Microsoft is pulling its post-quantum cryptography timeline forward. The new target? 2029.
Why the hurry? Quantum computing is advancing faster than expected. Microsoft Azure CTO Mark Russinovich said cryptographically relevant quantum computers could arrive sooner than anyone predicted — and the preparation work is enormous.
"Organizations need to start now," he said.
Microsoft’s Quantum Safe Program will now aim to transition critical products and services to post-quantum cryptography (PQC) by 2029. The company is also baking PQC requirements into its Secure Future Initiative (SFI).
Key focus areas: upgrading network cryptography to TLS 1.3, building crypto-agility for stored data, and migrating trust chains — code signing, certificate issuance, key protection, update pipelines — to PQC algorithms.
Crypto-agility is the technical term for not painting yourself into a corner. Microsoft says systems need to remove hard-coded algorithm assumptions and make algorithm upgrades routine, not emergency rewrites.
This follows President Trump signing an executive order setting a 2030 deadline for federal agencies to move high-value systems to PQC. Google and Cloudflare have both committed to quantum-safe infrastructure by 2029 as well.
The threat is real. "Harvest now, decrypt later" — adversaries collect encrypted data today, betting they can crack it once quantum arrives. That data includes government secrets, financial records, and private communications.
If your organization handles data that needs to stay confidential for more than a few years, this affects you. The migration window is closing.
