Product1 publisher3 min readPublished
Cloudflare applies to become a certificate authority that issues post-quantum certificates in 2027
Cloudflare plans to become a public certificate authority and issue post-quantum Merkle Tree Certificates from early 2027. Sites it fronts will manage both kinds from one system, so the planning work falls on old devices that will never add a new root.
The Product Desk · Product desk

What happened
- One newly standardized post-quantum signature algorithm produces 2,420 bytes per signature, against 64 bytes for today's elliptic curve schemes, and a typical connection carries several.
- Merkle Tree Certificates, an IETF draft Cloudflare co-authored, replace per-connection signatures with a small proof that the certificate sits in a trusted public log.
- Cloudflare plans to buy an established root certificate that older devices already recognize, and says that will make its certificates work on legacy hardware immediately.
- Applications are in with the root programs run by Chrome, Apple, Microsoft and Mozilla.
- Let's Encrypt, the nonprofit issuer, said in June that it expects to issue Merkle Tree Certificates in production in 2027.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint Cloudflare's conventional certificates depend on four separate browser and operating system vendors accepting it, so the ordinary half of the plan runs on their timelines.
- capability If log proofs hold up in production, a site can serve post-quantum certificates without adding several large signatures to every connection.
- precedent Two issuers aiming at production in 2027 turn an open-ended quantum forecast into a calendar year operators can plan budgets and testing against.
A customer's phone that has stopped getting software updates will never add a new root certificate to its trusted list [12]. Cloudflare's answer for that phone is the established root it intends to buy [13]. The announcement did not name the root or give a date for conventional issuance, which starts only after the browser root programs accept Cloudflare's applications [19][17].
Cloudflare pitches the new authority as preparation for the point when quantum computers can break current encryption [1]. Upgrading the web's security before that happens is "one of the biggest coordination challenges in the history of the internet," Chief Executive Matthew Prince said [10]. He tied the move to Universal SSL, the free certificate program Cloudflare launched in 2014 and says doubled the web's encrypted traffic overnight [11]. What is actually scheduled is one certificate format, issued from the same system as conventional ones [2].
Size is why the format exists. In the published comparison, each post-quantum signature is about 38 times the size of its elliptic curve counterpart [1]. According to Cloudflare, a joint experiment with Google's Chrome team, announced last October, was successful [6].
Cloudflare expects machines that can break today's encryption within years [4]. Going by the plan, site owners on Cloudflare will do very little on the server. They will manage both certificate types from one system [16], and RFC 9773 renewal signals let Cloudflare swap certificates across millions of sites in the background during a revocation [20].
The authority also changes who signs. Cloudflare's developer documentation names three outside issuers, Let's Encrypt among them, for Universal SSL [8]. The company called the web's reliance on a few dominant issuers a systemic risk if one fails or is compromised [9]. Its own operation is meant to be open to inspection between audits, with reproducible code builds and a live public health dashboard; certificate authorities today are mostly checked through periodic audits [15].
I think starting now makes sense for one group: teams whose clients no longer update. The tradeoff is that their plan depends on a root they cannot test against until Cloudflare names it. Two questions place each team in one box: who terminates your TLS, and whether your clients still take updates.
- Cloudflare terminates, clients update. Swaps are Cloudflare's job [20], and waiting costs little. - Cloudflare terminates, clients frozen. Coverage rests on the root Cloudflare buys [13]. - You terminate, clients update. The decision is an issuer, and Let's Encrypt is a second source for the format [7]. - You terminate, clients frozen. These devices never add new roots [12], so post-quantum certificates reach them only through a root they already hold.
What to watch
- Cloudflare naming the established root it buys and its current owner. That choice decides which legacy devices its certificates reach.
- Decisions by the Chrome, Apple, Microsoft and Mozilla root programs on Cloudflare's applications. Cloudflare's conventional issuance starts with those decisions.
- Whether Chrome turns last October's experiment into production support for Merkle Tree Certificates before Cloudflare's first-quarter 2027 start.