Post Quantum Cryptography Implementation at Cloudflare

Key Takeaways

  • Post quantum cryptography implementation requires a phased and strategic migration approach.
  • Cloudflare has been preparing for post-quantum migration since 2017.
  • Organisations must address both encryption and authentication upgrades.
  • Cryptographic inventories and executive support are essential for successful migration.
  • Real-world testing is critical to uncover compatibility and performance issues.

Episode 1: Inside Cloudflare’s Post-Quantum Journey: Bas Westerbaan on Real-World Implementation

We are delighted to share with you the launch and first episode of our new Podcast Shielded: The Last Line of Cyber Defense.

Hosted by our Global Business Development Director Johannes Lintzen, we dive into the world of post-quantum cryptography, examining how businesses and industries can prepare for the upcoming quantum revolution. From practical steps to real-world case studies and expert interviews, Shielded is an essential guide to navigating the future of cybersecurity.

In the first episode, Johannes Lintzen sits down with Bas Westerbaan, Research Engineer at Cloudflare, to explore what it really takes to achieve post quantum cryptography implementation at scale.

Quantum computers could break today’s encryption sooner than you think.

Is your organization ready to protect its most sensitive data?

While many organizations are just waking up to the quantum threat, Cloudflare has been preparing since 2017.

This conversation delivers practical insights, hidden challenges, and a step-by-step migration plan that organizations can follow before quantum computing disrupts traditional cryptographic security.

The Wake-Up Call: Why Post-Quantum Migration Can’t Wait

“If we all wait until the last moment, there will be more work than we expect.” – Bas Westerbaan

The transition to quantum-safe cryptography isn’t just an upgrade—it’s a fundamental shift in security infrastructure. Organizations that delay will face:

Risks of Delaying Migration

Organizations that delay post quantum cryptography implementation may face:

  • A backlog of urgent security overhauls, causing disruptions to IT systems
  • A scramble for compliance, as regulatory mandates push quantum-safe adoption
  • Vendor dependencies, as enterprises wait for software providers to catch up
  • Cloudflare’s journey offers a roadmap for companies at any stage of post-quantum readiness.

The Two-Phase Migration Reality

Traditional encryption and authentication mechanisms rely on cryptographic algorithms that quantum computers will eventually break. While organizations may be aware of the need to upgrade encryption, many overlook the need to transition authentication mechanisms as well.

If organizations only upgrade encryption, they remain vulnerable to quantum-based attacks on authentication mechanisms, including:

  • Forged digital signatures
  • Broken TLS authentication
  • Identity impersonation attacks

This dual migration approach addresses two distinct cryptographic threats:

Phase One: Encryption Upgrade (Start Now!)

The first stage of post quantum cryptography implementation focuses on preventing ‘harvest-now-decrypt-later’ (HNDL) attacks.

In these attacks, adversaries store encrypted data today with the intention of decrypting it when sufficiently powerful quantum computers become available.

This makes immediate encryption upgrades essential for protecting:

  • Intellectual property
  • Financial records
  • Long-term confidential communications
  • National security data

Phase Two: Authentication & Digital Signatures

The second phase focuses on upgrading authentication systems and digital signatures.

Quantum-resistant authentication standards ensure that:

  • TLS certificates remain secure
  • Digital signatures cannot be forged
  • Identity verification systems continue functioning safely

Even if encryption itself is protected, compromised authentication systems could still allow attackers to impersonate legitimate users and infrastructure.

The key takeaway is clear:

Focusing solely on encryption upgrades is not enough. Organizations must prepare for authentication migration as well.

Starting Your Quantum Journey: 3 Steps to Take Today

While a full PQC migration takes time, organizations can take immediate steps to begin their journey.

Step 1: Secure Executive Buy-In

PQC is not just a technical challenge, it’s a business risk. Without leadership support, migration efforts will stall.

  • Make post-quantum readiness a board-level priority.
  • Frame it as a security and compliance issue – delayed action could mean regulatory penalties and data breaches.
  • Assign a dedicated PQC task force to drive adoption.

Step 2: Conduct a Cryptographic Inventory

Most organizations don’t know where their cryptography is used.

  • Survey engineering teams to map existing cryptographic dependencies.
  • Identify legacy systems that may break when upgrading encryption.
  • Assess third-party vendor dependencies to avoid supply chain risks.

Step 3: Build Internal PQC Expertise

The lack of in-house PQC knowledge is one of the biggest migration roadblocks.

  • Establish a Post-Quantum Center of Excellence to oversee implementation.
  • Provide training on PQC protocols to IT & security teams.
  • Stay updated with industry regulations & best practices.

A cryptographic inventory is the foundation of a successful migration. Organizations must understand their existing infrastructure before making changes.

