William OGOU Cybersecurity Blog

Published

- 12 min read

Cloudflare CA: Free Post-Quantum Certificates with MTCs in 2027

img of Cloudflare CA: Free Post-Quantum Certificates with MTCs in 2027

Cloudflare’s Birthday Week, September 29, 2026. Cloudflare announced that it intends to become a public certificate authority (CA), with plans to issue production post-quantum certificates in the form of Merkle Tree Certificates (MTCs) from Q1 2027. The company has applied to the Chrome, Apple, Microsoft, and Mozilla root programs and signed an agreement to acquire a broadly trusted GlobalSign root.

For customers, this is both a future certificate service and part of a wider Cloudflare post-quantum roadmap. Cloudflare plans free ACME-based MTC issuance, but it is not issuing public certificates yet. In the meantime, customers can already use Cloudflare services for post-quantum key exchange, ML-DSA origin authentication, certificate monitoring, and visibility into negotiated TLS algorithms.

The two announcements Steve Goldsmith’s plan for a public CA and Mari Galicer’s technical deep dive into MTCs show how Cloudflare wants to take customers from today’s origin and edge protections toward post-quantum certificate authentication, without requiring a disruptive cutover.

What Cloudflare Customers Need to Know

  • Planned: a public Cloudflare CA. Applications are in progress with four root programs; a GlobalSign root agreement aims to provide broad device compatibility. Issuance has not started.
  • Planned: free MTC certificates from Q1 2027. Cloudflare intends to offer standard Merkle Tree Certificate issuance at no cost through ACME, alongside classic certificates under one service and lifecycle.
  • Available now: post-quantum origin controls. Automatic Key Exchange prefers X25519MLKEM768 when an origin supports it; Authenticated Origin Pulls and Custom Origin Trust Store support ML-DSA origin authentication.
  • Available now: visibility and legacy-origin options. Cloudflare exposes TLS key-exchange data in analytics and logs, offers Certificate Transparency Monitoring, and Cloudflare Tunnel can provide a post-quantum path to origins that are difficult to upgrade.
  • Customer action: prepare ACME Renewal Information (ARI)-capable automation, measure current PQC adoption, and watch for unexpected classical certificates as post-quantum authentication rolls out.

Cloudflare’s PQC Services: What You Can Use Today

The new CA is a future service, not the only way to improve post-quantum readiness on Cloudflare. Customers can make progress now across visitor traffic, origin connections, and certificate management.

Protect and Measure Visitor Connections

Post-quantum key exchange protects confidentiality against harvest-now, decrypt-later attacks: an adversary records encrypted traffic today, hoping to decrypt it with a future quantum computer. For supported visitors, Cloudflare negotiates hybrid ML-KEM key exchange. TLS key-exchange telemetry lets customers measure how much traffic to their domains actually uses X25519MLKEM768, rather than assuming that TLS encryption automatically means post-quantum protection.

In Cloudflare’s dashboard, HTTP Traffic Analytics shows the distribution of visitor-side key-exchange groups. Log Explorer and Logpush can expose ClientTLSKeyExchangeGroup on individual HTTP requests, giving teams evidence for audits and a way to filter connections still using classical algorithms. Cloudflare Radar provides broader context on post-quantum adoption across the Internet.

For a step-by-step domain check, see Is My Website Quantum-Safe? How to Check PQC in 5 Minutes.

Upgrade the Cloudflare-to-Origin Connection

The second TLS connection Cloudflare to the customer origin has its own key exchange. Automatic Key Exchange scans origin capabilities and selects the strongest supported group, preferring X25519MLKEM768 when available. It is enabled by default and can also avoid unnecessary retry round trips when an origin only supports classical groups.

Customers can check origin-side key exchange using the OriginTLSKeyExchangeGroup field in Logpush. If the origin does not yet support post-quantum key exchange, upgrade its TLS stack and check for manually configured curve lists that override modern defaults. For an origin that cannot be changed, Cloudflare Tunnel provides a post-quantum encrypted cloudflared-to-Cloudflare connection without requiring an upgrade to the legacy server itself.

See Cloudflare Post-Quantum TLS: Automatic Key Exchange Explained for the scan, negotiation, and rollout details.

Authenticate Origins with ML-DSA

Encryption and authentication solve different problems. Hybrid key exchange protects a session secret; it does not stop an attacker with a sufficiently capable quantum computer from forging a classical certificate and impersonating an endpoint.

Cloudflare already supports post-quantum ML-DSA certificates for the Cloudflare-to-origin connection:

  • Authenticated Origin Pulls (AOP) lets an origin authenticate Cloudflare using a post-quantum client certificate.
  • Custom Origin Trust Store (COTS) lets Cloudflare validate an origin certificate that chains to a customer-managed ML-DSA CA. COTS requires Advanced Certificate Manager.

