Security3 publishers2 min readPublished Updated
Cloudflare's planned certificate authority targets Q1 2027 for post-quantum Merkle Tree Certificates
Cloudflare plans to become a public certificate authority and start production issuance of post-quantum Merkle Tree Certificates in the first quarter of 2027. Teams planning a post-quantum migration now have an issuer-side date to test web PKI against.
The Watch · Security desk

What happened
- Cloudflare agreed to acquire publicly trusted root key material from GlobalSign so older, unpatched devices trust its certificates, and expects the deal to close within two months.
- Cloudflare has applied to the Chrome, Apple, Microsoft and Mozilla root programs, all four applications are pending, and classical issuance begins only after acceptance.
- Post-quantum algorithms produce signatures of 2,420 bytes against 64 bytes for current elliptic curve schemes, according to SC World.
- Site owners will manage classic and MTC certificates in one system, with no forced cutover between the two types.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Classical issuance waits on four vendors' root-program reviews, so the start of Cloudflare's conventional certificates depends on Chrome, Apple, Microsoft and Mozilla timing more than on Cloudflare's.
- exposure Sites that move issuance to Cloudflare trade reliance on the dominant CAs for reliance on Cloudflare's CA, with a public health dashboard and reproducible builds as the offered checks.
- capability RFC 9773 renewal signaling would let Cloudflare swap certificates across millions of sites in the background during a revocation, without owners reissuing by hand.
Q1 2027 is Cloudflare's date for issuing MTCs in production [2]. That is the issuer's date. On the browser side there is one experiment on the record: Cloudflare ran it with Chrome first and says it is building on it [6]. Help Net Security's account links root-program acceptance to classical issuance [4]. It does not say whether production MTCs wait for the same reviews, or when a browser will verify MTCs outside a trial.
Size is why a new format is needed. By SC World's figures, a post-quantum signature is about 38 times the size of the elliptic curve signature it replaces [1]. With an MTC, the browser checks a lightweight proof that the certificate appears in a trusted public log, so the heavy signatures are not sent with every connection [5]. Cloudflare co-authored the design. It is still an IETF draft specification [5].
The urgency in the announcement comes from Cloudflare's own estimate. The company expects quantum computers able to break today's encryption within years [9]. "Upgrading the web's security before quantum computers can break it is one of the biggest coordination challenges in the history of the Internet," said Matthew Prince, Cloudflare's CEO and co-founder [8].
Cloudflare's second argument is about concentration. The company says much of the web's certificate issuing rests on a small set of dominant CAs, so one failure or compromise would spread widely [10]. Its answer is a new high-scale issuer, and that issuer is Cloudflare [10].
Both reports relay Cloudflare's announcement [1]. SC World's brief credits Silicon Angle as its source [14].
What to watch
- Rulings by the Chrome, Apple, Microsoft and Mozilla root programs on Cloudflare's pending applications, which gate its classical issuance.
- Whether the GlobalSign root key purchase closes within the two months Cloudflare expects.
- Any browser announcing production verification of MTCs beyond the earlier Chrome experiment, and movement of the IETF draft.