Post-quantum work has moved past key exchange, to certificates and downgrades
For two years the visible part of the post-quantum migration was key exchange: hybrid ML-KEM switched on in browsers and at the edge. The announcements of the last days show the work moving to the harder layers behind it.
Key exchange is largely done at the front door. Cloudflare says about 70% of browser traffic reaching its network is protected with hybrid ML-KEM, but only about 15% of the origin servers it connects to use it. To help close that gap it is adding per-connection key-exchange data to its logs and traffic analytics, so customers can see how much of their own domain's traffic is post-quantum. Source: https://blog.cloudflare.com/post-quantum-visibility
Certificates are the next wall. Swapping post-quantum signatures into today's certificates would, in Cloudflare's words, cause "unacceptable performance degradation" at Internet scale. Its answer is Merkle Tree Certificates: the company is becoming a certificate authority that will issue them, targeting early 2027 for inclusion in Chrome's Quantum-resistant Root Store, with standard issuance free of charge. Source: https://blog.cloudflare.com/pq-ca-with-mtcs
Downgrades undo the upgrade. As long as endpoints support both classical and post-quantum cryptography, an attacker in the path can try to make each side believe the other lacks post-quantum support. Cloudflare describes a design flaw it found in IPsec that allows such an attack, worked with the IETF on a mitigation, and has shipped it in beta across its IPsec products. Source: https://blog.cloudflare.com/ipsec-downgrade-protection
And the cost has to come down in ordinary runtimes. In the JDK, ML-KEM and ML-DSA are written in Java, and HotSpot replaces a handful of hot polynomial operations with CPU-specific intrinsics, keeping the Java code as a fallback. Source: https://inside.java/2026/09/30/faster-post-quantum-cryptography-with-jdk-intrinsics

What connects them
Each item is about the part of the migration a single switch cannot do: origins that were never upgraded, a certificate system that has to change shape, protocols that must refuse to fall back, and libraries that must make the new algorithms cheap enough to leave on. Cloudflare's target for full post-quantum security is 2029. For most teams, the useful first step is the least glamorous one this week offered: measure which of your own connections are already post-quantum, and which are not.