Crypto libraries · Cloud & CDN

Google

Google has deployed hybrid ML-KEM key exchange in browser and cloud paths while post-quantum signatures remain preview-stage in Cloud KMS.

ShippingVerified through 2026-09-06
Products

Verified capability

2 records
Crypto libraries

Chrome 131+ TLS stack

Shipping
Hybrid key exchange
X25519MLKEM768 enabled by default
PQC certificate authentication
Not enabled
CChromium security blog and TLS group defaultsChecked 2026-09-06
Open first-party evidence

Do not infer: That browser-visible connections are authenticated with post-quantum signatures.

Cloud & CDN

Google Cloud services and KMS

Partial
API endpoint key exchange
Hybrid ML-KEM deployed
Cloud KMS PQC signing
Preview for ML-DSA and SLH-DSA
Organisation target
Full readiness by 2029
CGoogle Cloud first-party roadmapChecked 2026-09-06
Open first-party evidence

Do not infer: That every customer workload or authentication pathway is already post-quantum secure.

Roadmap explorer

Published milestones

3 dated steps
  1. 2024-09-13
    statementC

    Chrome's ML-KEM transition documented

    Google documented the move from experimental Kyber to the standardized ML-KEM hybrid group used by Chrome.

    A new path for Kyber on the web
  2. 2026-08
    previewC

    Cloud KMS signatures and roadmap published

    Google Cloud documented quantum-safe digital-signature support and its broader service transition plan.

    Google Cloud quantum-safe signatures
  3. 2029
    targetC

    Full readiness target

    Google's published roadmap targets readiness across its cloud estate; this is a vendor target, not a guarantee for every customer workload.

    Google Cloud PQC roadmap
Compare OpenSSLCompare OpenSSHCompare SignalCompare ThalesCompare Amazon Web ServicesCompare Infineon