Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

An Inside Look at Microsoft’s Quantum-Safe Program

An Inside Look at Microsoft's Quantum-Safe Program

Quick answer: Microsoft’s Quantum Safe Program (QSP) is the company’s initiative to migrate its own infrastructure and help customers migrate to post-quantum cryptography. In June 2026, Microsoft accelerated its target from 2033 to 2029, citing faster-than-expected quantum research progress and new US and French government deadlines. Organizations running Microsoft infrastructure should treat this as a signal to start their own cryptographic inventory now.

Key Takeaways

  • Microsoft accelerated its Quantum Safe Program completion target from 2033 to 2029 on June 30, 2026, citing a shorter expected timeline to cryptographically relevant quantum computers.
  • The acceleration followed the June 22, 2026 U.S. Executive Order setting 2030 to 2031 PQC deadlines for federal civilian systems, and France’s June 16, 2026 decision that ANSSI will stop certifying non-quantum-safe security products.
  • Microsoft has already integrated ML-KEM and ML-DSA into SymCrypt, its core cryptographic library for Windows and Azure, and enabled TLS hybrid key exchange.
  • Microsoft joins Google and Cloudflare, both of which have also committed to 2029 targets for their own post-quantum migrations.
  • For organizations running Microsoft infrastructure, the accelerated timeline is a signal to start cryptographic inventory now rather than wait for a mandate.

Microsoft’s Role in the Post-Quantum Transition

Our modern lives are powered by a layer of cryptographic security that operates largely in the background. It protects our personal data, secures our transactions, and validates our digital identities. This security is based on complex mathematical problems that are currently unsolvable by even the most powerful supercomputers. But the emergence of quantum computing is set to change everything. While still in its early stages, a scaled quantum computer could one day break these cryptographic locks, forcing a fundamental shift to new methods known as post-quantum cryptography (PQC).

Microsoft is a major participant in the global effort to prepare for this transition. The company’s ongoing work is unified under the Quantum Safe Program (QSP), a comprehensive, multi-year initiative designed to secure its own infrastructure while helping its customers and partners navigate this complex journey.

The Program in Action

The QSP’s strategy is not a “flip-the-switch” moment, but a deliberate, phased transition that reflects the scale of the challenge. Microsoft originally set a 2033 completion target, positioned two years ahead of the 2035 deadline referenced by many governments. On June 30, 2026, Microsoft Azure CTO Mark Russinovich announced that the company is accelerating that target by four years, to 2029, for its entire portfolio of products and services. Microsoft attributed the acceleration to faster-than-expected progress in quantum research, alongside two recent government actions: the U.S. Executive Order of June 22, 2026, which set 2030 and 2031 PQC migration deadlines for federal civilian systems, and France’s June 16, 2026 decision that ANSSI will stop certifying security products that are not quantum-safe. The revised timeline puts Microsoft alongside Google and Cloudflare, both of which have also committed to 2029 targets for their own post-quantum migrations.

Microsoft PQ Research

The QSP’s phased approach includes:

  • Phase 1: Foundational Security Components: This initial phase focuses on integrating PQC algorithms into the core cryptographic libraries and APIs that underpin Microsoft’s platforms. For example, the company has integrated PQC algorithms like ML-KEM and ML-DSA into SymCrypt, its core cryptographic library for Windows and Azure. This provides the foundational building blocks for developers to begin creating quantum-safe applications. Additionally, Microsoft has enabled TLS hybrid key exchange to begin addressing the immediate “Harvest Now, Decrypt Later” (HNDL) threat, where encrypted data is collected today to be decrypted by a future quantum computer.
  • Phase 2: Core Infrastructure Services: With the foundational components in place, the program is now prioritizing the most critical systems. This includes updating services for identity and authentication (such as Microsoft Entra), as well as key and secret management and signing services. Securing these essential elements first establishes a strong base for the wider transition.
  • Phase 3: All Services and Endpoints: The final and most extensive phase involves a broad rollout of PQC across the entire Microsoft ecosystem. This includes all Windows operating systems, Azure services, Microsoft 365, data platforms, and AI services, providing comprehensive, end-to-end protection. Microsoft’s accelerated timeline now targets this full rollout by 2029.

CBOM Secure

Gain complete visibility with continuous cryptographic discovery, automated inventory, and data-driven PQC remediation.

