Cloudflare will issue quantum-resistant certificates with Merkle Trees

Cloudflare is making strong progress on Merkle Tree Certificates (MTCs) after a successful experimental deployment with Chrome. The company’s move addresses a critical challenge in the shift to cryptography, an industry upgrade aimed for completion by 2029, by offering a solution to performance issues that would arise from simply swapping existing certificates.

After gaining broad industry support, MTCs have emerged as the preferred path forward, allowing for transparency as a core property rather than an add-on. “Having a CA that supports both classical certificate and MTC issuance allows us to default to the most secure authentication method available,” Cloudflare states, providing a painless and performant upgrade path for a large portion of the internet.

Cloudflare’s Launch of a Post-Quantum Certificate Authority

Cloudflare operated an earlier deployment in 2026, issuing Merkle Tree Certificates (MTCs) backed by traditional certificate chains for a subset of its domains on the “free” plan, and serving these to 50 percent of users of Chrome Beta 146 as part of a feasibility experiment. This trial involved domains using Cloudflare’s complimentary service tier, allowing the company to test the practical application of MTCs in a live environment before formally launching its post-quantum Certificate Authority (CA), the company says.

The experiment’s results are informing Cloudflare’s full-scale deployment strategy, targeting early 2027 inclusion in Chrome’s new Quantum-resistant Root Store, a critical step in wider adoption. The company’s approach to building this new CA prioritizes transparency from the outset, integrating it with existing facilities, operations and compliance functions, while simultaneously developing the software stack for issuance and mirroring.

This simultaneous construction allows Cloudflare to align the new post-quantum PKI architecture with its core values and global network infrastructure. The company describes this process as aiming to be as transparent as possible. Cloudflare’s commitment extends beyond simply meeting the requirements of the PQ Root Program. It is actively building a system designed for scalability and efficient handling of post-quantum signatures.

Cloudflare’s development of MTC issuance capabilities is not isolated; the company anticipates and encourages the emergence of additional CAs to support broader MTC adoption. They have expressed eagerness to collaborate with any browser vendor interested in deploying MTCs, signaling a commitment to industry-wide cooperation in the transition to post-quantum cryptography.

Web PKI Challenges with Imminent Quantum Computing

The transition to Merkle Tree Certificates (MTCs) represents a fundamental shift in how web trust is established, moving away from traditional certificate chains to a system prioritizing transparency as a core operational requirement. This architectural change addresses a critical scaling issue. Post-quantum signatures are projected to increase the data volume certificate transparency logs must store by 40 times, potentially misaligning incentives for log operators at internet scale.

Cloudflare’s decision to become a certificate authority (CA) and support MTC issuance is driven by the need to efficiently distribute trust without overwhelming existing infrastructure. Traditional certificate authorities validate domain ownership and bind it to a public key, relying on certificate chains to distribute trust. However, additions like key revocation checks and certificate transparency have increased the number of signatures required during a typical TLS handshake.

MTCs circumvent this issue by batching certificates into an append-only Merkle tree, allowing a CA to sign the root of the tree instead of individual certificates. This approach enables browsers to verify certificates using compact inclusion proofs against a signed tree head, significantly reducing the computational burden. Cloudflare’s development of its CA involves not only adapting to new post-quantum Root Program requirements but also building a complete issuance and mirroring software stack alongside traditional CA functions, according to the company.

The company’s architecture for MTCs maintains the core responsibilities of a CA, domain validation and certificate issuance, but fundamentally alters how trust is established. Instead of directly signing certificates and then logging them, the CA maintains a transparency log backed by a Merkle tree, with inclusion proofs serving as the trust anchor. MTCs exist in two forms, both compatible with the existing X.509 certificate format.

In standalone form, the certificate’s signature includes a cosigned tree head of an issuance log and an inclusion proof demonstrating its presence within the tree. Alternatively, in landmark-relative form, the signature consists solely of the lightweight inclusion proof, eliminating the need for heavyweight post-quantum signatures if clients can obtain tree heads through mechanisms like browser updates. When a website requests a certificate, Cloudflare’s ACME server, a fork of the Boulder software used by Let’s Encrypt, verifies domain control.

Upon successful validation, the CA serializes the data, adds it to the append-only log, and computes an updated state, signing a checkpoint attesting to the issuance of all entries in the Merkle tree up to that point. This checkpoint and updated log state are then sent to a trusted cosigner, which stores a copy of the issuance log and verifies its append-only consistency, ensuring transparency and availability for the broader ecosystem.

The cosigner’s role provides confidence to clients and monitors that a separate trusted party has observed the same log state and validated the CA’s integrity.

