Quantum-resistant key exchange is moving beyond endpoints and into the network data path.
Netskope announced on August 24, 2026 that its Secure Web Gateway (SWG) now supports X25519MLKEM768, a hybrid method that pairs elliptic-curve X25519 with NIST’s post-quantum ML-KEM-768 key-encapsulation mechanism. The company says the support covers both directions of the proxy path: client-to-Netskope and Netskope-to-destination-server.
That inline placement is the point for security leaders. Protecting the full gateway path is a wider attack surface than endpoint-only PQC rollouts, which matters for teams tracking NSA CNSA 2.0 and NIST PQC migration.
Netskope built the capability on an OpenSSL 3.5 upgrade and gates it behind a tenant-level feature flag for opt-in testing. Transaction events log PQC usage, so teams can see which sessions use the hybrid exchange and pilot in production without a forced cutover.
Federal buyers should read the scope carefully. The feature is available now in commercial environments only. Support for FedRAMP, Canada’s PBMM, Data Plane on-Premises, and Virtual Private Edge is described as planned for future releases with no committed date, so this release alone does not equal mandate-readiness for regulated environments.
Source: Netskope Blog



Leave a Reply