What's the difference between a VPN protocol, a cipher, and post-quantum encryption?
Summary
A protocol such as WireGuard, OpenVPN or IPsec decides how the encrypted tunnel is built and kept up. A cipher such as AES-256-GCM or ChaCha20-Poly1305 is what scrambles the data inside that tunnel and detects tampering. Post-quantum encryption, in practice ML-KEM, which NIST standardized as FIPS 203 in August 2024, changes only how the two ends agree on a key at the start of a connection. With WireGuard the cipher is fixed by the protocol and with OpenVPN it is negotiated, so you rarely pick between AES and ChaCha20 yourself.
Four kinds of name on one spec sheet
A vendor's feature list might mention WireGuard, AES-256, NordLynx, Lightway and "quantum-resistant encryption" in the same breath. They are different kinds of thing:
- Protocols build and maintain the tunnel. WireGuard, OpenVPN, and IPsec with IKEv2.
- Ciphers encrypt the traffic and check it hasn't been altered. AES-GCM and ChaCha20-Poly1305.
- Key exchange lets both ends arrive at a shared secret. Curve25519, IKEv2, and hybrid schemes that add ML-KEM.
- Products and branded protocols package the above with apps and admin tools. NordLynx and Lightway are examples.
Zero-trust network access (ZTNA) doesn't fit any of these slots. It is an approach to access, where each person is let into specific apps instead of onto a whole network, and it is sold alongside business VPNs. What it costs per user is on our ZTNA pricing page.
WireGuard, OpenVPN and IPsec
WireGuard uses a fixed set of primitives. Its protocol page lists ChaCha20 for encryption with Poly1305 for authentication, Curve25519 for key exchange, BLAKE2s for hashing, SipHash24 for hashtable keys and HKDF for key derivation. There is no cipher setting to change. The same page notes an optional pre-shared key that adds a layer of symmetric-key crypto, which it mentions as a route to post-quantum resistance.
OpenVPN negotiates. In OpenVPN 2.7 the default list of data ciphers is AES-256-GCM, AES-128-GCM and CHACHA20-POLY1305, or just the two AES options where ChaCha20-Poly1305 isn't available. If the client and server share no cipher, the connection is dropped.
IPsec is a family of standards, not a single protocol. RFC 7296, which defines IKEv2, calls IKE a component of IPsec and gives it two jobs: mutual authentication between the two ends, and setting up and maintaining the security associations that carry the encrypted traffic.
AES-256-GCM or ChaCha20-Poly1305?
Both are authenticated encryption (AEAD), meaning one operation both hides the data and detects tampering. AES is defined in NIST's FIPS 197 in three key lengths, 128, 192 and 256 bits, and works on 128-bit blocks. GCM is the mode that adds the tamper check. ChaCha20-Poly1305 pairs the ChaCha20 stream cipher with the Poly1305 authenticator and is specified in RFC 8439.
In practice the protocol makes the choice. A WireGuard-based product uses ChaCha20-Poly1305. An OpenVPN product uses whatever the two sides agree on from the list above.
"Uses AES" is not the same as FIPS validated
If a contract or regulator requires FIPS, the cipher name settles nothing. NIST's Cryptographic Module Validation Program says a product does not meet FIPS 140-2 or 140-3 by implementing an approved function and holding algorithm certificates. What counts is whether the cryptographic module inside the product appears on the CMVP validated list.
The rules changed in September 2026. FIPS 140-2 modules could be used in new systems through September 21, 2026. After that date their certificates move to the Historical list, which NIST says agencies should keep out of new systems, though they can stay in existing ones. FIPS 140-3 is the standard now being validated, so a vendor sheet that says only "FIPS 140-2 validated" describes a module for legacy use.
What post-quantum encryption protects against
Post-quantum cryptography is ordinary math-based cryptography designed to hold up against future quantum computers. NIST is careful to separate it from quantum cryptography, which relies on quantum physics itself.
The usual argument for moving early is "harvest now, decrypt later": someone records encrypted traffic today and waits for a quantum computer able to break it. Data that has to stay secret for years is exposed to that even if nobody can read it now.
What is at risk is public-key cryptography, the part used to agree on keys and sign things. In a November 2024 draft (NIST IR 8547), NIST says existing symmetric standards such as AES are less vulnerable to quantum attack and that it does not expect a move away from them as part of the post-quantum migration. So a post-quantum VPN still encrypts traffic with AES or ChaCha20. The handshake is what changes.
FIPS 203, published August 13, 2024, defines three ML-KEM parameter sets. In order of increasing security and decreasing performance they are ML-KEM-512, ML-KEM-768 and ML-KEM-1024. ExpressVPN, the one vendor in the table below that names its method, describes a hybrid that combines a classical key exchange with ML-KEM.
Who has announced post-quantum support
This is not a ranking. We haven't tested these products, and the list only records what each vendor has published.
| Product and protocol | What the vendor announced | Caveats |
|---|---|---|
| NordVPN, NordLynx | Linux app in September 2024, then Windows, Android, iOS and macOS in early 2025 | Off until you switch it on. The algorithm isn't named |
| Surfshark, WireGuard | Announced January 19, 2026. On automatically when WireGuard is selected | No platforms or algorithm named |
| ExpressVPN, Lightway | January 2025 move from Kyber to ML-KEM, in a hybrid with classical key exchange | Arrives with the latest app version. The Rust rewrite announced in February 2025 and audited by Cure53 and Praetorian is a separate change |
| ExpressVPN, WireGuard | August 6, 2025 launch of WireGuard with hybrid ML-KEM on iOS, Android and Windows | A separate implementation from Lightway |
All four announcements are about consumer apps. On the business side, the ExpressVPN for Teams page describes Lightway as quantum-safe. NordLayer's features page names AES-256 and ChaCha20 and says nothing about post-quantum protection, and Surfshark's page for teams doesn't mention it either.
Post-quantum support covers the key exchange at the start of each session. Sign-in, multi-factor authentication and who can reach which system are separate parts of the setup.
Sources
- https://www.wireguard.com/protocol/
- https://openvpn.net/community-docs/community-articles/openvpn-2-7-manual.html
- https://www.rfc-editor.org/rfc/rfc7296.html
- https://csrc.nist.gov/pubs/fips/197/final
- https://www.rfc-editor.org/rfc/rfc8439.html
- https://csrc.nist.gov/projects/cryptographic-module-validation-program
- https://csrc.nist.gov/Projects/cryptographic-module-validation-program/validated-modules
- https://www.nist.gov/cybersecurity-and-privacy/what-post-quantum-cryptography
- https://csrc.nist.gov/pubs/ir/8547/ipd
- https://csrc.nist.gov/pubs/fips/203/final
- https://nordvpn.com/blog/post-quantum-cryptography/
- https://surfshark.com/blog/surfshark-launches-post-quantum-protection-on-wireguard
- https://www.expressvpn.com/blog/ml-kem-lightway-upgrade/
- https://www.expressvpn.com/news-pr/lightway-in-rust/
- https://www.expressvpn.com/blog/expressvpn-launches-post-quantum-wireguard-blueprint-vpn-industry/
- https://www.expressvpn.com/teams
- https://nordlayer.com/features/
- https://surfshark.com/for-teams
Related on this site
- ZTNA pricing: what zero-trust network access costs per user
- Business VPN dedicated IP cost: what the fixed charge adds per person
- Will a VPN give my Make.com scenarios a fixed IP address?
- Business VPN pricing: cost per user across every vendor
Written by Kaz (pen name). Published September 28, 2026. The facts above come from the vendor and standards pages listed under Sources. We have not used these products. Corrections: contact form.