Cloudflare protects most connections from future quantum attacks at the edge. The rest of the stack still uses pre quantum cryptography. Cloudflare Connect 2026 takes up the harder half.
When Cloudflare turns on hybrid post-quantum key exchange for a connection, only half the migration is done. The other half runs on whatever sits behind the edge: customer origins, the ISPs and carriers in the middle, and the certificate authorities that vouch for every site's identity. Cloudflare Connect 2026, the company's annual infrastructure conference in San Francisco from October 19 to 21, is where the company will try to drag the rest of the stack across the line before its 2029 deadline.
"Post-quantum cryptography" is the term for a new generation of encryption algorithms designed to resist attacks from future quantum computers, machines powerful enough to break the math that secures most of today's internet traffic. The risk is a "harvest now, decrypt later" attack: adversaries record encrypted traffic today and decrypt it once quantum hardware matures. Researchers call the moment that happens "Q-Day," and the year it lands is still genuinely debated.
Cloudflare has been moving on this for nearly a decade, according to a preview of the conference agenda published by The Qubit Report. The published timeline runs from continuous research starting in 2017, through 2022 hybrid key-agreement experiments on the edge, to 2025 when the WARP client gained PQC support. In 2026 the milestones accelerate: in February, Cloudflare One became the first SASE (Secure Access Service Edge) platform with full modern PQC encryption; in April the company accelerated its roadmap to full post-quantum security by 2029; on April 30, post-quantum IPsec, using a hybrid form of the ML-KEM key-encapsulation algorithm, became generally available; and in July, post-quantum authentication using the ML-DSA digital-signature algorithm was enabled to origins. The company frames the deployment as happening without specialized hardware and at no extra cost to customers.
The current footprint is the part that makes the 2029 target plausible, and also the part that exposes its limits. Cloudflare's own data, republished in the agenda materials, says more than 65 percent of human traffic on its network is now protected by hybrid X25519MLKEM768, a key-exchange scheme that pairs a classical algorithm with a quantum-resistant one. That number sets the bar: any origin that wants to be quantum-safe on the user side has to speak a hybrid cipher to the edge, and Cloudflare's edge is now ready for most of them.
The structural problem is what sits on the other side of the edge. A user request that arrives at a Cloudflare data center protected by ML-KEM still has to terminate at an origin server, traverse middle-mile networks, and authenticate against a certificate chain that, for many operators, is still rooted in classical cryptography. Cloudflare can flip the switch on its own infrastructure; the rest of the stack is not under its control. The Merkle Tree Certificates session on the conference agenda, led by Cloudflare's Christopher Patton, is the company's attempt to push the certificate authority layer forward. Merkle Tree Certificates are a new kind of short-lived, hash-tree-based certificate designed to scale WebPKI, the Web's public-key infrastructure and the system of trusted certificate authorities that signs every site's identity, without the bottlenecks of today's long-lived, per-domain certificates. The WebPKI transition is the slowest leg of the migration by design.
The "no extra cost, no specialized hardware" framing is also company-controlled language. Both claims are technically accurate for the edge: ML-KEM runs on standard CPUs and the rollout is bundled into existing Cloudflare plans. Neither claim speaks to what customers have to do on their own origins, the procurement work involved in rotating to ML-DSA-signed certificates, or the coordination cost of getting every transit provider on a hybrid handshake. The 2029 target is a commitment Cloudflare made about its own infrastructure; it is not a guarantee about the rest of the internet.
Three sessions at Moscone West are framed around this work. On Tuesday, October 20, Cloudflare's Sharon Goldberg and Wesley Evans will run "Q-Day is coming," a 45-minute slot in the Security & Compliance track, billed as an update on the company's quantum migration work. The same day, in the Secure AI track, Patton's "Merkle Tree Certificates and the next phase of the WebPKI" is positioned as the technical bridge from today's certificate hierarchy to one that can sign at internet scale. On Wednesday, October 21, a 20-minute Web Performance & Frameworks slot on "Securing Internet traffic for the quantum computing era" closes the program, with speakers still listed as TBA.
The conference is a reporting occasion, not a verdict. The thing to watch in October is not whether Cloudflare's edge stays ahead of the deployment curve (it will), but whether the company can name specific origin operators, certificate authorities, and transit partners who have committed to matching its 2029 timeline. The number to track after the conference is whether the post-quantum origin-authentication rate, currently the slowest part of the migration, moves at all in the quarter that follows. The 2029 target is a Cloudflare commitment. The rest of the internet has to match it for the migration to land.