Crypto libraries · Cloud & CDNGoogle
Google has deployed hybrid ML-KEM key exchange in browser and cloud paths while post-quantum signatures remain preview-stage in Cloud KMS.
ShippingVerified through 2026-09-06
Products
2 recordsVerified capability
Crypto libraries
ShippingChrome 131+ TLS stack
- Hybrid key exchange
- X25519MLKEM768 enabled by default
- PQC certificate authentication
- Not enabled
CChromium security blog and TLS group defaultsChecked 2026-09-06
Open first-party evidence Do not infer: That browser-visible connections are authenticated with post-quantum signatures.
Cloud & CDN
PartialGoogle Cloud services and KMS
- API endpoint key exchange
- Hybrid ML-KEM deployed
- Cloud KMS PQC signing
- Preview for ML-DSA and SLH-DSA
- Organisation target
- Full readiness by 2029
CGoogle Cloud first-party roadmapChecked 2026-09-06
Open first-party evidence Do not infer: That every customer workload or authentication pathway is already post-quantum secure.
Roadmap explorer
3 dated stepsPublished milestones
- 2024-09-13statementC
Chrome's ML-KEM transition documented
Google documented the move from experimental Kyber to the standardized ML-KEM hybrid group used by Chrome.
A new path for Kyber on the web - 2026-08previewC
Cloud KMS signatures and roadmap published
Google Cloud documented quantum-safe digital-signature support and its broader service transition plan.
Google Cloud quantum-safe signatures - 2029targetC
Full readiness target
Google's published roadmap targets readiness across its cloud estate; this is a vendor target, not a guarantee for every customer workload.
Google Cloud PQC roadmap