MikhbarMIKHBAR
Artificial Intelligence

Cloudflare Adds Post-Quantum Visibility for Domains

Cloudflare has expanded its security portfolio by introducing granular visibility into post-quantum encryption directly at the domain level.

Cloudflare Adds Post-Quantum Visibility for Domains

New Domain-Level Visibility Features

Cloudflare has introduced additional post-quantum cryptography visibility tools into its Application Security and Logs products. Users can now inspect and graph the adoption of post-quantum TLS 1.3 encryption for live traffic directly from within Logpush, Log Explorer, and the HTTP Traffic Analytics dashboard. By surfacing the key exchange algorithm negotiated on every incoming request from visitors, the platform gives customers granular, per-connection telemetry to audit their post-quantum posture, assess compliance, and identify cryptographic gaps across their domains.

Cloudflare is targeting 2029 for full post-quantum security. Executing a cryptographic transition at scale requires detailed telemetry, and the company has already deployed post-quantum encryption across many products, including its cloud-proxy platform and on every on-ramp and off-ramp of its SASE platform.

Is your domain using post-quantum encryption? Now you can see for yourself
Image related to the report from Cloudflare Blog · Source: Cloudflare Blog

Macro and Domain-Level Perspectives

When addressing post-quantum visibility, macro-level insights have previously been available through Cloudflare Radar to track global post-quantum encryption statistics for visitor connections and origin servers. Data from Cloudflare Radar shows that about 70% of browser-generated traffic hitting the network is protected with post-quantum encryption using hybrid ML-KEM, as outlined by FIPS 203. Meanwhile, only about 15% of origins that Cloudflare connects to currently use hybrid ML-KEM.

While macro views offer Internet-wide readiness metrics, customers have requested the ability to examine individual domain behavior. Previously, visibility was limited to knowing the TLS version used by individual domains, but not the specific cryptographic algorithms paired with them. This new capability allows organizations to determine the exact fraction of traffic utilizing post-quantum encryption for specific domains.

Cloudflare Adds Post-Quantum Visibility for Domains
Image related to the report from Cloudflare Blog · Source: Cloudflare Blog

Post-Quantum Cryptography in TLS 1.3

In 2024, the National Institute of Standards and Technology stated that RSA and Elliptic Curve Cryptography should be deprecated by 2030, prompting governments and regulators to adopt similar deadlines. Consequently, many products utilize post-quantum encryption through a cryptographic key agreement algorithm called hybrid ML-KEM to counter harvest-now-decrypt-later attacks.

Within TLS 1.3, the key exchange group X25519MLKEM768 serves as the recommended algorithm for post-quantum encryption and is preferred by major browsers. This hybrid approach combines the Elliptic Curve Diffie-Hellman Key Exchange over curve X25519 with the post-quantum Module Lattice Key Encapsulation Mechanism, providing dual-layer security where a compromise of only one exchange still leaves the resulting shared secret secure.

Cloudflare Adds Post-Quantum Visibility for Domains
Image related to the report from Cloudflare Blog · Source: Cloudflare Blog

Transitioning Toward Full Post-Quantum Security

Beyond encryption, the broader transition involves post-quantum authentication to upgrade certificates and signatures away from RSA and ECC toward algorithms like ML-DSA. Cloudflare has recently enabled origins to use ML-DSA-44 certificates over TLS 1.3 and launched a certificate authority supporting post-quantum Merkle Tree Certificates, although hybrid ML-KEM encryption remains more broadly deployed at this stage.

image3.png
Image related to the report from Cloudflare Blog · Source: Cloudflare Blog

Sources

  • Cloudflare BlogIs your domain using post-quantum encryption? Now you can see for yourself

Continue chronologically

Related entity coverage