← All stories
● Covered by 4 sources · 7 reportsMedium impact6 neutral

Cloudflare moves to post-quantum cryptography with ML-KEM and ML-DSA

🔄 Updated 7d ago — new reporting from InfoQ
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Cloudflare is adopting ML-KEM encryption and ML-DSA signatures.
  • These algorithms were standardized by NIST in 2024.
  • Cloudflare targets full post-quantum security by 2029.
  • Google Cloud KMS launched a preview of quantum-safe key import for software-based cryptographic keys.
  • Quantum-safe key import protects encryption keys during transit.
  • Cloud KMS PQC insights are now generally available.
  • JDK 24 includes ML-KEM and ML-DSA via the standard JCE API.
  • RSA-wrapped TLS sessions are vulnerable to future decryption by quantum computers.

Transitioning to Post-Quantum Cryptography

Cloudflare is migrating its encryption and signature mechanisms to post-quantum algorithms, specifically ML-KEM and ML-DSA. This change addresses the anticipated vulnerabilities posed by quantum computers to classical cryptographic methods like RSA and ECC.

Standardization and Current Usage

The ML-KEM encryption and ML-DSA signatures were standardized by the U.S. National Institute of Standards and Technology (NIST) in 2024 after a comprehensive international competition. Notably, the majority of traffic handled by Cloudflare is currently utilizing ML-KEM for enhanced security against potential quantum attacks.

Future Goals and Current Limitations

Cloudflare aims to achieve full post-quantum security by 2029. However, the existing ML-DSA algorithm presents challenges, such as larger data sizes and limitations compared to RSA and ECC. NIST is actively working on advancing more efficient post-quantum signature schemes.

The Importance of Continued Development

Despite the immediate need for ML-DSA, the pursuit of more effective post-quantum signature algorithms remains critical. This focus is essential to ensure robust security measures are in place as quantum computing technology advances.

Updates

🕒 2026-08-28 · new reporting from InfoQ
  • JDK 24 includes ML-KEM and ML-DSA via the standard JCE API.
  • RSA-wrapped TLS sessions are vulnerable to future decryption by quantum computers.
🕒 2026-08-20 · new reporting from Google Cloud Blog
  • Google Cloud KMS launched a preview of quantum-safe key import for software-based cryptographic keys.
  • Quantum-safe key import protects encryption keys during transit.
  • Cloud KMS PQC insights are now generally available.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~19 min · 16 stories · Sep 04

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Organizations can begin migrating to post-quantum cryptography (PQC) in Spring Boot applications by upgrading to JDK 24, which includes ML-KEM and ML-DSA via the standard JCE API. This migration is critical because current RSA-wrapped TLS sessions are vulnerable to future decryption by quantum computers, posing a risk to sensitive data.

Google Cloud Key Management Service (KMS) has launched a preview of quantum-safe key import for software-based cryptographic keys. This update allows enterprises to protect encryption keys during transit against potential "store now, decrypt later" attacks from future quantum computers, enhancing data sovereignty in multicloud environments.

Google Cloud released an updated roadmap for migrating its infrastructure to post-quantum cryptography (PQC), aiming for full readiness by 2029. This initiative addresses the increasing threat from quantum hardware advancements by focusing on mitigating Store Now Decrypt Later (SNDL) risks, strengthening digital signatures, and building cryptographic agility.

Google Cloud announced its updated roadmap to migrate all internal and customer-facing services to post-quantum cryptography (PQC) by 2029. This migration aims to protect data from future quantum computer decryption and strengthen digital signatures against forgery, aligning with anticipated industry standards and regulatory deadlines.

Cloudflare has enabled post-quantum authentication for its Authenticated Origin Pulls and Custom Origin Trust Store products, using ML-DSA signatures to secure connections between Cloudflare and customer origin servers. This update addresses the threat of quantum computers breaking classical credentials and performing impersonation attacks, marking a milestone in Cloudflare's post-quantum migration roadmap.

Google Cloud Key Management Service (Cloud KMS) now offers general availability for quantum-safe digital signatures (ML-DSA, SLH-DSA) and post-quantum key encapsulation (ML-KEM). This update helps organizations transition to quantum-safe cryptography to protect data integrity against future quantum computing threats and comply with evolving regulatory requirements.

Cloudflare is transitioning its encryption methods to ML-KEM and ML-DSA to address quantum computing threats. The U.S. NIST standardized these algorithms in 2024, and Cloudflare aims for full post-quantum security by 2029.