Google Cloud has published a detailed migration roadmap for post-quantum cryptography, setting 2029 as the deadline for full readiness across its infrastructure. The plan, unveiled on August 11, 2026, lays out a phased approach to replacing the cryptographic foundations that protect virtually everything online, from banking transactions to medical records to blockchain networks.
The three-phase plan
Google Cloud’s roadmap breaks the quantum threat into distinct risk categories, each with its own deadline.
The first priority, targeted for the end of 2027, focuses on what cryptographers call “store now, decrypt later” attacks. This is the scenario where adversaries, whether nation-states or sophisticated criminal organizations, are already harvesting encrypted data today with the expectation that future quantum computers will crack the encryption.
The second phase, due by end of 2028, tackles integrity and non-repudiation risks through quantum-safe digital signatures and certificates. These are the mechanisms that verify identity and prove that data hasn’t been tampered with.







