Cloudflare plans to become a public Certificate Authority, acquiring root key material from GlobalSign and applying to major browser programs to issue classical TLS and post-quantum Merkle Tree Certificates. The initiative aims to scale quantum-safe encryption for the internet and begin production MTC issuance by early 2027.
Cloudflare (NYSE: NET), a provider of connectivity clouds, has shared plans to set up an autonomous public Certificate Authority (CA) that features an open, automated, high-capacity issuance platform built to carry the Web Public Key Infrastructure (Web PKI) into the post-quantum era. The service is designed to issue both traditional digital certificates and next-generation post-quantum Merkle Tree Certificates (MTCs) to prevent widespread web outage risks and combat harvest now, decrypt later
adversary campaigns from the same system.
The announcement arrived during the company’s annual Birthday Week, establishing a high-scale trust provider intended to transition the Web Public Key Infrastructure into the post-quantum era according to the reporting.
Cloudflare plans to issue quantum-safe TLS certificates
Acquiring GlobalSign Root Material and Seeking Browser Program Trust

A root certificate tells browsers and devices whether to trust a CA. At the time of writing, Cloudflare does not issue publicly trusted certificates itself. To achieve immediate backward compatibility and ensure day-one device reach across legacy smartphones, operating systems, and unpatched embedded hardware, Cloudflare signed a definitive agreement to acquire established, publicly trusted Root CA key material from GlobalSign.
The method: Cloudflare intends to accelerate its launch by acquiring one of GlobalSign’s pre-existing root certificates that is already trusted by web browsers. This way, it can issue certificates directly “on day one,explains Cloudflare Product Manager Steve Goldsmith in a company blog post. The root certificate purchased from GlobalSign is likely
GlobalSign Root R5″, valid until January 2038. This allows Cloudflare enough time to embed its own root certificate within browsers, freeing itself entirely from third-party trust dependencies down the road. Concurrently, Cloudflare has submitted applications to have its proprietary root certificates integrated into the trust frameworks maintained by Chrome, Apple, Microsoft, and Mozilla. Classical certificate issuance is expected to begin after the browser root program process, with production MTC issuance scheduled for Q1 2027.
Solving Post-Quantum Signature Bloat With Merkle Tree Certificates

Cloudflare Plans Public Certificate Authority for Post-Quantum Security
Cloudflare plans post-quantum certificates via its new public CA. The company intends to issue both classic TLS certificates and post-quantum Merkle Tree Certificates (MTC). Merkle Tree Certificates supply a streamlined, verifiable approach to authentication as post-quantum signatures threaten to inflate TLS handshakes and certificate transparency logs. Cloudflare’s new certificate authority will support MTC issuance at scale.
In February, Google announced a solution: Merkle Trees. These hierarchical data structures use cryptographic hashes and mathematical functions to authenticate large volumes of data using only a tiny fraction of that information. The setup, evaluated by Google and Cloudflare through select pilot programs, reduces handshake data to roughly 40 kilobytes—matching current processing levels. The WebPKI currently depends on a multi-link chain of quantum-vulnerable signatures to establish a certificate’s authenticity. Because swapping those signatures out for quantum-resistant ones would demand prohibitive resources, the traditional chains are substituted with compact Merkle Tree proofs. To finish validating such a proof, a certificate authority needs only to sign a single “tree head” capable of representing millions of individual certificates.
Cloudflare is making strong progress on Merkle Tree Certificates (MTCs) after a successful experimental deployment with Chrome. By resolving performance roadblocks that would otherwise stem from a direct certificate replacement, the company’s action tackles a major hurdle in the cryptographic transition, which the industry aims to wrap up by 2029. Having secured widespread industry backing, MTCs have become the preferred path forward, allowing for transparency as a core property rather than an add-on. Having a CA that supports both classical certificate and MTC issuance allows us to default to the most secure authentication method available,
Cloudflare states, providing a painless and performant upgrade path for a large portion of the internet.

Automation Standards and the 2027 Production Schedule
Cloudflare indicated that its CA will produce standard certificates alongside a post-quantum variant known as Merkle Tree Certificates (MTCs), with production issuance of MTCs slated for the first quarter of 2027. Cloudflare notes that certificate issuance across the web relies heavily on a limited group of major CAs, meaning a single failure or security breach could have widespread consequences. It also expects quantum computers able to break today’s encryption within years. A new high-scale issuer is its answer to the first problem, and MTCs are its answer to the second.
Certificate Authorities sit at the centre of the web’s trust model. They verify website identities and allow browsers to establish encrypted connections. Cloudflare pointed out that this responsibility is concentrated among a small number of providers, leaving the wider internet vulnerable if any single issuer experiences an outage or security compromise.
Production issuance of Merkle Tree Certificates is scheduled to begin in the first quarter of 2027.