Harvest Now, Migrate by 2029: Microsoft Accelerates Its Quantum-Safe Cryptography Timeline
Microsoft accelerates its Quantum Safe Program to transition critical products to post-quantum cryptography by 2029, citing harvest-now-decrypt-later risk and new government deadlines.
Quantum computing headlines often focus on qubit counts and error rates. Microsoft is making a parallel bet on a problem that arrives before the machines break encryption: migrating the world's cryptography to post-quantum standards.
In a June 30 blog post, Azure CTO Mark Russinovich announced that Microsoft is accelerating its Quantum Safe Program, targeting transition of critical products and services to post-quantum cryptography (PQC) by 2029—two years ahead of many government completion deadlines.
Why the timeline moved
For years, PQC planning was framed as distant. That perspective is shifting. Russinovich cited recent U.S. and French government guidance pushing quantum-safe adoption as early as 2030 for high-risk systems. The immediate threat model includes "harvest now, decrypt later"—adversaries storing encrypted traffic today for future decryption.
Microsoft's July 10 Secure Future Initiative progress report reinforced the urgency, embedding PQC as a measured engineering requirement across network traffic, data-at-rest protection, and trust-chain modernization.
What the program covers
The Quantum Safe Program spans identity, infrastructure, data, and supply-chain security. Near-term work focuses on three areas:
- Upgrading network cryptography, including TLS 1.3 with hybrid post-quantum algorithms
- Building crypto-agility for stored data so organizations can swap algorithms without rewriting applications
- Modernizing trust chains for identity, signing, and certificates
Quantum-safe algorithms ML-KEM and ML-DSA are already available across major Microsoft platforms, the company says.
Policy context
A June 2026 U.S. executive order sets federal key-establishment deadlines of December 31, 2030, and digital-signature deadlines of December 31, 2031. CISA and NIST are directed to publish guidance on cryptographic bill-of-materials minimum elements.
Microsoft's 2029 target sits inside that window—and ahead of the company's broader 2033 full-transition goal for all services.
What this is not
Accelerating PQC readiness does not mean quantum computers can already break modern encryption. Microsoft has not publicly detailed quantum advances behind the timeline shift. The move is a security roadmap response to policy pressure and the harvest-now threat model—not proof of cryptanalytic breakthrough.
For enterprise buyers, the practical test is whether Microsoft delivers product-by-product migration instructions mappable to cryptographic inventories before 2029 arrives.
Sources
- Microsoft Security Blog — Accelerating the quantum-safe timeline (June 30, 2026)
- Microsoft Security Blog — Securing our future: July 2026 progress report on Microsoft's Secure Future Initiative (July 10, 2026)