Tue, 6 Oct 2026

Cloudflare plans public CA for post-quantum web security

Cloudflare is preparing to become a public certificate authority, offering automated digital certificates that support existing encryption standards and next-generation post-quantum Merkle Tree Certificates.

The company said the planned service will give websites a route to post-quantum protection without requiring new tools or major infrastructure changes. The vendor intends to broaden resilience in the web’s certificate ecosystem while preparing for advances in quantum computing.

Certificate authorities issue the digital certificates websites use to prove their identity and establish encrypted connections. Cloudflare said reliance on a small number of dominant issuers creates systemic risk if one experiences a compromise, outage or operational failure.

“Twelve years ago, Cloudflare made encryption free and automatic for millions of websites,” said Matthew Prince, chief executive and co-founder of Cloudflare. “Today, we’re taking the next step by building an open, transparent and reliable Certificate Authority for the entire Internet.”

Cloudflare plans to acquire publicly trusted root certificate key material from GlobalSign, which it said would help certificates work on older smartphones, operating systems and other devices with outdated trust stores. The transaction is subject to customary closing conditions and is expected to close within two months, according to Cloudflare.

The company has also applied for inclusion in the root programmes operated by Chrome, Apple, Microsoft and Mozilla. These applications are part of the process required for broad browser and device recognition.

Cloudflare said its public certificate authority would support both traditional certificates and Merkle Tree Certificates (MTCs). MTCs combine certificate issuance and transparency logging in a structure based on append-only Merkle trees. A certificate can then be verified using an inclusion proof linked to a signed tree, rather than relying on large individual post-quantum signatures for every certificate.

Related:  Quantum computing encryption comes to the device

The approach is intended to reduce the performance and storage burden associated with post-quantum cryptography. Cloudflare said post-quantum signatures could significantly increase the size of certificates and transparency logs, making a more compact structure necessary for deployment at internet scale.

The company’s planned service will include a public health dashboard, reproducible software builds and wider operational and technical disclosures. Cloudflare also plans to use automated renewal signalling under RFC 9773 to trigger certificate replacement across affected websites during revocations or security updates.

Cloudflare said it would initially issue classical certificates after completing the relevant browser root-program processes. Production MTC issuance is scheduled to begin in the first quarter of 2027. The company’s service page is currently inviting organisations to join a waitlist for updates and potential early access.

The new CA is intended to support a gradual transition rather than an immediate replacement of conventional certificates. Website operators would be able to manage classical TLS certificates and MTCs through one system while browsers, operating systems and devices progressively adopt post-quantum capabilities.

Related Stories

MORE STORIES