blog.cloudflare.com 29 Sept 2026, 13:00 UTC

Cloudflare Tracks Post Quantum Encryption Across Live TLS Traffic

Cloudflare Tracks Post Quantum Encryption Across Live TLS Traffic
CyberSIXT Evidence Panel Source marked as original reporting

CLOUDFLARE has expanded its post-quantum (PQ) visibility capabilities to show, in live traffic, how much post-quantum encryption is being used in TLS 1.3 connections. The new tools feed into Cloudflare’s Application Security and Logs products, enabling domain‑level insight via Logpush, Log Explorer, and the HTTP Traffic Analytics dashboard.

By surfacing the key exchange algorithm negotiated for each incoming connection, customers can audit their PQ posture, assess compliance, and identify cryptographic gaps across their domains.

The article explains that most browsers now rely on a hybrid approach, combining classical ECDHE (eg X25519, P-256, P-384) with post‑quantum ML‑KEM (notably X25519MLKEM768) for TLS 1.3. This “belt‑and‑suspenders” strategy aims to protect traffic from harvest‑now, decrypt‑later attacks.

Cloudflare notes that roughly 70% of visitor traffic to its network uses post‑quantum X25519MLKEM768 on the visitor side, while about 15% of origin connections employ hybrid PQ crypto, with some legacy or non‑PQ configurations still in play. The visibility features include a new TLS Key Exchange card in the HTTP Traffic Analytics dashboard, plus a ClientTLSKeyExchangeGroup field in logs to show per‑connection PQ usage.

For organisations with legacy origins, Cloudflare recommends using a Cloudflare Tunnel to preserve TLS 1.3 with PQ encryption without upgrading the origin server. Cloudflare emphasises that PQ encryption is now a practical step for many users aiming to mitigate long‑term risk ahead of broader post‑quantum authentication deployment.

View full article

Article by CyberSIXT