
Cloudflare becomes a CA and will issue Merkle Tree Certificates
Cloudflare has announced that it is building its own certificate authority and aims for inclusion in Chrome's Quantum-resistant Root Store in early 2027. Standard Merkle Tree Certificate issuance will be free of charge.
Cloudflare said on September 29, 2026 that it is becoming a certificate authority and that the new CA will issue Merkle Tree Certificates (MTCs), targeting Chrome's Quantum-resistant Root Store in early 2027.
The Web PKI is what lets a browser decide whether it is connecting to the right website. Quantum computers have pushed the industry to upgrade to post-quantum (PQ) cryptography by 2029, but Cloudflare argues that swapping in PQ signatures at Internet scale would cost too much performance.
Why PQ signatures break the current model
To authenticate about a billion TLS servers, the Web PKI uses certificate chains to distribute trust instead of preloading every public key into every client. Revocation checks and certificate transparency (CT) added more signatures: a typical TLS handshake now carries five signatures and two keys. PQ signatures are about 40 times larger, and Cloudflare estimates they would balloon CT log storage by 40x.
Cloudflare has run the Nimbus CT logs since 2016 and is now launching Raio, a family of static logs.
How Merkle Tree Certificates work
MTCs are a draft specification from the IETF PLANTS working group. Certificates are batched into an append-only Merkle tree, and the CA signs the root of that tree instead of many individual certificates. A browser verifies a certificate with a compact inclusion proof checked against a signed tree head. Cloudflare sums up the rule as: "don't log what you issue, issue by logging."

The CA still validates domain control and issues certificates, but it also runs mirroring cosigners that keep a copy of the issuance log and check it stays append-only. Chrome's Quantum-resistant Root Program requires at least two cosignatures. MTCs fit the X.509 format: standalone certificates carry a cosigned tree head and an inclusion proof, landmark-relative ones only the lightweight proof.
Chrome experiment: billions of certificates
Cloudflare ran a bootstrap CA that issued MTCs backed by a traditional chain for selected free-plan domains and served them to 50% of Chrome Beta 146, delivering billions. A landmark-relative certificate needs one public key, one signature and an inclusion proof under 1 kB in the handshake, and at median landmark MTCs were 9% faster than a classical chain. The experiment wound down in August 2026.
What remains open
Cloudflare says open questions need the full PKI ecosystem: whether independent monitors can verify MTC logs at production volume, whether enough CAs and cosigners will emerge, and how browsers should balance landmark certificates against fallbacks. Before its CA can be trusted, the company must apply to Chrome's Quantum Resistant root store and pass a rigorous evaluation.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.