Adversaries are already collecting encrypted data today, intending to decrypt it once a cryptographically-relevant quantum computer (CRQC) becomes available. Google warns this makes the threat immediate, not theoretical .
Google's own research shows that elliptic curve cryptography (used across TLS, Bitcoin, and SSH) can be broken with roughly 20x fewer physical qubits than earlier estimates suggested . This collapses the expected arrival window of a CRQC to 2029 .
Google and industry analysts note that AI tools are enabling more sophisticated attack automation, faster vulnerability discovery, and larger-scale HNDL collection — compounding the risk that by the time a CRQC exists, adversaries will already have vast stores of encrypted material ready to decrypt .
Bitcoin's ECDSA signatures and all TLS-based financial infrastructure are vulnerable to Shor's algorithm. If a CRQC arrives by 2029 without prior migration, the entire Bitcoin UTXO set, banking TLS connections, and payment card transactions could be compromised retroactively and in real time .
Google's timeline is 2 years ahead of the NSA's target and roughly 6 years ahead of NIST's guidance, reflecting the company's assessment that the risk window has shortened dramatically.
| Entity | Timeline | Notes |
|---|---|---|
| 2029 | Hard internal deadline; previously aligned with NIST | |
| NSA (CNSA 2.0) | 2031 | National security systems target |
| NIST | ~2035 | Broad federal guideline for migration completion |
On August 13, 2024, NIST finalized and published the first three Federal Information Processing Standards for post-quantum cryptography :
These standards provide the cryptographic primitives that Google, Cloudflare, and other organizations are now racing to deploy by their 2029 targets.
Cloudflare announced its own accelerated 2029 target for full PQC security, including post-quantum authentication, in an April 2026 blog post. Cloudflare explicitly noted that Google's acceleration and the independent advances in quantum hardware factored into its decision . This dual commitment from two of the internet's largest infrastructure providers signals that 2029 is emerging as a de facto industry deadline, far ahead of government recommendations.
Google's 2029 PQC migration deadline is driven by: (1) new quantum research cutting qubit requirements ~20x, (2) active HNDL attacks already collecting data, (3) AI's amplification of cyber threats, (4) existential risk to Bitcoin and financial cryptography, and (5) the availability of finalized NIST standards (FIPS 203/204/205) that make large-scale migration technically feasible. The timeline is about 2–6 years more aggressive than U.S. government targets, and it aligns with Cloudflare's parallel 2029 commitment, making 2029 the new industry "Q-Day" milestone.