Cloudflare Becomes a Post-Quantum Certificate Authority, Using Merkle Tree Architecture to Keep TLS Lean at Internet Scale
Cloudflare has announced plans to become a post-quantum Certificate Authority, targeting Q1 2027 to begin issuing production-ready quantum-safe TLS certificates. ARS TECHNICA
The move directly addresses the growing “harvest now, decrypt later” threat, where adversaries collect encrypted internet traffic today, intending to decrypt it once sufficiently powerful quantum computers exist.
The key technical challenge is size. Standard post-quantum X.509 certificates using algorithms like ML-DSA would expand TLS handshakes by roughly 40 times, creating serious performance implications at internet scale.
Cloudflare’s solution is Merkle Tree Certificates (MTCs), a new architecture that keeps TLS handshake sizes near current levels of around 40 kilobytes by embedding certificate transparency directly into issuance rather than attaching it separately.
Early trials with Chrome Beta 146 showed a 9% median speed improvement over classical certificate chains. Both hybrid and fully post-quantum certificates will be offered free. The initiative involves a root acquisition from CA GlobalSign and requires coordination with browser vendors, operating systems, and infrastructure providers.
Google piloted similar Merkle Tree solutions in February 2026, signalling industry-wide momentum toward quantum-resistant internet infrastructure. Read our previous Cybersecurity related news article here.

