Confluent Cloud is building a roadmap toward post-quantum cryptography (PQC) readiness, driven by the 'harvest now, decrypt later' threat. Key steps include enabling TLS 1.3 by default for all clusters by April 30, 2026, and moving toward a hybrid key exchange model combining classical and PQC signatures. Confluent is aligning with NIST FIPS 203, 204, and 205 standards, investigating ML-KEM, ML-DSA, and SLH-DSA integration across public endpoints. For data at rest, AES-256 on AWS and GCP is already considered PQC-compliant, while Azure support via OCT-HSM is under investigation. The Cloud Security Alliance has set April 14, 2030 as the deadline for post-quantum infrastructure readiness.

4m read timeFrom confluent.io
Post cover image
Table of contents
Data-in-Transit EncryptionData-at-Rest EncryptionPost-Quantum Crypto Resilience

Sort: