On April 1, 2026, Google moved its internal readiness deadline for "Q Day" forward to 2029 — the point at which quantum computers will be capable of breaking the public-key cryptography that protects banks, militaries, governments, and virtually every person on Earth.
What Q Day Means
RSA and Elliptic-Curve Cryptography (EC) — the two algorithms on which virtually all digital security is based — will be broken by sufficiently powerful quantum computers. Not "theoretically someday," but according to Google, within three years.
"As a pioneer in quantum and post-quantum cryptography, it is our responsibility to lead by example and share an ambitious timeline," wrote Heather Adkins (VP Security Engineering) and Sophie Schmieg (Senior Cryptography Engineer) in a Google blog post.
What Google Is Already Doing
- Android 17: Receives ML-DSA support (a NIST-standardized post-quantum signature algorithm) in the Hardware Root of Trust. Developers can generate PQC keys in the Android Keystore and store them in secure hardware
- Verified Boot: ML-DSA is being integrated into the Android Verified Boot Library — the boot sequence is thus protected against quantum attacks
- Play Store: Google plans to migrate all developer signatures to PQC
- Remote Attestation: Being transitioned to post-quantum cryptography
Why the Urgency?
The 2029 deadline surprised even experienced cryptography experts. Brian LaMacchia, who led Microsoft's post-quantum transition from 2015 to 2022, called the timeline "a significant acceleration beyond anything we have seen so far — even beyond US government mandates."
The background: Google simultaneously published a whitepaper showing that future quantum computers can break Elliptic-Curve Cryptography with fewer qubits and gates than previously assumed. This significantly compresses the timeframe.
What This Means for Businesses
Every company that stores encrypted data today must assume that this data could be decryptable in three years. "Harvest now, decrypt later" — attackers collect encrypted data today and decrypt it as soon as quantum computers become available. Anyone with sensitive long-lived data (patents, health records, state secrets) has an acute problem.
Sources: Google Security Blog (04/01/2026), Ars Technica, SecurityWeek, Google Research Whitepaper, TechRepublic.