Home › Intelligence › Brief
BREACH BRIEF⚪ Informational Advisory

Cloudflare Launches Post‑Quantum Certificate Authority Using Merkle Tree Certificates

Cloudflare is now a public‑key certificate authority issuing Merkle Tree Certificates that provide quantum‑resistant signatures at scale. The move gives organizations a clear, auditable path to meet emerging cryptographic control requirements.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 blog.cloudflare.com
⚪
Severity
Informational
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
blog.cloudflare.com

Cloudflare Launches Post‑Quantum Certificate Authority Using Merkle Tree Certificates

What Happened – Cloudflare announced that it is now operating a public‑key certificate authority (CA) that issues Merkle Tree Certificates (MTCs). MTCs embed post‑quantum‑resistant signatures while preserving performance at Internet scale. The service will be free, with the first Chrome‑compatible quantum‑resistant root store expected in early 2027.

Why It Matters for Trust & Control Assurance

  • Demonstrates a concrete path for meeting cryptographic‑control objectives that require quantum‑resistant algorithms, a control area increasingly referenced in audit frameworks.
  • Provides publicly auditable issuance via Cloudflare’s Certificate Transparency (CT) logs, giving organizations defensible evidence of compliance with transparency and key‑management requirements.
  • Enables continuous control‑assurance programs to capture evidence of a secure, future‑ready TLS authentication stack without sacrificing performance.

Who Is Affected – Enterprises and SaaS providers that rely on TLS for web services, CDN customers, and any organization that must demonstrate strong cryptographic controls to regulators or auditors.

Recommended Actions

  • Review your TLS certificate lifecycle policy and map the upcoming post‑quantum requirement to the relevant control objective (cryptographic protection).
  • Begin collecting evidence of current certificate issuance processes (CT log submissions, key‑management procedures) to support future audits.
  • Pilot MTC issuance for high‑risk external‑facing services and document the results in your control‑evidence repository.

Source: Cloudflare Security Blog

Technical Notes

  • Merkle Tree Certificates use a Merkle‑tree‑based aggregation of signatures to achieve post‑quantum security with low latency.
  • Cloudflare continues to operate the Nimbus CT log family and is adding the Raio static CT logs for transparent issuance.
  • The quantum‑resistant root store is slated for Chrome rollout in early 2027, aligning with industry timelines for PQ migration.

Source: Cloudflare Security Blog

📰 Original Source
https://blog.cloudflare.com/pq-ca-with-mtcs/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →