Quantum computing is not yet able to break today’s encryption, but the timeline has compressed dramatically in recent months and sensible security teams are not waiting to find out when it will. Governments, standards bodies, and large enterprises have started moving now, because encrypted data captured today can be stored and decrypted later, once a capable quantum computer exists. Security teams call this “harvest now, decrypt later”, and it is a real risk for any organization that handles data with a long shelf life: health records, financial history, government communications, or trade secrets.
NIST finalized its first set of post-quantum cryptography standards in 2024, including ML-KEM, the key-encapsulation mechanism built for this exact problem. 87% of organizations report they are planning, testing, or implementing PQC initiatives * so the direction is clear. With agencies and regulated industries setting migration timelines, vendors across the industry should all now be adding quantum-resistant options to their products.
Netskope has been preparing for this shift for some time. In a June 2025 post, we walked through five places in the Netskope One architecture where encryption is used, and we said we were focusing on NIST’s ML-KEM 768 to build stronger protection across our infrastructure. That work continues today.
We’re now extending that work into Netskope One Next Gen SWG (Secure Web Gateway). We’ve added support for X25519MLKEM768, a hybrid key-exchange algorithm which pairs elliptic-curve cryptography (the method in wide use today) with a post-quantum method. This ensures that a connection stays protected even if one of the two approaches is broken in the future. This support covers both directions of traffic: client to Netskope, and Netskope to the destination server.
What that looks like in practice:
- Turn it on when you’re ready. It’s a tenant-level feature flag, built for controlled testing, not a forced flip.
- Fast, because it’s native. Built on the OpenSSL 3.5 upgrade, not bolted on.
- You can see it working. Transaction events show PQC use, so this isn’t a black box.
- This is available in commercial environments today, with support for other environments (including FedRAMP (US), PBMM (Canada), Data Plane on-Premises, and Virtual Private Edge) planned for future releases.
This is one step in a longer migration. Cryptographic standards, vendor support, and client compatibility will keep evolving, and we expect to keep expanding coverage as they do.
If you handle data that needs to stay confidential for years, it’s worth understanding where PQC fits in your environment now. Reach out to your Netskope team, and we’ll walk through what this means for your traffic and your timeline or if you are ready to take your first step with Netskope click here.
DigiCert, 2026 Quantum Readiness Outlook (survey of 1,001 IT/security decision-makers across the US, UK, and Australia, released July 23, 2026)