
Cloudflare Certificate Authority and Post-Quantum TLS Certs
Cloudflare plans a public certificate authority with a GlobalSign root and post-quantum Merkle Tree Certificates targeted for Q1 2027. Here's how.
The Cloudflare certificate authority announced on September 29, 2026 is a notable step toward post-quantum web security. Cloudflare says it will become a publicly trusted certificate authority (CA), issuing the TLS certificates that let browsers verify websites, and that it plans to begin production issuance of Merkle Tree Certificates, a design built for the post-quantum era, in the first quarter of 2027.
- Cloudflare has signed a definitive agreement to acquire publicly trusted root CA key material from GlobalSign; the deal is expected to close within two months.
- It has applied to the Chrome, Apple, Microsoft and Mozilla root programs.
- Classic certificates will be issued after browser root program acceptance.
- Production Merkle Tree Certificate issuance is targeted for Q1 2027.
What is a certificate authority, and why does Cloudflare want to be one?
Every padlock in your browser rests on a chain of trust. A certificate authority vouches that a website really owns its domain, and browsers ship lists of trusted root certificates to check those vouchers. Becoming a new public CA from scratch takes years, which is why Cloudflare is acquiring existing root key material from GlobalSign, a long-established CA. Cloudflare's blog notes that this root has been trusted since 2012, which helps certificates work on older devices.
CEO Matthew Prince framed it as the next chapter of a long effort: "Twelve years ago, Cloudflare made encryption free and automatic for millions of websites. Today, we're taking the next step by building an open, transparent and reliable Certificate Authority for the entire Internet."
What are Merkle Tree Certificates?
Post-quantum cryptography protects against future quantum computers, but post-quantum signatures are much larger than today's. Sending several of them in every TLS handshake would slow connections down. Merkle Tree Certificates (MTCs) address that. Instead of each connection carrying a full chain of big signatures, an MTC proves that a certificate is recorded in a trusted, publicly logged registry using a compact proof.
Cloudflare co-authored the IETF draft that defines MTCs, and its own engineering post describes building a post-quantum CA around them. It is a clean example of security engineering that plans ahead rather than reacting later, the same thinking behind Google Cloud's 2029 post-quantum roadmap.
How will the Cloudflare CA be run?
Cloudflare's blog outlines an operating model built on automation and openness:
- ACME-first issuance and renewal, the automated protocol popularized by free certificate services
- ACME Renewal Information (RFC 9773), so certificates can be replaced quickly without downtime if an incident requires it
- A live public health dashboard, which Cloudflare describes as glass-box transparency
Pricing was not stated in the announcement. Cloudflare has also been applying AI to its own migration: a companion post describes an internal AI tool that inventories where cryptography is used across its codebases as it works toward post-quantum readiness.
When can websites get post-quantum certificates?
Not immediately. Cloudflare says classic certificate issuance begins after the browser root programs accept its application, and it targets production MTC issuance for Q1 2027. The browser programs have their own public review processes, so those timelines are plans rather than guarantees.
Why this matters for web security
Cloudflare already has deep post-quantum experience, from IPsec downgrade protection for post-quantum tunnels onward. A new, automation-first CA with transparent operations adds diversity to the certificate ecosystem, and a practical post-quantum certificate format gives the whole web a path to quantum-safe TLS without a performance penalty. Follow more defensive security news in our AI security section.
Sources: Cloudflare Blog: Building a certificate authority for the whole Internet — September 29, 2026; Cloudflare Blog: Building a post-quantum certificate authority with Merkle Tree Certificates — September 29, 2026; The Quantum Insider: Cloudflare public certificate authority for post-quantum security — September 29, 2026.
More Ai Security Stories

Thales Sentinel Envelope Plus: Shielding Code From AI Agents
Thales Sentinel Envelope Plus hardens compiled apps against AI reverse engineering. In tests, an AI agent found 0 of 10 bugs after using 970x more tokens.

Android 17 Advanced Protection: 6 New Anti-Spyware Defenses
Android 17 Advanced Protection adds 6 new defenses, including Intrusion Logging with 12 months of encrypted logs and USB lockdown. Here's how each works.

Legit Security Agent Auto-Fixes Vulnerable Dependencies
Legit Security's agentic remediation now fixes vulnerable open-source dependencies, re-scans before and after, and opens a pull request for review.
