As quantum computing edges from theoretical threat toward practical reality, Cloudflare has announced plans to establish a public certificate authority dedicated to issuing quantum-safe TLS certificates — a quiet but foundational act of preparation for a future in which today's cryptographic assumptions may no longer hold. The initiative draws on Merkle tree structures to authenticate web traffic in ways that resist quantum decryption, and by making this infrastructure public rather than proprietary, Cloudflare extends its role from edge network to cryptographic steward of the broader internet
Cloudflare to Launch Public Certificate Authority for Quantum-Safe TLS
Preparing internet infrastructure for a threat that may not arrive for decades
Why does Cloudflare need to build its own certificate authority for this? Couldn't existing CAs just issue quantum-safe certificates?
They could, and some are experimenting with it. But Cloudflare is positioning itself as infrastructure—the way it already operates DNS resolvers and edge networks. A dedicated public CA signals commitment and makes it easier for organizations to adopt quantum-safe certificates at scale.
The source material is thin on actual technical details. We know Merkle trees are involved, but we don't know the specific post-quantum algorithms, the timeline for launch, or whether this CA will be free like Let's Encrypt or have a different model.
When would organizations actually need to switch over?
That's the open question. Quantum computers capable of breaking current encryption don't exist yet. But the "harvest now, decrypt later" risk means sensitive data encrypted today could theoretically be decrypted in the future. So the logic is to start transitioning before the threat materializes.
Right—and that's a real security principle, but it also means we're asking organizations to invest in infrastructure for a threat that may be 10 or 20 years away. The source doesn't tell us whether Cloudflare has a recommended migration timeline.
Is this a competitive move?
Almost certainly. Let's Encrypt dominates the public CA space. If quantum-safe certificates become standard, Cloudflare wants to be a trusted provider from the beginning rather than playing catch-up.
The source mentions that other providers are exploring post-quantum options, but doesn't name them or describe their progress. We're inferring competition from the announcement itself, not from reported facts about what competitors are doing.
Der Puls
- The 'harvest now, decrypt later' threat — where adversaries archive encrypted traffic today to decrypt it once quantum computers mature — is pushing the security industry to act before the danger fully arrives.
- Current TLS certificates, the backbone of web authentication and encryption, rely on mathematical problems that sufficiently powerful quantum machines could unravel, leaving years of internet traffic potentially exposed.
- Cloudflare is building a dedicated public certificate authority using post-quantum algorithms and Merkle tree cryptography, making quantum-safe certificates accessible to organizations that lack resources to build their own infrastructure.
- The move puts Cloudflare in direct competition with Let's Encrypt and other major certificate authorities already exploring post-quantum options, signaling that the race to secure internet infrastructure is accelerating.
- NIST finalized post-quantum cryptographic standards in 2022, and with major tech companies now moving from testing to production, Cloudflare's public CA arrives at a moment when adoption timelines are becoming concrete rather than speculative.
As quantum computing edges from theoretical threat toward practical reality, Cloudflare has announced plans to establish a public certificate authority dedicated to issuing quantum-safe TLS certificates — a quiet but foundational act of preparation for a future in which today's cryptographic assumptions may no longer hold. The initiative draws on Merkle tree structures to authenticate web traffic in ways that resist quantum decryption, and by making this infrastructure public rather than proprietary, Cloudflare extends its role from edge network to cryptographic steward of the broader internet. It is the kind of move that rarely makes headlines but shapes the architecture of trust for years to come.
Cloudflare announced this week that it will build and operate a public certificate authority dedicated to issuing quantum-safe TLS certificates — a move designed to harden internet infrastructure against a threat that, while still theoretical, is growing harder for the security industry to defer.
The vulnerability at stake is structural. The certificates that encrypt web traffic and verify website identities today rely on cryptographic algorithms that quantum computers could theoretically break. Security researchers worry about a 'harvest now, decrypt later' scenario, in which adversaries collect encrypted data now and decrypt it once quantum hardware matures. Cloudflare's new CA will issue certificates built on post-quantum algorithms, using Merkle trees — a cryptographic structure that verifies data integrity without depending on the mathematical problems quantum machines are expected to solve easily.
By making this a public authority rather than a proprietary tool, Cloudflare is positioning itself as infrastructure for the wider internet ecosystem, extending its existing role as a public resolver and edge network into the cryptographic foundation layer. The timing is deliberate: NIST finalized post-quantum standards in 2022, major technology companies have begun production testing, and competitors including Let's Encrypt are exploring similar options. Cloudflare's dedicated CA signals confidence that demand will grow as organizations move from experimentation into deployment.
For most users and website operators, the transition will be largely invisible — browsers and servers will absorb the new algorithms quietly. But the underlying promise remains the same: proving a website is what it claims to be, and keeping the conversation between user and server private. Cloudflare is betting that the quantum-safe version of that promise will become as unremarkable as the classical version is today.
Cloudflare announced plans this week to build and operate a public certificate authority dedicated to issuing quantum-safe TLS certificates—a significant step toward hardening internet infrastructure against a threat that remains theoretical but increasingly urgent in security circles.
The move addresses a specific vulnerability in how the internet currently works. Today's TLS certificates, which encrypt web traffic and authenticate websites, rely on cryptographic algorithms that quantum computers could theoretically break. A sufficiently powerful quantum machine could, in principle, decrypt years of archived internet traffic retroactively—a concern security researchers call "harvest now, decrypt later." Cloudflare's new CA will issue certificates using post-quantum cryptographic algorithms designed to resist quantum attacks, even as classical computers continue to dominate computing infrastructure.
The technical approach centers on Merkle trees, a cryptographic structure that can verify data integrity without relying on the mathematical problems that quantum computers are expected to solve easily. By building this as a public certificate authority rather than keeping it proprietary, Cloudflare is positioning itself to serve as infrastructure for the broader internet ecosystem. The company has long operated as a public resolver and edge network; this CA represents an extension of that role into the cryptographic foundation layer.
The timing reflects a shift in how the security industry thinks about quantum threats. While large-scale quantum computers capable of breaking current encryption do not yet exist, the timeline for their arrival remains uncertain—estimates range from years to decades. The cryptographic community has settled on this uncertainty as reason enough to begin transitioning now. The National Institute of Standards and Technology finalized post-quantum cryptographic standards in 2022, and major technology companies have begun testing implementations. Cloudflare's public CA makes that transition more accessible to organizations that lack the resources to build their own quantum-safe infrastructure.
The announcement also signals competitive positioning. Other major internet infrastructure providers—including Let's Encrypt, which operates the world's largest public CA—have begun exploring post-quantum options. Cloudflare's move to establish a dedicated public authority suggests confidence that demand for these certificates will grow as organizations move beyond testing and into production deployment.
For most website operators and internet users, the shift will be largely invisible. Browsers and servers will need to support the new algorithms, and certificate issuance processes will need to accommodate longer key sizes and different validation procedures. But the underlying principle remains unchanged: proving that a website is what it claims to be, and encrypting the conversation between user and server. Cloudflare is betting that the quantum-safe version of that proof will become as routine as the classical version is today.