This article, which was first published on Government Technology Insider, discusses how quantum computing is reshaping cybersecurity priorities for federal agencies and enterprises, driven largely by the threat of “harvest now, decrypt later” attacks. Pulling insights from the “Securing the DoW’s Digital Perimeter with Cloudflare One PQC” webinar, featuring Jeremy Corey, Senior Solutions Engineer at Cloudflare, it explores the reasons why organizations should prioritize post-quantum cryptography now rather than as a future roadmap item.
The rise of quantum computing is forcing organizations to rethink their cybersecurity postures. While practical quantum systems capable of cracking modern encryption may be years away, this threat is already affecting how many agencies and enterprises approach long-term data protection. The issue revolves around “harvest now, decrypt later” attacks, where adversaries collect encrypted data with the expectation that future quantum capabilities will eventually allow them to decrypt it.
During the “Securing the DoW’s Digital Perimeter with Cloudflare One PQC,” webinar, Jeremy Corey, Senior Solutions Engineer, at Cloudflare discussed how post-quantum cryptography (PQC), traffic privacy, and authentication modernization are becoming crucial components of future cyber resilience strategies. He emphasized that organizations should already be assessing how quantum-safe protections fit into today’s infrastructure rather than treating PQC as a future roadmap item.
Moving Beyond Classical Cryptography
Corey explained that many internet security mechanisms still rely on certificate infrastructures and classical cryptography, which quantum computing could eventually compromise. He described the company’s efforts on post-quantum encryption and authentication, saying, “We’re stopping quantum adversaries from attacking live systems after Q-day.” He pointed out that if organizations continue to rely only on classical PKI-backed certificates, attackers may eventually impersonate trusted websites and services.
To address this, Cloudflare is building a post-quantum authentication roadmap that supports ML-DSA and Merkle Tree Certificates (MTCs). Corey described MTCs as “an answer to the next generation of certificate formats that enables post-quantum signatures at scale.” The goal of these efforts is to help organizations transition toward quantum-safe authentication without compromising performance in large-scale internet environments.
Additionally, he pointed to one of the main technical obstacles to PQC adoption: “Post-quantum signatures are 10 to 100 times larger than classical encryption-based digital signatures,” he said, noting that this can have a significant impact on TLS handshake performance across the internet.
PQC Adoption is Accelerating
The company’s telemetry offers a real-world view on the rate of adoption of PQC. Its post-quantum key exchange implementation is already securing billions of requests every day, giving organizations visibility into adoption trends across a significant portion of global internet traffic.
During the webinar, Corey pointed to Cloudflare’s Radar data, revealed that over a seven-day measurement period, human-generated HTTPS requests using post-quantum key exchange had recently surpassed 70 percent. He noted that adoption depends on both client browsers and servers supporting PQC algorithms, underscoring that organizations still have major infrastructure upgrades ahead.
He also emphasized that there is still substantial modernization work to be done by many organizations. He said, “Only 10 percent of our customer origin servers sitting behind Cloudflare’s network support hybrid PQC.” He framed this gap as proof that organizations are still figuring out the operational and infrastructure changes required to fully support PQC.
Building Quantum-Safe Cyber Resilience
Throughout the conversation, Corey emphasized that post-quantum security is no longer theoretical. Organizations are beginning to implement quantum-safe encryption and authentication capabilities while also reassessing how they safeguard sensitive metadata and traffic from increasingly sophisticated adversaries.
As federal agencies continue to modernize their digital infrastructure, the shift to post-quantum security will increasingly influence approaches to cyber resilience, identity protection, and secure internet communications. Securing the broader patterns and signal that adversaries can use to extract intelligence from network traffic is a challenge that goes beyond simply protecting encrypted content alone.