
Cloudflare is gearing up to become one of the first major Internet infrastructure players to issue quantum-safe TLS certificates at scale, positioning itself as a new public certificate authority for the post-quantum web. The company plans to offer hybrid certificates that pair conventional X.509 TLS with a post-quantum counterpart called Merkle Tree Certificates, and to make them free for both paying and free customers. To hit the ground running, Cloudflare has agreed to acquire publicly trusted root key material from CA GlobalSign, giving its certificates instant recognition across existing browsers and legacy devices once the deal closes. Production issuance of Merkle Tree Certificates is currently targeted for early 2027, aligned with Chrome’s Quantum-resistant Root Store rollout.
Underneath the flashy “quantum-safe” label is a genuine looming problem: powerful quantum computers could eventually break today’s widely used public-key algorithms, letting attackers decrypt traffic they have been quietly recording for years. Cloudflare has already rolled out post-quantum key agreement support in TLS 1.3 using a hybrid X25519MLKEM768 scheme to blunt so-called harvest-now-decrypt-later attacks, and now it is moving to shore up the certificate and signature side of the handshake as well. The plan is to lean on ML-DSA, the post-quantum digital signature algorithm standardized by NIST, while using Merkle Tree Certificates to keep those bulky signatures from slowing web performance to a crawl.
Merkle Tree Certificates are the industry’s current favorite answer to the nasty size problem created by post-quantum signatures. Instead of signing each individual certificate and shipping a full chain with every TLS handshake, an MTC authority batches many certificates into an append-only Merkle tree and signs just the tree head. Browsers or other clients then verify a compact inclusion proof—essentially a short sequence of cryptographic hashes—against that signed tree head, proving a given certificate was legitimately issued without requiring the full, oversized post-quantum signature on every connection. Because a certificate is only valid if it appears as a leaf in a publicly auditable Merkle tree, transparency logging is baked directly into the issuance process, closing gaps that previously allowed mis-issued or rogue certificates to lurk in the shadows.
This approach represents a fundamental re-architecture of the WebPKI, shifting from optional Certificate Transparency logs to a world where being logged is the very definition of being issued. Cloudflare’s decision to bootstrap its new authority with an existing GlobalSign root—likely the long-lived GlobalSign Root R5 already embedded in major browsers—means quantum-safe certificates can reach old smartphones, forgotten smart TVs, and other devices that are no longer getting updates. That day-one reach is crucial, because replacing or reconfiguring every legacy box on the planet is a non-starter, yet the web cannot safely move to post-quantum crypto if large swaths of users simply see certificate errors.
Cloudflare is not alone in betting on Merkle Tree Certificates as the way forward. Let’s Encrypt has announced it is planning an MTC-based path to post-quantum WebPKI, with a staging environment slated for late 2026 and production support in 2027. Other major certificate authorities, including Sectigo and DigiCert, are running MTC pilots and playgrounds that test how to batch certificates, verify Merkle proofs, and integrate these new structures with existing browser trust stores. Google, for its part, has been documenting the design and performance trade-offs of MTCs and is preparing Chrome’s Quantum-resistant Root Store to accept these next-generation certificates.
For site operators already sitting behind Cloudflare, the promise is that moving to quantum-safe certs will be almost invisible: hybrid classic-plus-MTC certificates will be provisioned automatically and will not add noticeable latency to TLS handshakes with up-to-date clients. Cloudflare says these certificates will be free, lowering the barrier for small indie devs, fan sites, and niche communities that otherwise might have delayed adopting post-quantum protection. The hard work now shifts to browser vendors, operating system teams, and other certificate authorities, who will spend the next few years wiring Merkle Tree support, new root stores, and PQC libraries into the stack so that when the first truly dangerous quantum machines arrive, the web’s padlocks are already one step ahead.








