA 2.0 and NIST IR 8547 deprecation windows of 2030-2035, yet procurement records and contract language show federal agencies still require legacy algorithm support through at least 2028. This creates an overlap period where hybrid deployments must remain interoperable while quantum-vulnerable keys are retired. Google’s choice to open-source Caliptra and OpenTitan components for quantum-secure boot mirrors earlier moves in the Titan and OpenTitan projects but does not yet address supply-chain attestation gaps reported in third-party audits of similar silicon.
Independent verification of Google’s stated ML-KEM rollout is limited to public endpoint tests; no third-party measurement of internal administrative tooling coverage has been released. Historical patterns from the 2016-2020 Chrome TLS 1.3 transition show customer adoption lagged default changes by 18-24 months. The same lag on PQC settings would push meaningful SNDL mitigation past the 2027 target for many tenants.
Next milestones include 2026 support for quantum-safe key import in Cloud KMS and 2028 rollout of quantum-resistant certificates and IAM bindings. Agencies holding data under CNSA 2.0 mandates will need to validate hybrid configurations against their own procurement clauses before 2028 contract renewals.
NIST: CNSA 2.0 will require RSA-2048 deprecation in new federal procurements by Q4 2030.
Sources (3)
- [1]Primary Source(https://www.securityweek.com/google-cloud-sets-out-post-quantum-roadmap-with-2029-readiness-goal/)
- [2]Supporting Source(https://csrc.nist.gov/pubs/ir/8547/final)
- [3]Supporting Source(https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF)