Cloudflare prepares the Internet for the quantum era with a new post-quantum certificate strategy.Cloudflare is preparing for a major change in Internet security: the company has announced its intention to become a public Certificate Authority (CA) and to support both traditional certificates and new post-quantum technologies designed for a future in which quantum computers could threaten today’s public-key cryptography.
At the center of the initiative are Merkle Tree Certificates (MTCs), which Cloudflare says can help address the size and performance challenges associated with post-quantum signatures.
For ordinary users, the transition may be almost invisible.
Behind the scenes, however, it could affect one of the fundamental trust mechanisms of the Internet: how a browser verifies the identity of a website.
What is a Certificate Authority?

When a browser connects to an HTTPS website, it needs to verify that the server is actually associated with the domain it claims to represent.
Digital certificates provide that identity binding.
Certificates are issued and signed through the Web Public Key Infrastructure, or Web PKI.
Cloudflare has been one of the largest consumers of publicly trusted certificates for years, but the company says it has never issued those certificates itself.
Now it intends to enter that infrastructure directly.
Why are quantum computers a concern?
Modern public-key cryptography relies on mathematical problems that are extremely difficult for classical computers.
Large-scale quantum computers could eventually change that equation.
Algorithms such as Shor’s algorithm theoretically threaten some of the mathematical foundations used by important public-key systems.
That does not mean today’s quantum computers can break HTTPS at Internet scale.
They cannot.
The concern is long-term.
Encrypted information captured today could potentially be stored and decrypted later if sufficiently capable quantum computers become available.
This is commonly described as:
Harvest Now, Decrypt Later.
Cloudflare’s proposed solution
Cloudflare says its planned public CA will support:
- conventional certificates;
- post-quantum certificates;
- Merkle Tree Certificates;
- automated certificate issuance.
The goal is to allow websites to adopt stronger cryptographic protection without rebuilding their entire infrastructure.
Cloudflare has also agreed to acquire established publicly trusted Root CA key material from GlobalSign, with the aim of maintaining broad compatibility across the Web PKI ecosystem.
Why are post-quantum certificates difficult?
One of the central engineering problems is size.
Some post-quantum signature schemes produce signatures substantially larger than the signatures used in conventional cryptography.
Simply replacing classical algorithms with post-quantum ones could make certificate chains much larger.
That can affect:
- TLS handshake sizes;
- network latency;
- memory consumption;
- server performance;
- constrained devices.
Cloudflare’s Merkle Tree Certificate approach is intended to address some of those scaling problems.
What are Merkle Tree Certificates?
A Merkle tree is a cryptographic data structure built from hashes.
It allows large collections of data to be represented and verified through a tree of cryptographic relationships.
Cloudflare is applying the concept to post-quantum certificates in an attempt to reduce the overhead that would otherwise accompany larger post-quantum signatures.
The broader objective is straightforward:
increase cryptographic resilience without making the Web PKI impractically large or slow.
Will users need to do anything?
Not immediately.
Most of the work happens behind the scenes.
A user would still visit:
and expect the browser to establish a secure HTTPS connection.
If the new technologies are properly integrated into browsers, operating systems and server infrastructure, much of the transition could happen without users noticing.
That is consistent with Cloudflare’s stated goal of integrating the new approach into the existing Web PKI rather than requiring a complete rebuild.
Cloudflare has already deployed post-quantum protection
The announcement is not Cloudflare’s first step into post-quantum security.
The company says it has researched post-quantum cryptography since 2017 and has been expanding hybrid post-quantum key agreement across its network.
Cloudflare currently targets 2029 for becoming fully post-quantum secure across its product portfolio.
Its Radar data also shows significant post-quantum key-exchange adoption in HTTPS traffic, although adoption depends on both client and server support.
This cannot be solved by Cloudflare alone

A global post-quantum transition requires cooperation across the ecosystem.
That includes:
- certificate authorities;
- browsers;
- operating systems;
- servers;
- TLS libraries;
- standards organizations;
- cloud providers;
- website operators.
If any critical part of the chain cannot understand the new algorithms or certificate structures, compatibility becomes a problem.
That is why the transition is expected to be gradual.
What does this mean for businesses?
Businesses do not need to purchase quantum computers.
They do need to understand where cryptography is being used.
That includes:
- websites;
- APIs;
- VPNs;
- cloud services;
- payment systems;
- mobile applications;
- sensitive databases.
Organizations will increasingly need a cryptographic inventory showing which algorithms, certificates and keys are used throughout their infrastructure.
They also need crypto-agility: the ability to replace cryptographic components without rebuilding an entire system.
The wider Internet is changing at the same time

Cloudflare has also reported a dramatic increase in traffic generated by AI agents.
According to the company, requests from AI agents on its network increased by more than 1,700% over the past year, while more than half of observed Internet traffic is now non-human.
That creates an unusual convergence.
The Internet is being redesigned for:
quantum-resistant security
and
software agents acting on behalf of people.
Both trends raise fundamental questions about identity, authentication and trust online.
What happens next?
Cloudflare now needs to turn its announcement into a working CA infrastructure.
That involves:
- building the CA;
- securing browser and platform trust;
- integrating post-quantum certificates;
- testing compatibility;
- managing performance overhead;
- scaling the system globally.
Cloudflare is reportedly targeting the first quarter of 2027 for its initial post-quantum web certificates.
The Internet is not waiting for quantum computers to become powerful enough to break current cryptography.
The transition is already beginning.
Cloudflare wants to become a public Certificate Authority and use technologies such as Merkle Tree Certificates to prepare Web PKI for the post-quantum era.
For ordinary users, the change may eventually be almost invisible.
For businesses and infrastructure operators, the message is more immediate:
the cryptography protecting today’s Internet may not be the cryptography protecting tomorrow’s data.
Verified facts: Cloudflare’s planned public CA; support for conventional and Merkle Tree Certificates; GlobalSign Root CA key-material agreement; Cloudflare’s existing PQC work; 2029 full post-quantum target.
Editorial note: Large-scale quantum attacks against today’s Internet cryptography are not an operational threat today. This article covers preparation for a future threat.