Is your domain using post-quantum encryption? Now you can see for yourself
- ID
- 29818
- Status
- summarized
- Published
- 29 Sep 2026, 9:00 PM
- Fetched
- 29 Sep 2026, 10:55 PM
- Provider
- Cloudflare Blog
- Category
- infrastructure
- Original URL
- https://blog.cloudflare.com/post-quantum-visibility/
- Source URL
- https://blog.cloudflare.com/rss/
Summary
- Score
- 6.0
- Created
- 29 Sep 2026, 10:56 PM
- Tags
- Audience
- developerssaas_founders
What happened
Cloudflare added per-connection post-quantum TLS visibility to Logpush, Log Explorer, and the HTTP Traffic Analytics dashboard, exposing the key-exchange algorithm negotiated on every incoming request so customers can audit PQ posture per domain. Its Radar data shows roughly 70% of browser-generated traffic to Cloudflare is already protected with hybrid ML-KEM (FIPS 203), but only about 15% of the origins Cloudflare connects to use it. Cloudflare is targeting full post-quantum security by 2029, and says many customers face quantum-readiness deadlines around 2030; it also recently launched Automatic Key Exchange for the Cloudflare-to-origin connection to reveal which algorithms an origin supports.
Why it matters
The 70% visitor vs 15% origin gap is the actionable number: if you run an origin behind Cloudflare, your visitors are probably already negotiating hybrid ML-KEM while your own origin likely is not, so the weak link is on your side of the connection. You can now pull the negotiated key-exchange field from Logpush or Log Explorer per domain to find which of your origins still fall back to classical cryptography, and check whether outdated origin TLS config is downgrading a connection that could support PQ. There is no Malaysia-specific or regional detail in this post; treat it as a general infrastructure item.
Discussion angle
Walk through the 70/15 split live: what does it actually take to move an origin to hybrid ML-KEM, and would anyone here change their TLS termination or load-balancer config before a 2030-style deadline rather than after?