Together, AOP and COTS can provide mutual post-quantum authentication between Cloudflare and an origin. They are available now for origin-facing TLS; MTCs target public WebPKI authentication between browsers and websites. See the ML-DSA origin authentication guide for configuration steps.

Monitor Certificates for Downgrade Paths

Cloudflare’s Certificate Transparency Monitoring helps domain owners find certificates issued for their domains. As post-quantum authentication is introduced, use CT monitoring and Radar to flag unexpected classical RSA/ECDSA certificates for domains intended to use post-quantum authentication. Such certificates can create a downgrade route if a client still trusts the classical credential.

This is a practical role for Cloudflare’s existing monitoring services alongside the new CA: MTCs make certificate issuance transparent by design, while CT monitoring helps customers notice unexpected issuances and potential misuse of domain validation.

The New Cloudflare CA: A Planned Customer Service

Cloudflare says it has spent more than a decade as a large certificate consumer, provisioning certificates for millions of domains through multiple CAs and maintaining primary and backup paths. It now plans to add its own CA to that supply chain extending its experience operating Universal SSL and certificate packs into a public ACME service for the wider Internet.

Broad Compatibility Through Two Trust Paths

A new root cannot reach every browser, operating system, or device immediately. It takes time to enter root programs and propagate through updates, and some clients may never receive those updates. Cloudflare’s definitive agreement to acquire a GlobalSign root, trusted since 2012, is intended to provide compatibility with a broad installed base from the start. New Cloudflare roots are intended to meet future root-program requirements, including policies that limit root age.

The root applications and acquisition are steps in progress, not completed browser approval. Cloudflare is not issuing certificates yet, and customer compatibility will depend on root-program acceptance and client support.

ACME Issuance With Automated Renewal

Cloudflare plans an ACME-first issuance service. Customers already using ACME should be able to move by changing the directory URL rather than adopting a new toolchain. Cloudflare says it will require ACME Renewal Information (ARI, RFC 9773) support: clients must poll the renewal endpoint and follow the CA’s renewal windows so that certificate replacement can be coordinated, particularly during revocation or security incidents.

The CA is designed around operational resilience as well as cryptography. Cloudflare says it intends to publish reproducible builds of its certificate-signing software, attest the hardware security modules that protect CA keys, and maintain a public dashboard for issuance health and incidents. It also plans to pull forward renewal windows and spread replacement issuance when affected certificates need to be retired.

Classic and Post-Quantum Certificates in One Lifecycle

Cloudflare does not expect the WebPKI to switch to MTCs overnight. Websites and clients will continue using classic certificates for years, while post-quantum certificate support spreads through browsers, CAs, and monitoring tools. The proposed Cloudflare CA is intended to support both classic certificates and MTCs within one service and lifecycle, so customers can adopt gradually rather than running parallel certificate systems or performing a hard cutover.

Cloudflare also says it will be Customer Zero: it plans to use certificates from its new CA in its own services and operations, exercising the infrastructure at Cloudflare scale before asking the broader ecosystem to rely on it.

Why Cloudflare Is Building Merkle Tree Certificates

Cloudflare CA

Public-key certificates authenticate a website by binding a domain name to a public key through a chain of signatures. A typical TLS handshake already carries multiple certificates, keys, signatures, and transparency information. Post-quantum signatures are roughly 40 times larger than classical signatures; simply replacing every classical signature in today’s certificate chains would increase handshake and Certificate Transparency data substantially. Cloudflare estimates CT log storage could grow by a similar factor.

MTCs, developed through the IETF PLANTS working group, change the structure rather than just swapping in larger signatures. A CA batches certificate entries into an append-only Merkle tree and signs a tree checkpoint. A website presents a compact inclusion proof showing its certificate is in that tree. One signed tree head can vouch for many certificates, while independent mirroring cosigners retain log copies and check that the tree only grows consistently.

MTCs can be delivered in two forms:

  • Standalone certificates contain the signed tree information and inclusion proof, allowing verification without a recent browser update.
  • Landmark-relative certificates carry a smaller proof tied to a signed tree landmark distributed to browsers out of band. A small number of batch signatures can then cover many certificates; standalone certificates remain a fallback for new, offline, or out-of-date clients.

Cloudflare plans to build on Boulder, the ACME software used by Let’s Encrypt, and its open-source Rust transparency log, Azul, for mirroring. Chrome’s draft Quantum-resistant Root Program policy calls for at least two cosignatures from distinct organizations. Cloudflare says its own MTCs will have an independent cosignature and that its mirror will also support other pilot CAs.

MTC Performance: What the Chrome Experiment Proved

Cloudflare reports serving billions of experimental MTCs backed by traditional certificate chains to 50% of Chrome Beta 146 for selected domains. A landmark-relative handshake needed one public key, one signature, and an inclusion proof under 1 KB. The experiment found these MTC handshakes were 9% faster at median than classical certificate chains.

