Cloudflare announced plans to launch a public Certificate Authority (CA) that will issue both conventional digital certificates and next-generation Merkle Tree Certificates (MTCs), according to announcements made on September 29, 2026. The move aims to diversify trust away from a small group of dominant issuers and prepare web infrastructure for the arrival of quantum computers capable of breaking current encryption standards. Production MTC issuance is scheduled for the first quarter of 2027, following a successful experiment with Chrome.
Addressing Systemic Web PKI Risk
Every secure website relies on certificate authorities to verify identity and enable encrypted web traffic. Cloudflare CEO and co-founder Matthew Prince noted that upgrading web security ahead of quantum capabilities represents a massive coordination challenge. By operating an open CA, the company intends to provide an independent alternative that reduces concentration risk across the Web PKI ecosystem.

Deploying Merkle Tree Certificates for Post-Quantum Scale
To prevent the severe performance bottlenecks that traditional post-quantum signatures would cause during TLS handshakes, Cloudflare’s new CA will support Merkle Tree Certificates. Post-quantum signatures are significantly larger than classical keys, a factor that threatens to inflate certificate transparency log sizes by forty times. MTCs solve this by batching certificates into an append-only Merkle tree, allowing a CA to sign the root rather than individual items. Browsers can then verify certificates using lightweight inclusion proofs, cutting down computational overhead. Cloudflare previously tested MTC issuance on 50 percent of users running Chrome Beta 146 across select free-tier domains.
Securing Legacy Device Trust via GlobalSign Agreement
Older smartphones, operating systems, and embedded devices that no longer receive software updates require trusted root certificates to validate connections. To achieve immediate ubiquity on legacy hardware, Cloudflare agreed to acquire established Root CA key material from GlobalSign, with the transaction expected to close within two months pending customary conditions. Cloudflare has also submitted formal applications to root programs run by Apple, Microsoft, Google for Chrome, and Mozilla. Traditional certificate issuance will begin once those regulatory and technical acceptance processes conclude.
Transparent Operations and Automated Certificate Management
The newly proposed CA infrastructure will feature a live public health dashboard and reproducible code builds to maintain operational transparency. Site operators will manage classical and MTC certificates through a single unified system without requiring a forced cutover. Cloudflare plans to utilize automated renewal signaling under RFC 9773 to handle background certificate replacements across millions of domains during routine security updates or revocations.
Keep reading