Cloudflare Post-Quantum Certificates 2027 Launch
Cloudflare plans to launch post-quantum website certificates in early 2027, aiming to future-proof internet security against quantum computing threats.
Introduction
Cloudflare has announced plans to establish itself as a public certificate authority (CA), responsible for issuing digital certificates that secure web traffic and authenticate website identities. The initiative includes conventional certificates alongside a post-quantum cryptographic solution known as Merkle Tree Certificates (MTCs), which will enter production during the first quarter of 2027.
Addressing Current Challenges
The company highlighted concerns about the current reliance on a limited number of dominant CAs, where a single failure or breach could have widespread consequences. Additionally, Cloudflare anticipates the emergence of quantum computing capabilities capable of undermining existing encryption standards within the next several years.
Post-Quantum Cryptographic Solution
To address these challenges, the firm is introducing a high-scale CA to diversify the ecosystem and MTCs to future-proof authentication processes. A root certificate serves as a foundational trust anchor for browsers and devices, verifying the legitimacy of a CA.
Acquisition and Compatibility
Cloudflare has secured an agreement to acquire publicly trusted root key material from GlobalSign, ensuring compatibility with older devices that no longer receive software updates. This transaction is expected to finalize within two months, pending standard regulatory approvals.
“Twelve years ago, Cloudflare made encryption free and automatic for millions of websites. Today, we’re taking the next step by building an open, transparent, and reliable Certificate Authority for the entire Internet,” stated Matthew Prince, CEO and co-founder of Cloudflare.
Technical Implementation
Cloudflare has also submitted applications to the root programs of Chrome, Apple, Microsoft, and Mozilla, with classical certificate issuance contingent on approval from these entities. All four applications remain under review.
Merkle Tree Certificates (MTCs)
MTCs, developed in collaboration with the Internet Engineering Task Force (IETF) as a draft specification, enable browsers to verify certificate legitimacy through lightweight cryptographic proofs. Unlike traditional post-quantum signatures, which are computationally intensive, MTCs avoid transmitting these signatures during every connection.
Future-Proofing Measures
Cloudflare tested the technology with Chrome and is expanding its implementation. The firm also plans to deploy a public health dashboard and provide reproducible code builds to enhance transparency. Automated renewal signaling (RFC 9773) will facilitate background certificate replacements across millions of sites during routine revocations or security updates.
Conclusion
Cloudflare’s approach addresses vulnerabilities in the current certificate infrastructure while preparing for quantum computing threats. The company’s strategy emphasizes backward compatibility and forward-looking security measures to ensure uninterrupted web operations.
