Google Publishes Post-Quantum Cryptography Roadmap

Earlier this month, Google Cloud published a roadmap for post-quantum cryptography (PQC). This roadmap aims for migration to PQC by 2029.
The migration strategy is centered on three domains:
- Defending today’s encrypted data against adversaries operating with a “harvest now, decrypt later” mindset
- Secure digital signatures to protect against falsified data and identities
- Construct systems capable of adapting to new cryptographic standards with minimal effort.
Google is pursuing Merkle Tree Certificates with Cloudflare rather than inputting post-quantum signatures into X.509 certificates.
Jason Soroko, Senior Fellow at Sectigo, shares his insights on this roadmap below.
Jason Soroko, Senior Fellow at Sectigo:
Cryptographers, including teams at Google and Cloudflare, with contributions from Sectigo, have been developing a new approach. Merkle Tree Certificates (MTCs) do not force large post-quantum signatures into an infrastructure that wasn't designed for them. Instead, they rethink how certificates are built and delivered for the post-quantum era.
Public key infrastructure (PKI) is ubiquitous in all our technology stacks. Cloud applications, AI-driven workloads, and billions of connected devices all rely on fast, constant TLS handshakes. If post-quantum authentication slows those handshakes down, everyone feels it.
MTCs are important because they remove that tradeoff in two important ways:
- Merkle Tree Certificates Help Keep the Internet Fast. Forcing traditional post-quantum signatures onto public websites would balloon handshake sizes and degrade the user experience, especially on mobile and high-latency connections. MTCs sidestep the problem by replacing multiple large signatures with one compact inclusion proof, holding overhead close to what users experience today. As a result, we get to keep using the internet exactly the way we do now, fast, and uninterrupted, with quantum resistance underneath.
- Merkle Tree Certificates Make Transparency Part of the Design. In today's PKI, Certificate Transparency (CT) logging is bolted onto the side of issuance as a separate step. When logging fails, a certificate can sit out in the wild unnoticed, creating a security blind spot. MTCs invert that relationship. The act of creating a certificate is the act of logging it. If a certificate is not in the tree, it simply does not exist. That matters because authentication in a post-quantum world cannot be truly secure without total visibility. MTCs make the two inseparable.
The momentum behind this shift is real and measurable. Browsers have signaled that MTCs are their preferred path for bringing post-quantum certificates to the public web, and feasibility experiments are already running against live internet traffic. Sectigo believes MTCs represent the most promising route to post-quantum authentication that preserves the performance and scalability organizations depend on today.
At the same time, we continue to track the broader post-quantum ecosystem, from NIST-standardized algorithms such as ML-DSA to evolving IETF specifications, browser roadmap decisions, and enterprise adoption requirements. The full scope of what MTCs can do is still coming into focus. What is clear is that organizations must have visibility, automation, and crypto agility to adapt as standards mature.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!







