Cloudflare Certificate Authority: Post-Quantum Web PKI Gets a New Trust Anchor

Cloudflare Certificate Authority: Post-Quantum Web PKI Gets a New Trust Anchor

Cloudflare has announced its intent to become a public Certificate Authority. A CA is the service that issues the digital certificates every secure website needs. The new CA will issue classic TLS certificates and post-quantum Merkle Tree Certificates from a single system. Production issuance of the post-quantum format is scheduled for the first quarter of 2027.

Cloudflare has also signed a definitive agreement to acquire publicly trusted Root CA key material from GlobalSign. The deal should close within two months.

The company frames the move against two systemic risks at once. A small set of dominant issuers concentrates trust on the web. That is fragile if any one of them fails or is compromised. And most certificate infrastructure predates the quantum computing problem entirely.

CEO Matthew Prince calls the web’s pre-quantum upgrade “one of the biggest coordination challenges in the history of the Internet.” The framing earns its drama. This is the company that made TLS free for millions of sites in 2014, doubling encrypted traffic overnight. Until now it never issued a certificate itself. That changes now.

Why post-quantum breaks certificates as they exist

The problem is size. ML-DSA-44, one of the smaller post-quantum signature schemes NIST standardized, produces signatures of roughly 2,420 bytes. ECDSA-P256, the elliptic-curve scheme most sites use today, produces 64 bytes. A typical Web PKI handshake carries five signatures and two public keys. Swap in ML-DSA and a single handshake blows past 10 kilobytes.

Cloudflare’s own research shows a meaningful share of TLS connections fail at that scale on real-world networks. The rest slow down. Naively re-issuing today’s certificates with post-quantum algorithms would measurably degrade the web. The certificate format itself has to change.

How Merkle Tree Certificates work

MTCs are a draft specification in the IETF’s PLANTS working group, co-authored by Cloudflare engineers. Instead of signing every certificate individually, the CA batches certificates into an append-only Merkle tree and signs the tree head. A browser verifies a certificate with a compact inclusion proof: a chain of cryptographic hashes, not a stack of signatures.

An optional optimization goes further. “Landmark” certificates carry no signatures at all, relying on log information the browser already holds. The design also rebuilds transparency into issuance. Instead of issuing a certificate and logging it separately, the CA certifies by logging. Certificate Transparency stops being an add-on and becomes a requirement of operation.

The evidence this works at scale is already public. From October 2025, Cloudflare ran an experiment with Chrome. It served MTCs to half of Chrome Beta 146 users on selected free-plan domains. It served billions of certificates successfully. At the median, landmark MTCs were 9% faster than classical signature chains.

The experiment wound down in August 2026, and Ars Technica reports the design keeps handshake data at roughly today’s levels.

The bought root and the trust question

The quieter half of the announcement is the GlobalSign deal. A root certificate is what tells browsers and devices to trust a CA. A brand-new root faces a long courtship. Root program inclusion takes months to years.

And old phones that no longer receive updates will never learn to trust it. GlobalSign’s root has been trusted since 2012 and reaches legacy hardware a fresh root never will.

Cloudflare’s engineering blog is blunt about the logic. The acquired root covers the devices of the past. New roots give standing under future policies that cap how old a trusted root may be. Buying ubiquity is pragmatic. It is also a reminder that trust in the Web PKI is transferable property.

Browsers still hold the gate. Cloudflare has applied to the Chrome, Apple, Microsoft and Mozilla root programs, and classical issuance begins only after acceptance. For MTCs, Chrome’s new Quantum-resistant Root Program applies its own bar. Its draft policy requires at least two cosignatures per certificate, one from an independent organization. Cloudflare says it will operate mirrors for other CAs and require an independent cosignature on its own certificates.

The field is moving anyway

Cloudflare is early, not alone. Let’s Encrypt committed to MTCs as its post-quantum path in June. The nonprofit targets a staging environment late this year and production in 2027. DigiCert is experimenting publicly. Chrome has named MTCs its preferred path for post-quantum web authentication.

The timelines converge from every direction. Google will migrate its own services by 2029, and Cloudflare’s release targets complete post-quantum readiness the same year. NIST’s draft guidance deprecates RSA-2048 and P-256 after 2030 and disallows them after 2035. The EU roadmap targets high-risk systems by 2030 and broad migration by 2035.

Nobody here is acting on a quantum computer that exists today. They act on harvest-now-decrypt-later and a decade-long coordination lead time.

What this means for site owners

Three practical takeaways. First, nothing changes immediately — the CA is intent plus pending applications, and the GlobalSign deal has not closed. Watch the root program processes, which happen in the open. Second, when MTC issuance starts in 2027, Cloudflare says standard issuance will be free, as with Universal SSL in 2014.

The rational planning move: inventory your ACME pipelines and non-Cloudflare certificates now. Migration support will vary by client. Third, treat post-quantum readiness as a 2027-2029 program, not a 2035 problem. The side announcements matter here. IPsec downgrade protection, traffic-visibility dashboards and cryptography discovery tooling are the audit instruments you will need.

Cloudflare Certificate Authority: Post-Quantum Web PKI Gets a New Trust Anchor

Editor’s Note

This article draws on Cloudflare‘s releases of 29-30 September 2026 and its engineering blogs. Further sources: the IETF PLANTS draft, Let’s Encrypt’s June 2026 roadmap, and reporting by Ars Technica and SiliconANGLE. The “quantum computers within years” estimate, the glass-box transparency commitments and the legacy-device compatibility claims are company statements. Note that the GlobalSign acquisition is announced but not closed, and root program inclusion is pending. The interpretation of the root purchase as time-buying is TechRecast’s own.