In March, Google announced it would accelerate its plan to transition to post-quantum cryptography (PQC) to 2029, moving six years ahead of guidance from the National Institute of Standards and Technology (NIST) and two years ahead of the National Security Agency’s (NSA) requirements for national security systems. This shift was accompanied by a detailed roadmap, breaking down the migration into three risk domains and linking each to specific products and services. For organizations involved in digital security, the most notable aspect is Google's focus on building systems that can adapt to evolving cryptographic standards with minimal effort—what the company calls "cryptographic agility."
The push for cryptographic agility reflects a growing awareness that digital security standards, certificate formats, and operational needs will continue to evolve rapidly. Cybercriminals are already collecting encrypted data, assuming that future quantum computers will be able to decrypt it. This means that data with long-term confidentiality needs—such as health records, national archives, or intellectual property—is already at risk from technology that doesn't exist yet. While quantum-resistant algorithms like ML-DSA can solve the encryption problem, they require significantly larger keys and signatures. If deployed using today’s public key infrastructure (PKI), they could slow down or even break existing secure connections, especially on legacy systems and high-latency networks.
To address these challenges, Google is developing Merkle Tree Certificates (MTCs), a new kind of digital certificate designed to maintain fast, secure internet connections in the quantum era. Traditional website certificates use multiple digital signatures to prove a site's identity. However, quantum-resistant versions of these signatures are too large and could slow down the internet. MTCs solve this by using a Merkle tree structure, a method of organizing data in a way that makes it easy to verify without carrying the full weight of each signature. The certificate authority (CA) records all issued certificates in a public, tamper-evident log, and the website only needs to show a short path of digital fingerprints to prove its authenticity. Browsers can then verify this path against a summary of the log they already have. Importantly, MTCs are still X.509 certificates, the standard format used today, and they work alongside traditional certificates rather than replacing them.
In current systems, transparency is an added step after a certificate is issued. A CA signs a certificate and submits it to independent logs, which then issue signed timestamps (SCTs) confirming the certificate's publication. However, a compromised log could falsely claim a certificate was published when it wasn't. MTCs change this by making transparency a core part of the certification process. A certificate is only valid if it appears in the CA's public log, and browsers verify this directly during each connection. This ensures that any certificate not in the log is invalid, making the system more secure and transparent. As a result, transparency is not only maintained in the quantum era but strengthened.
MTCs are not solely a Google initiative. The design is being developed by a group that includes Google, Apple, Cloudflare, and Geomys, with contributions from certificate authorities like Sectigo and support from organizations like Let's Encrypt. The goal is to create an open standard that any certificate authority can implement, free from control by a single company. This collaborative effort means that the organizations shaping the future of web security are those actively involved in the working group. Those who remain outside may find themselves following decisions made by others, rather than influencing them. The opportunity to get involved is still open, and the timeline for adoption is flexible.
While Google has set a 2028 target for MTCs, this date is tied to ongoing standardization work at the Internet Engineering Task Force (IETF), and such timelines can shift. However, the overall direction seems clear. Google plans to support quantum-resistant certificates only in the MTC format, not as traditional X.509 certificates with quantum-resistant signatures. While classical signatures and X.509 certificates have worked well for decades, the rise of quantum computing necessitates a redesign. For organizations, the key takeaway is not that they need MTCs immediately, but that they should be prepared to adopt them—or whatever future standards emerge—without requiring long, complex engineering efforts. This is the essence of cryptographic agility that Google is building into its strategy.
In practical terms, organizations should start by creating a complete inventory of their certificates and cryptographic assets, as they can’t migrate what they can’t see. They should also implement automated certificate lifecycle management, as shorter certificate lifetimes will make manual processes unsustainable before quantum computers even arrive. Additionally, they should request a written post-quantum roadmap from their certificate authority. The full capabilities of MTCs are still being explored, and they may not be the only solution the industry adopts. However, those that invest in cryptographic agility, certificate management, and visibility today will be best positioned to adapt as post-quantum standards develop. The future of digital trust will belong to those who can evolve as quickly as the technology they rely on.
Google Advances Post-Quantum Cryptography with Merkle Tree Certificates
AI-rewritten from original reportingHow it works
post-quantummerkle-tree-certificatesgooglecryptographydigital-trustnsa



