Skip to content

Product1 publisher2 min readPublished

Google's own post-quantum deadline runs two years ahead of the NSA's target

Google said faster progress in quantum hardware and error correction moved its migration to 2029. A Caltech, Berkeley and Oratomic paper published the same month put the qubits needed for Shor's algorithm as low as 10,000.

The Product Desk · Product desk

Illustration accompanying Google's own post-quantum deadline runs two years ahead of the NSA's target

What happened

  • Google set 2029 as its own deadline for finishing the move to post-quantum cryptography, a target the company adopted in March.
  • The National Security Agency is working to a 2031 target and NIST's guideline for national security systems is 2035, both later than the date Google set for itself.
  • Google said it pulled its timeframe in because quantum hardware and error correction advanced faster than expected, lowering the number of qubits needed to threaten current encryption.
  • A paper from Caltech, UC Berkeley and the startup Oratomic put the machine needed to run Shor's algorithm at 10,000 to 26,000 qubits, roughly two orders of magnitude below the millions once assumed.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Whoever owns the crypto inventory now has to pick a calendar. NIST's guideline allows six more years than Google allowed itself, and taking it means disagreeing with the party that can see the hardware.
  • constraint Dependency chains run deep, so your finish date is set by the weakest cryptographic component you depend on. A team that converts every line of its own code can still be exposed through third-party components it cannot re-architect.
  • exposure Traffic captured off the wire today is exposed on the attacker's schedule, so any secret that has to hold into the 2030s is compromised no matter which year the migration finishes.
  • cost Doing this at the network layer puts the budget and the labour on whoever owns the fabric, and application owners who never touch their own code get counted as migrated.

Somewhere in your organization a spreadsheet is being filled in with algorithm names, key sizes and hostnames. The column that decides your timeline is the last one: who can change this. For a load balancer your team operates, that is your team. For the signature check inside a vendor's auto-updater, it is the vendor, and their roadmap is your deadline [7].

Google said 2029 without naming a month [2]. The column making the case ran on 13 September 2026 [13], so a team that started that week has about 28 months if 2029 means January and about 39 if it means December [15]. Y2K, the comparison the column itself reaches for, got roughly two years of well-funded remediation across the industry. The column's argument is that Q-Day has a similar or shorter runway with a small fraction of the attention [9].

The piece recommends migrating at the network layer, upgrading a small number of control points instead of thousands of applications, because changing the estate application by application before 2029 is not realistic [10][11]. It is a serious argument. The fabric in question carries and secures traffic between applications [11]. The digital signatures that authenticate software updates sit inside the applications and their vendors' build pipelines [7]. Upgrading the fabric moves the sessions. It does not touch the keys an updater trusts.

The claim that application-by-application progress is going slowly rests on the author's conversations with carriers, enterprises and governments, without a survey or a count [12]. The dates and the qubit estimate are the only numbers on the record: 10,000 to 26,000 qubits for a fault-tolerant machine running Shor's algorithm, against the millions once assumed [5].

So the sorting question has two axes, and neither of them is how many systems you own. First, can you change the algorithm yourself. Second, does the secret have to hold past 2029. Systems you control carrying short-lived session data are a scheduling problem, and the fabric upgrade genuinely helps there. Systems you do not control, protecting data that has to stay secret into the 2030s, you raise with the vendor this quarter. Harvest now, decrypt later means captured traffic simply waits for the hardware. Some of what organizations treat as secure today is already compromised, according to the column [8].

What to watch

  • Whether NIST or the NSA moves its published dates closer to 2029 as other groups test the 10,000 to 26,000 qubit estimate.
  • Whether any large operator publishes a measured migration rate for its own estate rather than assessment anecdotes.
  • Whether software vendors commit to dates for the update signature chains their customers cannot change themselves.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories