Enterprise Adoption & Migration: Where Post-Quantum Cryptography Stands in Late 2026
Introduction
Post-quantum cryptography (PQC) has moved from standards-committee discussion to active migration programs across industry and government alike. A clear signal of that shift: Google and Microsoft have both moved their internal migration targets forward to 2029. When two of the world's largest cloud and platform providers accelerate their own timelines, it's a useful data point for every organization - enterprise, government, or federal - building its own migration plan.
Why the Pace Is Picking Up
NIST finalized the first three PQC standards in August 2024 - FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) - with HQC added as a backup key-encapsulation mechanism in March 2025. These standards, along with federal guidance setting migration expectations for high-value and high-impact systems, have given organizations across sectors a common technical foundation to plan against.
Since then, growing awareness of "harvest now, decrypt later" risk and continued advances in quantum research have prompted many organizations — cloud providers among them — to treat migration as an active engineering priority rather than a future item. Government agencies and standards bodies have played a central role in making this possible, by establishing the algorithms and timelines the rest of the ecosystem is now building against.
Microsoft: Accelerating the Quantum Safe Program
In June 2026, Microsoft announced it is moving the completion target for its Quantum Safe Program (QSP) - its company-wide PQC migration effort - from 2033 to 2029. The program focuses on three priorities:
-
Network cryptography: Adopting TLS 1.3 as a baseline, since it's required to support hybrid post-quantum key exchange combining classical cryptography with ML-KEM.
-
Crypto-agility: Designing systems so cryptographic algorithms can be upgraded without architectural redesign, using self-describing metadata or versioned formats that let systems read older data while writing in newly approved algorithms.
- Trust chains: Applying PQC to code signing, certificate issuance, key protection, and update pipelines.
Windows Server 2025 added general availability of ML-DSA support (44/65/87) in Active Directory Certificate Services in May 2026, and Microsoft's ADCS implementation supports composite certificates that pair a classical signature (RSA or ECDSA) with an ML-DSA signature — both must validate for trust to be established. Microsoft has also emphasized that the hardest part of migration for most organizations isn't choosing an algorithm — it's locating where cryptography is already embedded across networks, storage, identity systems, and third-party software.

Google: Building Toward 2029
Google set its own 2029 target in March 2026, organized around its internal Quantum Threat Model, which prioritizes protecting long-lived encrypted data, ensuring signature integrity, and securing certificate infrastructure. Recent steps include:
-
Chrome: Hybrid post-quantum key exchange (ML-KEM) has been supported since 2024. In early 2026, Google introduced work on Merkle Tree Certificates (MTCs) with the IETF's PLANTS working group — a certificate format designed to keep TLS handshakes fast as post-quantum signatures grow larger.
-
Google Cloud: NIST-standardized algorithms (ML-KEM, ML-DSA, SLH-DSA) are now generally available in Cloud KMS, with hybrid quantum-safe key exchange rolled out across API endpoints and load balancers.
-
Android 17: Added ML-DSA-based signature protection, extending PQC to the consumer device layer at scale.
- Internal infrastructure: Already running on quantum-safe protocols via Google's internal ALTS transport layer.
Cloudflare has also committed to a 2029 target and reports that a majority of human-generated traffic on its network already uses post-quantum encryption.
What This Means for Migration Planning
Google and Microsoft's timelines give enterprise, government, and federal teams a useful reference point — much of the underlying protocol and infrastructure work is being handled by major providers, provided organizations adopt the updated protocols and APIs as they become available. Across sectors, three practices are proving consistent:
-
Inventory first. Cryptography is often embedded in legacy systems, third-party software, and hardware that hasn't been fully mapped. Discovery is typically the longest part of any migration.
-
Hybrid rollout by default. Running classical and post-quantum algorithms together — in key exchange, signatures, or both — preserves compatibility while reducing exposure, and provides real operational data before full cutover.
-
Crypto-agility as infrastructure. Systems built to swap algorithms without a full redesign will adapt more easily as standards continue to evolve.
The common thread across government guidance and industry roadmaps alike is the same: 2026 is the year to build cryptographic inventories and crypto-agile systems, so that by 2029 organizations have real options rather than a deadline-driven scramble.
Where ZTPass Fits In
While cloud and platform providers work through browser and infrastructure migration, ZTPass has been focused on a layer that carries its own hardware constraints: PQC-ready identity credentials.
Has your organization mapped its identity infrastructure for PQC readiness?
Visit www.ztpass.com to learn how ZTPass can help you pilot quantum-safe, hardware-rooted authentication.