Cloudflare Becomes a Certificate Authority for Post-Quantum Certificates
Cloudflare has applied to four browser root programs, agreed to buy a publicly trusted root from GlobalSign, and set production Merkle Tree Certificates for the first quarter of 2027. The si
TL;DR
- A certificate authority is an organisation that browsers trust to sign the TLS certificates that prove a website's identity, and Cloudflare is the network and security company that has now applied to become one.
- On 29 September 2026 Cloudflare announced its intent to become a public certificate authority, issuing classical TLS certificates and post-quantum Merkle Tree Certificates from one system.
- It has applied for inclusion in the Chrome, Apple, Microsoft and Mozilla root programs and signed a definitive agreement to acquire an established, publicly trusted root from GlobalSign, trusted across browsers and devices since 2012.
- Classical issuance follows acceptance by the root programs; production Merkle Tree Certificate issuance is targeted for the first quarter of 2027.
- The technical obstacle that pushed this work later than key exchange is size: post-quantum signatures run roughly 40 times larger than classical ones, and MTCs replace them with an inclusion proof against a public log.
- Renewal automation becomes a condition of issuance, through ACME Renewal Information as standardised in RFC 9773.
- The pace belongs to the browser root programs, and the published planning assumption is a parallel period measured in years.
- For an operations team, the preparation is design work: automated renewal, a certificate inventory that records which endpoint holds which chain and when it expires, and a signature algorithm treated as configuration that can change on a schedule.
The application turns issuance into infrastructure Cloudflare operates
Cloudflare has been one of the largest consumers of publicly trusted certificates on the internet for more than a decade and, as its engineers put it, had never issued one. The 29 September announcement changes that: the company has applied for inclusion in the Chrome, Apple, Microsoft and Mozilla root programs, and it has signed a definitive agreement to acquire an established, broadly trusted root from GlobalSign so that certificates are recognised on older devices from the first day of issuance.

The two-path structure is the part worth understanding. A brand-new root takes years to propagate into the installed base, and it never reaches the devices that have stopped receiving updates. The GlobalSign root has been trusted across browsers, operating systems and devices since 2012 and covers that long tail, while the new root Cloudflare is submitting for inclusion is built for where the ecosystem is heading, including the programmes that are starting to cap how old a trusted root may be. Cloudflare is explicit that it is not issuing certificates yet, and that the first classical certificates follow acceptance by the root programmes.
The operating commitments attached are unusually specific for a certificate authority. Renewal automation becomes a condition of issuance: Cloudflare will issue only to clients that support ACME Renewal Information, standardised in RFC 9773, so that subscribers poll a renewal endpoint and act on published windows. The company has also committed to publishing reproducible builds of the software that signs certificates, attesting the hardware security modules that hold its keys, and running a public dashboard for issuance health. Its stated design goal is to fail small, limiting the blast radius of any single incident.
The size problem that put signatures behind key exchange
Post-quantum key exchange moved first for a straightforward reason. Futurum Research's analysis of the announcement makes the distinction precisely: a certificate only has to resist forgery while it is valid, so there is no harvest-now, decrypt-later problem for a web certificate, while recorded traffic does carry that risk. That is why hybrid key exchange shipped across browsers and runtimes ahead of anything on the authentication side.

Signatures are harder because of their size. By Cloudflare's figures, post-quantum signatures run roughly 40 times larger than the classical ones they replace, which would bloat every handshake and every certificate transparency store by the same factor. The company's own framing is that a simple drop-in upgrade carries a noticeable performance cost and no security benefit before a cryptographically relevant quantum computer exists, which is a fair description of the problem: the work is expensive now, and its payoff is on the far side of a migration the web has to complete anyway.
Futurum's judgement on where that work sits is blunt and is worth quoting in full: "PKI is the hardest and highest-stakes target in any post-quantum program, since every post-quantum connection downstream depends on a post-quantum chain of trust."
How Merkle Tree Certificates replace a signature with a proof
Merkle Tree Certificates are a draft specification in the IETF, co-authored by Cloudflare, that changes where the trust anchor lives. Instead of signing each certificate and logging it afterwards, the authority maintains a transparency log backed by a Merkle tree and signs the tree head: a checkpoint attesting that it issued every entry in the log up to that point. The certificate itself then proves nothing by signature; it proves inclusion, by carrying a sequence of hashes from its own leaf to that tree head.
Publicly trusted certificates can be served in two forms under this design. In standalone form, the certificate's signature value contains a cosigned tree head and an inclusion proof. In landmark-relative form, the client obtains cosigned tree heads out of band, for example through a browser update, and the certificate carries only a lightweight inclusion proof with no heavyweight post-quantum signatures at all. Cloudflare ran the mechanism as an experiment with Chrome Security before this announcement, and Chrome has named MTCs the preferred path for post-quantum authentication, with Cloudflare targeting production issuance in the first quarter of 2027 and certificates issued through ACME at no charge.

