09/30/2026, 17.45
by GiuliaSales
Condividi su Facebook Condividi su Twitter Condividi su Pinterest Condividi su Telegram Condividi su WhatsApp

Cloudflare Launches Post-Quantum CA to Shield Web from Quantum Threats

Cloudflare is becoming a public Certificate Authority to issue quantum-safe TLS certificates, using Merkle Tree Certificates to prevent future decryption.
Cloudflare Launches Post-Quantum CA to Shield Web from Quantum Threats
Key points
  • Cloudflare is establishing a public Certificate Authority (CA) to issue both traditional and post-quantum TLS certificates.
  • The company will use Merkle Tree Certificates (MTCs) to protect web traffic from future quantum computing attacks.
  • To ensure immediate global trust, Cloudflare is acquiring Root CA key material from GlobalSign.
  • Production of post-quantum certificates is scheduled to begin in Q1 2027.

The digital foundation of trust that secures nearly every interaction on the internet is facing an existential threat. For decades, Transport Layer Security (TLS) certificates have ensured that when a user visits a website, the connection is encrypted and the identity of the server is verified. However, the looming arrival of cryptographically relevant quantum computers threatens to render these current encryption standards obsolete. In response, Cloudflare has announced its intention to become a public Certificate Authority (CA), creating a pathway for the global web to transition toward quantum-safe security.

The quantum threat to current encryption

Most of the internet's current security infrastructure was designed long before quantum computing moved from theoretical physics to practical engineering. Today's encryption relies on mathematical problems that are nearly impossible for classical computers to solve but could be trivial for a sufficiently powerful quantum machine. If a quantum computer can break the underlying cryptography of TLS certificates, the privacy of global data transmissions would vanish, allowing attackers to decrypt sensitive communications retrospectively or impersonate secure websites.

Cloudflare identifies this as one of the most significant coordination challenges in the history of the internet. The risk is not just future-dated; the concept of harvest-now-decrypt-later means that encrypted data stolen today could be decrypted once quantum hardware matures. By establishing its own CA, Cloudflare aims to provide a safety net that allows the web to upgrade its defenses before the threat becomes a reality.

Hybrid security via Merkle Tree Certificates

To bridge the gap between the current era and the post-quantum future, Cloudflare is introducing a hybrid approach. The new CA will not simply replace old certificates but will issue both traditional TLS certificates and a next-generation equivalent known as Merkle Tree Certificates (MTCs). This dual-issuance strategy ensures that the internet does not break during the transition.

MTCs use a form of cryptography specifically designed to withstand attacks from quantum computers. By offering these as part of an open-source platform, Cloudflare is attempting to democratize access to high-level security. According to the company, these hybrid certificates will be available for free to both paying and non-paying users, removing the financial barrier to adopting quantum-safe standards. This move mirrors Cloudflare's effort twelve years ago when it made basic encryption free and automatic for millions of websites.

Solving the trust problem with GlobalSign

A Certificate Authority is only useful if browsers and operating systems trust it. Normally, a new CA must spend years building a reputation and applying to the root programs of major tech giants like Apple, Google, Microsoft, and Mozilla. To bypass this slow climb and achieve immediate ubiquity, Cloudflare has agreed to acquire established, publicly trusted Root CA key material from Cloudflare's partner, GlobalSign.

This acquisition is a strategic masterstroke for deployment speed. By utilizing an existing root, websites that switch to Cloudflare-issued certificates will be recognized as secure immediately, even on legacy hardware, older smartphones, and operating systems that no longer receive software updates. While Cloudflare has still applied to join the official root programs of the major browser vendors, the GlobalSign acquisition provides an immediate bridge to global trust.

Timeline for the post-quantum rollout

The transition to a quantum-safe web will happen in stages. Cloudflare expects the issuance of classical certificates to begin once the browser root program processes are finalized. However, the more critical milestone is the production of Merkle Tree Certificates. The company has scheduled the production issuance of MTCs for Q1 2027.

