Key facts
- Cloudflare plans to issue quantum-safe TLS certificates in the first quarter of 2027.
- The new certificates will use Merkle Trees, a hierarchical data structure employing cryptographic hashes.
Cloudflare plans to issue quantum-safe TLS certificates in the first quarter of 2027, utilizing Merkle Trees to enhance security against future quantum computing threats. The new system aims to streamline certificate issuance and logging processes.

The transition to quantum-safe TLS certificates is crucial for securing online communications against future threats posed by quantum computers, which could break current encryption methods. Cloudflare's adoption of Merkle Trees aims to improve efficiency and security in digital certificate management.
Cloudflare intends to begin issuing quantum-safe Transport Layer Security (TLS) certificates in the first quarter of 2027, employing Merkle Trees to bolster security against potential threats from quantum computing. This initiative aims to replace the current Web Public Key Infrastructure (WebPKI) system, which relies on quantum-vulnerable signatures.
Google previously introduced Merkle Trees, a hierarchical data structure that uses cryptographic hashes to verify large amounts of information efficiently. Cloudflare and Google have been testing this design in pilot programs, which reduces the handshake data to approximately 40 kilobytes, comparable to current levels. The new system replaces the multi-link chain of signatures with compact Merkle Tree proofs, where a certificate authority signs a single 'tree head' that can represent millions of certificates.
Under the proposed system, a certificate's authenticity is proven by a 'landmark,' a lightweight proof that the certificate exists within the tree. Industry standards mandate that TLS certificates be published in append-only distributed ledgers known as public transparency logs, a practice implemented after the 2011 DigiNotar hack. The Merkle Tree approach integrates logging directly into the certificate issuance process, making transparency a core operational requirement rather than an add-on, according to Cloudflare engineer Mari Galicer.
Cloudflare's plan also includes the Automated Certificate Management Environment (ACME) for issuing and renewing certificates, and a mechanism for sending signatures out-of-band if a server is inaccessible. Shor's algorithm, a quantum computing threat, could potentially forge classical encryption signatures and compromise certificate logs, enabling attackers to forge signed certificate timestamps.
Pick the topics you care about. Get only what matters, on your cadence.