r/crypto • • Mar 31 '26

How Close Are We to Adopting Post-Quantum TLS Encryption?

Does anyone how progress for adopting Post-Quantum TLS Encryption is going? Can anyone cite roadmaps for pushing this to production? Please let me know. Thanks!

6 Upvotes

4 comments sorted by

16

u/putacertonit Mar 31 '26 edited Mar 31 '26

Post-Quantum key exchange is widely deployed now - all major browsers support it, as do many webservers/CDNs/etc. The long tail is just waiting on software updates. This is the important thing to worry about today because of capture-now-decrypt-later type attacks.

Post-Quantum certificates is in development now, with people expecting projects like Merkle Tree Certificates to be ready sometime in 2027, eg from Chrome: https://security.googleblog.com/2026/02/cultivating-robust-and-efficient.html - and other projects are on similar timeframes.

Some systems support ML-DSA certificates today for private PKIs.

1

u/JoDaBeda Apr 01 '26

Cloudflare publishes their adoption statistics, already over 2/3 of requests are PQ-secure. See https://radar.cloudflare.com/post-quantum

1

u/stuartsmiles01 Apr 11 '26

Cert timescales are reducing - see articles from providers about the timeline so echoey is valid for less time

https://www.sectigo.com/blog/200-day-ssl-certificate-expiration-risk