This rollout follows successful experiments conducted with Chrome, proving that post-quantum certificates can be implemented without incurring significant performance overhead. For the end-user and the business owner, the transition is designed to be seamless; the goal is to allow millions of websites to move to post-quantum security at the flip of a switch without requiring a complete rebuild of their existing infrastructure.

Reducing systemic risk in the PKI ecosystem

Beyond the quantum threat, Cloudflare's entry into the CA market addresses a structural weakness in the Public Key Infrastructure (PKI). Currently, trust is concentrated among a small number of dominant issuers. This centralization creates a systemic risk: if one of the few major CAs is compromised or suffers a catastrophic failure, a significant portion of the web's security could collapse.

Upgrading the web’s security before quantum computers can break it is one of the biggest coordination challenges in the history of the Internet.

By building an open, transparent, and reliable CA, Cloudflare intends to diversify the trust landscape. This decentralization makes the overall ecosystem more resilient, ensuring that the failure of a single entity does not jeopardize the security of the entire global network.

Strategic implications for global enterprises

For businesses operating in the USA, UK, and other global markets, this development signals a shift in how digital risk must be managed. While the immediate threat of a quantum computer is not yet present in the commercial sector, the regulatory and compliance landscape is shifting. In the US, government agencies have already begun discussing the transition to post-quantum cryptography to protect national security data.

Enterprises in the UK and global markets should view the arrival of MTCs as a critical component of their long-term cybersecurity roadmap. The ability to implement quantum-safe certificates without performance degradation means that companies can now begin planning for a post-quantum environment without sacrificing user experience. For those in highly regulated sectors such as finance or healthcare, adopting these standards early will likely become a benchmark for data compliance and fiduciary responsibility as the industry moves toward 2027.

The move by Cloudflare essentially shifts the burden of quantum readiness from the individual business owner to the infrastructure provider. By integrating this into the connectivity cloud, the technical complexity of quantum-safe migration is abstracted away, allowing entrepreneurs to focus on growth while their underlying security evolves automatically.

FAQ

What are Merkle Tree Certificates (MTCs)?

MTCs are a type of post-quantum certificate that uses cryptography designed to be resistant to attacks from quantum computers, unlike traditional TLS certificates.

Will I have to pay for these quantum-safe certificates?

No, Cloudflare has stated that these hybrid certificates will be free for both paying and non-paying users.

When will post-quantum certificates be available for production?

Cloudflare expects to begin production issuance of Merkle Tree Certificates in Q1 2027.

Why did Cloudflare acquire root material from GlobalSign?

To ensure that certificates are trusted immediately by all browsers and devices, including legacy hardware, without waiting years for root program approvals.


Sources: Arstechnica, Cloudflare, Thequantuminsider ·

Hai una domanda su questo dossier?

Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.

Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.

oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email

Condividi su Facebook Condividi su Twitter Condividi su Pinterest Condividi su Telegram Condividi su WhatsApp
Printable version
CLOSE X
Share this story
See also
OpenAI Dots: The Rise of Always-On Proactive AI Agents
OpenAI launches Dots, always-on AI agents capable of proactive research and background tasks. Discover how these agents impact business workflows and …
30/09/2026 20:10
Innodata Launches Motion-Capture Lab to Scale Physical AI Training
Innodata opens a New Jersey R&D lab using Vicon technology to provide sub-millimeter 3D motion data for humanoid robots, accelerating Physical AI deve…
30/09/2026 19:32
Google Analytics 4 Expands Cross-Channel Reporting to App Conversions
Google Analytics 4 now integrates app conversions into cross-channel reports, allowing advertisers to align app and web attribution for better ROI tra…
30/09/2026 19:17
Nvidia and Wall Street Turn AI Compute into a 0B Asset Class
Nvidia partners with BlackRock, Goldman Sachs, and others to treat AI factories as investable infrastructure, unlocking 0B in third-party capital.
29/09/2026 19:41
Nvidia Eyes Insurance Partnerships to Scale AI Infrastructure
Nvidia is in early talks with insurers to mitigate financing risks for neocloud providers, aiming to turn AI chips into a standardized investable asse…
29/09/2026 19:41


Newsletter

Subscribe to glacom updates or change your preferences

Subscribe now