Industry NewsAI Business & Ecosystem
Cloudflare announces public Certificate Authority to prepare the web for post-quantum security

Article content
Cloudflare has announced its intention to become a public Certificate Authority (CA), expanding its role in the infrastructure that enables websites to establish trusted and encrypted connections.
The proposed CA will support both traditional encryption and post-quantum Merkle Tree Certificates (MTCs), giving website operators a path toward post-quantum authentication without requiring immediate infrastructure changes.
The move comes as the web's certificate infrastructure faces two parallel challenges: reliance on a relatively small number of dominant certificate issuers and the need to prepare for cryptographic threats associated with future quantum computing.
Building a new layer of web trust
Certificate Authorities play a fundamental role in web security by issuing digital certificates that allow browsers and other systems to verify website identities and establish encrypted connections.
Cloudflare says its public CA would add another high-scale issuer to the existing Web Public Key Infrastructure, while introducing an approach designed around automation, transparency and post-quantum readiness.
The company has also agreed to acquire publicly trusted Root CA key material from GlobalSign. Cloudflare says this will help certificates issued through its CA gain recognition across the existing Web PKI ecosystem, including on legacy devices.
Preparing for the post-quantum web
A central element of Cloudflare's proposal is support for Merkle Tree Certificates.
MTCs are designed to provide a more compact approach to post-quantum certificate authentication. Cloudflare says the certificates can verify that a certificate has been logged in a trusted registry using lightweight proofs, reducing the need to transmit large post-quantum signatures with every connection.
Cloudflare plans to begin production MTC issuance in the first quarter of 2027, subject to the relevant development and acceptance processes.
The company has also been working on broader post-quantum cryptography initiatives, including visibility tools for post-quantum TLS adoption and support for post-quantum technologies across its network.
Supporting today's web while preparing for tomorrow
Moving the web toward post-quantum security cannot happen overnight, particularly because millions of websites still need to support older smartphones, operating systems and other devices.
Cloudflare's proposed approach is therefore designed to support traditional certificates alongside next-generation certificates.
The company has applied for inclusion in the Chrome, Apple, Microsoft and Mozilla root programs, while its planned acquisition of established root certificate material is intended to provide broader compatibility across the existing web ecosystem.
Cloudflare says classical certificate issuance will begin following completion and acceptance of the relevant browser root program processes.
Transparency built into certificate operations
Cloudflare also says the new CA will be designed around greater operational transparency.
The company plans to publish detailed technical and operational information, provide reproducible code builds and maintain a public health dashboard so that the wider Internet community can monitor the service.
This approach is intended to give website operators and the broader security community greater visibility into the infrastructure responsible for issuing and managing trusted certificates.
Automating certificate incident response
Another focus is the ability to respond quickly when certificates need to be replaced or revoked.
Cloudflare plans to use automated renewal signalling based on RFC 9773 to trigger certificate replacements across large numbers of websites without requiring manual intervention.
The company says this could reduce the risk of widespread disruption during certificate revocations or security incidents.
For website operators, the goal is to make certificate management increasingly automated while maintaining compatibility with existing infrastructure.
A transition toward post-quantum authentication
Cloudflare's proposed public CA represents a broader effort to prepare web authentication infrastructure for the eventual arrival of sufficiently capable quantum computers.
The company launched Universal SSL in 2014, helping make automated and free TLS certificates widely available. Its proposed CA extends that work into certificate issuance itself, while introducing support for post-quantum authentication technologies.
Cloudflare expects production MTC issuance to begin in the first quarter of 2027. Until then, the company says website owners and developers can follow its engineering updates and register for early access notifications.
The broader transition will require cooperation across browsers, operating systems, infrastructure providers and website operators, making post-quantum readiness a long-term effort across the web ecosystem.
About Cloudflare
Cloudflare is a connectivity cloud company providing services designed to help organisations make applications, networks and employees faster and more secure. Its global network supports security, performance, connectivity and developer services for organisations ranging from large enterprises to small businesses and nonprofits.
Source and Credits
Source: Cloudflare official announcement, “Cloudflare Announces Public Certificate Authority for the Post-Quantum Web”
Additional source: Cloudflare Blog, “Building a certificate authority for the whole Internet”
Credits: Cloudflare