Cloudflare’s Bold Move: A Public Certificate Authority for a Post-Quantum Web
Cloudflare, the leading connectivity cloud company, has just announced its intention to become a public Certificate Authority (CA), an open service that issues digital certificates websites need to encrypt traffic and prove their identity to visitors. This move is a significant step towards securing the web against the looming threat of quantum computing, which could potentially break today’s encryption.
The impact will be far-reaching: every website that uses Cloudflare’s services will have access to free, automated certificates for both traditional encryption and next-generation post-quantum Merkle Tree Certificates (MTCs). This means websites won’t need to worry about updating their security infrastructure or installing new tools – they’ll simply receive the necessary certificates from Cloudflare. By doing so, Cloudflare aims to mitigate the systemic risk associated with relying on a small number of dominant certificate issuers.
The web’s current certificate infrastructure was largely built before quantum computing became a practical concern. Today, most websites rely on traditional encryption methods that may not be able to withstand the power of a future quantum computer. Quantum computers capable of breaking today’s encryption are expected within years, leaving much of the web unprepared for this shift.
By becoming a public CA, Cloudflare is taking a proactive approach to addressing this problem. “Twelve years ago, we made encryption free and automatic for millions of websites,” said Matthew Prince, CEO and co-founder of Cloudflare. “Today, we’re taking the next step by building an open, transparent, and reliable Certificate Authority for the entire Internet.” By providing a permanent safety net that balances support for older devices with brand-new, post-quantum technology, Cloudflare is ensuring the web stays fast, reliable, and secure for all devices.
To ensure seamless recognition of its certificates across the web, Cloudflare plans to acquire an established root certificate. A root certificate is what tells browsers and devices whether to trust a CA, so acquiring one means websites using Cloudflare-issued certificates will be recognized immediately – even on legacy hardware that no longer receives software updates. This move is designed to give Cloudflare’s certificates broad recognition across the web as quickly as possible.
Cloudflare’s public CA is also focused on transparency and speed. The company plans to publish detailed operational and technical insights, share reproducible code builds, and maintain a live, public health dashboard so the Internet community can inspect operations in real time. This level of transparency is unprecedented for a certificate authority, and it demonstrates Cloudflare’s commitment to building trust with its users.
The implications of this move are significant: by providing free, automated certificates that support both traditional encryption and post-quantum MTCs, Cloudflare is creating a more secure web that’s better equipped to handle the challenges of quantum computing. This isn’t just about protecting individual websites – it’s about safeguarding the entire web against the threats of the future.
So what can website owners take away from this development? First and foremost, don’t wait for others to act. Cloudflare is offering free, automated certificates that support post-quantum MTCs, but you’ll need to be proactive in adopting these new technologies if you want to stay ahead of the curve. Second, prioritize transparency and security when selecting a certificate authority. By choosing a provider like Cloudflare that’s committed to openness and speed, you can rest assured that your website is protected against the threats of the future.
Source: Dark Reading — 2026-09-29