Cloudflare to Launch Post‑Quantum Merkle Tree Certificates in Early 2027
What Happened – Cloudflare announced it will become a public Certificate Authority and will issue both conventional TLS certificates and a new post‑quantum format called Merkle Tree Certificates (MTCs). Production issuance of MTCs is slated for Q1 2027, after the company acquires a trusted root from GlobalSign and completes pending root‑program applications with Chrome, Apple, Microsoft and Mozilla.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a cryptographic‑protection control that continuously validates the strength of algorithms against emerging threats (e.g., quantum‑capable adversaries).
- Provides a concrete example of a continuous‑evidence program: Cloudflare’s public health dashboard, reproducible builds, and automated renewal signaling give organizations verifiable proof of certificate lifecycle management.
- Aligns with the Control Mapping capability, enabling enterprises to map their TLS‑certificate processes to a single control objective that satisfies multiple frameworks (NIST CSF, ISO 27001, etc.).
Who Is Affected – Cloud‑infrastructure providers, SaaS platforms, e‑commerce sites, and any organization that relies on TLS certificates for web traffic encryption.
Recommended Actions
- Inventory all TLS certificates and record algorithm versions.
- Map your cryptographic‑algorithm control to the relevant VCF objective (e.g., “ensure cryptographic mechanisms are fit for purpose”).
- Begin a migration plan to support post‑quantum certificates once they become available, documenting each step for audit readiness.
Source: Help Net Security
Technical Notes
- MTCs use a lightweight proof‑of‑presence model to avoid transmitting heavy post‑quantum signatures on every handshake.
- Cloudflare will acquire a trusted root from GlobalSign and will rely on RFC 9773 for automated renewal signaling.
Source: same as above