Skip to content

Technical

Hybrid TLS migration: X25519 + ML-KEM in practice

Hybrid TLS combines classical and post-quantum key exchange so connections remain secure if either layer holds — the near-term deployment pattern for ML-KEM.

Hybrid TLS X25519 ML-KEM handshake diagram.
NIST PQC Standards Update: On-Ramp Signatures and Global Roadmaps | RWPQC 2026 Watch on YouTube

Why hybrid first

Full cutover to PQC-only TLS risks interoperability failures with legacy clients. Hybrid key exchange (e.g., X25519 + ML-KEM-768) requires an attacker to break both layers.

Cloudflare's roadmap deployed hybrid ML-KEM for most proxied traffic before tackling post-quantum authentication. FIPS 203 defines ML-KEM parameters enterprises should standardize on.

Lab to production path

  1. Prototype with Open Quantum Safe oqs-provider and Docker demos.
  2. Test against test.openquantumsafe.org for cipher suite interoperability.
  3. Pilot on non-production endpoints; capture handshake traces for audit evidence.
  4. Roll out per NIST IR 8547 priority tiers.

The RWPQC session covers NIST guidance on hybrid implementations (SP 800-56C references).

Evidence auditors expect

  • Before/after algorithm tags from re-scans
  • Handshake appendix showing ML-KEM negotiation
  • CBOM export reflecting updated cipher policy

See also hybrid TLS handshake appendix blog.

This quarter

  1. Enable hybrid KEM on one staging load balancer.
  2. Verify client compatibility matrix (browser, API clients, IoT).
  3. Document rollback procedure before production promotion.

Continue on the Q-Day hub: Hybrid TLS guide

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-21

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.