A cryptography engineer calls for an urgent rollout of quantum-resistant cryptography, saying the risk of inaction is now unacceptable, after Google's warning
My position on the urgency of rolling out quantum-resistant cryptography has changed compared to just a few months ago.
Context & Ripple Effects
The call follows Google’s 2029 post-quantum migration target, which turns a long-running cryptographic risk into an operational timetable for a major platform. Earlier coverage framed the underlying issue as quantum computing’s eventual ability to undermine widely used public-key methods; the immediate question has shifted from selecting replacement algorithms to deploying them across real systems.
The urgency also sits alongside the UK NCSC’s 2035 post-quantum transition guidance for critical sectors. Together, these signals make migration planning consequential well before a quantum-capable attack arrives, because cryptographic dependencies are embedded in identities, protocols, devices, and archived data.
First-order effects
- Security and infrastructure teams face added pressure to inventory where current public-key cryptography is used and to prioritize systems that will remain in service for years.
- Google’s stated timetable becomes a practical planning reference for organizations and vendors that interoperate with its services, rather than a distant research milestone.
Second-order effects
- Cryptography, cloud, and device suppliers will be pushed to demonstrate migration paths and compatibility for quantum-resistant schemes; customers will increasingly weigh deployability alongside algorithm choice.
- Critical-infrastructure operators may bring post-quantum work forward as the gap between Google’s target and the UK’s sector-wide guidance highlights the risk of treating migration as a last-minute compliance project.
Third-order effects
- If large platforms and public-sector guidance continue to converge, cryptographic agility—being able to replace algorithms without rebuilding services—could become a standard procurement and architecture requirement.
- The transition is likely to reward implementation capacity as much as cryptographic research: the hard constraint will be upgrading long-lived, interconnected systems without disrupting trust or interoperability.
The trend: Post-quantum cryptography is moving from a standards-and-research problem toward a multi-year infrastructure migration in which deployment readiness becomes the central competitive and security issue.