Microsoft pulls its post-quantum deadline forward to 2029

Started by Harbour, Jul 02, 2026, 05:24 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Microsoft pulls its post-quantum deadline forward to 2029   Views(Read 108 times)

Harbour

So Microsoft just told everyone the quantum clock is ticking faster than they thought. Their Azure CTO says the risk horizon has shifted and cryptographically relevant quantum computers could show up sooner than the old estimates suggested. They are speeding up the whole Quantum Safe Program to hit post-quantum crypto across critical products by 2029

What stands out to me is the framing that the work required is significant so orgs need to start now. That is not the usual vague hand waving you get from vendors on this topic. It reads like they actually believe the migration is going to take years of grinding through TLS stacks and certificate policies

The concrete stuff they listed is upgrading network crypto to TLS 1.3 and building crypto agility so algorithms can swap without redesigning systems. That agility piece is the smart part because nobody knows exactly which PQC algorithms survive the next round of cryptanalysis. If you can hot swap them you are not betting the farm on one choice

My honest take is that 2029 is still optimistic for a company that size given how much legacy garbage runs under Azure. But even announcing it publicly puts pressure on the rest of the industry to stop treating harvest now decrypt later as a hypothetical. This is the kind of thing this whole forum exists for so I am glad they are moving

My team is always one signing away

LostReece55

2029 feels aggressive for something Azure sized. I will believe it when I see the certificate lifetimes actually shrink in production
Lurker since the beginning

Policy Wizard

Crypto agility is the real headline here, not the date. If you cannot swap algorithms fast you are stuck no matter what deadline you pick
Measure twice, post once

CollapseState

Harvest now decrypt later has been a known threat for years though. Why is everyone suddenly acting surprised

Sigma

Because the hardware timelines just moved. Read the other threads on Majorana 2 and it makes more sense

Amber Tiger

Question for the crowd, does anyone actually trust the current NIST PQC picks enough to deploy them without agility as a fallback

VioletBarrel

TLS 1.3 first is the correct order of operations. You cannot layer PQC on top of a mess

Hannah

I work adjacent to this and the hard part is never the flagship product, it is the thousand internal services nobody documented

EventHorizon

Kind of wild that a marketing announcement is more concrete than most standards bodies have managed

Cached Stephen

Anyone know if this covers on prem Windows Server or just cloud services

Related Topics (5)

Save money on everyday spending Free cashback on thousands of retailers
View offer