Video companion
Cloudflare's 2029 PQ roadmap: what enterprises should copy
Cloudflare enabled post-quantum encryption for most customer traffic in 2022, then accelerated authentication migration to 2029. Their roadmap is a useful benchmark for enterprise programs.

What Cloudflare's roadmap teaches
Cloudflare's post-quantum roadmap separates two migration tracks:
- Post-quantum encryption (KEM) — mitigates HNDL on key exchange. Cloudflare deployed hybrid ML-KEM in TLS 1.3 for most proxied traffic.
- Post-quantum authentication (signatures) — harder because certificate chains, CT logs, and client trust stores must move together.
Their 2029 target aligns with industry timeline shifts and NIST IR 8547 federal guidance. ML-KEM (FIPS 203) is the KEM standard Cloudflare and others deploy in hybrid mode.
The embedded RWPQC session covers global roadmaps including EU coordinated implementation — useful context for multinationals.
What it does not cover
Cloudflare controls its edge stack; most enterprises depend on mixed vendors, legacy appliances, and third-party SaaS. Your inventory must include dependencies you do not operate directly.
This quarter
- Read Cloudflare's PQC product documentation.
- Compare your TLS termination points against Cloudflare's milestone sequence (KEM first, signatures second).
- Request PQ readiness statements from critical SaaS vendors.
Continue on the Q-Day hub: PQC deadlines guide
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- Cloudflare targets 2029 for full post-quantum securityCloudflare · 2026Cloudflare's accelerated PQ roadmap including post-quantum authentication milestones.
- FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM)NIST · 2024-08Standardized post-quantum key encapsulation (formerly Kyber).
- NIST IR 8547: Transition to Post-Quantum Cryptography StandardsNIST · 2024Federal transition guidance with deprecation timelines for quantum-vulnerable algorithms.
- Recent advances push Big Tech closer to the Q-Day danger zoneArs Technica · 2026-04How Google and Cloudflare accelerated timelines and why authentication migration is now prioritized.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.