Cloudflare Lays Out Plans to Rebuild the Web's Certificate System Before Quantum Computers Can Break Today's Cryptography

For most people, the cryptography protecting a website is invisible. A browser connects, a few certificates pass back and forth, and a padlock appears. The machinery underneath is one of those parts of the internet that works precisely because almost nobody has to think about it. 

But that machinery was built around assumptions about computers that may not hold forever.

The interesting problem is not simply that quantum computers could eventually break some of today's public-key cryptography. The harder problem is replacing that cryptography without making the web dramatically slower, larger, or more complicated in the process. 

A conventional attempt at putting post-quantum signatures into today's certificate system could make the cryptographic material exchanged during a TLS handshake many times larger. 

Cloudflare says some post-quantum signatures are roughly 20 times larger than the classical equivalents they would replace.

That makes Cloudflare's announcement more interesting than simply another promise to make TLS "quantum safe." 

The company says it is building a public Certificate Authority that will issue both conventional certificates and a newer format called Merkle Tree Certificates, or MTCs. 

Production issuance is planned for the first quarter of 2027, subject to the surrounding browser and Web PKI work.

The distinction matters because certificates are not just cryptographic keys attached to websites. 

They are part of a much larger trust system involving certificate authorities, browsers, operating systems, transparency logs and root programs. Changing one component without accounting for the others can create a system that is theoretically secure but impractical to deploy.

Today''s Web PKI depends heavily on digital signatures. 

A browser receiving a certificate needs to establish that it was legitimately issued and that the chain of trust eventually leads to a certificate authority it recognizes. Certificate Transparency adds another layer by requiring certificates to be publicly logged, allowing the ecosystem to detect certificates that should not exist.

Quantum computing complicates both sides of that arrangement. 

Algorithms such as Shor's algorithm could eventually undermine widely used public-key systems, potentially allowing an attacker with a sufficiently capable quantum computer to forge signatures. 

That creates a future authentication problem distinct from the "harvest now, decrypt later" threat that has received much of the attention around post-quantum encryption. 

Cloudflare has already been deploying post-quantum key agreement to address the latter, while its current roadmap puts post-quantum authentication on a longer timetable.

The obvious response would be to replace today's signatures with larger quantum-resistant ones. Cryptographically, that makes sense. Operationally, it creates a problem. 

Post-quantum algorithms such as ML-DSA require substantially larger public keys and signatures than algorithms such as ECDSA. A TLS connection happens at enormous scale, and certificates can be transmitted repeatedly across billions of connections. Adding tens of kilobytes to those exchanges is not a minor change, particularly for mobile networks, constrained devices and intermediary infrastructure.

Merkle Tree Certificates approach the problem differently. 

Instead of making every certificate carry a long sequence of large signatures, the system organizes certificates into a cryptographically verifiable Merkle tree. The certificate authority signs a compact representation of the tree, while an individual certificate can be accompanied by a relatively small proof showing where it belongs. 

The browser can then verify that proof rather than receiving the entire collection of signatures that would otherwise be necessary.

Image
Cloudflare
Illustrating how an ACME (Automatic Certificate Management Environment) protocol leverages ACME Renewal Information (ARI) to manage fleet-wide digital certificate rotations without downtime

There is another subtle change buried in the design. 

Certificate Transparency has historically been something that happens alongside certificate issuance. MTCs incorporate public logging into the certificate architecture itself. The certificate is effectively tied to its presence in the public log, making transparency part of the mechanism used to establish trust rather than an additional process bolted onto it.

Google has already been testing this direction in Chrome. 

In February, the Chrome team announced plans for a separate Quantum-resistant Root Store and said it did not intend to simply add conventional X.509 certificates containing post-quantum cryptography to the existing Chrome Root Store. 

Instead, its planned system is built around MTCs, with an initial public bootstrapping phase targeted for the first quarter of 2027 and broader onboarding of certificate authorities planned later in 2027.

Cloudflare's role is therefore less about inventing an isolated replacement for TLS certificates and more about becoming part of a broader redesign of the Web PKI. 

The current MTC specification is being developed through the IETF's PLANTS working group, with contributors from Google, Apple, Cloudflare and others. 

The latest Internet-Draft, published in September 2026, describes MTCs as a new form of X.509 certificate that integrates public logging and is specifically intended to reduce the cost of large post-quantum signatures. It remains a standards-track work in progress rather than a finished Internet standard.

That last point is important because the dates attached to the project are targets, not guarantees. 

Image
Cloudflare
The current trust ecosystem

Cloudflare says its new CA will first need to complete the relevant browser root-program processes, while production MTC issuance is targeted for early 2027. 

Chrome has its own staged deployment plan, and the underlying IETF specification is still evolving. The technology being described is real and already being tested, but the final shape of the ecosystem has not been frozen.

Cloudflare is also trying to solve a less glamorous problem: what happens when something goes wrong. 

A public certificate authority is a piece of critical internet infrastructure, and certificates sometimes have to be revoked or replaced quickly. 

Cloudflare says its proposed CA will use automated renewal signaling to accelerate certificate replacement, while publishing reproducible builds, information about its key-protection hardware and a public operational dashboard. 

Those plans are aimed at making CA operations more observable than the traditional model of periodic audits alone.

There is a practical reason Cloudflare wants an established trust anchor as well. 

The company has announced an agreement to acquire publicly trusted root CA key material from GlobalSign, subject to closing conditions. It has also applied to the root programs operated by Chrome, Apple, Microsoft and Mozilla. 

The goal is to avoid creating a new certificate authority that works only on freshly updated software while leaving older browsers, phones and other devices unable to recognize its certificates.

Image
Cloudflare
The architecture updated for Merkle Tree Certificates (MTCs)

The approach is deliberately transitional. 

Websites will not suddenly wake up one morning with their conventional certificates invalidated. Cloudflare expects classical certificates and MTCs to coexist for years, with the same CA infrastructure handling both. 

That reflects the reality of the Web PKI, where browsers, operating systems, servers and network equipment are replaced on very different schedules.

It also explains why the word "certificate" can be misleading when describing the coming change. 

The difficult part is not generating a new certificate file. 

It is coordinating a new method of proving that the certificate is legitimate, publicly logged and still trusted, while keeping the amount of information exchanged during a normal web connection within the limits that today's internet can tolerate.

The quantum computer that could make these changes urgent does not need to exist yet for the engineering work to matter. 

Image
Cloudflare
Delivering post-quantumsignatures efficiently

Internet infrastructure moves slowly, and certificate authorities, browsers and operating systems have to agree on standards before millions of websites can depend on them. Waiting until a cryptographically capable quantum computer is operational would leave little room for an orderly migration.

For now, MTCs are best understood as an attempt to change the architecture around certificates before the underlying cryptographic assumptions become obsolete. 

Cloudflare is preparing a CA to issue them, Google is preparing a browser trust system for them, Apple and other companies are participating in the standards work, and Let's Encrypt has separately said it plans to support MTCs as well.

What eventually reaches a browser may still look remarkably ordinary. A connection will be made, the certificate will be checked, and the page will load. 

The difference will be hidden deeper down, in the mathematics and infrastructure used to establish that the server on the other end really is the server it claims to be. 

That is probably the least visible kind of internet upgrade, and in this case, that is the point.

Published