DEV Community

Tran Tien Van
Tran Tien Van

Posted on Originally published at vandatateam.com

Quantum-Safe Key Import Lands in Google Cloud KMS

Google Cloud KMS now previews quantum-safe key import, wrapping your BYOK keys in transit with NIST ML-KEM. Here is what it protects, and how to adopt it.

Key takeaways

  • In August 2026, Google Cloud previewed quantum-safe key import in Cloud KMS for software keys, wrapping customer-supplied keys in transit with post-quantum cryptography.
  • The wrapping uses NIST-standardized ML-KEM (FIPS 203) in three hybrid options, X-Wing, ML-KEM-768, and ML-KEM-1024, layered with classical AES-256-GCM.
  • It directly targets Store-Now-Decrypt-Later attacks, where an adversary records key material today to break it with a future quantum computer.
  • The big win is scope: you keep your existing Bring-Your-Own-Key pipelines and downstream KMS integrations, and only swap the wrapping mechanism.
  • Van Data Team's recommendation: inventory your long-lived secrets and data first, then protect those import paths in the preview, since the feature is not yet GA.

📖 Read the full guide on Van Data Team → Quantum-Safe Key Import Lands in Google Cloud KMS

Top comments (0)