Home › Intelligence › Brief
BREACH BRIEF⚪ Informational Advisory

Cloudflare to Launch Post‑Quantum Merkle Tree Certificates in Early 2027

Cloudflare will become a public Certificate Authority and begin issuing post‑quantum Merkle Tree Certificates in Q1 2027. The move highlights the need for continuous cryptographic‑control assurance and provides a transparent evidence model for audit readiness.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 helpnetsecurity.com
⚪
Severity
Informational
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
2 recommended
📰
Source
helpnetsecurity.com

Cloudflare to Launch Post‑Quantum Merkle Tree Certificates in Early 2027

What Happened – Cloudflare announced it will become a public Certificate Authority and will issue both conventional TLS certificates and a new post‑quantum format called Merkle Tree Certificates (MTCs). Production issuance of MTCs is slated for Q1 2027, after the company acquires a trusted root from GlobalSign and completes pending root‑program applications with Chrome, Apple, Microsoft and Mozilla.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a cryptographic‑protection control that continuously validates the strength of algorithms against emerging threats (e.g., quantum‑capable adversaries).
  • Provides a concrete example of a continuous‑evidence program: Cloudflare’s public health dashboard, reproducible builds, and automated renewal signaling give organizations verifiable proof of certificate lifecycle management.
  • Aligns with the Control Mapping capability, enabling enterprises to map their TLS‑certificate processes to a single control objective that satisfies multiple frameworks (NIST CSF, ISO 27001, etc.).

Who Is Affected – Cloud‑infrastructure providers, SaaS platforms, e‑commerce sites, and any organization that relies on TLS certificates for web traffic encryption.

Recommended Actions

  • Inventory all TLS certificates and record algorithm versions.
  • Map your cryptographic‑algorithm control to the relevant VCF objective (e.g., “ensure cryptographic mechanisms are fit for purpose”).
  • Begin a migration plan to support post‑quantum certificates once they become available, documenting each step for audit readiness.

Source: Help Net Security

Technical Notes

  • MTCs use a lightweight proof‑of‑presence model to avoid transmitting heavy post‑quantum signatures on every handshake.
  • Cloudflare will acquire a trusted root from GlobalSign and will rely on RFC 9773 for automated renewal signaling.

Source: same as above

📰 Original Source
https://www.helpnetsecurity.com/2026/09/30/cloudflare-certificate-authority-2027/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →