Cloudflare Boosts TLS 1.3 Security with Automated Post-Quantum Cryptography Integration
September 11, 2026
Cloudflare is implementing an automated, proactive integration of post-quantum cryptography into TLS handshakes, designed to maintain compatibility and minimize handshake failures.
The system automatically selects post-quantum key exchange for connections to compatible origin servers, strengthening TLS 1.3 security and reducing handshake latency.
Independent coverage from SDx Central highlights the security and performance impact of post-quantum key exchange in Cloudflare’s large-scale traffic.
This approach resolves a TLS 1.3 handshake limitation where the client shares a key before the server signals its preference, which could cause retries and higher latency.
Cloudflare reports protecting about 45 billion connections per day and a notable drop in handshake delays, with HelloRetryRequest shares falling from roughly 52% to 3.7%.
Deployment is on by default for new and existing Cloudflare domains whose origins support TLS 1.3, with ongoing work to add finer-grained controls and improved detection.
The Automatic Key Exchange capability probes origin servers to identify supported algorithms and selects the strongest compatible option, prioritizing the hybrid post-quantum X25519MLKEM768, with fallback to classical algorithms when necessary.
Summary based on 1 source
Get a daily email with more Tech stories
Source

MSSP Alert • Sep 11, 2026
Cloudflare enhances security with automatic post-quantum key exchange