Growing PQC at the edge belies deeper quantum-readiness challenges
GeneralThe quantum threat is becoming an increasing concern for security leaders, but many may be mistaking protection at their website’s front door for quantum readiness across their business. More than half (54%) of the world’s top 1 million websites now support post-quantum key exchange, according to research from F5 Labs, an encouraging statistic given that just 27% of CISOs in a June KPMG survey said they are actively implementing post-quantum cryptography (PQC). But F5 Labs’ State of PQC on the Web study found that much of that apparent progress comes from content delivery network (CDN) providers switching on protection, rather than organizations upgrading their own infrastructure for what 38% of CISOs see as top high-impact emerging threat, according to KPMG’s survey. “54% sounds like we’re halfway to a quantum-safe web, but we need to be clear about what we’re measuring,” says David Warburton, director of F5 Labs. “Much of that support comes from CDN providers switching PQC on by default. Remove Cloudflare-hosted sites and the figure drops to 22%.” F5 Labs looked only at the website’s front end without accessing an enterprise’s application servers behind the CDN — for example, Akamai, Cloudflare, Amazon CloudFront — or determining whether their internal traffic uses PQC. “Those internal connections could potentially be an even bigger target for harvest now, decrypt later attacks,” Warburton says. Or as Serhii Nikolaichuk, founder of The Capital Index, an engineering firm that builds attestation systems, puts it, everything behind what the CDNs have turned on, “the hop to the origin, service meshes, VPNs, SSH, and code signing, is invisible from outside, and that’s where enterprise readiness actually lives.” Beyond the edge Independent experts back F5 Labs’ broad conclusions, warning that true post-quantum readiness requires upgrading every layer in the technology stack. Edge adoption is meaningful progress, but it is not a reliable measure of enterprise readiness, according to Anastazija Pažin, senior cybersecurity consultant at management consultancy Deloitte. “CDN-enabled PQC provides genuine protection for the client-to-edge connection,” says Pažin. “The limitation is that this protection does not automatically extend to the origin server, internal APIs, service-to-service communications, or enterprise PKI.” Post-quantum adoption is moving fastest where it can be enabled centrally, and one reason for this mismatch is that implementation guidance has only recently started to catch up with the core standards, says Ben Packman, chief strategy officer at PQC specialists PQShield. “NIST finalized its first PQC standards in 2024 while the IETF, for example, only published the standard defining hybrid post-quantum key exchange mechanisms for TLS 1.3 in August this year,” says Packman. Technical debt Reliance on legacy technologies combined with other dependencies mean that the quantum cryptography upgrade path is far from trivial. Organizations have older clients, partner integrations, and change-control processes that make it difficult to upgrade everything quickly. Many vendors haven’t yet updated their products to support PQC, either. “The 54% figure measures PQC key exchange support. PQC certificates aren’t yet available for the public internet,” notes Warburton. “Merkle Tree Certificates should help desktop and mobile browsers, but plenty of other environments will need PQC certificates, and their much larger size will cause problems.” Certificate management also represents a technology obstacle. “If you’re still provisioning certificates manually, you’re going to face serious challenges when 47-day certificate lifetimes are enforced,” Warburton concludes. The PQC-readiness gap is particularly striking in sectors handling sensitive, long-lived data. For example, only 35% of government and telecommunications websites in the study supported post-quantum key exchange. Industry differences Government and critical infrastructure organizations tend to have more long-lived operational technology, self-hosted systems, and slower procurement cycles, creating additional challenges for quantum readiness. Across F5 Labs’ wider sample, more than one in 10 responding websites still lacked support for TLS 1.3 — a prerequisite for the post-quantum key exchanges that F5 tested. F5 argues that while protection at a website’s public edge is a valuable step it fails to establish whether an organization’s servers and internal applications are quantum ready. However, Chris Hickman, CSO at digital trust infrastructure vendor Keyfactor, says that F5’s figures fail to reflect the full scope of PQC preparations. “For example, the leading industries for full PQC readiness include financial, telecommunications, and government, with healthcare starting to accelerate efforts more rapidly,” Hickman says. “Again, I believe the difference in this result is a web focus versus organizational initiative, of which the web is only one element.” Financial institutions and critical infrastructure operators are increasingly addressing PQC through cryptographic inventories, risk assessments, and migration roadmaps. But planning maturity should not be confused with deployment maturity, Deloitte’s Pažin says. “Financial institutions face complex dependencies involving HSMs [hardware security modules], payment infrastructure, PKI, and third-party services,” says Pažin. “Telecommunications providers must consider large-scale network infrastructure and interoperability. Industrial environments introduce additional challenges through long-lived operational technology, constrained devices, and limited opportunities for disruptive upgrades.” Pažin adds: “Consequently, organizations with relatively mature cybersecurity governance can still face substantial implementation challenges.” Preparing for PQC Organizations should embark on their upgrade path to PQC by first carrying out an inventory of their existing use of cryptography, prioritizing data that must remain confidential for years, and planning upgrades to the systems that will take longest to change. “That means looking beyond your public website to internal applications, APIs, VPNs, identity systems, and embedded libraries,” F5 Labs’ Warburton advises. “Build a cryptographic bill of materials and make sure someone owns the process of keeping it up to date.” Enterprises should proceed by removing legacy dependencies, enable hybrid PQC where they can, and automate certificate management. “You need to be able to change algorithms and certificates without turning every update into a major infrastructure project,” Warburton adds. Deloitte’s Pažin concludes: “Meaningful enterprise readiness assessment should examine whether an organization understands its cryptographic dependencies, has prioritized assets according to quantum-related risk, and can replace vulnerable algorithms without major architectural disruption.”
Read full story at CSO Online →