Cloudflare sets Q1 2027 target for quantum-resistant TLS certificates
The company says its planned free hybrid certificates will use Merkle Tree proofs to keep handshake data near current levels. Issuance has not begun.

Cloudflare expects to begin issuing free hybrid TLS certificates in the first quarter of 2027, adding a post-quantum option to the system that authenticates websites. The company says the certificates will be available to paying and non-paying users, but they are not being issued yet.
The plan uses Merkle Tree Certificates alongside conventional TLS certificates. Cloudflare says the design is intended to withstand quantum-computer attacks while keeping the data exchanged during a TLS handshake close to current levels.
That matters because replacing today’s certificate signatures with quantum-resistant alternatives could greatly increase the data carried in each handshake. Merkle Tree proofs instead let a certificate authority sign a single tree head representing many certificates, with browsers handling a compact proof for an individual certificate.
Cloudflare plans to acquire an already trusted certificate root from GlobalSign and says it is working with root programmes and other WebPKI participants. It also plans to support certificate issuance and renewal through ACME, with a mechanism to send signature updates separately if a server cannot provide them.
The wider shift to post-quantum website security will require changes across browsers, operating systems, certificate authorities and internet infrastructure, and is expected to take years. Cloudflare says it will share milestones as the work progresses.