A Commitment to Global Collaboration

Microsoft’s work on PQC is deeply collaborative. The company is actively working with various standards bodies, including the National Institute of Standards and Technology (NIST) and the Internet Engineering Task Force (IETF). This is crucial for ensuring that the PQC algorithms and standards being developed are globally recognized and interoperable. Microsoft’s participation in these efforts, including its contributions to the Open Quantum Safe project, helps foster a more secure ecosystem for everyone.

What This Means for You

Microsoft’s ongoing work on PQC provides a valuable reference point for any organization. It underscores the importance of a well-planned transition and offers a clear signal that the time for action is now. For organizations using Microsoft products and services, this means:

  • A Clear Mandate to Act: The public timeline from a major tech provider like Microsoft highlights the need for all organizations to begin their own PQC preparations, starting with a cryptographic inventory to understand their current risk exposure.
  • Early Access: The availability of PQC capabilities for Windows Insiders and Linux users provides a low-risk environment to begin testing and piloting new algorithms. This is a valuable opportunity to assess the performance impacts and operational challenges of PQC on your own systems before a full-scale migration.
  • Industry Alignment: By contributing to global standards, Microsoft helps ensure that the PQC solutions you eventually implement will be compatible with a broader ecosystem, reducing the risk of vendor lock-in and ensuring a smoother transition.

PQC Advisory Services

Gain post-quantum readiness with expert-led cryptographic assessment, migration strategy, and hands-on implementation aligned to NIST standards.

How Encryption Consulting Can Help

The migration to a quantum-safe environment is a significant undertaking, and it can feel overwhelming. While technology providers like Microsoft are developing the necessary tools, the task of planning and executing the transition for your specific environment requires specialized expertise.

At Encryption Consulting, we offer PQC Advisory Services designed to help you navigate this process with confidence. We can help you with:

  • PQC Assessment: We’ll help you identify and inventory all of your cryptographic assets, providing a clear picture of your quantum risk and where to focus your efforts.
  • PQC Strategy & Roadmap: We’ll help you create a customized, step-by-step plan to transition to quantum-safe algorithms without disrupting your business operations.
  • PQC Implementation: We provide hands-on support to smoothly integrate new, quantum-safe algorithms into your existing security setup, ensuring a seamless and secure transition.

Conclusion

The quantum threat to our current encryption is a real and pressing issue that the cybersecurity community is actively addressing. The work being done by Microsoft provides a valuable roadmap and a clear signal for all organizations to begin their PQC journey. By understanding the phases of this transition, aligning with industry standards, and working with specialized partners, your organization can ensure its data remains secure, both now and in the quantum-powered future.

Frequently Asked Questions

What is Microsoft’s Quantum Safe Program (QSP)?

The Quantum Safe Program is Microsoft’s company-wide initiative to migrate its own infrastructure to post-quantum cryptography while helping customers and partners do the same. It covers foundational cryptographic libraries, core infrastructure services like identity and key management, and eventually all Windows, Azure, Microsoft 365, data, and AI services.

When does Microsoft plan to complete its PQC migration?

Microsoft originally targeted 2033. On June 30, 2026, Microsoft accelerated that target to 2029 for its entire portfolio of products and services, citing faster-than-expected progress in quantum research and new government deadlines in the US and France.

Why did Microsoft move its timeline up by four years?

Microsoft cited advances in quantum research that have shifted its risk assessment, alongside two government actions in June 2026: the U.S. Executive Order setting 2030 and 2031 PQC deadlines for federal civilian systems, and France’s decision that ANSSI will stop certifying security products that are not quantum-safe. The move also aligns Microsoft with Google and Cloudflare, which set similar 2029 targets.

What has Microsoft already implemented toward PQC readiness?

Microsoft has integrated the NIST-standardized ML-KEM and ML-DSA algorithms into SymCrypt, its core cryptographic library for Windows and Azure, and has enabled TLS hybrid key exchange to address harvest-now-decrypt-later risk in data moving today.

What should organizations running Microsoft infrastructure do now?

Start with a cryptographic inventory to understand where quantum-vulnerable algorithms are in use, then use Microsoft’s Windows Insider and Linux early-access channels to pilot PQC capabilities before Microsoft’s broader rollout reaches production systems.