Google Cloud KMS Adds Generally Available Quantum-Safe Digital Signatures
Published: August 13, 2026
What’s New?
As quantum computing develops, cybersecurity professionals are getting ready for a breakthrough in the protection of digital information. The conventional public-key cryptographic algorithms that ensure the security of digital signatures may, in the long run, be compromised by the revolutionary power of quantum computers.
To minimize that risk, Google Cloud has announced general availability of the quantum-safe digital signature feature in its Google Cloud Key Management Service (Cloud KMS).
Integrated into Cloud KMS are the new functionalities ML-DSA and SLH-DSA — two standardized post-quantum cryptographic digital signature algorithms. In addition, ML-KEM is also available for post-quantum key encapsulation.
This announcement is an important milestone for organizations as they continue to protect their data, software, transactions, and other digital assets with integrity and authenticity against future quantum threats.
Why Quantum-Safe Digital Signatures Matter?
Digital signatures are an integral aspect of contemporary cybersecurity. They allow organizations to confirm the identity of the individual who provided or authorized the data and the authenticity of the information.
Digital signatures are widely employed in software distribution, certificates, financial transactions, legal documents, identity management systems, and enterprise software applications.
All current public-key cryptography systems depend on mathematical problems that are extremely complicated to be solved by conventional computers. A sufficiently powerful quantum computer will disrupt the assumptions made for these data security mechanisms.
Recommended: Google Cloud KMS Introduces Quantum-Safe Digital Signatures Align with NIST’s PQC Standards
It is a real issue for sensitive information meant to be reliable for years. For example, a signed transaction now may need to be durable for a timeline of 10 years or more.
As a result, organizations cannot afford to wait until quantum computers hit the market and proceed with transitioning their systems. Google states that many standards bodies and government organizations are already establishing timeframes for quantum-safe technology transitions.
Google Cloud KMS Makes PQC Signatures Generally Available
With Google Cloud’s latest announcement, quantum-proof digital signatures are no longer limited to experimental or preview use in Cloud KMS.
Cloud KMS is a tool through which companies can create, manage and use cryptographic keys without the full overhead of running key management systems. The addition of PQC opens the door for incorporating quantum-proof signatures in existing applications through the Cloud KMS API.
The service now offers a range of algorithms from ML-DSA and SLH-DSA to cover different security and performance angles.
The Supported Algorithms include:
- SLH-DSA-SHA2-128s – NIST Security Level 1 using a state-less hash-based solution.
- ML-DSA-44 – NIST Security Level 2 and offers a speedy alternative.
- ML-DSA-65 – NIST Security Level 3 and offers a good trade-off between security and performance.
- ML-DSA-87 – NIST Security Level 5, suitable for those demanding the highest level of security and longevity of data.
This selection gives organizations enough room to find a quantum-resistant algorithm according to the needs of their security profile, application, and performance requirements.
ML-DSA and SLH-DSA: Two Different Approaches
A noteworthy feature of Google’s implementations is the fact that it enables the use of two different types of post-quantum digital signatures.
ML-DSA was standardized under FIPS 204 and is based on Turing machine concepts. MLDSA is characterized by different levels of security. Moreover, it is meant to achieve a good level of effectiveness applicable for various types of needs.
Recommended: AWS KMS Embraces the Quantum Era with ML-DSA Digital Signature Support
SLH-DSA was standardized under FIPS 205 and is based on a particular algorithm known as hash-based digital signature algorithm. Its mathematical properties allow organizations to adopt more than a single technology. The plagiarism of approaches allows organizations to prevent several security failures as well.
Solving the Challenge of Large Data Payloads
Once again, post-quantum cryptography presents a true operational difficulty, namely the significant volume of data involved in the processes of cryptography. Therefore, key management systems must guarantee secure key protection and effective execution of the operations with the use of the keys.
The use of mass data signatures requires either management services to be involved in the processes, which would lead to constraints such as bandwidth and latency, or employing an HSM to sign data.
Google Cloud resolves the issue with the help of the pre-hash and external-µ versions.
The complete volume of the data is not required to go to a secure signing system because, first, an application can convert that data into a hash, which is reduced to a fixed-size digest, and this digest will go just to the secure signing system.
In line with Google, it may be stated that adopting this methodology may assist in alleviating the flow of information through the security barrier and at the same time keeping backward compatibility with pure ML-DSA validators.
External-µ variants are also capable of achieving mathematical binding between the public key and message representative employed in the non-resignable property.
Is it of major importance for organizations that regularly sign high-volume digital files, such as software or document packages, datasets, etc.
What This Means for Businesses
In this context, this new technology can serve as the groundwork to enterprises for their post-quantum transition plans. Sectors like banking, government, medicine, telecom, military, vital infrastructure, and IT often use digital signatures that adhere to trustworthiness for a long period of time thus, shifting to quantum-proof technology becomes part of the overall security and compliance strategy.
Instead of waiting for quantum computing to become a future risk, companies may start the analysis by identifying areas where traditional cryptography is still used as well as those where migration is required.
A practical migration strategy may include:
- Inventory existing cryptographic systems and identify where digital signatures are used.
- Determine data longevity requirements, particularly for information that must remain verifiable for many years.
- Test PQC algorithms against existing applications and workflows.
- Evaluate performance and compatibility before large-scale deployment.
- Develop a crypto-agility strategy that makes future algorithm changes easier.
- Monitor regulatory requirements and industry standards as quantum-safe migration timelines evolve.
Why General Availability Is Significant
Transitioning to general availability means much more than releasing a new product. It indicates that post-quantum cryptography is becoming increasingly available for usage outside laboratories and research institutes.
A recently released industry report points out some operational advantages of how Google implemented this technology, especially its external hashing for bigger loads and many security levels. This makes it applicable for real-life processes rather than small experiments.
For developers who already use Cloud KMS, the good news is that the new algorithms can be used with the existing Cloud KMS engine and an API. It can simplify the implementation of quantum-secure signing in already existing apps that depend on Google’s key management services.
The Road Ahead for Post-Quantum Security
The quantum-resilient digital signatures represent only one dimension of the post-quantum security transition firms must undergo. In addition, they should focus on encryption, key exchange methods, certificates, hardware security modules, identity systems, software libraries, and third-party components.
For Google, the Cloud KMS initiative aims to employ ML-KEM and quantum-resilient signatures to demonstrate how post-quantum technology can help in different areas of cryptographic processes.
The transition will take time and will involve algorithm assessment, applications update, verification of interoperability, training of the security teams, and preparation of migration strategies. Fortunately, the existence of standardized PQC algorithms on a well-known cloud platform offers organizations a solid foundation for completing this journey.
Conclusion
The introduction of quantum-resilient signatures by Google Cloud KMS is considered to be a significant step forward on the way to post-quantum cybersecurity. With the help of ML-DSA, SLH-DSA, pre-hashed processes, and external-µ options, Google not only meets the modern application requirements but also assures high level of performance.
Cloud Code Signing
Seamless Automated Code Signing Tasks without Need of Physical HSM or Token using Cloud Code Signing Certificate.
Code Signing as a Service