Cloudflare's 2029 Target, HPE's 24 to 48 Months, Dell's 1.2 Million Old Servers and QuSecure's Vendor-Reported TRL 7: Four Post-Quantum Clocks Against EO 14412's 2030 and 2031 Deadlines

Quentir Defense Monitor

Evidence-based insights for quantum defense and security. Published by Quentir Systems LLC · September 4, 2026.

Cloudflare's 2029 Target, HPE's 24 to 48 Months, Dell's 1.2 Million Old Servers and QuSecure's Vendor-Reported TRL 7: Four Post-Quantum Clocks Against EO 14412's 2030 and 2031 Deadlines

Four companies put dates and numbers on the post-quantum migration in the first week of September 2026, and none of them is a government. Cloudflare's roadmap, restated in the German trade press on 4 September, targets completion in 2029; HPE told enterprises on 4 September to plan on 24 to 48 months; Dell told investors on 1 September that 1.2 million of its installed servers are old enough that customers are refreshing them, with security requirements among the reasons; and QuSecure reported on 2 September that its platform ran under soldier operation at a US Army exercise and, by the company's reading, reached Technology Readiness Level 7. Read against Executive Order 14412's 2030 and 2031 federal deadlines, the four give a program office something the policy documents do not: the pace at which suppliers say they can move, and the size of the installed base that has to be carried along.

The four announcements measure different things. Cloudflare's is a post-quantum roadmap with dated milestones, the first of which it has announced support for. HPE's is a lead-time estimate for a large enterprise. Dell's is a count of hardware that customers are replacing whatever the cryptography does. QuSecure's is a readiness level reported by the company from a field exercise. This Monitor reads each one for what it can support, then sets all four beside the federal calendar and beside what the founder of this site wrote about lead times in War on the Rocks in July.

What Cloudflare Published on 7 April 2026 and Delivered on 29 July 2026

Cloudflare's post-quantum roadmap, written by Bas Westerbaan and published on 7 April 2026, is the document heise online summarized for German readers on 4 September. It states that hybrid post-quantum key agreement has been on by default since 2022 and that more than 65 percent of human traffic to Cloudflare is now post-quantum encrypted. The remaining work is authentication, and the roadmap dates it in four steps: ML-DSA signatures for connections from Cloudflare to customer origin servers by mid-2026, post-quantum authentication for visitor connections using Merkle Tree Certificates by mid-2027, the Cloudflare One suite by early 2028, and a target of the whole network post-quantum secure in 2029. Customers, the roadmap says, do not need to take mitigating action, a statement that concerns the encryption already on by default; the authentication milestones below do ask origin operators to act. The document gives its own reason for the pace: the March 2026 estimate from the Caltech group behind Oratomic that Shor's algorithm could run at cryptographically relevant scale with about 10,000 reconfigurable neutral-atom qubits.

Cloudflare announced support for the first roadmap capability inside the mid-2026 window. On 29 July 2026 Luke Valenta and Kevin Guthrie announced that Authenticated Origin Pulls and Custom Origin Trust Store now support ML-DSA signatures, which covers the authentication of the connection between Cloudflare and the customer's own server. Support is where the customer's work begins: using the capability requires compatible tooling on the origin, origin configuration, and trust settings that leave a downgrade attack nothing to fall back to, so the milestone is complete for each origin only when its operator has acted. The visitor side is harder because it depends on browsers and certificate authorities, which is why Cloudflare is developing Merkle Tree Certificates with Google at the Internet Engineering Task Force with deployments targeted for 2027. The roadmap's own phrasing is that browsers, applications and origins all need to upgrade, and Cloudflare controls none of them.

What HPE and Dell Told Enterprises in the Same Week: 24 to 48 Months, and 1.2 Million Servers

HPE's contribution is an estimate. In a piece carried by the Italian trade outlet Bitmat on 4 September 2026, the company puts migration of core systems at 24 to 36 months and the broader infrastructure transition at 24 to 48 months or more, depending on scope, legacy dependencies, supplier readiness, validation cycles and operational complexity. It lists the places where cryptography is hardest to change, hardware-rooted identity, secure boot, firmware signing, infrastructure control planes, long-lived certificates and internal public key infrastructure, and it says plainly that a vendor's statement of being PQC-ready is not sufficient, since operational readiness requires interoperability, validation and support as the standards keep moving. Its closing advice is to align infrastructure refresh cycles with post-quantum requirements so that new purchases reduce the migration debt instead of adding to it.

