Cloudflare announced Tuesday that it plans to issue quantum-proof TLS certificates, positioning itself among the first certificate authorities to offer cryptography widely believed to resist attacks from quantum computers. The internet infrastructure giant said it will operate an open source platform capable of issuing both conventional TLS certificates and a post-quantum equivalent known as Merkle Tree Certificates — and it will give those hybrid certificates away free to both paying and non-paying users.
The move is significant less because of any single product than because of what it signals: the beginning of a years-long, industry-wide rebuild of the Web Public Key Infrastructure (WebPKI), the trust system that underpins every encrypted connection on the internet.
The mechanics: hybrid certificates and a borrowed root
Cloudflare's approach is deliberately pragmatic. Rather than asking the entire ecosystem to rip out existing cryptography overnight, the company will issue hybrid certificates that pair classic TLS cryptography with post-quantum algorithms. That dual approach preserves compatibility with browsers and operating systems that have not yet been updated while gradually normalizing quantum-resistant signatures.
To achieve ubiquity quickly, Cloudflare is acquiring an already trusted certificate root from CA GlobalSign — a shortcut that sidesteps the lengthy and bureaucratic process of getting a new root trusted by browsers, mobile platforms, and device vendors. According to Ars Technica, Cloudflare said the move will let millions of websites use post-quantum certificates at the flip of a switch and without incurring any increased performance overhead.
"Cloudflare said the move will let millions of websites use post-quantum certificates at the flip of a switch and without incurring any increased performance overhead."
Why now? The narrowing path to Q-Day
The urgency stems from a threat model that security researchers call "harvest now, decrypt later." Adversaries — including state-level actors — are already recording encrypted traffic today on the assumption that a sufficiently powerful quantum computer will eventually be able to decrypt it. Data with a long confidentiality horizon, such as medical records, government communications, and intellectual property, is already at risk even though the decrypting machine does not yet exist.
Help Net Security reported that Cloudflare has moved up its post-quantum deadline as researchers narrow the path to Q-Day, the hypothetical moment when quantum computers can break current public-key cryptography. The company's post-quantum website certificates are scheduled for early 2027 — an aggressive timeline that reflects growing confidence among researchers that the cryptographic transition can no longer be treated as a distant concern.
An architectural overhaul, not a feature update
The transition is far more complex than swapping one algorithm for another. A central challenge, as Ars Technica noted, is that quantum-proof signatures are much larger than their classical counterparts. They must still be transmitted efficiently during web requests and recorded in certificate transparency logs — the public ledgers that let the ecosystem detect counterfeit certificates improperly assigned to websites.
Merkle Tree Certificates are designed to address precisely that problem, compressing multiple signatures into a single tree structure so that the resulting proof remains small enough to travel across the wire without crippling performance.
Even so, the WebPKI makeover will take years to complete. It requires coordinated work by an untold number of engineers who design operating systems, browsers, certificate authorities, and the broader internet infrastructure. No single vendor — not even one with Cloudflare's reach — can complete the migration alone.
Safer and faster?
Dark Reading framed the shift with the headline "Post-Quantum Web Could be Safer, Faster," an argument that runs counter to the assumption that stronger cryptography always costs performance. Cloudflare's claim of no increased overhead rests on the Merkle Tree design, which could ultimately reduce the size of the data that servers and clients must exchange during the TLS handshake.
If that holds at scale, the post-quantum transition may be one of the rare security upgrades that users never notice — or that actually improves the experience.
A fuzzy roadmap and vendor-driven momentum
Not everyone is convinced the path is clear. CSO Online struck a more skeptical note, characterizing the state of post-quantum cryptography as one in which vendors are driving forward while the roadmap remains fuzzy. The criticism is not that the technology is wrong, but that coordination across browser makers, hardware vendors, cloud providers, and enterprises remains incomplete.
Cloudflare's acquisition of a GlobalSign root is, in part, an acknowledgment of that fragmentation. Trust stores are slow to change, and standards bodies move deliberately. By buying an existing trusted root rather than building trust from scratch, Cloudflare is trading a measure of independence for speed.
Implications and what to watch
- Adoption timeline: Hybrid certificates could appear on millions of sites well before 2027, but full post-quantum-only deployments will lag for years.
- Compatibility risk: Older clients that cannot parse hybrid certificates may fail or fall back to classical cryptography, potentially weakening guarantees.
- Transparency logs: The ecosystem must agree on how to log and verify post-quantum certificates without bloating ledger sizes.
- Competitive pressure: Rival CAs and cloud providers will likely accelerate their own post-quantum roadmaps in response.
For now, Cloudflare's announcement is best understood as a starting gun rather than a finish line. The company has committed the infrastructure and the trust anchor; the harder work — convincing the rest of the internet to follow — is only beginning.




