blog.cloudflare.com 29 Sept 2026, 13:00 UTC

Cloudflare Unveils Merkle Certificates for a Quantum-Safe Web

Cloudflare Unveils Merkle Certificates for a Quantum-Safe Web
CyberSIXT Evidence Panel Source marked as original reporting

CLOUDFLARE announces that its new certificate authority will issue Merkle Tree Certificates (MTCs) as part of a redesigned post-quantum Web PKI. The aim is to scale post-quantum signatures without sacrificing transparency. MTCs batch certificates into a Merkle tree and sign the tree root, allowing clients to verify a certificate via a compact inclusion proof rather than validating each certificate individually. The approach couples issuance with logging, making transparency a core requirement.

Cloudflare plans to support both classical certificates and MTCs, enabling a secure, upgradeable path to post-quantum authentication and paving the way for Chrome’s Quantum-resistant Root Store trials.

The article outlines how the MTC ecosystem differs from today’s model. CAs continue to validate domain control and bind it to a public key, but logs are maintained as a Merkle-tree-backed, cosigned record, with mirrors (cosigners) storing issuance logs to ensure consistency and availability. There are two forms of MTCs: standalone certificates with a cosigned tree head and inclusion proof, or landmark-relative certificates that rely on out-of-band landmark updates.

Cloudflare’s experiment with Chrome demonstrated that landmark MTCs can reduce handshake data significantly while preserving security, with a median 9% improvement over traditional signatures in their test. The company notes the need for broad ecosystem participation, including monitors, mirrors, and browser vendors, and plans to apply to Chrome’s root store process before widely trusting MTCs. The goal remains to provide a scalable, transparent, and secure PQ upgrade path for the Internet.

View full article

Article by CyberSIXT