
Google Cloud KMS adds generally available quantum-safe digital signatures
Google Cloud KMS now offers generally available post-quantum digital signatures based on NIST ML-DSA and SLH-DSA standards.
Google Cloud has made post-quantum digital signatures generally available in Cloud Key Management Service, giving security teams a managed path to begin protecting long-lived signatures before large-scale quantum computers are practical. The July 29 announcement covers ML-DSA and SLH-DSA signing algorithms, along with ML-KEM support for key encapsulation, and positions the release as part of enterprise migration planning for cryptography that may need to remain trustworthy for many years.
What changed in Cloud KMS
The new Cloud KMS signing options include ML-DSA-44, ML-DSA-65, ML-DSA-87 and SLH-DSA-SHA2-128s, spanning several NIST security categories and use cases. Google's documentation, updated the same day, lists the post-quantum signing algorithms under the asymmetric-signing purpose with API names that begin with PQ_SIGN. It also notes that RSA and elliptic-curve signing are susceptible to future quantum attacks, while post-quantum signing is intended for long-term non-repudiation.
The operational detail that matters most for large systems is support for pre-hash and external-mu variants. Instead of sending a very large payload into a key service or hardware security module for signing, an application can hash the data locally and send a compact representative for the signing operation. Google says this helps lower bandwidth and latency while staying compatible with pure ML-DSA verifiers, an important point for storage, software supply chain, document integrity and compliance workflows that sign high-volume data.
Why it matters
The release arrives as governments and standards bodies press organizations to inventory and replace cryptography that could be weakened by future cryptographically relevant quantum computers. NIST finalized ML-DSA as FIPS 204 and SLH-DSA as FIPS 205 in 2024, giving cloud vendors and regulated industries stable standards to implement. NSA's CNSA 2.0 guidance has also pushed national security system operators toward quantum-resistant algorithms on defined timelines.
- For developers, the change means post-quantum signing keys can be created and used through existing Cloud KMS APIs rather than managed in a separate cryptographic stack.
- For security leaders, it creates a practical test bed for migration plans, audit requirements and application compatibility checks.
- For data owners, the focus is integrity and authenticity: signatures created today may need to verify reliably well into the quantum era.
Google is presenting the feature as a migration milestone, not a claim that every workload should switch immediately. Organizations still need to decide where long-term signatures matter, how verifiers will be updated, and whether software, HSM-backed or external key arrangements fit their risk model. The strongest near-term use is likely controlled pilots around signed artifacts, records and high-value archives where post-quantum verification can be introduced without disrupting production systems.
Sources
Cover photo by Brett Sayles on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment