Google Cloud published a post-quantum cryptography migration roadmap that maps service-level milestones to Google’s broader commitment to complete its PQC transition by 2029. The plan prioritizes protections against store-now-decrypt-later risks by the end of 2027, followed by digital signatures, attestations, foundational services, and key management by the end of 2028, while acknowledging that some hardware-rooted components may remain on longer replacement cycles beyond 2029.
Google said several milestones are already complete, including quantum-confidential ALTS in 2025, PQC support for Google Cloud API endpoints and load balancers in 2026, and general availability in Cloud KMS for ML-KEM, ML-DSA, and SLH-DSA. The roadmap also notes dependencies on evolving standards for certificate and signature work, including Merkle Tree Certificates, and makes clear that customers will need to update client software, manage key lifecycles, and enable quantum-safe configurations to complete parts of the migration.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Google Cloud published a post-quantum cryptography migration roadmap on August 11, 2026. The roadmap assigns milestones across store-now-decrypt-later protections, integrity and non-repudiation, and foundations and key management, aligned to Google's 2029 migration commitment.
The core Merkle Tree Certificate specification reached working-group draft revision 05 on July 6, 2026. Google cites the draft's still-evolving status as a dependency affecting certificate and signature rollout timing.
Google announced a company-wide target to complete its post-quantum cryptography migration by 2029. This target is referenced as the broader commitment that the later Google Cloud roadmap aligns to.
Chrome and Cloudflare have been testing the Merkle Tree Certificate design against live traffic since February 2026. The testing is cited as part of ongoing work around certificate-related post-quantum standards.
Google lists post-quantum support for Google Cloud API endpoints and for application and proxy load balancers as completed in 2026. The roadmap notes API endpoints use ML-KEM in hybrid mode and load balancers use X25519MLKEM768 hybrid key exchange for TLS 1.3.
Google lists quantum-confidential ALTS as a completed post-quantum cryptography milestone in its roadmap. The completion is anchored only to the year 2025.
Google Cloud said Cloud KMS has reached general availability for the post-quantum algorithms ML-KEM, ML-DSA, and SLH-DSA. The roadmap article cites this as an already shipped quantum-safe capability alongside hybrid key exchange support in other Google Cloud services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourceinfosecurity-magazine.com
Open sourcepostquantum.com
Open sourcecloud.google.com
Open sourcedatatracker.ietf.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.