Cloudflare Adds Post‑Quantum TLS Visibility to Logs and Analytics, Enabling Domain‑Level Quantum‑Readiness Audits
What Happened – Cloudflare announced new visibility tools in its Application Security, Logpush, Log Explorer, and HTTP Traffic Analytics products. The features surface the exact key‑exchange algorithm negotiated on every TLS 1.3 connection, letting customers audit post‑quantum (PQ) encryption adoption per domain and spot cryptographic gaps.
Why It Matters for Trust & Control Assurance
- Demonstrates continuous monitoring of a critical cryptographic control (algorithm selection) that many compliance programs require evidence for.
- Provides defensible telemetry that can be used as audit evidence when mapping to the “Cryptographic Controls” objective in a control‑assurance framework.
- Enables organizations to identify and remediate legacy or mis‑configured TLS settings before a quantum‑readiness deadline, reducing risk of future data exposure.
Who Is Affected – SaaS providers, cloud‑native applications, and any organization that routes traffic through Cloudflare’s edge network (technology, financial services, health‑tech, etc.).
Recommended Actions
- Activate the post‑quantum visibility dashboards for each domain you own.
- Compare observed algorithm usage against your internal cryptographic policy and record any deviations.
- Incorporate the collected telemetry into your continuous control‑monitoring program to satisfy audit requirements for cryptographic key management. Source: https://blog.cloudflare.com/post-quantum-visibility/
Technical Notes
- Visibility is provided for TLS 1.3 handshakes that negotiate hybrid ML‑KEM (FIPS 203) key‑exchange.
- Cloudflare reports ~70 % of visitor‑to‑Cloudflare traffic already uses hybrid PQ encryption; only ~15 % of origin‑to‑Cloudflare connections do.
- Automatic Key Exchange reveals supported algorithms on origins, helping detect outdated configurations. Source: https://blog.cloudflare.com/post-quantum-visibility/