"If a certificate is not in the tree, it simply does not exist." Jason Soroko's blunt assessment of Merkle Tree Certificates captures the operational tradeoffs Google Cloud is explicitly managing as it maps a multi‑year shift to quantum‑resistant cryptography.
Three risk domains and interim deadlines
Google Cloud published a roadmap on August 12 that divides its post‑quantum migration into three risk domains derived from the company's quantum threat model. The roadmap targets mitigation of store‑now‑decrypt‑later (SNDL) risk — the exposure created when data harvested today could be decrypted by a future quantum computer — for completion by the end of 2027. Two other major domains, hardening digital signatures against forgery and rebuilding key management for cryptographic agility, are scheduled to run to the end of 2028. Those 2028 targets sit ahead of a 2029 date Google set alongside Cloudflare and Microsoft.
What has already shipped: ML‑KEM, ML‑DSA, SLH‑DSA, hybrid TLS and ALTS
Google Cloud has already put several capabilities into production. API endpoints including google.com and *.googleapis.com now offer quantum‑safe key exchange using NIST‑standardized ML‑KEM in hybrid mode. Application and proxy load balancers support hybrid key exchange for TLS 1.3; that support is initially opt‑in so customers can validate behavior without disrupting existing applications. Cloud KMS reached general availability for ML‑KEM, ML‑DSA and SLH‑DSA, and Google completed a quantum‑confidential version of ALTS — Google's internal traffic protocol — in 2025.
Several other services are scheduled for later releases: Cloud VPN and Interconnect are planned for 2026 and 2027, Private CA for 2027, and Cloud IAM together with a quantum‑safe Cloud HSM for 2028.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleThe certificate problem and Merkle Tree Certificates
Google flagged an additional constraint around certificates: post‑quantum signature sizes are large enough to affect certificate chain validation performance. The company is addressing that with Merkle Tree Certificates, an approach that replaces multiple large signatures across a chain with a single, compact inclusion proof backed by a tree. Jason Soroko, a senior fellow at certificate lifecycle management provider Sectigo, described the model as keeping "overhead near current levels" and said the method "also folds transparency logging into issuance rather than bolting it on."
Soroko's succinct formulation — "If a certificate is not in the tree, it simply does not exist" — underscores a change in how issuance, transparency logging and validation will interact under the design Google is promoting.
Hardware timelines and Google's warning about 2029
Not all elements of the transition are purely software updates. Google noted that timelines for some physical components may extend beyond 2029 because the transition depends in part on natural equipment replacement cycles. The company also warned in March that "a cryptographically relevant quantum computer could arrive as early as 2029," a calendar point that frames the urgency behind its staged deadlines.
What this means for customers, hardware vendors, and security teams
- Customers: Google was explicit that customers will carry part of the load. They need to update client‑side software to negotiate post‑quantum handshakes and manage their own asymmetric key lifecycles as the Cloud platform introduces hybrid and post‑quantum options.
- Hardware vendors: Because some physical components may not be replaced on Google’s 2027–2028 cadence, vendors and procurement teams should expect equipment life cycles to push some transitions beyond 2029.
- Security teams: The rollout schedule — with Cloud VPN and Interconnect arriving in 2026–2027, Private CA in 2027, and Cloud IAM and a quantum‑safe Cloud HSM in 2028 — gives security teams concrete checkpoints to track and validate their own readiness efforts.
Google Cloud's roadmap establishes a phased, risk‑based approach: mitigate the immediate SNDL threat first, then tackle signatures and key management, while rolling out hybrid and post‑quantum primitives in production services now. The timetable places the first major milestone at the end of 2027 and ties subsequent work to customers' updates and the longer cadence of hardware replacement — all against a company warning that a cryptographically relevant quantum computer "could arrive as early as 2029."




