News

Cloudflare Launches Public Certificate Authority to Secure the Web Against Quantum Threats

Connectivity cloud company Cloudflare (NYSE: NET) has announced its intention to become a public Certificate Authority (CA), introducing an open, automated, and high-scale issuance service designed to transition the Web Public Key Infrastructure (Web PKI) into the post-quantum era. Announced during the company’s annual Birthday Week, the initiative establishes an independent, globally trusted certificate provider capable of issuing both classical TLS certificates and next-generation Merkle Tree Certificates (MTCs) to prevent widespread web outage risks and combat “harvest now, decrypt later” adversary campaigns.

To ensure day-one device reach across legacy smartphones, operating systems, and unpatched embedded hardware, Cloudflare has signed a definitive agreement to acquire established, publicly trusted Root CA key material from GlobalSign (trusted across browsers since 2012). Concurrently, Cloudflare has formally submitted applications for inclusion in the official root programs of Google Chrome, Apple, Microsoft, and Mozilla. By combining GlobalSign’s legacy root coverage with new post-quantum root store applications, Cloudflare establishes immediate backward compatibility while building standing under emerging browser policies, such as Chrome’s recently announced Quantum-Resistant Root Program.

The core structural innovation of Cloudflare’s public CA lies in solving the Post-Quantum Signature Scaling Problem. Standard post-quantum signature algorithms (such as ML-DSA or SLH-DSA) produce signatures up to 40× larger than classical RSA or ECDSA keys, adding massive network overhead that threatens to degrade TLS handshake speeds and flood public Certificate Transparency (CT) logs. Cloudflare addresses this via Merkle Tree Certificates (MTCs)—a standards-based specification co-authored by Cloudflare within the IETF PLANTS working group.

[ Cloudflare Post-Quantum Public CA Architecture & System Capabilities ]
Infrastructure LayerCore Protocol & Technical SpecificationsOperational Impact & Web PKI Advantages
• Post-Quantum Issuance• Merkle Tree Certificates (MTCs)
• Batching certificates into append-only Merkle trees
• Compact inclusion proofs (<1 kB) replacing full PQ signatures
• Eliminates 40× post-quantum payload bloat
• Landmark-relative certificates deliver a 9% TLS handshake speedup over classical chains
• Automated Lifecycle• ACME First (fork of Boulder framework)
• Mandatory RFC 9773 (ARI) renewal signaling
• Zero-downtime background certificate rotations
• Enables instant mass revocations during security incidents without subscriber site outages
• Transparency & Trust• “Issue by Logging” Architecture
• Independent Mirroring Cosigners (Rust-based Azul log)
• Reproducible software builds & HSM attestations
• Merges certificate issuance with CT logging as a first-party requirement
• Live public dashboard replaces static, point-in-time point audits
• Root Material & Reach• Acquired GlobalSign Root CA key material
• Pending Chrome, Apple, Microsoft, & Mozilla root inclusions
• Ubiquitous trust across legacy clients (since 2012) and future quantum-resistant root stores

MTCs redesign the PKI paradigm from “log what you issue” to “issue by logging.” Instead of signing every certificate individually with heavy post-quantum keys, the CA batches certificate requests into an append-only Merkle tree, signing only the tree head checkpoint. During a TLS handshake, the web server presents a lightweight inclusion proof (a short sequence of cryptographic hashes) linking its public key to a trusted landmark subtree distributed out-of-band to browsers. In production trials conducted with Chrome Beta 146 across Cloudflare domains, landmark-relative MTCs demonstrated a 9% net performance speedup at the median over classical signature chains while maintaining cryptographic auditability.

Operating as its own “Customer Zero,” Cloudflare will route its global edge network—terminating TLS for over 20% of global web traffic—through the new CA stack. Classical certificate issuance will begin upon completion of browser root approval processes, while production Merkle Tree Certificate issuance is scheduled for Q1 2027. The acquisition of GlobalSign’s Root CA key material is expected to close within two months, establishing an independent, post-quantum safety net for the global Internet.

Review the primary release via Cloudflare Press Room here, inspect technical engineering details on the Cloudflare CA Architecture Blog here, examine Merkle Tree Certificate specifications on Cloudflare MTC Deep-Dive here, and explore enterprise migration pathways via Cloudflare Post-Quantum Cryptography Portal here.

In GQI Portal

The players behind the news

The team that writes QCR tracks every company, deal and technology in the GQI Factory, GQI's verified database of the quantum industry. Next up: every story linked to its players, coming to QCR's paid plans.

Leave a comment

All fields are required. Your email address will not be published.