By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Standardizing Post-Quantum IPsec: Cloudflare Adopts Hybrid ML-KEM to Replace Ciphersuite Bloat
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Standardizing Post-Quantum IPsec: Cloudflare Adopts Hybrid ML-KEM to Replace Ciphersuite Bloat
News

Standardizing Post-Quantum IPsec: Cloudflare Adopts Hybrid ML-KEM to Replace Ciphersuite Bloat

News Room
Last updated: 2026/03/07 at 6:18 AM
News Room Published 7 March 2026
Share
Standardizing Post-Quantum IPsec: Cloudflare Adopts Hybrid ML-KEM to Replace Ciphersuite Bloat
SHARE

Cloudflare recently implemented a new standardized approach to Post-Quantum IPsec, moving away from previous ‘ciphersuite bloat’ in favor of a hybrid ML-KEM exchange. The move signals a shift in how wide-area networks (WANs) will meet the NIST 2030 deadline for quantum-resistant encryption without requiring specialized hardware

The company brings hybrid Module-Lattice-based Key-Encapsulation Mechanism (ML-KEM) to Cloudflare IPsec and the Cloudflare One Appliance, wrapping up what Cloudflare calls the “post-quantum SASE equation” allowing organizations to finally lock down private network traffic end-to-end against “harvest now, decrypt later” attacks, the ones in which bad actors grab encrypted data today and sit on it until quantum computers are powerful enough to crack it open.

Matthew Prince, Cloudflare’s CEO and co-founder, put it bluntly:

Securing the Internet against future threats shouldn’t be a complex burden. Since 2017, we’ve been doing the heavy lifting to bake post-quantum standards directly into the fabric of our network. By bringing this protection to our entire SASE platform, we’re making post-quantum security the default—no hardware upgrades, no complex configurations, and no added cost.

Earlier, NIST set a hard 2030 deadline for ditching RSA and Elliptic Curve Cryptography in favor of quantum-resistant algorithms. Late 2024 brought a clear signal that the days of classical public-key cryptography are numbered. Germany’s BSI and the UK’s NCSC have been saying the same thing.

Cloudflare’s approach follows draft-ietf-ipsecme-ikev2-mlkem, which standardizes post-quantum key exchange for IPsec in the same way TLS has. The hybrid setup runs ML-KEM in parallel with classical Diffie-Hellman. Think of it as belt-and-suspenders security: ML-KEM handles quantum threats, Diffie-Hellman covers classical attacks.

IPsec’s road to post-quantum looked nothing like TLS’s journey. Early attempts with RFC 8784 leaned on pre-shared keys or quantum key distribution, neither of which worked well in practice. Pre-shared keys don’t offer forward secrecy against quantum adversaries. QKD needs specialized hardware, which is a non-starter for most deployments. Then RFC 9370 came along and allowed up to seven different algorithms running at once. Cloudflare called this “ciphersuite bloat.” Palo Alto Networks went all-in with seven-plus PQC ciphersuites, most of which don’t play nice with other vendors.

The draft-ietf-ipsecme-ikev2-mlkem spec finally got IPsec aligned with how TLS does things. Cloudflare built production hybrid ML-KEM support into its IPsec IKEv2 Responder and ran tests against the strongSwan reference implementation to ensure it works.

The Cloudflare One Appliance got the upgrade automatically on February 11th via version 2026.2.0. Since the appliance uses TLS instead of IKEv2, the update was pretty straightforward—just a jump from TLS 1.2 to TLS 1.3 with hybrid ML-KEM baked in.

Cloudflare IPsec is still in closed beta while the company works on interoperability with third-party branch connector vendors. Security Brief Australia noted the changes slot into Cloudflare’s global network with high-availability routing that automatically reroutes traffic if a data center goes down.

The full picture now includes post-quantum encryption across TLS, MASQUE, and IPsec on-ramps and off-ramps. Over 60% of human-generated TLS traffic hitting Cloudflare’s network already uses hybrid ML-KEM, according to Cloudflare Radar data.

None of this costs extra. CISA recognized the split between key agreement and digital signature migrations in its January 2026 publication. Cloudflare’s current push focuses on key establishment through hybrid ML-KEM. Digital signatures are less urgent since they’re designed to stop active adversaries with quantum computers, which don’t exist yet.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article 7 best flowers to sow in March for amazing spring colors 7 best flowers to sow in March for amazing spring colors
Next Article I tried to give smartwatches a second chance, but it didn’t go well I tried to give smartwatches a second chance, but it didn’t go well
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

The Anker SOLIX E10 is the ultimate whole-home backup system
The Anker SOLIX E10 is the ultimate whole-home backup system
News
Your next Galaxy phone might let you turn your wild ideas into real phone features — here’s why that’s a big deal
Your next Galaxy phone might let you turn your wild ideas into real phone features — here’s why that’s a big deal
News
What does the US military’s feud with Anthropic mean for AI used in war?
What does the US military’s feud with Anthropic mean for AI used in war?
Software
F1 2026: Everything to Know About Streaming on Apple TV This Season
F1 2026: Everything to Know About Streaming on Apple TV This Season
News

You Might also Like

The Anker SOLIX E10 is the ultimate whole-home backup system
News

The Anker SOLIX E10 is the ultimate whole-home backup system

26 Min Read
Your next Galaxy phone might let you turn your wild ideas into real phone features — here’s why that’s a big deal
News

Your next Galaxy phone might let you turn your wild ideas into real phone features — here’s why that’s a big deal

5 Min Read
F1 2026: Everything to Know About Streaming on Apple TV This Season
News

F1 2026: Everything to Know About Streaming on Apple TV This Season

9 Min Read
From Avatar to Sinners: How (and Where) to Watch All of the 2026 Oscar-Nominated Films
News

From Avatar to Sinners: How (and Where) to Watch All of the 2026 Oscar-Nominated Films

8 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?