All posts

Post-Quantum Cryptography: The Countdown Is On

Golden quantum computer in a bright data center – The countdown is on

Quantum computers were long considered a topic for fundamental research; for IT security, they are already a present-day concern. In 2026, the subject finally reached the boardroom: the White House has set a binding migration deadline of the end of 2030 by executive order, and Google and Cloudflare have moved their own timelines forward to 2029. The reason is not panic but sober math: a sufficiently large quantum computer breaks the public-key algorithms that virtually every encrypted connection on the internet relies on today. Time to put the topic in context and show what is already protected. The countdown has already started, even though the quantum computer itself has not arrived.

Harvest now, decrypt later: the risk does not wait for Q-Day

The most common misconception about quantum security: "This only affects us once the quantum computer actually exists." In reality, the relevant attack is already underway. In "harvest now, decrypt later" attacks, adversaries record encrypted traffic now and decrypt it in a few years, once the computing power exists. For short-lived data, that is tolerable. For anything that still needs to be confidential in five or ten years (design data, health data, contracts, strategic planning, communications with public authorities), it is not.

So what matters is not the day the first cryptographically relevant quantum computer goes into operation. What matters is the day your data is intercepted. And that can be any day it travels with classical encryption only.

The timeline is getting concrete: 2029 and 2030

The year 2026 shows how seriously the situation is being taken. In June, the White House issued an executive order on post-quantum cryptography: US federal agencies must move their most sensitive systems to quantum-safe encryption by December 31, 2030, with quantum-safe authentication to follow by the end of 2031. Suppliers to these agencies are also being brought into scope through corresponding FIPS requirements by the end of 2030. Back in April, Cloudflare had already moved its own target for full post-quantum security forward to 2029, after research advances significantly lowered the effort estimates for quantum attacks; Google is also planning for 2029. And in Europe, the roadmaps of the BSI and the EU Commission for applications that need protection point in the same direction: around 2030.

These dates are closer than they sound. Experience shows that cryptography migrations stretch over years: inventory, vendor coordination, testing, rollout, legacy systems. Anyone who wants to be done by 2030 does not start in 2029.

What post-quantum cryptography actually means

The good news: the math is done. The US standards institute NIST has finalized the new algorithms, first and foremost ML-KEM for key exchange, developed to a large extent by European cryptographers. In practice, the new algorithms are used in hybrid mode: classical and post-quantum cryptography combined, so the connection remains secure even if one of the two schemes should turn out to be weak.

It is important to distinguish two work streams. The more urgent one is encrypting traffic. It protects against harvest now, decrypt later and therefore has to come first. The second is authentication, meaning quantum-safe certificates and signatures; it needs to be in place before quantum computers can mount real attacks. And one detail that is easily overlooked: a system that supports ML-KEM but continues to accept purely classical connections remains vulnerable to downgrade attacks. Quantum security only holds up once it is enforced.

Cloudflare: quantum-safe as the standard, not a paid extra

Few providers have pushed the migration as long and as consistently as Cloudflare. Since 2022, post-quantum encryption has been active for all websites and APIs behind the Cloudflare network. By now, more than 65 percent of human traffic to Cloudflare is already encrypted with quantum-safe methods. Since 2025, the same applies to the Zero Trust platform: corporate traffic passing through Cloudflare's tunnels is transported with quantum-safe encryption, even when the applications behind them have not yet migrated. That is exactly what makes this approach interesting for mid-sized companies: the hardest part of the migration is shifted into the platform.

The stance behind it is notable as well: at Cloudflare, post-quantum security is part of the standard, not a paid security add-on. By 2029, Cloudflare aims to be fully quantum-safe, including authentication. Details are available in Cloudflare's post-quantum blog .

What this means for KAEMI customers today

This is where it gets practical: as a Cloudflare partner, KAEMI manages services directly on this platform, from Zero Trust access and SASE/SSE to protecting and delivering applications. These connections already use Cloudflare's quantum-safe key exchange today. In concrete terms: the traffic that flows through these services across the public internet is protected against harvest-now-decrypt-later attacks right now, with no migration project and no additional costs.

So if you secure access and applications through KAEMI with Cloudflare today, the most important first step of the post-quantum migration (traffic across the public internet) is already behind you. To see what this looks like architecturally, visit our pages on SASE/SSE

and Application Security .

What companies should do now

The first step is a cryptography inventory: where is encryption used in the company (TLS on websites and APIs, VPN connections, site-to-site links, machine-to-machine traffic, certificate infrastructure)? Which data needs to remain confidential for a long time? From there, prioritization almost takes care of itself: first the traffic across the public internet, because it is the easiest to record; then internal systems and authentication. Just as important is crypto-agility: setting up systems so that algorithms can be swapped out in the future without launching a major project every time. And finally, there is a question for every supplier: what does your post-quantum roadmap look like?

For a compact overview of all Cloudflare products for application security, see our Cloudflare page .

If you want to know where your company stands: in a joint analysis workshop, we make data flows and attack surfaces visible, including the question of which part of your traffic could already run quantum-safe today. Get in touch .

Want to protect your web apps and APIs from flaws like this for good?

KAEMI implements and manages WAF, DDoS protection, bot and API management on the Cloudflare platform — as a managed service.