Cloudflare Plans Public CA for Post-Quantum Certificates
Cloudflare announced its intention to become a public Certificate Authority (CA) that will issue both traditional TLS certificates and post-quantum Merkle Tree Certificates. This plan, revealed on September 29, 2026, positions one of the internet’s largest infrastructure providers to issue publicly trusted certificates designed for an era when quantum computers may compromise current encryption.
Cloudflare’s Stated Plans
Cloudflare frames this initiative as a progression from its Universal SSL offering, launched in 2014, which provided free TLS certificates to millions of websites. The company plans to acquire publicly trusted Root CA key material from GlobalSign to ensure recognition of Cloudflare-issued certificates by older phones and devices that no longer receive software updates. Additionally, Cloudflare has applied to the Chrome, Apple, Microsoft, and Mozilla root programs through their respective public processes.
Key details provided by Cloudflare include:
- The issuance of two certificate types: classical TLS certificates and post-quantum Merkle Tree Certificates (MTCs).
- MTCs are based on an IETF draft specification co-authored by Cloudflare, designed to verify certificate logging in a trusted registry using lightweight proofs.
- Classical certificate issuance should begin after acceptance into browser root programs.
- Production MTC issuance will begin in the first quarter of 2027.
- The acquisition of GlobalSign key material should close within approximately two months, subject to closing conditions.
The MTC design aims to circumvent the performance overhead of incorporating large Post-Quantum Cryptography (PQC) signatures into the handshake by avoiding the transmission of heavy post-quantum signatures with every connection. Cloudflare already incorporates post-quantum key exchange within its own TLS stack.
Impact of a Public CA on the PQC Discussion
Public Certificate Authorities operate within browser and operating system trust stores. This necessitates adherence to WebTrust or similar audits, publication of CP/CPS documents, robust revocation services, and acceptance into each vendor’s root program. Cloudflare’s stated intent alone does not confer these; root inclusion and audits are the prerequisites.
The timing of this announcement aligns with broader pressures for cryptographic migration. Organizations increasingly worry about “harvest-now-decrypt-later” attacks, where malicious actors collect encrypted data today with the intent of decrypting it once capable quantum machines become available. This risk is frequently cited by companies like Arqit when advocating for transitioning away from classical public-key schemes.
It’s important for readers to distinguish that PQC certificate issuance is distinct from FIPS 140-3 module validation and the underlying NIST standards. Public research investment in this sector continues to grow, encompassing national initiatives such as the Virginia Quantum Hub and open-source tooling. If Cloudflare successfully gains acceptance into root programs, post-quantum certificates will transition from experimental concepts into trusted components of browser certificate chains. Until then, it remains a plan with a defined timeline.