The root programmes set the real date
Cloudflare's own milestone list is careful about sequencing: the GlobalSign acquisition is expected to close within two months and is subject to customary conditions, classical issuance begins after the root programmes accept the application, and MTC issuance follows in early 2027 inside Chrome's quantum-resistant root store. Nothing in that sequence is fully inside Cloudflare's control, and Futurum's analysis states the constraint directly: the browser root programmes set the timeline, and the certificate authority works inside the calendar they publish. Let's Encrypt is pursuing free MTCs on a similar schedule, which gives the ecosystem more than one route to the same architecture.
The policy clock runs alongside. Executive Order 14412 directs federal agencies to move high-value systems to post-quantum key establishment by the end of 2030 and to post-quantum signatures by the end of 2031, with contractor requirements to follow, and Google has pulled its own internal migration target into 2029. Cloudflare's phrase for the transition, "a multi-decade migration", is the right planning assumption for anyone building against these deadlines: classical and post-quantum certificates run side by side well past 2027, and that parallel period is a steady state rather than a project with an end date.
What an operations team can prepare in the meantime
None of this requires action on a certificate today, and several of the requirements are visible early enough to be designed in. Renewal automation is the first, because a certificate authority that issues only to clients supporting ACME Renewal Information makes automated renewal a prerequisite rather than an optimisation. Certificate inventory is the second, since a landscape with classical and post-quantum chains running in parallel means knowing which endpoint holds which chain, and when each expires. Cryptographic agility is the third, which in practice means treating the signature algorithm as configuration that can be changed on a schedule. Teams auditing that ground now are doing security audit and hardening work that the post-quantum calendar will require regardless.

Two of our earlier readings cover the neighbouring halves of this migration. Post-quantum planning covers why key exchange moved first and what data-at-rest decisions look like, and our reading of Java 27's default post-quantum TLS shows what a platform-level switch looks like when it lands in a runtime rather than in a browser root store.
Sources
Source: Building a certificate authority for the whole Internet — blog.cloudflare.com/cloudflare-certificate-authority/, Cloudflare, published 29 September 2026, retrieved 2026-10-06 (the intent to become a public certificate authority, applications to the Chrome, Apple, Microsoft and Mozilla root programs, the definitive agreement to acquire a broadly trusted root from GlobalSign and the root's trust since 2012, the long tail of older clients that a new root never reaches, ACME Renewal Information under RFC 9773 as a condition of issuance, reproducible builds of signing software with attested hardware security modules and a public issuance dashboard, the stated aim to fail small, and production Merkle Tree Certificate issuance in the first quarter of 2027). Source: Building a post-quantum certificate authority with Merkle Tree Certificates — blog.cloudflare.com/pq-ca-with-mtcs/, Cloudflare, published 29 September 2026, retrieved 2026-10-06 (post-quantum signatures roughly 40 times larger than classical ones, the IETF draft specification for MTCs, the authority maintaining a transparency log backed by a Merkle tree and signing a checkpoint over its state, the inclusion proof serving as the trust anchor, the standalone form carrying a cosigned tree head and an inclusion proof, the landmark-relative form carrying no heavyweight post-quantum signatures when cosigned tree heads are obtained out of band, and Chrome naming MTCs the preferred path for post-quantum authentication). Source: Cloudflare Announces Public Certificate Authority for the Post-Quantum Web — cloudflare.com press release, published 29 September 2026, retrieved 2026-10-06 (issuance of classical certificates after completion of the root program application and acceptance process, production MTC issuance scheduled from the first quarter of 2027, the GlobalSign acquisition expected to close within two months subject to customary closing conditions, MTCs verified through lightweight proofs, and the single unified system for classical and post-quantum certificates). Source: Cloudflare becomes a certificate authority to tackle post-quantum signatures — futurumgroup.com, retrieved 2026-10-06 (PKI as the hardest and highest-stakes target of a post-quantum program with every downstream connection depending on the chain of trust, the absence of a harvest-now, decrypt-later problem for a web certificate that only resists forgery while valid, the 40x size problem behind MTCs and the faster handshakes measured in the Chrome experiment, browser root programs setting the pace, Let's Encrypt pursuing free MTCs on a similar schedule, Executive Order 14412's end-2030 key establishment and end-2031 signature deadlines for federal high-value systems, Google's internal migration target pulled into 2029, and Cloudflare's description of a multi-decade migration).
Source: Cloudflare certificate authority and Merkle Tree Certificate engineering posts plus the accompanying press release — blog.cloudflare.com and cloudflare.com, 29 September 2026; Futurum Research analysis of the announcement — futurumgroup.com, retrieved 2026-10-06. Figures: the two official Cloudflare graphics published with those posts, plus two Netics editorial diagrams rendered from the same sources.