Saturday, 10 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Google’s PQC roadmap puts traditional digital certificates under pressure

TechRadar ·
Google’s PQC roadmap puts traditional digital certificates under pressure

In March, Google moved its own post-quantum cryptography (PQC) migration deadline forward to 2029, a full six years ahead of NIST's guidance, and two ahead of the NSA's requirement for national security systems.

It was a terrific bit of security signaling, but now it is backed up by a new product-by-product roadmap organized around three risk domains, with milestones attached to named services.

For anyone whose job touches digital trust, the most significant of those three domains is Google’s attempt at enhancing foundational capabilities for cryptographic agility: building flexible systems that can adopt new cryptographic standards with minimal engineering effort as those standards evolve.

The message is that organizations should prepare for a future in which standards, certificate formats, and operational requirements continue to evolve, and evolve regularly, requiring cryptographic agility.

Why quantum risk is already a digital trust problem Adversaries are already harvesting and storing encrypted data today on the assumption that a future quantum computer will decrypt it (harvest now, decrypt later).

Anything with a long confidentiality tail, from health records to national archives to intellectual property, is already exposed to a machine that does not yet exist.

Quantum-resistant algorithms, like ML-DSA, solve the cryptographic problem, but they introduce much larger keys and signatures.

Deployed through today's public key infrastructure (PKI), they would inflate or possibly break the systems behind secure connections.

Legacy systems and high-latency networks would feel it most.

What is a Merkle Tree Certificate (MTC)? At the time this article is being written, the most significant development in Google's roadmap may be the easiest to miss.

Under Domain 2, Integrity and non-repudiation, a single line reads: “Google Trust Services, Merkle Tree Certificates, 2028”.

Merkle Tree Certificates (MTCs) are a new kind of website domain certificate designed to keep secure connections fast in the coming era of quantum computers.

Today a website proves its identity by presenting a certificate that carries several digital signatures, and the quantum-resistant versions of those signatures are so bulky they would slow down every secure connection on the internet.

MTCs solves this by having the certificate authority (CA) record everything it issues in a public, tamper-evident log, organized as a Merkle tree.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›