Summary of www.cloudflare.com:443 (HTTPS) SSL Security Test
Provided "as is" without any warranty of any kind.
This test was made 90 days ago and may be outdated
Refresh Test
Date/Time:May 24th, 2026 15:35 GMT+0
Source IP/Port:104.16.123.96:443
Protocol:HTTPS
Location:Unknown
Your final score:
- A
- B
- C
- F
A+
Test Results Summary for www.cloudflare.com
- This server on the tested port supports only hybrid ML-KEM key exchange groups, which are recommended by NIST for the transition period. The server’s certificate chain relies entirely on classical signature algorithms without post-quantum support. Show details.
- 2 SSL/TLS end-entity certificate(s) detected: the first certificate is a trusted RSA 2048 bits certificate with issuer WR1 valid until August 5, 2026; the second certificate is a trusted ECDSA 256 bits certificate with issuer WE1 valid until August 5, 2026. 5 certificate chain(s) detected. Show details.
- All 11 supported cipher suite(s) are compliant with PCI DSS. The server supports only PCI DSS compliant protocols: TLSv1.2 and TLSv1.3. All supported elliptic curves are compliant with PCI DSS: P-256, P-384, P-521 and X25519. No additional PCI DSS compliance issues were identified. Show details.
- 1 of 11 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports only HIPAA compliant protocols: TLSv1.2 and TLSv1.3. All supported elliptic curves are compliant with HIPAA: P-256, P-384, P-521 and X25519. No additional HIPAA compliance issues were identified. Show details.
- No issues related to industry best practices were identified. Show details.
Compliance Summary for www.cloudflare.com
- PCI DSS Compliance Passed: All 11 supported cipher suite(s) are compliant with PCI DSS. The server supports only PCI DSS compliant protocols: TLSv1.2 and TLSv1.3. All supported elliptic curves are compliant with PCI DSS: P-256, P-384, P-521 and X25519. No additional PCI DSS compliance issues were identified.
- HIPAA Compliance Failed: 1 of 11 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports only HIPAA compliant protocols: TLSv1.2 and TLSv1.3. All supported elliptic curves are compliant with HIPAA: P-256, P-384, P-521 and X25519. No additional HIPAA compliance issues were identified.
- GDPR Compliance Passed: All 11 supported cipher suite(s) are compliant with GDPR. The server supports only GDPR compliant protocols: TLSv1.2 and TLSv1.3. All supported elliptic curves are compliant with GDPR: P-256, P-384, P-521 and X25519. No additional GDPR compliance issues were identified.


