← Back to News

Cloudflare Warns on Post-Quantum Risk

2026-06-25 · cloudflare

Cloudflare published an analysis of the June 22, 2026 executive order on post-quantum security, warning that harvest-now-decrypt-later attacks make cryptographic migration urgent for data that will remain valuable for years. The post says federal agencies must move high-value systems to post-quantum encryption by 2030 and post-quantum authentication by 2031, while contractors and critical infrastructure operators will feel the same pressure through procurement and compliance requirements.


What Happened

Cloudflare highlighted the executive order's migration deadlines and noted that post-quantum encryption is already needed because adversaries can record encrypted data today and decrypt it later. The company also said more than two-thirds of browser traffic to Cloudflare is already protected with post-quantum encryption, while authentication migration is still early.

The Cost of Data Loss

The highest-risk data is not just live production traffic; it is archived material, identity records, private keys, backups, legal records, and operational secrets that may retain value for years. If those records are stolen now and decrypted later, the breach can surface long after the original compromise.

How Cold Storage Prevents This

Offline cold storage reduces the attack surface for long-lived recovery assets by keeping critical backups, seed material, and sealed archives away from continuously exposed systems. For sensitive archives, cold storage should be paired with crypto-agile encryption plans so offline copies remain recoverable and trustworthy through the post-quantum transition.

Read Original Post →