Cloudflare, Google and Apple: Who Is Rolling Out Post-Quantum Security in 2026

Updated | 4 min read | QUANTUM (QNT) community

From experiment to default

Only a few years ago, post-quantum cryptography on the web was a lab curiosity. In 2026 it is a default setting at some of the largest names in internet infrastructure. Here is what has been reported, with dates, so you can separate real deployment from marketing.

Cloudflare

Cloudflare says it turned on hybrid post-quantum key agreement for TLS back in 2022, before NIST had even finalized ML-KEM. In a blog post dated April 30, 2026, the company reported that more than two-thirds of human-generated TLS traffic to its network is protected with hybrid ML-KEM. Earlier in 2026 coverage had quoted figures around 60 percent, which fits a steadily rising trend (see the hybrid handshake guide).

The same post says Cloudflare has moved its target for full post-quantum security forward to 2029. It also notes that IPsec, the technology behind many VPNs, only got a full hybrid ML-KEM specification in late 2025, about four years after the TLS equivalent, and that standards for post-quantum authentication in IPsec are still needed. In other words, encryption is ahead of identity checking, a theme that runs through this whole series.

Google Chrome

Chromium based browsers (Chrome, Edge, Brave, Opera) use hybrid X25519MLKEM768 by default from version 131 onward, according to Cloudflare's developer documentation. Google's bigger announcement in early 2026 concerned certificates. The Chrome team said it has no immediate plan to add traditional X.509 certificates containing post-quantum cryptography to the Chrome Root Store. Instead it is developing Merkle Tree Certificates with partners in the IETF, and reported a phased path through the third quarter of 2027. The first phase is a feasibility study with Cloudflare using real internet traffic. Details are in the PKI guide.

Apple

Apple's contribution comes in two layers. For web connections, Cloudflare's documentation lists Safari 26 and later, with hybrid ML-KEM working system wide on iOS 26 and macOS Tahoe 26. For messaging, Apple announced iMessage PQ3 on February 21, 2024, covered in the messaging guide. Because a single operating system update reaches hundreds of millions of devices, Apple's move matters a lot for how quickly the whole web becomes post-quantum capable.

Firefox, Tor and server software

Firefox enables the hybrid by default from version 132 on desktop and 145 on Android, and Tor Browser from 15.0, per Cloudflare's listing. On the server side, NGINX uses it by default when built with OpenSSL 3.5 or later, Caddy from 2.10.0, and Traefik from 3.4.2. That is a big deal: open source defaults spread quickly because most website operators simply upgrade.

The gap to watch: servers behind the edge

A CDN can terminate the browser's quantum-safe connection, but the hop from the CDN to your own server may still be classical. Secondary reporting suggested only a minority of origin connections support the hybrid, though I could not confirm an exact figure from a primary source. If you run your own servers, check this hop. It is one of the easiest wins on a migration plan (see the checklist).

What is still missing

Cloudflare's documentation notes that no listed browser supports post-quantum signatures yet. Libraries including OpenSSL, BoringSSL and AWS-LC support ML-DSA, so the plumbing is arriving, but it is not switched on for web certificates. Anyone saying the whole web is "quantum safe" today is overstating. Key exchange is largely handled for supporting clients, and authentication is in progress.

Why this is good news for the quantum era

Every layer being deployed now, from handshakes to messaging apps, means that when large fault tolerant quantum computers do arrive (see the timeline), the most sensitive recorded traffic will already be out of reach. The people building quantum computers and the people building quantum-safe security are, in a sense, on the same team: one gives us new science, the other keeps the lights on while it happens.

A note on tokens

Headlines about post-quantum security are sometimes used to promote crypto tokens. A rollout by Cloudflare, Google or Apple says nothing about the value of any token, and the QNT memecoin has no connection to these companies or to Quantinuum Ltd. Read the risk factors. Not financial advice.

Sources and further reading

Reported as of 2026-10-09. Standards and rollout numbers change often, so check the primary documents before relying on any figure. This is education, not financial advice. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of any lab or government.

Frequently asked questions

How much web traffic is post-quantum protected?

Cloudflare reported on April 30, 2026 that more than two-thirds of human-generated TLS traffic to its network uses hybrid ML-KEM. That is Cloudflare's traffic only, not the entire internet.

What is Cloudflare's post-quantum goal?

The company reported moving its target for full post-quantum security forward to 2029.

Does Chrome support post-quantum certificates?

Not yet. Google reported it is pursuing Merkle Tree Certificates with a phased plan through Q3 2027 rather than adding post-quantum X.509 certificates to its root store.

Is Apple part of this?

Yes. Cloudflare lists Safari 26 and system-wide support on iOS 26 and macOS Tahoe 26, and Apple launched iMessage PQ3 in 2024.

Is QNT connected to these companies?

No. It is an independent memecoin. Nothing here is financial advice.

Share on X

Keep reading

All Quantum industry, people and AI guides | Back to top | Search the site

Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary

QUANTUM (QNT) is the quantum sector memecoin on Solana. See the live chart, buys and burnt supply or read the token facts. Questions? Join the Telegram.