Back to news

AWS Client VPN Lands in Four New Regions; Cloudflare Urges ML-DSA Now

AWS expands managed remote-access VPN coverage while Cloudflare argues enterprises should not wait for next-generation post-quantum signatures.

AWS Client VPN Lands in Four New Regions; Cloudflare Urges ML-DSA Now

What happened

Amazon Web Services has made its Client VPN service available in four additional regions: Canada West (Calgary), Mexico (Central), Asia Pacific (New Zealand), and Asia Pacific (Taipei). The fully managed offering lets distributed workforces connect securely to AWS-hosted or on-premises resources without deploying dedicated VPN hardware. Separately, Cloudflare published an analysis of nine post-quantum signature algorithm candidates currently under NIST evaluation, concluding that organizations should standardize on ML-DSA — the only post-quantum signature scheme NIST has formally approved so far — rather than waiting for potentially superior algorithms that remain years from standardization.

Why it matters for your business

The AWS regional expansion means companies operating in Calgary, Mexico City, Auckland, or Taipei can now keep VPN termination geographically close to their users and workloads, reducing latency and simplifying compliance with data-residency requirements. The pay-as-you-go model also removes the capital expenditure and maintenance burden associated with physical VPN appliances, which is particularly relevant for lean infrastructure teams scaling across multiple markets. On the cryptography front, Cloudflare's assessment is a practical signal: waiting for theoretically better post-quantum algorithms introduces unnecessary exposure. ML-DSA is standardized, production-ready, and available today — teams modernizing TLS stacks or code-signing pipelines should treat its adoption as an near-term action item rather than a future roadmap consideration.

What to watch next

AWS has been steadily filling geographic gaps in its managed networking portfolio, so further Client VPN region launches — particularly in the Middle East and Africa — are plausible before year-end. On the post-quantum front, NIST is expected to advance its nine candidate algorithms through additional evaluation rounds, and Cloudflare's own timeline suggests ML-DSA should be treated as a transitional standard rather than a permanent endpoint. Enterprises building cryptographic agility into their systems now will be better positioned to swap in successor algorithms once they clear standardization.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp