Cloudflare Targets Full Post-Quantum Security by 2029
Key point
Cloudflare has set 2029 as its target for full post-quantum security, including authentication.
Details
Cloudflare now says it will transition its entire product lineup to a post-quantum secure state by 2029. The key point is that this goes beyond encryption alone — it also means shifting authentication to quantum-resistant methods.
The backdrop is a series of rapid recent technical advances. Google disclosed improvements to a quantum algorithm that breaks ECC, and on the same day, Oratomic estimated the resources needed to break RSA-2048 and P-256, suggesting that a neutral atom computer at around 10,000 qubits could potentially break P-256.
Cloudflare does not view the quantum threat as merely a long-term issue. Until now, the focus has mainly been on using post-quantum encryption to block harvest-now/decrypt-later attacks, but as Q-Day gets closer, the more dangerous point becomes authentication. Once a trusted key is broken, it becomes possible to impersonate servers, hijack access privileges, and even abuse software updates.
Progress in quantum computing is happening simultaneously along three axes.
- Hardware: Multiple approaches — neutral atom, superconducting, ion-trap, photonics, topological qubits — are advancing rapidly.
- Error correction: Superconducting-type systems typically need about 1,000 physical qubits per logical qubit, but reconfigurable qubits like neutral atom systems have a much greater advantage.
- Software: The algorithms actually used to break cryptography are also improving.
Because of this combination, the Q-Day outlook is seen as having moved earlier than the previous post-2035 estimates. In particular, Cloudflare views neutral atom as a leading frontrunner, while stressing that other approaches cannot be entirely ruled out.
The priority now is authentication. HNDL defenses have already been applied across a substantial number of products, but going forward, downgrade attacks must also be blocked using measures such as PQ HSTS and certificate transparency, and any exposed passwords and access tokens must all be rotated. The challenge is that this isn't a one-time transition — it's a multi-year project entangled with internal systems, third-party dependencies, verification, and fraud monitoring.
Cloudflare's conclusion is clear. Companies should demand post-quantum support starting at the procurement stage, governments should establish a lead agency to coordinate standards and timelines, and for Cloudflare customers, the transition will happen by default so no separate action is needed. That said, the transition across the wider ecosystem — including browsers, applications, and origins — still remains to be done.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.