Cloudflare announced Tuesday a plan to issue quantum-proof TLS certificates, positioning itself as an early mover in post-quantum cryptography for web infrastructure. The company will acquire a trusted certificate root from CA GlobalSign to enable widespread deployment of these certificates with minimal performance impact.
The business logic is straightforward: by owning a certificate root, Cloudflare can issue both classical and post-quantum hybrid TLS certificates at no cost to users, accelerating adoption across its customer base while entrenching its position in the WebPKI ecosystem as the post-quantum transition accelerates.
The technical problem Cloudflare solves is real. Traditional quantum-resistant X.509 certificates would expand TLS handshake data by roughly 40 times, choking current internet infrastructure. Google introduced Merkle Tree Certificates in February as a workaround—hierarchical data structures that use cryptographic hashes to verify large information volumes with only a fraction of their contents. Cloudflare and Google have run limited pilot programs testing the design.
Merkle Tree proofs compress the handshake overhead to approximately 40 kilobytes, comparable to current requirements. This efficiency matters operationally: the current WebPKI relies on multi-link chains of signatures vulnerable to quantum attacks. Rather than replace each signature individually—a costly, distributed undertaking—Merkle Tree proofs replace these chains wholesale with compact, quantum-resistant alternatives.
Cloudflare has not yet begun issuing the certificates. Steve Goldsmith of Cloudflare said the company will share milestones and development details while collaborating with root programs and the broader WebPKI community, signaling a multi-year implementation timeline.
The economics favor early movers. Cloudflare controls a certificate root, reducing dependency on third-party certificate authorities and locking in user adoption through free issuance. As quantum threats mature and regulatory pressure mounts on encryption standards, owning infrastructure at the WebPKI layer positions Cloudflare as a critical node in enterprise security stacks.

