NewsLayer.com
NewsLayer PulseLIVEBTC$85,389+0.77%ETH$2,700+0.51%SOL$120.9+0.92%XRP$1.5+0.97%DOGE$0.0953+2.28%ADA$0.2514+2.42%Total Cap$2.86T+0.71%Layer Index55 Neutral

Cloudflare Becomes a Certificate Authority to Tackle Post-Quantum Signatures

Analyst(s): Fernando Montenegro Publication Date: October 2, 2026

The Futurum Group

Publisher

Oct 2, 2026 at 3:56 PM UTC · 8 分で読める

Cloudflare Becomes a Certificate Authority to Tackle Post-Quantum Signatures
Image via The Futurum Group
翻訳中…

Analyst(s): Fernando Montenegro
Publication Date: October 2, 2026

Cloudflare plans to become a public certificate authority, with production post-quantum Merkle Tree Certificates targeted for the first quarter of 2027. We see a credible move on the harder, signature side of the migration, though browser root programs will set the pace.

What Is Covered in This Article:

  • Cloudflare will issue classical and post-quantum certificates from a single certificate authority (CA), backed by a GlobalSign root and pending applications with four browser root programs.
  • Merkle Tree Certificates (MTCs) address the 40x size problem of post-quantum signatures, and the Chrome experiment showed faster handshakes.
  • Browser root programs, not Cloudflare, control the timeline, and Let’s Encrypt is pursuing free MTCs on a similar schedule.
  • A second free, large-scale issuer helps the resilience of the web’s public key infrastructure (PKI), but pairing the content delivery network (CDN) and CA roles within one provider is a dependency customers should weigh carefully.
  • Internal PKI, not public certificates, remains where most enterprise post-quantum exposure sits.

The News: On September 29, 2026, Cloudflare announced its intent to become a public certificate authority (CA), issuing both classical Transport Layer Security (TLS) certificates and post-quantum Merkle Tree Certificates (MTCs) from a single system. The company has signed a definitive agreement to acquire publicly trusted root CA key material from GlobalSign, a root trusted since 2012, so its certificates will be recognized on older devices; the deal is expected to close within two months. Cloudflare has also applied to the Chrome, Apple, Microsoft, and Mozilla root programs, with classical issuance to begin after acceptance and production MTC issuance targeted for the first quarter of 2027.

Article Intelligence

Topics

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium