Google has moved its own post-quantum cryptography (PQC) migration target to 2029. That is a deadline for Google’s preparation—not a prediction that a quantum computer will break today’s encryption in 2029, or proof that such a machine exists. The urgency is real for information that must stay secret for years: an attacker could collect encrypted data now and try to decrypt it later.
What Google’s 2029 timeline means
On March 25, 2026, Google security leaders Heather Adkins and Sophie Schmieg announced that the company is setting a 2029 timeline for its PQC migration. Google says it brought the target forward in response to progress in quantum hardware development, quantum error correction, and estimates of the resources needed to factor numbers on a future cryptographically relevant quantum computer (CRQC).
The date describes Google’s migration plan. It is not a global deadline, a guaranteed “Q-Day,” or a claim that a CRQC will be available by then. Google’s February 6, 2026, explainer, “The quantum era is coming. Are we ready to secure it?”, says nobody knows precisely when one will arrive.
Why prepare before a quantum computer can break encryption?
The near-term concern is often called “store now, decrypt later.” An adversary can capture encrypted information today and retain it in case a future CRQC can decrypt it. This makes the risk especially relevant to data whose confidentiality must last for many years, even if current systems remain secure against attacks using today’s computers.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitches#1 Best Overall
That confidentiality risk differs from the future threat to digital signatures. Google’s timeline discussion treats encryption and signatures as distinct migration priorities, and says it has reprioritized authentication migration. A future CRQC could undermine some public-key cryptography used in these functions, but the two risks do not have the same immediate consequences or timing.
| Cryptographic use | Why it matters | Timing concern |
|---|---|---|
| Encryption and key establishment | Protects data from being read by parties without the necessary key. | Long-lived sensitive information may be collected now for possible decryption later. |
| Digital signatures and authentication | Helps verify who created a message or is authorized to act. | The concern described by Google is a future CRQC threat; migration still needs to happen before such a machine exists. |
What post-quantum cryptography is
Post-quantum cryptography means cryptographic methods designed to resist attacks from both conventional computers and future quantum computers. It is a software-and-system transition, not a way to make existing encryption stronger simply by adding a quantum device.
Rank #2
Google says it has prepared for a post-quantum world since 2016, and that NIST announced its first PQC standards in 2024. Google identifies “crypto agility” as a key part of the transition: systems need to be able to update or replace cryptographic algorithms without disrupting services. Google Cloud’s PQC resource hub points to documentation on quantum-safe TLS key exchange, KMS support, and Tink cryptographic agility; current availability and product details should be checked in that official documentation.
What Google’s quantum resource estimates do—and do not—show
Google Research’s March 31, 2026, cryptocurrency paper estimates resources for implementing Shor’s algorithm against ECDLP-256, a mathematical problem used in elliptic-curve cryptography. These figures describe compiled circuits and a hypothetical fault-tolerant superconducting-qubit CRQC, not the capabilities of a present-day quantum computer.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →| Google Research estimate | What it describes |
|---|---|
| Fewer than 1,200 logical qubits and 90 million Toffoli gates | One compiled ECDLP-256 circuit. |
| Fewer than 1,450 logical qubits and 70 million Toffoli gates | A second compiled ECDLP-256 circuit. |
| Fewer than 500,000 physical qubits and a few minutes | Google’s estimate for running these circuits on a superconducting-qubit CRQC under stated standard assumptions about hardware capabilities. |
Google says the physical-qubit estimate is roughly 20 times lower than previous estimates. Logical qubits are the error-corrected units used in an algorithm; physical qubits are hardware components from which a fault-tolerant system would have to be built. Neither the estimate nor the assumed run time demonstrates that a suitable machine exists, establishes when one might arrive, or gives an independently verified probability of arrival.
What quantum computing could mean for Bitcoin and other cryptocurrencies
Google says most blockchain technologies and cryptocurrencies rely on ECDLP-256 for critical security aspects, making elliptic-curve cryptography a particular concern if a CRQC becomes available. The estimates above are therefore relevant to cryptocurrency systems, but they are not evidence that current quantum machines can steal coins or break wallets.
Rank #4
Google Research recommends that blockchain systems eventually transition to PQC and advises avoiding exposure or reuse of vulnerable wallet addresses. That is system-level guidance, not personalized advice about a particular wallet, transaction, or investment. Any transition also requires coordination among the software, services, and users that make up a blockchain ecosystem.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What organizations can do now
Google’s migration guidance points to preparation and prioritization rather than waiting for a firm arrival date. An organization can begin with a practical inventory and transition plan:
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBest Value
- Find public-key cryptography in use. Identify where systems use it for encryption, key exchange, signatures, or authentication, including dependencies on shared infrastructure and external providers.
- Prioritize by the consequence of exposure. Give early attention to information that must remain confidential for a long time, as well as authentication systems that need to be migrated before a CRQC exists.
- Plan for algorithm changes. Build crypto agility so algorithms can be replaced without an unplanned service disruption; account for the systems and partners that must change together.
- Use standards and current implementation guidance. Consult NIST’s PQC standards and the relevant platform documentation when choosing and deploying algorithms. Google’s explainer reports the first NIST standards announcement in 2024; the particular standards and product support should be verified in their current official documentation.
Google’s timeline is a company commitment, while its quantum-resource figures are conditional estimates. Together they explain why migration planning is starting now, without establishing when a quantum computer capable of breaking deployed public-key cryptography will arrive.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

