[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fasBdYHDsUR156Y2LX2WCvXbQLFJ1jtq5A0lNXjt6cgA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"e80c420e-468f-469d-96a4-edb0852ec674","google-clouds-2029-post-quantum-cryptography-deadline-signals-urgent-crypto-migration-need","d1e70f10-14fe-462e-a87f-31660f0c0c8f","Google Cloud's 2029 Post-Quantum Cryptography Deadline Signals Urgent Crypto Migration Need","The rise of quantum computing poses an existential threat to current public-key cryptographic standards, enabling adversaries to execute 'Store Now Decrypt Later' (SNDL) attacks — harvesting encrypted data today to decrypt it once quantum hardware matures. Google Cloud's 2029 readiness goal underscores that organizations cannot afford to wait; the migration window is narrowing rapidly given the complexity of updating cryptographic dependencies across large infrastructures. Failing to achieve cryptographic agility means that sensitive data protected today — including financial records, health data, and state secrets — could be retroactively exposed. This matters because many organizations have deeply embedded legacy cryptographic libraries that will require significant time, testing, and resources to replace.","**Immediate actions:**\n- Conduct a full cryptographic inventory to identify all systems, APIs, and data stores relying on RSA, ECC, or Diffie-Hellman key exchange.\n- Classify and prioritize long-lived sensitive data that is at highest risk from Store Now Decrypt Later attacks.\n- Begin piloting hybrid key exchange mechanisms (classical + PQC) on non-critical systems to build operational familiarity.\n\n**Long-term improvements:**\n- Adopt NIST-standardized post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA) into your cryptographic standards and engineering guidelines by 2026.\n- Build cryptographic agility into application architectures so algorithms can be swapped without full system rewrites.\n- Establish a formal PQC migration program with executive sponsorship, budget allocation, and a target readiness date no later than 2028.\n\n**Detection & governance measures:**\n- Integrate continuous cryptographic posture monitoring into your security tooling to flag deprecated or quantum-vulnerable cipher usage.\n- Align PQC migration milestones with regulatory reporting obligations (e.g., GDPR, NIS2, DORA) to avoid compliance gaps.\n- Require PQC readiness attestations from critical third-party vendors and cloud service providers as part of supply chain risk management.",[12,13,14,15,16,17,18,19,20,21,22,23],"NIST SP 800-208 (Post-Quantum Cryptography)","NIST FIPS 203 (ML-KEM)","NIST FIPS 204 (ML-DSA)","NIST FIPS 205 (SLH-DSA)","NIST SP 800-57 (Key Management Guidelines)","CIS Control 3 – Data Protection","CIS Control 16 – Application Software Security","NIST CSF 2.0 – Protect (PR.DS): Data Security","GDPR Article 32 – Security of Processing","NSA CNSA 2.0 Suite","ETSI EN 303 645 – Cryptographic Agility Guidance","ISO\u002FIEC 27001:2022 – A.8.24 Use of Cryptography","published","2026-08-14T12:21:15.000666+00:00","2026-08-14T12:21:14.711+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.securityweek.com\u002Fgoogle-cloud-sets-out-post-quantum-roadmap-with-2029-readiness-goal\u002F","google-cloud-sets-out-post-quantum-roadmap-with-2029-readiness-goal-b67e79","Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":45,"name":46,"slug":47,"description":48,"color":49},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]