Cloudflare to become a CA, post-quantum certs in 2027

Cloudflare to become a CA, post-quantum certs in 2027

Cloudflare is setting itself up as a public certificate authority (CA) and plans to issue post-quantum website certificates, known as Merkle Tree Certificates (MTCs), in production in the first quarter of 2027.

A CA issues the digital certificates that websites use to encrypt traffic and prove their identity to visitors. Cloudflare's new CA will offer both conventional certificates and MTCs.

The company gave two reasons for the move. First, it says most certificate issuance on the web depends on a small group of dominant CAs, so a failure or compromise at one of them could have wide effects. Second, it expects quantum computers capable of breaking today's encryption to arrive within years. A new high-scale issuer addresses the first problem. MTCs address the second.

Getting into the trust stores

A CA is only useful if browsers and devices trust it. That trust comes from root certificates, which tell software which CAs to accept.

To cover older phones and other devices that no longer receive software updates, Cloudflare has agreed to acquire publicly trusted root key material from GlobalSign. The company expects the deal to close within two months, subject to customary closing conditions.

Cloudflare has also applied to the root programs run by Chrome, Apple, Microsoft and Mozilla. All four applications are still pending. Classical certificate issuance will begin only after that acceptance process is complete.

"Twelve years ago, Cloudflare made encryption free and automatic for millions of websites. Today, we're taking the next step by building an open, transparent and reliable Certificate Authority for the entire Internet," said Matthew Prince, CEO and co-founder of Cloudflare.

"Upgrading the web's security before quantum computers can break it is one of the biggest coordination challenges in the history of the Internet," he added. "By balancing support for older devices with brand-new, post-quantum tech, we're providing a permanent safety net-so the Internet stays fast, reliable, and secure for all devices, no matter what comes next."

How Merkle Tree Certificates work

The main obstacle to post-quantum certificates is size. Post-quantum signatures are heavy, and sending them with every connection would add weight to each TLS handshake.

MTCs take a different approach. Instead of carrying full signatures, they let a browser confirm that a certificate appears in a trusted registry using lightweight proofs. This keeps the heavy signatures off the wire during normal connections.

Cloudflare co-authored the MTC specification as a draft at the IETF (Internet Engineering Task Force), the body that develops many of the internet's core standards. The company first ran an experiment with Chrome and says its production plans build on that work.

Transparency and automated renewal

Cloudflare says it will publish a live public health dashboard for the CA and provide reproducible code builds, so outsiders can check that the software running the CA matches the published code.

The company also plans to use automated renewal signaling, defined in RFC 9773. This lets it replace certificates in the background across millions of sites when routine revocations or security updates require it.

For site operators, Cloudflare says classic certificates and MTCs will be managed in one system. There will be no forced cutover from one type to the other.

Our Take

Cloudflare's announcement touches two long-standing concerns in web security at once: concentration in the CA market and the looming quantum threat to current cryptography. Pairing them in one launch suggests the company sees post-quantum migration as a chance to change how certificate issuance is structured, not just to swap algorithms.

For readers who run websites, the practical detail that matters most is the promise of no forced cutover. Being able to run classic and MTC certificates side by side should lower the risk of breaking access for older clients during the transition. Automated renewal signaling could also help during mass revocation events, when many certificates must be replaced quickly.

The key dependency is acceptance. None of the four root programs has approved Cloudflare yet, and the GlobalSign deal has not closed. It is worth watching how quickly Chrome, Apple, Microsoft and Mozilla move, and whether browsers beyond Chrome commit to supporting MTCs. The TLS stack itself also keeps producing problems, as the recent high-severity OpenSSL and WolfSSL flaws showed, so new certificate formats will need careful implementation in libraries as well as in browsers.