Real-World Implementation Challenges

“Experience matters – it’s not just if it’s fast when we’re sitting here with fiber internet. It’s also if you’re on the plain Wi-Fi.” – Bas Westerbaan

Performance Impact

While PQC algorithms generally perform well in controlled environments, real-world conditions vary significantly.

Testing across multiple environments and network conditions is critical for successful deployment.

Compatibility Issues

Cloudflare discovered that approximately 5% of connections failed due to improper TLS implementations when introducing post-quantum cryptography.

Some middleware systems struggled to process larger post-quantum keys despite technically supporting TLS.

This highlights why organizations must test infrastructure early to identify compatibility issues before full deployment.

The Compliance Catalyst: Why Regulation Is Accelerating Adoption

Governments and regulators are not waiting for businesses to act independently.

Regulatory Pressure Is Increasing

US federal mandates now increasingly require quantum-safe cryptography within procurement processes.

As a result:

  • Compliance is becoming a major migration driver
  • Early adopters gain competitive advantages
  • Organizations can position themselves ahead of regulatory deadlines

Businesses that proactively pursue post quantum cryptography implementation will be better prepared for future market and compliance expectations.

Practical Action Plan for Organizations

The best way to approach post-quantum migration is with a phased, strategic rollout.

Organizations that try to overhaul everything at once will face unnecessary complexity and delays. Instead, teams should take a targeted approach that starts with small, manageable changes and scales over time.

1. Start Small, Start Now

  • Begin with low-risk projects like internal applications, test environments, or non-critical systems.
  • Focus on areas where you have direct control (e.g., in-house software, internal TLS connections).
  • Use automated tools to streamline cryptographic upgrades.

2. Improve Key Management

  • Audit current cryptographic key management practices to identify gaps.
  • Implement automated key rotation to reduce risk.
  • Gain visibility into cryptographic assets to track progress and ensure compliance.

3. Rethink Security Architecture

  • Treat PQC migration as an opportunity to modernize security, rather than just a drop-in replacement.
  • Reevaluate legacy cryptographic implementations—some may no longer be necessary.
  • Explore higher-level architectural improvements, such as consolidating key management systems or adopting new cryptographic protocols.

Organizations that succeed in PQC migration won’t just swap encryption methods – they’ll rethink and strengthen their entire security infrastructure.

Looking Ahead: The Future of Cryptography

“All cryptography will be post-quantum cryptography in the future.” – Bas Westerbaan

The shift to post-quantum cryptography isn’t just about upgrading encryption – it’s about building resilience for a quantum-driven world. As quantum computing advances, traditional cryptographic systems will no longer be viable, forcing every industry to adapt or risk security failures.

Cloudflare’s experience proves that early adoption is possible, manageable, and essential.

Organizations that begin their PQC journey today will:

  • Future-proof their security against emerging threats.
  • Avoid last-minute compliance and regulatory pressures.
  • Stay ahead of competitors in securing digital assets.

Final Thoughts: The Time for Action Is Now

The transition to post-quantum security is not optional. It is inevitable.

Organizations that delay risk falling behind both operationally and competitively.

Those that begin post quantum cryptography implementation today will be better positioned to future-proof security infrastructure, navigate compliance requirements, and strengthen long-term resilience.

As Bas Westerbaan reminds us:

“Just get started with some things. I think that’s important. Just get started.”

Start Your Post-Quantum Migration Journey Today

Preparing for the quantum era requires more than awareness. It requires practical implementation strategies, phased deployment planning, and long-term cryptographic resilience.

You can hear the full conversation with Bas Westerbaan on Shielded: The Last Line of Cyber Defense, available now on Apple Podcasts, Spotify, and YouTube Podcasts.

Contact PQShield today to learn how your organisation can accelerate post quantum cryptography implementation, modernize cryptographic infrastructure, and prepare for the future of cybersecurity.

Frequently Asked Questions

What is post quantum cryptography implementation?

Post quantum cryptography implementation refers to the process of deploying quantum-resistant cryptographic algorithms, protocols, and infrastructure designed to withstand attacks from future quantum computers.

Why is post-quantum cryptography important?

Quantum computers could eventually break many widely used encryption systems. Post-quantum cryptography helps organisations protect sensitive data, digital identities, and communications against future quantum threats.

What is a harvest-now-decrypt-later attack (HNDL)?

A harvest-now-decrypt-later attack occurs when attackers collect encrypted data today with the intention of decrypting it later using future quantum computers.

Why is TLS 1.3 important for post-quantum migration?

TLS 1.3 supports modern cryptographic mechanisms required for post-quantum key exchange and secure communications. Many PQC deployments rely on TLS 1.3 as a foundational requirement.

What should organizations do first when preparing for PQC migration?

Organizations should begin by securing executive support, conducting cryptographic inventories, identifying legacy dependencies, and building internal expertise around post-quantum cryptography standards and migration planning.