Internet infrastructure provider Cloudflare has announced plans to begin issuing quantum-proof Transport Layer Security (TLS) certificates. The upcoming initiative positions the company among the earliest certificate authorities to provide cryptographic credentials designed to resist attacks from future quantum computers.
The deployment will rely on an open-source platform capable of generating both traditional TLS certificates and a post-quantum counterpart known as Merkle Tree Certificates. These hybrid certificates will be provided free of charge to both paying and non-paying Cloudflare customers. To help construct the required architecture and achieve widespread adoption across the web ecosystem, Cloudflare is acquiring an established, trusted certificate root from certificate authority GlobalSign. Cloudflare stated that this acquisition will allow millions of domains to activate post-quantum protections seamlessly without experiencing performance penalties.
The Impending Threat to Public Key Infrastructure
The transition forms part of a broader, systemic redesign of the web public key infrastructure (WebPKI), which underpins online encryption and authentication. Safeguarding this ecosystem against quantum computing requires fundamental architectural adjustments rather than an in-place swap of cryptographic algorithms.
Today’s WebPKI environment relies on multi-link chains of digital signatures that are vulnerable to quantum algorithms. In particular, a viable implementation of Shor’s algorithm would be capable of breaking classical cryptographic signatures as well as the public keys used across certificate logs. Such capabilities would enable malicious actors to forge signed certificate timestamps, falsely convincing browsers and operating systems that an illegitimate certificate had been properly vetted and recorded.
Directly converting conventional X.509 digital certificates to existing quantum-resistant algorithms introduces severe scalability hurdles. Standard quantum-safe replacements would expand the data exchanged during a standard TLS handshake by approximately 40 times. Because handshakes must occur whenever a client negotiates a secure session with a web server, the resulting bandwidth and processing overhead would overwhelm existing network infrastructure.
Merkle Trees and Lightweight Handshakes
To circumvent the handshake size limitation, the industry has turned toward Merkle Trees, an approach announced by Google in February. Merkle Trees are hierarchical, tree-like mathematical structures that use cryptographic hashes to verify large data collections using only a small subset of the total information. Cloudflare and Google have previously evaluated the concept through limited pilot testing, finding that Merkle Tree designs reduce handshake payloads to approximately 40 kilobytes, roughly matching the footprint of current web transactions.
Rather than transmitting cumbersome signature chains to client devices, the Merkle Tree system substitutes compact cryptographic proofs. Under this framework, a certificate authority needs to sign only a single root element known as a tree head, which can encompass millions of individual certificates. End-user browsers typically receive only a lightweight proof known as a landmark, verifying that the target domain’s certificate resides within the certified tree structure.
Integrated Certificate Transparency
The Merkle Tree model also reconfigures how certificate transparency is maintained across the internet. Under established industry standards, TLS certificates must be published to append-only distributed ledgers known as certificate transparency logs. Domain administrators monitor these public logs to catch unauthorized or counterfeit credentials issued for their domains.
Mandatory transparency mechanisms were originally introduced following the 2011 security breach of Dutch certificate authority DigiNotar, during which attackers forged roughly 500 bogus certificates for high-profile sites, including Google, which were subsequently used to intercept web traffic in Iran.
In the current PKI architecture, certificate issuance and log submission operate as separate procedures. Updates require introducing an additional link into the signature chain. Merkle Tree Certificates unify these actions directly. Cloudflare engineer Mari Galicer explained that by coupling issuance and logging together, transparency ceases to be an add-on and instead becomes a mandatory prerequisite for operational deployment.
Implementation Roadmap
Cloudflare’s rollout architecture incorporates several complementary protocols, including the Automated Certificate Management Environment (ACME) protocol, an open-source standard designed to automate certificate issuance and near-expiration renewals. The quantum-resilient framework will also support an out-of-band delivery channel—such as browser software updates—to distribute signatures if server downtime or connectivity failures prevent a client from obtaining landmark updates directly.
Transitioning the wider internet to quantum-resilient authentication is expected to take years of coordinated development across operating system developers, browser vendors, certificate authorities, and network providers. Cloudflare has confirmed that certificate issuance is not yet live.
Steve Goldsmith of Cloudflare noted that the company is committing to the development publicly, intending to report milestones as they are reached while coordinating directly with root certificate programs and WebPKI stakeholders. Cloudflare expects to begin issuing its post-quantum certificates in the first quarter of 2027.














