CLOUDFLARE has announced plans to issue quantum-proof TLS certificates as part of a wide‑ranging overhaul of the web’s public key infrastructure (WebPKI). The move would see Cloudflare operate a post‑quantum variant of certificates known as Merkle Tree Certificates, designed to resist attacks from quantum computers.
The company says the approach will apply a hybrid model that supports both traditional TLS certificates and their post‑quantum counterparts, and that issuing these certificates would be free for both paying and non‑paying users. To support rapid adoption, Cloudflare intends to acquire an already trusted certificate root from GlobalSign.
The technical concept hinges on replacing the current chain of quantum‑vulnerable signatures with Merkle Tree proofs, which can dramatically reduce handshake data and enable scalable issuance. In practice, a certificate authority would sign only a single “tree head” representing potentially millions of certificates, while transparency requirements would be satisfied via publicly auditable logs that are embedded in the issuance process.
Cloudflare notes that the system would integrate with existing mechanisms such as ACME and would include out‑of‑band signature delivery as a fallback if a server cannot receive a landmark update. They emphasise that the system will take years to implement, given the scope across browsers, operating systems, and certificate authorities. Cloudflare expects to begin issuing certificates in the first quarter of 2027, subject to regulatory and ecosystem readiness.