Post-Quantum
Post-quantum HTTPS authentication: what Chromium’s roadmap actually says
Post-quantum key agreement is not the same as post-quantum certificate authentication. Do not conflate the two in a board slide.
sslcertificates.io Editorial · Published 2026-09-21 · Fact-checked 2026-09-21 · Topic window 2026-09-10
Chromium has published a staged roadmap for post-quantum HTTPS authentication. That is not the same sentence as “TLS is post-quantum today.”
Key agreement (how the session key is established) and certificate authentication (how the server proves its identity) are different layers. Hybrid key agreement can ship while Web PKI still uses classical signatures on certificates.
Do not write a procurement slide that says “we are PQ ready” because a CDN enabled X25519MLKEM768. Ask: which certificates, which algorithms, which clients, which date.
This article is analysis, not a product claim. sslcertificates.io does not sell a post-quantum certificate SKU on the pricing page.
Sources
Related
Automate the lifecycle this article describes
Inventory, renewals and verified deployment are product surfaces — not adjectives.