← All news

general

Microsoft Brings Quantum-Safe Deadline Forward to 2029

2026-06-30

Microsoft has decided that quantum is no longer a someday problem. This week the company said it is accelerating its Quantum Safe Program, with a new goal of moving critical products and services onto post-quantum cryptography by 2029. The stated reasoning is that cryptographically relevant quantum computers, the kind that can actually break today's encryption, may arrive sooner than previously expected.

What Microsoft has not done is say what changed. There is no breakthrough cited, no new benchmark, no specific paper. Just a shifted risk horizon and a firm suggestion that everyone else should start moving too. BleepingComputer has asked for more detail and is still waiting.

Why the urgency, even without a working quantum computer

The pressure is not about today. It is about a strategy known as harvest now, decrypt later. Attackers do not need a quantum computer in 2025 to benefit from one in 2035. They only need to capture encrypted traffic now and sit on it. The maths catches up later.

Anything with a long shelf life is already exposed to that bet:

  • Medical records
  • Government and diplomatic communications
  • Intellectual property and trade secrets
  • Long-term financial and legal data

Apple, Google and Signal have been quietly folding post-quantum algorithms into their consumer products for exactly this reason. Microsoft is now doing the same on the enterprise side, and saying so out loud.

The Secure Future Initiative angle

The quantum-safe push is being woven into Microsoft's Secure Future Initiative, the broader security overhaul the company kicked off after a rough run of high-profile breaches. That programme has been about getting basics right at scale. Adding post-quantum readiness to it signals that Microsoft sees cryptographic agility as foundational rather than futuristic.

The advice that is actually useful

The most interesting line in the announcement is not the 2029 date. It is the guidance on where to start. Microsoft is telling organisations not to begin with the algorithms themselves. Start with the infrastructure.

The reason is mundane and slightly grim. Most environments cannot tell you where their cryptography actually lives. It is buried in libraries, embedded in firmware, hardcoded in legacy applications, baked into certificates that nobody documented when the person who set them up left in 2017. Swapping algorithms in that environment is not a project. It is a multi-year archaeology dig.

So the practical first move for anyone running enterprise systems is the boring one. Build an inventory. Find out what cryptographic algorithms are in use, where, by which systems, talking to whom, with what key lengths and what certificate lifespans. That work has value regardless of when quantum actually breaks RSA. It also happens to be the only way to be ready when it does.

The window is shorter than it looks

2029 sounds far away until you remember how long enterprise migrations actually take. Replacing TLS implementations across a global business, rotating long-lived certificates, updating embedded devices in the field, renegotiating standards with partners and regulators, none of it happens quickly. By the time the maths is genuinely broken, the migration window will have closed for anyone who waited.

Microsoft's accelerated timeline is not really a prediction about quantum computing. It is a statement about how long the rest of the work takes.

Microsoft Brings Quantum-Safe Deadline Forward to 2029 | RiskSense