Cloudflare One is the first SASE offering modern post-quantum encryption across the full platform
ID: a06fa2a9-c393-5601-9dfa-b819193f2543
STIX ID: report--a06fa2a9-c393-5601-9dfa-b819193f2543
Feed Name: Cloudflare Blog
Cloudflare announces post-quantum security across its Cloudflare One SASE, adding hybrid ML-KEM to IPsec (via draft-ietf-ipsecme-ikev2-mlkem), TLS 1.3/MASQUE, and the Cloudflare One Appliance to protect private and Internet-bound traffic against harvest-now-decrypt-later threats. The appliance GA includes PQC in version 2026.2.0, while Cloudflare IPsec with hybrid ML-KEM is in closed beta with an interoperability push for third-party branch connectors. The approach favors standardized, interoperable hybrid designs over PSK/QKD or ciphersuite sprawl, aligning with NIST and IETF guidance. Customers receive PQC upgrades at no additional cost.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
