Post-Quantum VPN (2026): Who Has It and Does It Matter Yet

Disclosure: VPNFin is reader-supported. If you buy a VPN through links on this page, we may earn a commission at no extra cost to you. This never affects our ratings — here’s our full disclosure.

A post-quantum VPN adds a second key exchange, based on ML-KEM, the algorithm NIST standardised as FIPS 203 on 13 August 2024, so that a future quantum computer couldn’t unlock sessions recorded today. The threat it answers is harvest now, decrypt later: capturing encrypted traffic now to decrypt once quantum machines arrive, possibly in the early 2030s, Comparitech notes. As of mid-2026, NordVPN, ExpressVPN and Mullvad offer it; Proton VPN had not deployed it, Encapsulated reports.

Does it matter yet? For most everyday use, not much. For data that must stay secret for a decade, yes. This page sets out who has it and when it’s worth switching on.

Post-Quantum VPN: Who Has It

ProviderStatus (mid-2026)Default or opt-in
NordVPNAll apps, on NordLynxSources disagree: opt-in toggle or default
ExpressVPNLightway, since January 2025Default on Lightway; opt-in on WireGuard
MullvadWireGuard, all platformsDefault on desktop since January 2025
Surfshark (Nord Security, like NordVPN)Announced as in progress in 2025Status unclear
Proton VPNNot deployed—

Check your own post-quantum VPN setting. Sources conflict on NordVPN: Encapsulated describes an opt-in toggle, while Technerdo calls it the default everywhere. The setting, where it exists, sits in the app’s connection settings. Our NordLynx guide explains how NordVPN adds it, and our reviews of Mullvad and ExpressVPN cover the other two.

Get NordVPN →
Post-quantum on NordLynx
Post-quantum VPN: which providers have it in 2026, and whether it's on by default

How a Post-Quantum VPN Works

A post-quantum VPN uses a hybrid. The post-quantum layer sits alongside the classical key exchange, so an attacker must break both to read a session, Encapsulated explains. In WireGuard-based setups it travels through WireGuard’s built-in pre-shared key slot, leaving the handshake unchanged.

Strength levels differ. ML-KEM-1024 roughly matches AES-256 strength. ExpressVPN has confirmed it uses ML-KEM-1024 in Lightway; NordVPN and Mullvad haven’t published their levels, Encapsulated notes. Our Lightway vs WireGuard guide covers ExpressVPN’s version.

The cost is small. ML-KEM-768 adds about 1 to 2 kilobytes to the handshake, VPNVertex notes; the encrypted connection itself runs at normal speed.

Read: Lightway vs WireGuard →
ExpressVPN’s post-quantum protocol
How a post-quantum VPN works: hybrid key exchange, ML-KEM levels and overhead

Does a Post-Quantum VPN Matter Yet?

Your useDoes it matter?Why
Streaming, public Wi-Fi, everyday browsingLittleNothing to protect for a decade
Work email, business documentsSomeDepends on how long they stay sensitive
Journalism, legal, medical, activismYesHarvested data could matter for years

Protection only runs forward. Switching it on protects traffic from that point; anything captured earlier stays exposed to future decryption, Comparitech explains. That’s the argument for enabling it early if your data is long-lived; our privacy VPN guide weighs the providers for that use.

Watch the trade-offs. On NordVPN, post-quantum works only on NordLynx, so it can’t be combined with obfuscation, VPNVertex notes. Our obfuscation guide explains why you might need the latter.

Does a post-quantum VPN matter yet? It depends on how long your data must stay secret

Related Guides

Protocols: our WireGuard vs OpenVPN guide covers the classical side of a post-quantum VPN’s handshake.

Trust: post-quantum keys don’t replace a no-logs policy, as our no-logs guide explains. A provider that logs your activity undoes any encryption gain.

How We Research

Provider status comes from Encapsulated’s July 2026 analysis and Tom’s Guide; the conflicting NordVPN claim from Technerdo; the threat model and timeline from Comparitech; overhead and the obfuscation trade-off from VPNVertex. The standard itself is NIST’s FIPS 203. We read all sources on 28 September 2026. NordVPN is one of our affiliate partners. Our full approach lives on the About Us page.

Post-Quantum VPN FAQ

What is a post-quantum VPN?

A VPN that adds a quantum-resistant key exchange, based on NIST’s ML-KEM standard, alongside the classical one, so recorded traffic can’t be decrypted by future quantum computers.

Which VPNs have post-quantum encryption?

As of mid-2026, NordVPN, ExpressVPN and Mullvad offer it. Surfshark announced work on it; Proton VPN had not deployed it.

Do I need a post-quantum VPN?

For everyday browsing and streaming, not urgently. For data that must stay confidential for years, it’s worth turning on now.

Does post-quantum encryption slow a VPN down?

Barely. It adds a small amount to the handshake; the connection itself runs normally.

What is harvest now, decrypt later?

Capturing encrypted traffic today to decrypt it once quantum computers can break current key exchange.

The Verdict

A post-quantum VPN is worth switching on if you have it, since the cost is tiny, but it isn’t yet a reason to change provider for everyday use.

If your work involves data that must stay secret for a decade, choose a provider that ships it now: NordVPN, ExpressVPN or Mullvad.

Read: Our VPN Audit Tracker →
Who has been independently checked
Scroll to Top