That result is promising, but it needs context: the test used classical signatures, and much of the speed gain came from omitting intermediate certificates. It was not yet a production measurement of full post-quantum MTC signatures. Cloudflare expects the compact format to help more as PQ signatures enter the handshake, but the production CA, browser support, root-program approval, and independent monitoring still have to come together.

A Cloudflare Customer Roadmap: Now, Before 2027, At Launch

TimingCloudflare service or actionCustomer outcome
NowMeasure visitor and origin TLS groups in Analytics and LogpushIdentify which connections use X25519MLKEM768 and which still use classical groups
NowUse Automatic Key Exchange; enable PQ groups on capable originsCloudflare can choose a post-quantum origin key exchange where supported
NowConfigure ML-DSA with AOP and, where appropriate, COTSAdd post-quantum authentication to Cloudflare-to-origin TLS
NowUse CT Monitoring and Radar; use Tunnel for hard-to-upgrade originsFind unexpected certificates and protect the tunnel leg without replacing a legacy origin
Before launchInventory ACME clients and test ARI; map browser and root-store requirementsPrepare renewal automation and avoid a rushed migration
From Q1 2027 (target)Evaluate Cloudflare’s public ACME CA and MTC support after issuance launches and required approvalsAdd a post-quantum certificate option under the proposed shared lifecycle

If your origin cannot issue or validate MTCs yet, you do not need to wait to improve security. Use Cloudflare’s current key-exchange controls and telemetry, deploy ML-DSA authentication on origin connections where it fits, and make certificate issuance visible. The planned CA is meant to make the next step easier, not to replace protections already available.

Conclusion: Cloudflare’s PQC Offer Is a Migration Path

Cloudflare’s announcement is more than a plan to sell certificates. It connects its existing managed certificate foundation, including Universal SSL, with current PQC services Automatic Key Exchange, ML-DSA support in AOP and COTS, Tunnel, Radar, Logpush, and Certificate Transparency Monitoring and a future public CA designed for classic and post-quantum issuance. Universal SSL is the existing certificate-management service; the PQC controls listed here provide the post-quantum protections and visibility.

The distinction matters: the CA and MTC issuance are planned for 2027, while Cloudflare’s origin key-exchange, ML-DSA authentication, and visibility capabilities are already available. Teams can use those services now, prepare ACME clients for ARI, monitor for downgrade certificates, and adopt MTCs when issuance and client trust are ready. That staged approach is Cloudflare’s proposed route to post-quantum certificates without making customers choose between stronger authentication and a working website.

To further enhance your cloud security and PQC readiness, contact me on LinkedIn Profile or [EMAIL].

Frequently Asked Questions (FAQ)

Is Cloudflare becoming a certificate authority?

Yes. Cloudflare announced its intention to become a public CA on September 29, 2026. It applied to the Chrome, Apple, Microsoft, and Mozilla root programs and signed an agreement to acquire a GlobalSign root. Cloudflare is not issuing certificates yet; production MTCs are targeted for Q1 2027, subject to the root-program process.

What are Merkle Tree Certificates and why do they matter for PQC?

MTCs batch certificate entries into an append-only Merkle tree, allowing the CA to sign a tree checkpoint while clients verify an individual certificate with a compact inclusion proof. This is designed to make post-quantum certificate authentication more efficient than adding signatures roughly 40 times larger to every traditional certificate chain.

Can customers get Cloudflare MTC certificates now?

No. Cloudflare has announced plans to offer standard MTC issuance at no cost through an ACME-first service, targeting Q1 2027. The CA is not issuing certificates yet and is still working through root-program processes. Cloudflare says ACME Renewal Information support will be required.

What post-quantum certificate features can Cloudflare customers use today?

Cloudflare supports ML-DSA certificates for origin authentication through Authenticated Origin Pulls and Custom Origin Trust Store. Customers can also use Automatic Key Exchange for post-quantum origin key agreement where supported, inspect TLS key-exchange telemetry, use Cloudflare Tunnel for legacy origins, and monitor Certificate Transparency. Public MTC issuance is a future service.

Why does Cloudflare want both an existing root and new roots?

A newly created root can take years to reach browsers and devices and may not reach clients that no longer receive updates. The GlobalSign root, trusted since 2012, is intended to provide broad compatibility, while new roots are intended to meet future root-program policies, including rules about root age.

What should security teams do now to prepare?

Measure X25519MLKEM768 on visitor and origin connections, enable post-quantum key exchange where origins support it, consider ML-DSA origin authentication with AOP and COTS, and monitor CT logs for unexpected classical certificates. Before Cloudflare CA issuance launches, check ACME client support for ARI and follow root-program updates.

Resources


William OGOU

William OGOU

Need help implementing Zero Trust strategy or securing your cloud infrastructure? I help organizations build resilient, compliance-ready security architectures.