Skip to content

Video companion

Cloudflare's 2029 PQ roadmap: what enterprises should copy

Cloudflare enabled post-quantum encryption for most customer traffic in 2022, then accelerated authentication migration to 2029. Their roadmap is a useful benchmark for enterprise programs.

Hybrid TLS post-quantum handshake diagram.
NIST PQC Standards Update: On-Ramp Signatures and Global Roadmaps | RWPQC 2026 Watch on YouTube

What Cloudflare's roadmap teaches

Cloudflare's post-quantum roadmap separates two migration tracks:

  1. Post-quantum encryption (KEM) — mitigates HNDL on key exchange. Cloudflare deployed hybrid ML-KEM in TLS 1.3 for most proxied traffic.
  2. Post-quantum authentication (signatures) — harder because certificate chains, CT logs, and client trust stores must move together.

Their 2029 target aligns with industry timeline shifts and NIST IR 8547 federal guidance. ML-KEM (FIPS 203) is the KEM standard Cloudflare and others deploy in hybrid mode.

The embedded RWPQC session covers global roadmaps including EU coordinated implementation — useful context for multinationals.

What it does not cover

Cloudflare controls its edge stack; most enterprises depend on mixed vendors, legacy appliances, and third-party SaaS. Your inventory must include dependencies you do not operate directly.

This quarter

  1. Read Cloudflare's PQC product documentation.
  2. Compare your TLS termination points against Cloudflare's milestone sequence (KEM first, signatures second).
  3. Request PQ readiness statements from critical SaaS vendors.

Continue on the Q-Day hub: PQC deadlines guide

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-21

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.