Cloudflare plans to become a public certificate authority (CA), an organization that issues the digital certificates websites use to encrypt traffic and prove who they are. The company said that its CA will issue conventional certificates and a post-quantum type called Merkle Tree Certificates (MTCs), with production MTC issuance scheduled for the first quarter of 2027.
Post-quantum website certificates from Cloudflare are scheduled for early 2027
Cloudflare plans to become a public certificate authority (CA), an organization that issues the digital certificates websites use to encrypt traffic and prove who they are. The company said that its CA will issue conventional…
Help Net Security
Publisher
Sep 30, 2026 at 3:09 AM UTC · 2 phút đọc

Cloudflare says much of the web’s certificate issuing rests on a small set of dominant CAs, so one failure or compromise would spread widely. It also expects quantum computers able to break today’s encryption within years. A new high-scale issuer is its answer to the first problem, and MTCs are its answer to the second.
A root certificate tells browsers and devices whether to trust a CA. Cloudflare has agreed to acquire publicly trusted root key material from GlobalSign so its certificates are recognized on older phones and other devices that no longer get software updates. The company expects that deal to close within two months, subject to customary closing conditions. It has also applied to the Chrome, Apple, Microsoft and Mozilla root programs, and classical issuance begins only after that acceptance process finishes. All four applications are pending.
Article Intelligence
Topics
Regulation Signal
in progressUpdated 2 tháng trước
SEC Crypto Asset Market Structure RulemakingRelated Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
