VPN protocols and post-quantum encryption
A protocol is the set of rules your VPN app uses to build its encrypted tunnel. You rarely need to choose one, but it helps to know what the names mean, and which VPNs are ready for quantum computers.
Last updated 8 Oct 2026
The short version
- Leave your VPN on its automatic setting. It picks the fastest protocol that works on your network.
- Switch protocol when the VPN won't connect, usually to one designed to look like ordinary web traffic.
- Post-quantum encryption protects what you send today from being decrypted by a quantum computer later. Some VPNs turn it on for you.
The standard protocols
- WireGuard is the modern default: fast, quick to reconnect, and with far less code than older protocols, which makes it easier to check for flaws. NordVPN's NordLynx is WireGuard with NordVPN's own system for assigning addresses. Mullvad now offers nothing else, having removed OpenVPN in January 2026 (Mullvad).
- OpenVPN is older and slower but very widely supported, which is why it's still the choice for routers. Proton VPN now offers it only in its Linux app (Proton VPN).
- IKEv2 copes well with a phone switching between Wi-Fi and mobile data, and is built into Apple devices and Windows.
- L2TP and PPTP are outdated, and none of the VPNs we compare lists them.
The providers' own protocols
Several providers have built their own, usually for speed or to get past networks that block VPNs:
- Lightway (ExpressVPN) is the default in its apps (ExpressVPN).
- NordWhisper (NordVPN) disguises VPN traffic as ordinary web traffic, for restrictive networks (NordVPN).
- Stealth (Proton VPN) does the same, and it's on the free plan too.
- Dausos (Surfshark) is new, and for now only in the macOS app from the App Store (Surfshark).
Speed claims for these come from the providers themselves; we haven't tested them. If you're travelling somewhere that blocks VPNs, the disguising ones matter more than speed: see our travel guide.
| VPN | Standard protocols | Its own protocol |
|---|---|---|
| CyberGhost | WireGuard, OpenVPN and IKEv2WireGuard and IKEv2 in the Windows app, with OpenVPN by manual setup; OpenVPN and WireGuard in the Android app. | None |
| ExpressVPN | WireGuard, OpenVPN and IKEv2WireGuard in the Windows, iOS and Android apps; OpenVPN in the apps; IKEv2 in the iOS, Mac, Windows and router apps. | LightwayLightway (UDP and TCP) is the default under the Automatic setting; the page says to try it first. |
| Mullvad | WireGuardWireGuard only: Mullvad removed OpenVPN from its apps and servers on 15 January 2026. | NoneNone, though Mullvad has its own ways to disguise WireGuard traffic (UDP-over-TCP, Shadowsocks, QUIC and LWO). |
| NordVPN | WireGuard, OpenVPN and IKEv2The apps offer NordLynx (WireGuard-based, the default), OpenVPN UDP/TCP and IKEv2/IPsec (Windows, macOS, iOS, Android, Linux). Manual WireGuard, OpenVPN and IKEv2 configs are also documented. No L2TP or PPTP. | NordWhisperA web-traffic-style protocol for restrictive networks, in the Windows, macOS, iOS, Android, Android TV and Linux apps. It is chosen in settings, and doesn't work with Dedicated IP, Meshnet or Onion Over VPN. |
| Private Internet Access | WireGuard, OpenVPN and IKEv2WireGuard and OpenVPN (the default) in the apps; IPSec (IKEv2) on iOS. | NoneNone. The apps also offer Shadowsocks and SOCKS5 proxies, which are standard tools. |
| Proton VPN | WireGuard and OpenVPNWireGuard in every app; OpenVPN only in the Linux app and by manual setup. Smart Protocol picks one automatically. IKEv2 remains on macOS until February 2027 but is being retired. | StealthStealth is obfuscated TLS tunnelling over TCP, on Windows, macOS, Android, iOS and Android TV, and on Linux only with the Proton Protocols beta turned on. It is included on the free plan. |
| Surfshark | WireGuard, OpenVPN and IKEv2OpenVPN in the Windows, macOS, iOS, Android and Linux apps; WireGuard in the Windows, macOS, iOS and Android apps, and by manual setup on Linux. IKEv2 by manual setup. | DausosSurfshark says Dausos is currently available only in the macOS App Store version of its app. |
Post-quantum encryption
Today's VPNs agree on an encryption key using maths a large enough quantum computer could one day break. Nobody can do that yet, but someone could record your encrypted traffic now and decrypt it later: "harvest now, decrypt later". Post-quantum key exchange uses newer methods, such as the US standards body NIST's ML-KEM, that quantum computers aren't expected to break.
For most people this is a long-term concern rather than an urgent one. It's worth having if what you send needs to stay private for years. Where a VPN has it, there's no reason not to turn it on.
- On by default: ExpressVPN's Lightway since October 2023 (ExpressVPN), Mullvad in all its apps (Mullvad) and Surfshark with WireGuard in its apps (Surfshark).
- A setting to turn on: NordVPN, with NordLynx only. It switches off on obfuscated servers, with a dedicated IP and with OpenVPN (NordVPN).
| VPN | Post-quantum encryption |
|---|---|
| CyberGhost | Not confirmed |
| ExpressVPN | Yes, on by defaultOn by default with Lightway (the Automatic setting) since October 2023, in every app. ExpressVPN says its WireGuard also has post-quantum protection. |
| Mullvad | Yes, on by defaultMullvad says quantum resistance is on by default in all its apps, on every platform. |
| NordVPN | Yes, if you turn it onA setting that works only with NordLynx. The help article lists Linux, Windows, Android, iOS, tvOS and Android TV (and gives macOS steps). It is off with OpenVPN, obfuscated servers, Dedicated IP and Meshnet. |
| Private Internet Access | NoPIA's encryption page describes WireGuard and OpenVPN encryption with no post-quantum option. |
| Proton VPN | NoProton describes post-quantum encryption as planned for its apps, not yet available. |
| Surfshark | Yes, on by defaultOn automatically when you use WireGuard in the apps; not with manual setups. |