This page documents production updates to Cloud Key Management Service. You can periodically check this page for announcements about new or updated features, bug fixes, known issues, and deprecated functionality.
Current version: v1
You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
August 24, 2026
Cloud KMS supports deleting key rings in General Availability.
For more information about deleting Cloud KMS resources, see Delete Cloud KMS resources.
August 06, 2026
Preview: Cloud KMS supports quantum-safe key import. You can use the following quantum-safe import methods:
HPKE_KEM_XWING_HKDF_SHA256_AES_256_GCMHPKE_KEM_ML_KEM_768_HKDF_SHA256_AES_256_GCMHPKE_KEM_ML_KEM_1024_HKDF_SHA256_AES_256_GCM
For more information about quantum-safe key import, see Quantum-safe key import.
July 29, 2026
Cloud KMS Autokey with same-project key storage (formerly known as Autokey for delegated key management) is generally available. Autokey with same-project key storage can be used on its own or alongside Autokey with dedicated-project key storage (formerly known as Autokey for centralized key management).
For more information, see Enable Cloud KMS Autokey. To learn how to set guardrails to constrain how Autokey is used in your organization, see Control Autokey usage.
July 16, 2026
Cloud KMS supports the following post-quantum computing (PQC) signing algorithms in General Availability:
PQ_SIGN_HASH_SLH_DSA_SHA2_128S_SHA256PQ_SIGN_ML_DSA_44PQ_SIGN_ML_DSA_44_EXTERNAL_MUPQ_SIGN_ML_DSA_65PQ_SIGN_ML_DSA_65_EXTERNAL_MUPQ_SIGN_ML_DSA_87PQ_SIGN_ML_DSA_87_EXTERNAL_MUPQ_SIGN_SLH_DSA_SHA2_128S
For more information about supported algorithms, see PQC signing algorithms. For more information about PQC signing, see Post-quantum cryptography (PQC) digital signature.
July 07, 2026
The Cloud KMS overview dashboard Asymmetric PQC insights chart is generally available. You can use the Asymmetric PQC insights chart and details view to identify how many and which of your asymmetric keys are susceptible to attacks from future quantum computers. This information is an important input into your quantum computing modernization planning and process.
For more information about the Asymmetric PQC insights chart, see View asymmetric post-quantum cryptography (PQC) insights.
May 14, 2026
The Cloud KMS Encryption metrics dashboard and project-level key tracking are generally available. You can use the Encryption metrics dashboard to review summaries and details of your keys used in customer-managed encryption key (CMEK) integrations and the resources that they protect. The Encryption metrics dashboard and the key Usage tracking tab support both centralized key management using a dedicated key project and delegated key management using keys stored in the same projects as the resources that they protect.
For more information about the Encryption metrics dashboard, see View encryption metrics. For more information about project-level key tracking, see View key usage.
March 02, 2026
Cloud KMS deletion of keys and key versions is generally available. Keys and key versions must meet deletion criteria before they can be deleted. Names of deleted keys can't be reused.
For more information, including deletion criteria, see Delete Cloud KMS resources.
February 11, 2026
Cloud KMS Autokey for projects is available in Public Preview. Autokey for projects lets you enable Cloud KMS Autokey for delegated key management. In delegated key management, keys created by Autokey are created in the same project as the resources they protect. This option is suitable for your organization if project administrators are in charge of key management for the projects they manage.
You can still use Cloud KMS Autokey for centralized key management in a folder, where all keys that protect resources in that folder are created in a dedicated key project. You can also use centralized key management in a folder, with certain projects within that folder configured to use delegated key management and same-project keys instead of creating keys in the dedicated key project.
You can enable Autokey for projects on individual projects or on all projects within a folder. For more information, see Enable Cloud KMS Autokey.
January 20, 2026
Cloud KMS is available in the following region:
asia-southeast3
For more information, see Cloud KMS locations.
December 17, 2025
Single-tenant Cloud HSM is now generally available. With Single-tenant Cloud HSM, you can create and manage dedicated single-tenant instances. Each instance is a cluster of partitions on HSMs in a single Cloud KMS region. Google manages the HSMs, but you have administrative control over your instance.