· via Cloudflare blog
Cloudflare adds per-domain post-quantum TLS visibility as it targets 2029 PQ readiness
Cloudflare's logs and analytics now show which TLS key exchange algorithm was negotiated on every request to a domain, part of a push toward full post-quantum readiness by 2029.

Cloudflare has added post-quantum cryptography visibility to its Application Security and Logs products, giving customers per-connection detail on which TLS key exchange algorithm visitors actually negotiate. According to the company's blog, the data is available in Logpush, Log Explorer and the HTTP Traffic Analytics dashboard, where a new TLS Key Exchange card breaks traffic down by algorithm for any domain on the platform.
From internet-wide stats to per-domain answers
Cloudflare already publishes aggregate post-quantum adoption figures through Cloudflare Radar, and the picture they paint is lopsided. Roughly 70% of browser-generated traffic reaching Cloudflare's network is protected with hybrid ML-KEM (FIPS 203), while only about 15% of the origin servers Cloudflare connects to use it. Those figures are blended across all traffic and all origins, and customers told Cloudflare they needed to zoom in — to answer questions like what share of requests to a specific domain arrives post-quantum encrypted.
Until now, the company exposed the TLS version used at individual domains but not the algorithms negotiated within that version. Cloudflare also recently launched Automatic Key Exchange for the Cloudflare-to-origin leg, which reports which cryptographic algorithms an origin supports, since outdated configuration can leave even a capable origin connecting with classical cryptography.
What the new telemetry shows
The key exchange group to watch is X25519MLKEM768, which Cloudflare describes as the only recommended post-quantum option in TLS 1.3 and the one now preferred by most major browsers. No TLS 1.2 or earlier connection can be post-quantum. The group is a hybrid: it runs classical elliptic-curve Diffie-Hellman over X25519 alongside the lattice-based ML-KEM, combines the two shared secrets, and encrypts the session with the result. As long as either primitive holds up, the connection remains secure.
In the new dashboard card, traffic splits into post-quantum X25519MLKEM768, classical ECDHE groups such as X25519 and P-256, a "None" bucket covering RSA key agreement on TLS 1.2 or below (or no TLS at all), and a small residue still using X25519Kyber768Draft00 — an earlier draft algorithm Cloudflare deliberately kept until usage shrinks, to avoid breaking clients for which it is the only route to PQ encryption.
Encryption is only half the migration, though. Cloudflare notes that post-quantum authentication — moving certificates and signatures off RSA and ECC toward schemes like ML-DSA — lags behind. It recently announced support for ML-DSA-44 origin certificates over TLS 1.3 and a certificate authority that will issue post-quantum Merkle Tree Certificates.
Inside the migration: an AI tool named CryptoLabe
A companion post details how Cloudflare is steering its own transition, for which it has set a 2029 deadline for full post-quantum readiness, ahead of the roughly 2030 quantum-readiness deadlines many of its customers face. Because most Cloudflare code lives in one centralised source-control platform, the company built an internal tool called CryptoLabe — named after the mariner's astrolabe — to inventory cryptographic use across its codebase.
The post is candid about why naive search fails: grepping for algorithm names overcounts by matching dead or test-only code, undercounts by missing defaults, indirect dependencies and configuration stored in distant files, and cannot explain how an algorithm is used. A classical ECDSA signature inside a JWT needs a completely different fix than one in TLS, SSH or IPsec. CryptoLabe instead runs two-stage AI scans. A discovery stage sweeps source, configuration, manifests, lockfiles, scripts, tests and documentation to produce raw observations. An analysis stage then re-verifies each finding, traces how the cryptography behaves at runtime, inspects related repositories when needed, reviews its own conclusions, and assigns a classification such as "classical encryption", "classical signature" or "classical token" — the latter catching RS256 and ES256 JWTs, for which RFC 9964 defines an ML-DSA-based replacement. When evidence is thin, the tool reports "more evidence needed", "external dependency" or "unknown" rather than guessing. CryptoLabe stays internal, but Cloudflare says it is publishing its learnings so other organisations can build on the approach.
Why it matters
NIST stated in 2024 that RSA and elliptic-curve cryptography should be deprecated by 2030, and governments and regulators have since backed that timeline. The urgency comes from harvest-now-decrypt-later attacks: traffic captured today with classical key exchange can be decrypted once capable quantum computers exist, which matters for any data that stays sensitive for three to ten years — public sector, defence, finance, telecom and healthcare among them. The gap between 70% browser-side and 15% origin-side adoption shows how much of the ecosystem still needs to move, and Cloudflare's implicit argument is that you cannot migrate, or prove compliance with, what you cannot see. The new per-domain telemetry gives customers that evidence, while CryptoLabe offers an early look at how large organisations might lean on AI models to inventory cryptography across sprawling codebases.
- #cloudflare
- #post-quantum-cryptography
- #tls
- #encryption
- #security
- #ai