Merkle Tree Certificates Scale Post-Quantum Signatures

Cloudflare’s planned launch of a certificate authority supporting Merkle Tree Certificates (MTCs) addresses a fundamental scaling challenge in the transition to cryptography, aiming to minimize performance impacts for end users. Traditional certificate chains, already burdened with multiple signatures and keys for validation, face a substantial increase in overhead due to signatures being approximately 40 times larger than their classical counterparts. This expansion would create expensive processing demands for clients, certificate authorities, logs, and monitoring systems if simply applied to existing infrastructure.

This approach allows for the efficient coverage of billions of certificates with a small set of MTC batch signatures, periodically transmitted to TLS clients. While landmarks offer further scaling benefits, the company recognizes the necessity of standalone MTCs to accommodate newly installed, offline, or outdated clients needing a fallback option.

On the certificate transparency side, MTCs also streamline scaling properties by requiring logs to store only hashes of public keys, eliminating per-entry signatures. The signature on the tree head then covers the entire log, preventing certificate explosion because the CA issuance log becomes the definitive source for all issued certificates. Log consumers then only need to fetch a single copy of each certificate, a significant reduction in data transfer and processing requirements.

“This moment calls for a new approach to the Web PKI, one that allows us to treat transparency as a first-party property rather than an add-on,” the company stated, emphasizing the design philosophy behind MTCs. The shift to MTCs is a technical adjustment and a fundamental redesign of the Web PKI, positioning transparency as an inherent property rather than an added layer.

Cloudflare is targeting early 2027 for inclusion of MTCs in Chrome’s newly launched Quantum-resistant Root Store, a key milestone in the broader industry effort to upgrade to cryptography by 2029, the firm reports. This timeline highlights the urgency of implementing scalable solutions like MTCs to ensure a smooth transition without compromising user experience or security.

Certificate Transparency Monitoring Detects PQ Downgrades

Certificate Transparency Monitoring is being adapted to identify instances where servers attempt to downgrade to weaker, pre-quantum cryptographic standards during the transition to security. Cloudflare launched its Certificate Transparency Monitoring system in 2019, and the tool’s capabilities are now being extended to scrutinize the implementation of authentication as organizations begin upgrading their servers. This monitoring will help detect potential downgrades.

The shift to Merkle Tree Certificates (MTCs) alters how certificate transparency logs operate, impacting scaling properties and data management. This is particularly important given the target of 2029 for widespread adoption of cryptography, a deadline that necessitates proactive monitoring and rapid response to potential security breaches.

This dual-issuance capability allows for a smooth transition, ensuring that systems can fall back to classical cryptography if support is unavailable, while still prioritizing the strongest available security. The company hopes other CAs will emerge to support MTC adoption, and is eager to collaborate with any browser seeking to deploy MTCs. The ability to detect and respond to downgrades is becoming increasingly vital as the industry prepares for the quantum era.

MTC Architecture: Issuance via Transparency Logs

Cloudflare is streamlining certificate transparency with a new approach centered on Merkle Tree Certificates, reducing the data volume monitors must process by eliminating redundant entries. Traditionally, certificate transparency systems have faced scaling issues as certificates are logged multiple times, in various formats, across numerous logs, demanding extensive downloads and processing to ensure complete coverage. This inefficiency stems from transparency being added as an afterthought to existing certificate infrastructure.

This architecture also introduces Mirroring cosigners, which maintain copies of issuance logs to verify their integrity and ensure ongoing availability for the wider ecosystem. The company notes that MTCs can be encoded in the familiar X.509 certificate format, easing integration with existing client software.

Two forms of MTCs are possible, both using the X.509 format. Domain owners who have already upgraded to post-quantum authentication are advised to monitor certificate transparency logs for any unexpectedly issued legacy certificates. Detecting these unexpected issuances is important to prevent clients from reverting to potentially malicious downgrade paths.

Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of Rusty Flint

Rusty Flint

Rusty is a quantum science nerd. He's been into academic science all his life, but spent his formative years doing less academic things. Now he turns his attention to write about his passion, the quantum realm. He loves all things Quantum Physics especially. Rusty likes the more esoteric side of Quantum Computing and the Quantum world. Everything from Quantum Entanglement to Quantum Physics. Rusty thinks that we are in the 1950s quantum equivalent of the classical computing world. While other quantum journalists focus on IBM's latest chip or which startup just raised $50 million, Rusty's over here writing 3,000-word deep dives on whether quantum entanglement might explain why you sometimes think about someone right before they text you. (Spoiler: it doesn't, but the exploration is fascinating)

Latest Posts by Rusty Flint: