Cloudflare Announces Public Certificate Authority for the Post-Quantum Web

Cloudflare’s Bold Move to Secure the Post-Quantum Web

In a major breakthrough for internet security, Cloudflare has announced its intention to become a public Certificate Authority (CA), marking a significant shift towards protecting websites from the looming threat of quantum computers. This move is particularly timely as computing power advances, threatening to break current encryption methods and leaving many websites vulnerable.

The new CA will issue digital certificates that enable encrypted connections and verify a website’s identity, but with a crucial difference: it will support both traditional encryption and next-generation post-quantum Merkle Tree Certificates (MTCs). This means every website will have a path to stay protected as computing power advances – without requiring new tools or rebuilds. Cloudflare has also agreed to acquire established root certificate material from GlobalSign, ensuring its certificates are recognized across the web.

The current certificate infrastructure is built on trust concentrated in a small number of dominant issuers, creating systemic risk if any one of them fails or is compromised. Moreover, most of this infrastructure was created before quantum computing became a practical concern. Quantum computers capable of breaking today’s encryption are expected to become operational within years, and much of the web is not prepared for that shift.

Cloudflare’s CEO, Matthew Prince, emphasizes the importance of upgrading the web’s security before it’s too late: “Twelve years ago, Cloudflare made encryption free and automatic for millions of websites. Today, we’re taking the next step by building an open, transparent, and reliable Certificate Authority for the entire Internet.” By supporting both traditional and post-quantum encryption methods, Cloudflare is providing a permanent safety net – ensuring the internet remains fast, reliable, and secure for all devices, regardless of what comes next.

To ensure certificates work on older smartphones, operating systems, and devices that no longer receive software updates, Cloudflare plans to acquire an established root certificate. This means websites using Cloudflare-issued certificates will be recognized immediately, including on legacy hardware. The company has also applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs, following the public process established by each.

By launching a new public CA, Cloudflare is not only upgrading its own services but also contributing to the development of more secure internet infrastructure. This move will add an independent, high-scale issuer to the foundation of certificate authorities, reducing reliance on a small set of dominant issuers and mitigating systemic risk.

In conclusion, Cloudflare’s bold move towards becoming a public CA is a significant step forward for internet security. As computing power advances and quantum computers become operational, having a reliable Certificate Authority that supports both traditional and post-quantum encryption methods will be crucial in protecting websites from potential threats. Businesses and individuals relying on online services should take note of this development and consider how to prepare their own infrastructure for the shift towards post-quantum security.

In practical terms, if you’re responsible for managing a website or online service, it’s essential to stay informed about the evolving landscape of internet security. Consider exploring options for upgrading your encryption methods and certificates to ensure they remain compatible with future-proof technologies.


Source: Dark Reading — 2026-09-29