Dell supplied the number that turns HPE's advice into a budget line. Reporting second-quarter fiscal 2027 results on 1 September 2026, the company recorded revenue of USD 47 billion, up 58 percent, with traditional server and networking revenue up 122 percent to USD 10.5 billion. On the call, vice chairman and chief operating officer Jeff Clarke attributed that growth to existing enterprise customers refreshing older infrastructure, consolidating data centers and addressing security and resiliency requirements, and said that 1.2 million installed assets are still 14th-generation servers or older. Dell's 17th-generation servers consolidate six to eight of those into one, and the 18th generation, due to ship in October, twelve to fourteen into one. The Japanese business outlet Strainer, in its account of the same call, reports Clarke saying the older machines cannot meet new security requirements such as post-quantum cryptography, which makes the refresh unavoidable. That is a vendor describing its own demand, and it should be read as one; the count of 1.2 million servers is Dell's, and the share of them in networks that carry long-lived secrets is unknown. What the number does establish is that Dell has identified a large installed base of older assets and links the current refresh demand to security and resiliency requirements, and HPE's advice is to make the cryptography ride along with any refresh that happens.

Quantum pillar: post-quantum cryptography (migration and crypto-agility). Use posture: defensive. Technology readiness: TRL 7 of 9. Rung seven means a near-final system has run in the environment where it belongs, and that is the level QuSecure itself reports for its platform after soldiers operated it at an Army exercise; this Monitor carries the level as vendor-claimed, since no independent assessment of the run has been publicly identified, and the Cloudflare, HPE and Dell items are roadmaps, estimates and sales figures that sit on no rung of the ladder.

What QuSecure Reported From Project Convergence Capstone 6 on 2 September 2026, and the Clock Its Product Manager Named

Quentir's daily blog already read QuSecure's release as a procurement-evidence item when it asked what post-quantum buying counted as proof in the first week of September, so the recap here is short and the new material is the clock. The release of 2 September 2026 states that QuProtect R3 reached Technology Readiness Level 7 after operating under soldier-led conditions at Project Convergence Capstone 6 at Fort Irwin, California, where it provided quantum-resistant communications, cryptographic agility, and cryptographic discovery and inventory for Army tactical networks; the company ties the rating to the Post-Quantum Cryptography Coalition's Solution Analysis Guide and says the product holds the top score in that guide's technical-readiness area. The sentence that belongs in this post is product manager Joey Lupo's: the exercise demonstrated, he said, that tactical networks can be hardened against the quantum threat before a possible 2029 Q-day. Executive vice president Brian Cunningham added that Executive Order 14412 and the Department of War's PQC strategy have set binding deadlines every federal agency now has to meet, and that the Army is not waiting. Two cautions belong beside those quotes. The readiness level is the company's reading of a coalition guide against its own exercise result; the Army has published no assessment of the run, and a TRL assigned by the vendor is a claim to be checked, which is why this Monitor's readiness panel above says so. And the coverage carried an error worth flagging for anyone building an inventory from headlines: one outlet's headline described the product as quantum key distribution, while its own body text and the company's release describe post-quantum cryptography, a software migration on existing networks. The two are different technologies with different cost and readiness profiles.

How the Four Clocks Fit the Federal Calendar, and What Before Q-Day Said About Lead Times on 20 July 2026

Executive Order 14412 of 22 June 2026 sets post-quantum key establishment on federal high-value assets and high-impact systems by the end of 2030 and digital signatures by the end of 2031, and the Office of Management and Budget's memorandum M-26-15 requires every agency migration plan by 22 October 2026, a calendar Quentir's daily blog walked through when it read five post-quantum dates that arrive before the federal plans are due. Those dates cover specified federal systems; national security systems, which is where an Army tactical network sits, are addressed separately in the order, so the Fort Irwin result and a civilian agency's web services are not on one clock. Set the commercial clocks against the federal ones. HPE's 24 to 48 months, counted from September 2026, ends between late 2028 and late 2030, which straddles the federal deadline. Cloudflare's visitor-side authentication is targeted for 2027 and its network for 2029, one year inside the deadline, on the assumption that browsers and certificate authorities move with it. QuSecure's product manager is working to a possible 2029 Q-day, which is earlier than any federal date. Dell's 18th-generation servers ship in October 2026, and a server bought then is a purchase whose cryptography the buyer will live with across every one of those dates.

