New public CA will support conventional TLS and post-quantum Merkle Tree Certificates, aiming to make the web’s transition to quantum-resistant security more seamless.
Cloudflare is moving deeper into the Internet’s trust infrastructure with plans to become a public Certificate Authority (CA), adding a new layer to its strategy of making encryption automated, scalable and ready for the next generation of computing.
The proposed CA will issue traditional digital certificates while also supporting Merkle Tree Certificates (MTCs), a post-quantum approach designed to strengthen web security against the potential threat posed by quantum computing.
The move addresses two challenges emerging simultaneously. Certificate issuance today is concentrated among a relatively small number of major providers, creating systemic dependency, while much of the web’s existing cryptographic infrastructure was designed before quantum computing became a practical security consideration.
Cloudflare plans to acquire an established root certificate to ensure certificates remain trusted by older smartphones, operating systems and other legacy devices. It has also applied for inclusion in the root programmes operated by Chrome, Apple, Microsoft and Mozilla.
“Twelve years ago, Cloudflare made encryption free and automatic for millions of websites. Today, we’re taking the next step by building an open, transparent and reliable Certificate Authority for the entire Internet.” — Matthew Prince, CEO and Co-founder, Cloudflare
The company is positioning transparency as another differentiator. Its planned CA will provide detailed operational and technical information, reproducible code builds and a public health dashboard. Cloudflare also plans to use automated renewal signalling to enable certificate replacement across large numbers of websites during revocations or security incidents.
MTCs are central to the post-quantum strategy. Rather than requiring large post-quantum signatures to be transmitted with every connection, the certificates use lightweight proofs to verify that a certificate has been recorded in a trusted registry.
Cloudflare also intends to allow website owners to manage conventional TLS certificates and MTCs within a single system, enabling a gradual transition rather than forcing organisations into an immediate cryptographic migration.
“Upgrading the web’s security before quantum computers can break it is one of the biggest coordination challenges in the history of the Internet,” Prince said. “By balancing support for older devices with brand-new, post-quantum tech, we’re providing a permanent safety net.”
Cloudflare expects to begin issuing classical certificates after completing the relevant browser root-program processes, with production MTC issuance scheduled for the first quarter of 2027.
The larger significance is that post-quantum readiness is increasingly becoming an infrastructure issue rather than a future cryptography project. By combining automated certificate management, broad device compatibility and a transition path to quantum-resistant technology, Cloudflare is attempting to make that change largely invisible to developers and website operators.
