Cloudflare is trying to redesign one of the Internet’s most invisible trust systems before quantum computing turns today’s website-authentication signatures into a scaling problem.
On September 29, Cloudflare said it is building a public Certificate Authority that will support both conventional web certificates and post-quantum Merkle Tree Certificates. In its technical explanation of the new post-quantum CA, the company argues that simply swapping much larger post-quantum signatures into today’s Web PKI would make TLS handshakes and certificate-transparency infrastructure substantially heavier.
Cloudflare summarized that problem in its September 29 announcement on X: Merkle Tree Certificates are intended to keep authentication compact and auditable while allowing the new CA to issue post-quantum credentials at Internet scale.
The problem is authentication, not just encryption
When a browser opens an HTTPS site, cryptography does more than encrypt traffic. The browser also needs evidence that the server actually controls the domain it claims to represent. Certificate Authorities, certificate chains and browser root stores form the trust system that makes that authentication possible.
That is a different job from protecting bulk data with symmetric cryptography. Techniques such as stream ciphers encrypt data efficiently once communicating systems already share the necessary secret material. Website authentication instead depends heavily on public-key signatures—and those are among the primitives that must migrate before cryptographically relevant quantum computers become practical.
Cloudflare estimates that post-quantum signatures are roughly 40 times larger than the classical signatures used in today’s certificate ecosystem. It also estimates that simply carrying those larger signatures into existing certificate-transparency architecture could increase stored CT data by about 40 times.
Merkle Tree Certificates change what gets signed
The proposed answer is not to put a giant post-quantum signature on every certificate and keep everything else unchanged. Instead, Merkle Tree Certificates batch certificate entries into an append-only Merkle tree. The Certificate Authority signs a checkpoint representing the tree state, while an individual website receives a compact inclusion proof showing that its certificate data appears inside that authenticated structure.
That shifts the trust model toward “issue by logging.” A browser can validate the inclusion proof against a trusted tree state instead of receiving a separate heavyweight post-quantum signature for every individual certificate. Independent cosigners and mirrors are intended to make equivocation—showing different issuance histories to different observers—harder to hide.
For security teams, that architecture reinforces why a current cryptographic inventory matters. Organizations cannot migrate what they have not identified: TLS endpoints, certificate lifecycles, signing systems, key stores and software dependencies all become part of the post-quantum transition.
Cloudflare already tested MTCs with Chrome
Cloudflare says it ran a 2026 experiment with Chrome Beta 146 using a bootstrap Certificate Authority and served billions of Merkle Tree Certificates during the trial. In the common landmark-relative case, the browser received one public key, one signature and an inclusion proof smaller than 1 KB.
The company reports that landmark-relative MTC handshakes were 9% faster at the median than the classical certificate-chain path used in its experiment, while cautioning that much of that improvement came from eliminating the intermediate certificate. The experiment also used classical signatures rather than the larger post-quantum signatures the architecture is ultimately intended to handle.
Ars Technica’s independent report similarly frames the project as a major change to website authentication rather than an already-finished replacement for conventional TLS certificates. Cloudflare still has to pass browser and root-program approval processes before its new CA can become broadly trusted.
A public CA is a high-trust infrastructure role
Operating a Certificate Authority is not equivalent to launching an ordinary cloud product. A publicly trusted CA can bind domain identities to public keys accepted by browsers, which makes operational security, auditing, signing-key protection and policy enforcement central to the system.
The same principle appears in local computing through hardware roots of trust: a security architecture becomes useful only when the root that anchors later verification is protected strongly enough to deserve that trust. Web PKI applies that problem globally, across browsers, CAs, domains and transparency monitors.
The transition is designed to be gradual
Cloudflare is not proposing an overnight retirement of ordinary certificates. The planned CA is intended to support conventional certificates and Merkle Tree Certificates in parallel so websites and clients can migrate at different speeds.
That matters because post-quantum authentication has a different deployment problem from post-quantum key exchange. Every browser, CA, transparency system, server stack and monitoring tool must agree on how the new trust path works, while older clients still need a usable fallback.
The next milestones are therefore institutional as much as cryptographic: root-program approval, independent cosigners, production-scale monitoring and real certificate issuance. Cloudflare says its Chrome experiment proved the design can function at very large scale; the harder test is whether the wider Web PKI ecosystem can operate it reliably without concentrating too much trust or breaking compatibility.
BitcoinVersus.Tech
Advertisement
Editor’s Note
This report distinguishes Cloudflare’s announced Certificate Authority plans and experimental MTC results from a fully approved, broadly trusted production CA. The featured cover is an original editorial illustration and is not duplicated in the article body.
We volunteer daily to ensure the credibility of the information on this platform is Verifiably True. If you would like to support our research initiatives, please donate here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb
BitcoinVersus.tech is not a financial advisor. This media platform reports on financial subjects purely for informational purposes.

Leave a comment