In Before Q-Day: The Race to Quantum First, published in War on the Rocks on 20 July 2026, the founder of this site and Joseph Federici of the US-China Economic and Security Review Commission wrote that cryptographic migrations historically take a decade or more, that the slowest systems to change are the ones that matter most, such as weapons platforms, industrial controls and satellites, and that if the machine arrives in 2035 the migration still has to start now. The week's announcements are the commercial version of that argument: a content network plans seven years from its 2022 start to its 2029 finish with the whole browser ecosystem cooperating, and an enterprise vendor tells its customers to plan on up to four. The founder's earlier War on the Rocks essay, "A Bletchley Park for the Quantum Age" of 6 November 2025, asked governments to publish dated adoption milestones, to procure only validated cryptography, and to test what is deployed instead of what vendors promise. Cloudflare's roadmap with its first capability announced on 29 July is what a published dated milestone looks like from the supplier side; the Fort Irwin run is a test of deployed equipment under operation, reported so far only by the vendor that was tested.

For a program office the four announcements translate into three questions to put to any supplier. Does the vendor have a dated roadmap of its own, with a milestone already met, in the form Cloudflare has published? Does the refresh plan reconcile equipment age with the migration, so that the servers Dell will ship in October carry the algorithms the network will need in 2031? And where a vendor reports a readiness level from an exercise, who other than the vendor assessed it? Each question is answerable only from a cryptographic inventory, which is where this Monitor's reading of the ASD and NCSC guidance that both start with the inventory left the same reader yesterday. None of the four announcements read for this post states a FIPS 140-3 validation status for the algorithms it ships, and none of the four names a parameter set, where the Department of War's own request for information, read by Quentir's daily blog this week, specifies ML-KEM-1024; so the inventory entry each announcement supports is a date and a claim, with the validation and parameter columns still empty.

The dated items to watch are Dell's October shipment of the 18th-generation servers, which either carry post-quantum firmware signing or do not; the 22 October 2026 deadline for federal migration plans; Cloudflare's 2027 visitor-side milestone, which depends on the Merkle Tree Certificate work at the IETF; and whether the Army publishes its own reading of the QuSecure run before next year's exercise. Each will show whether the commercial clocks keep the time their owners have announced.

Sources

Primary source: Cloudflare, "Cloudflare's post-quantum roadmap" by Bas Westerbaan, 7 April 2026, for the 2022 key-agreement default, the 65 percent figure, the four dated milestones, the customer statement, the Oratomic reference and the sentence that browsers, applications and origins need to upgrade; Cloudflare, "Post-quantum authentication to origins is now supported" by Luke Valenta and Kevin Guthrie, 29 July 2026, for ML-DSA in Authenticated Origin Pulls and Custom Origin Trust Store, the OpenSSL 3.5.0 requirement, the downgrade instruction and the 2027 Merkle Tree Certificate target; QuSecure, release of 2 September 2026, for the TRL 7 claim, the functions demonstrated, the coalition guide, the SBIR and C5ISR history and the Lupo and Cunningham quotations; Dell Technologies, second-quarter fiscal 2027 results release of 1 September 2026, for the revenue figures; Executive Order 14412 of 22 June 2026 and OMB memorandum M-26-15, for the 2030 and 2031 destinations and the 22 October 2026 plan deadline; the Australian Signals Directorate's planning guidance of 20 July 2026 and the NCSC's migration timelines guidance, for the inventory-first ordering cited from this Monitor's earlier post. Secondary accounts: heise online, 4 September 2026, for the German summary of the roadmap; Bitmat, 4 September 2026, for HPE's 24 to 36 and 24 to 48 month estimates, its list of hard-to-change dependencies and its advice on refresh cycles; Strainer, 2 September 2026, for Jeff Clarke's 1.2 million servers, the consolidation ratios and the statement on post-quantum requirements; Quantum Zeitgeist and ExecutiveBiz, 3 September 2026, for the headline discrepancy and the additional Cunningham quotation. War on the Rocks, "Before Q-Day: The Race to Quantum First," 20 July 2026, by the founder of this site with Joseph Federici, and "A Bletchley Park for the Quantum Age," 6 November 2025, by the founder of this site, for the lead-time and testing positions. The judgments are this Monitor's own: the decision to carry QuSecure's TRL 7 as a vendor-claimed level, the arithmetic setting HPE's estimate against the 2030 date, the three supplier questions and the observation that no announcement states a validation status or parameter set.

  1. post-quantum roadmap
  2. Authenticated Origin Pulls and Custom Origin Trust Store now support ML-DSA signatures
  3. second-quarter fiscal 2027 results on 1 September 2026
  4. release of 2 September 2026
  5. Before Q-Day: The Race to Quantum First
Previous
Previous

Tampere University and Nokia Bell Labs Adapt MIMO Space-Time Coding to Rydberg Atomic Quantum Receivers in a September 2026 Paper

Next
Next

ASD's LATICE Guidance of 20 July 2026 and the NCSC's Workshop Report of 22 July 2026 Both Start With the Cryptographic Inventory, and the EU's End-2030 Date Leaves Little Time to Build One