Technical
Hybrid TLS migration: X25519 + ML-KEM in practice
Hybrid TLS combines classical and post-quantum key exchange so connections remain secure if either layer holds — the near-term deployment pattern for ML-KEM.

Why hybrid first
Full cutover to PQC-only TLS risks interoperability failures with legacy clients. Hybrid key exchange (e.g., X25519 + ML-KEM-768) requires an attacker to break both layers.
Cloudflare's roadmap deployed hybrid ML-KEM for most proxied traffic before tackling post-quantum authentication. FIPS 203 defines ML-KEM parameters enterprises should standardize on.
Lab to production path
- Prototype with Open Quantum Safe oqs-provider and Docker demos.
- Test against test.openquantumsafe.org for cipher suite interoperability.
- Pilot on non-production endpoints; capture handshake traces for audit evidence.
- Roll out per NIST IR 8547 priority tiers.
The RWPQC session covers NIST guidance on hybrid implementations (SP 800-56C references).
Evidence auditors expect
- Before/after algorithm tags from re-scans
- Handshake appendix showing ML-KEM negotiation
- CBOM export reflecting updated cipher policy
See also hybrid TLS handshake appendix blog.
This quarter
- Enable hybrid KEM on one staging load balancer.
- Verify client compatibility matrix (browser, API clients, IoT).
- Document rollback procedure before production promotion.
Continue on the Q-Day hub: Hybrid TLS guide
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM)NIST · 2024-08Standardized post-quantum key encapsulation (formerly Kyber).
- Cloudflare targets 2029 for full post-quantum securityCloudflare · 2026Cloudflare's accelerated PQ roadmap including post-quantum authentication milestones.
- NIST IR 8547: Transition to Post-Quantum Cryptography StandardsNIST · 2024Federal transition guidance with deprecation timelines for quantum-vulnerable algorithms.
- Open Quantum Safe ProjectOpen Quantum Safe · 2024liboqs reference implementations, TLS integrations, and prototype PQC demos.
- NIST PQC Standards Update: On-Ramp Signatures and Global Roadmaps (RWPQC 2026)RWPQC 2026 (YouTube) · 2026Dustin Moody on FIPS 203–205 status, Falcon/HQC, on-ramp signatures, and 2035 deprecation tiers.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.