Site navigation

Google Fast‑Tracks Quantum Security Deadline to 2029

Tom Quinn

,

Google PQC
“As a pioneer in both quantum and PQC, it’s our responsibility to lead by example and share an ambitious timeline,” said Heather Adkins, Google.

Google is accelerating its move to post‑quantum cryptography (PQC), targeting full migration by 2029 as fears of quantum‑enabled cyber-attacks grow.

In a new blog post, the tech giant’s VP of security engineering, Heather Adkins, warned that quantum security frontiers “may be closer than they appear,”  with today’s encryption methods already proving vulnerable.

In May, Google’s Quantum AI research team published a paper showing that a quantum machine with around one million noisy qubits (quantum bits) could theoretically crack the widely used 2048-bit RSA encryption in just one week.

That is a dramatic reduction on Google’s earlier estimates, which suggested that as many as twenty million qubits would be needed to break 2048-bit RSA, leading researchers to recommend that vulnerable systems should be phased out after 2030, and banned outright after 2035.

Though such quantum-level threats are outside most adversaries’ capabilities for now, Adkins pointed to the threat posed by “store-now-decrypt-later” attacks, with threat actors currently hoovering in encrypted data to exploit as soon as a Cryptographically Relevant Quantum Computer (CRQC) exists.

Having last month issued a call to action urging the security community and policymakers to get ready for the quantum era, Google said its updated timeline reflects rapid progress in quantum hardware, error‑correction techniques, and refined estimates of how much quantum power is needed to break current cryptography.

“As a pioneer in both quantum and PQC, it’s our responsibility to lead by example and share an ambitious timeline. By doing this, we hope to provide the clarity and urgency needed to accelerate digital transitions not only for Google, but also across the industry,” wrote Adkins.

According to Google, it is already working to put quantum-grade protections in place for end users, with the firm integrating PQC digital signature protection within Android 17, providing PQC solutions within Google Cloud, and guidance for business leaders on migrating their services to PQC through its ISE Crypto PQC working group.


Recommended reading


Research from Capgemini last summer found that nearly two-thirds of organisations consider quantum computing as the most critical threat they face over the next five years, with 70% of firms working on or planning to use quantum-safe solutions, particularly within telecoms, finance, and defence. 

However, the study found that while around half of early adopters have run PQC pilots, often in partnership with cloud providers and specialist vendors, few have a clear roadmap for enterprise-wide transition.

Last year, the UK’s National Cyber Security Centre urged organisations in key sectors to start preparing for future quantum threats, but on a far longer timeline than Google’s, targeting full migration by 2035, a similar transition schedule to the G7, which recently advised firms should integrate PQC by 2034 at the latest.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data