Cloudflare adds per-domain post-quantum TLS visibility to Logs and Analytics
Cloudflare now shows the post-quantum TLS key exchange negotiated per domain in Logpush, Log Explorer and HTTP Traffic Analytics, as it targets full PQ security by 2029.
Cloudflare has added post-quantum (PQ) cryptography visibility tools to its Application Security and Logs products, letting customers see the key exchange algorithm negotiated on every incoming request. According to the company, the data can now be inspected and graphed in Logpush, Log Explorer and the HTTP Traffic Analytics dashboard.
Until now, Cloudflare says it exposed the TLS version used at individual domains — TLS 1.3, TLS 1.2 and so on — but not the cryptographic algorithms used with that version. That gap meant customers could not answer a question like “What fraction of traffic to my domain www.example.com is using post-quantum encryption?” The company says the new telemetry is aimed at auditing post-quantum posture, assessing compliance and finding cryptographic gaps across domains.
What the aggregate numbers show
Cloudflare already tracks Internet-wide adoption through Cloudflare Radar. From Radar, the company says about 70% of browser-generated traffic hitting its network on the visitor-to-Cloudflare connection is protected with post-quantum encryption using hybrid ML-KEM (FIPS 203), while just about 15% of origins Cloudflare connects to use hybrid ML-KEM.
Those figures are aggregates: the first across all browser-generated traffic Cloudflare sees, the second across all origins it connects to. Cloudflare recently launched Automatic Key Exchange for the Cloudflare-to-origin connection, which shows which cryptographic algorithms a given origin supports — useful because an outdated configuration can push an origin to classical cryptography even when it does support post-quantum encryption.
Timing and the transition
Cloudflare says it is targeting 2029 for full post-quantum security, and notes many customers are working toward quantum-readiness deadlines around 2030. The company says it has already deployed post-quantum encryption across many products, including its cloud-proxy platform and every on-ramp and off-ramp of its SASE platform, and has made post-quantum encryption the default in many products.
The new visibility features are described by Cloudflare as available now in Logpush, Log Explorer and the HTTP Traffic Analytics dashboard. The company has not published separate pricing for the tools in the announcement.
Related reading
Sources
Some links on this page may be affiliate links. If you buy through them we may earn a commission at no extra cost to you. See our affiliate disclosure.