Microsoft Pulls Post-Quantum Deadline Forward to 2029
Azure CTO Mark Russinovich says the 'risk horizon' has moved. Redmond now wants PQC-ready systems four years ahead of the industry's 2033 target.

Key points
- Microsoft has moved its post-quantum cryptography target to 2029, ahead of most national agency deadlines of 2033.
- Azure CTO Mark Russinovich cited accelerating quantum research as the reason for the earlier deadline.
- ML-KEM, ML-DSA and SLH-DSA, the NIST-finalised algorithms, are already landing in Microsoft's cryptographic library SymCrypt.
- Enterprises face an inventory problem: most don't know where their cryptography lives.
- Microsoft has not confirmed whether the 2029 target covers on-premises Windows Server and Active Directory.
Why is Microsoft moving faster than everyone else?
Microsoft is pulling its post-quantum cryptography deadline forward by roughly four years, citing faster-than-expected progress in quantum computing research. In a Tuesday post, Azure CTO Mark Russinovich said the company will aim to have quantum-safe algorithms deployed across its products by 2029, ahead of the 2033 timeline set by most national cybersecurity agencies. "Advances in quantum research and development have shifted the risk horizon," Russinovich wrote.
Harvest-now-decrypt-later attacks, where adversaries collect encrypted traffic today to crack it once a capable quantum machine exists, are no longer a concern for a distant decade. Nation-state operators are widely believed to be running exactly that playbook. RSA and elliptic-curve cryptography, which underpin TLS and VPN connections along with code signing, are the primary targets. Symmetric algorithms fare better but still lose some margin.
What algorithms is Microsoft deploying?
Microsoft's plan leans on the three algorithms NIST finalised in 2024: ML-KEM for key encapsulation, ML-DSA for digital signatures, and SLH-DSA as a hash-based signature backup. All three are already appearing in SymCrypt, the cryptographic library underneath Windows and Azure.
Russinovich framed the acceleration as a supply-chain problem more than a math problem. Rolling out new algorithms across hardware security modules, firmware signing and PKI hierarchies takes years. Waiting until a quantum computer exists is waiting too long.
How does this fit with government timelines?
The 2029 target sits inside a tightening band of official guidance. The UK's National Cyber Security Centre published a three-phase migration roadmap earlier this year calling for discovery by 2028 and full migration by 2035. The US National Security Agency's CNSA 2.0 suite requires software and firmware signing to be quantum-safe by 2025 for national security systems, with broader deadlines through 2033. We reported in June that a White House executive order mandates high-value federal assets shift to post-quantum cryptography by 2030 to 2031. Redmond is now firmly in the earlier camp.
Should you worry about your own systems?
Customers should expect PQC options in Azure Key Vault first, followed by hybrid key exchange in TLS connections to Microsoft services and quantum-safe signing in Windows update infrastructure. Hybrid modes, running classical and post-quantum algorithms in parallel, will carry most of the load during the transition.
For enterprises, the harder problem is inventory. Our June reporting found that only 5% of security teams have a defined post-quantum strategy, a year after NIST published its first three standards. Certificate stores, embedded devices and legacy applications all hold keys that need rotating onto new algorithms. Microsoft's shifted deadline puts real pressure on vendors down the stack.
Russinovich's post did not say whether the 2029 target is internal-only or extends to on-premises Windows Server and Active Directory, where cryptographic agility has historically lagged. That gap is worth watching.



