Sunday, October 4, 2026 Latest NASA, Russia and China Race to Deploy Nuclear Reactors on the Moon Our standards
Technology

Cloudflare Plans to Establish Public CA for Post-Quantum TLS Certificates

Cloudflare plans to become a public Certificate Authority, acquiring root key material from GlobalSign and applying to major browser programs to issue classical TLS and…

The HTTPS concept with highlighted glowing S. HyperText Transfer Protocol Secure. Increasing the security of encryption. The
The HTTPS concept with highlighted glowing S. HyperText Transfer Protocol Secure. Increasing the security of encryption. The

Cloudflare plans to become a public Certificate Authority, acquiring root key material from GlobalSign and applying to major browser programs to issue classical TLS and post-quantum Merkle Tree Certificates. The initiative aims to scale quantum-safe encryption for the internet and begin production MTC issuance by early 2027.

Cloudflare (NYSE: NET), a provider of connectivity clouds, has shared plans to set up an autonomous public Certificate Authority (CA) that features an open, automated, high-capacity issuance platform built to carry the Web Public Key Infrastructure (Web PKI) into the post-quantum era. The service is designed to issue both traditional digital certificates and next-generation post-quantum Merkle Tree Certificates (MTCs) to prevent widespread web outage risks and combat harvest now, decrypt later adversary campaigns from the same system.

The announcement arrived during the company’s annual Birthday Week, establishing a high-scale trust provider intended to transition the Web Public Key Infrastructure into the post-quantum era according to the reporting.

Cloudflare plans to issue quantum-safe TLS certificates

Acquiring GlobalSign Root Material and Seeking Browser Program Trust

Cloudflare Plans to Establish Public CA for Post-Quantum TLS Certificates
Photo: quantumcomputingreport.com

A root certificate tells browsers and devices whether to trust a CA. At the time of writing, Cloudflare does not issue publicly trusted certificates itself. To achieve immediate backward compatibility and ensure day-one device reach across legacy smartphones, operating systems, and unpatched embedded hardware, Cloudflare signed a definitive agreement to acquire established, publicly trusted Root CA key material from GlobalSign.

The method: Cloudflare intends to accelerate its launch by acquiring one of GlobalSign’s pre-existing root certificates that is already trusted by web browsers. This way, it can issue certificates directly “on day one,explains Cloudflare Product Manager Steve Goldsmith in a company blog post. The root certificate purchased from GlobalSign is likelyGlobalSign Root R5″, valid until January 2038. This allows Cloudflare enough time to embed its own root certificate within browsers, freeing itself entirely from third-party trust dependencies down the road. Concurrently, Cloudflare has submitted applications to have its proprietary root certificates integrated into the trust frameworks maintained by Chrome, Apple, Microsoft, and Mozilla. Classical certificate issuance is expected to begin after the browser root program process, with production MTC issuance scheduled for Q1 2027.

Solving Post-Quantum Signature Bloat With Merkle Tree Certificates

A glowing, neon tree with spiraling branches fills the frame against a dark, textured background in shades of blue and purple
Photo: Quantum Zeitgeist

Cloudflare Plans Public Certificate Authority for Post-Quantum Security

Cloudflare plans post-quantum certificates via its new public CA. The company intends to issue both classic TLS certificates and post-quantum Merkle Tree Certificates (MTC). Merkle Tree Certificates supply a streamlined, verifiable approach to authentication as post-quantum signatures threaten to inflate TLS handshakes and certificate transparency logs. Cloudflare’s new certificate authority will support MTC issuance at scale.

In February, Google announced a solution: Merkle Trees. These hierarchical data structures use cryptographic hashes and mathematical functions to authenticate large volumes of data using only a tiny fraction of that information. The setup, evaluated by Google and Cloudflare through select pilot programs, reduces handshake data to roughly 40 kilobytes—matching current processing levels. The WebPKI currently depends on a multi-link chain of quantum-vulnerable signatures to establish a certificate’s authenticity. Because swapping those signatures out for quantum-resistant ones would demand prohibitive resources, the traditional chains are substituted with compact Merkle Tree proofs. To finish validating such a proof, a certificate authority needs only to sign a single “tree head” capable of representing millions of individual certificates.

Cloudflare is making strong progress on Merkle Tree Certificates (MTCs) after a successful experimental deployment with Chrome. By resolving performance roadblocks that would otherwise stem from a direct certificate replacement, the company’s action tackles a major hurdle in the cryptographic transition, which the industry aims to wrap up by 2029. Having secured widespread industry backing, MTCs have become the preferred path forward, allowing for transparency as a core property rather than an add-on. Having a CA that supports both classical certificate and MTC issuance allows us to default to the most secure authentication method available, Cloudflare states, providing a painless and performant upgrade path for a large portion of the internet.

Cloudflare Plans to Establish Public CA for Post-Quantum TLS Certificates
Photo: heise.de

Automation Standards and the 2027 Production Schedule

Cloudflare indicated that its CA will produce standard certificates alongside a post-quantum variant known as Merkle Tree Certificates (MTCs), with production issuance of MTCs slated for the first quarter of 2027. Cloudflare notes that certificate issuance across the web relies heavily on a limited group of major CAs, meaning a single failure or security breach could have widespread consequences. It also expects quantum computers able to break today’s encryption within years. A new high-scale issuer is its answer to the first problem, and MTCs are its answer to the second.

Certificate Authorities sit at the centre of the web’s trust model. They verify website identities and allow browsers to establish encrypted connections. Cloudflare pointed out that this responsibility is concentrated among a small number of providers, leaving the wider internet vulnerable if any single issuer experiences an outage or security compromise.

Production issuance of Merkle Tree Certificates is scheduled to begin in the first quarter of 2027.

Accuracy matters. See something that needs attention? Read our corrections policy or contact the newsroom.

Technology Editor

Maya Serrano

Maya Serrano is the editorial identity for TellingPointy's Technology desk, covering artificial intelligence, platforms, software, hardware, cybersecurity, and digital policy. Serrano's work translates complex systems without sanding away the important details. Her desk asks who controls a technology, what data and incentives power it, where the real limits sit, and how a product or policy changes the balance among users, companies, governments, and the wider public.