Cloudflare Said on 29 September 2026 It Will Become a Public Certificate Authority: From Chrome's February Decision to the First Post-Quantum Merkle Tree Certificates in Early 2027
In 1858 the colony of South Australia changed how land was owned. Under the old deeds system a buyer proved title by tracing a chain of conveyances back through every previous owner, and each link could hide a forgery. Robert Torrens's Real Property Act made the government register itself the title: a name entered in the register was the owner, subject to statutory exceptions such as fraud, and the chain of paper behind it largely stopped mattering. Lawyers still call the idea "title by registration."
The web's certificate system is about to make a similar move. Today a browser trusts a site by checking a chain of signatures from the site's certificate up to a root it already knows. The replacement that Chrome has chosen for the post-quantum era, Merkle Tree Certificates, works more like the Torrens register. Cloudflare's engineers sum up its key idea as "don't log what you issue, issue by logging." On 29 September 2026 Cloudflare said it intends to run one of the first registers of this kind as a public certificate authority. The steps that led there, and the dates that follow, are below.
Practical takeaway. Key exchange on the web is already largely post-quantum: Cloudflare reports that about 70 percent of browser traffic reaching its network uses hybrid ML-KEM, while only about 15 percent of the origin servers it connects to do. Authentication is the half still waiting, and its route now runs through Chrome's Quantum-resistant Root Store and a certificate format that is still an IETF draft. Cloudflare targets its first production certificates for early 2027, subject to admission by Chrome.
What Chrome decided in February 2026: no post-quantum X.509 certificates in its root store
The starting problem is size. Cloudflare's engineers count five signatures and two public keys in a typical TLS handshake once revocation and certificate transparency are included, and post-quantum signatures are roughly forty times larger than the classical ones they replace. Swapping them into today's chains would slow every connection and swell the public transparency logs, which Cloudflare estimates would need to store about forty times more data. Quentir's read of Cloudflare's 1.1.1.1 resolver validating ML-DSA-44 signatures in DNSSEC showed the same size problem in another protocol, where each signature runs to 2,420 bytes.
Chrome's answer, as its draft root policy recalls, was announced in February 2026: Chrome will not add traditional X.509 certificates containing post-quantum cryptography to the Chrome Root Store. Post-quantum trust would instead come through a separate Quantum-resistant Root Store made up of Merkle Tree Certificate authorities and independent mirroring operators. The decision governs trust in Chrome only, but it strongly shapes deployment incentives for every CA and site that wants its post-quantum certificates to work in Chrome.
What the Chrome Beta 146 experiment measured before Cloudflare wound it down in August 2026
During 2026 Cloudflare and Chrome tested the format on real traffic. Cloudflare ran a "bootstrap CA" that issued Merkle Tree Certificates, backed by a conventional chain, for a selection of domains on its free plan, and served them to half of Chrome Beta 146. Cloudflare reports serving billions of these certificates. In the common case the handshake carried one public key, one signature and an inclusion proof of under one kilobyte. At the median, connections were 9 percent faster than with a classical chain, and Cloudflare concedes that most of the gain came from dropping intermediate certificates. The test used classical signatures, so the gain with post-quantum signatures is still an expectation. The experiment began winding down in August 2026.
The mechanism behind those numbers is the tree. A CA adds each certificate to an append-only Merkle tree and signs the tree head once for the whole batch. A browser that already holds a recent signed tree head, delivered out of band as a "landmark," needs only a short chain of hashes to confirm that a site's certificate is in the tree. Servers keep a standalone form as a fallback for browsers that are offline or newly installed.
What the IETF PLANTS draft of 21 September 2026 specifies, and who wrote it
The format is defined in draft-ietf-plants-merkle-tree-certs, now a working-group document of the IETF's PLANTS group. Version 06 was posted on 21 September 2026, eight days before Cloudflare's announcement. Its authors are David Benjamin, Devon O'Brien, Bas Westerbaan, Luke Valenta and Filippo Valsorda. It is an Internet-Draft and not an RFC, so the details can still change.
Chrome has written its own rules on top of the draft. The Chrome Quantum-resistant Root Program policy, still a draft at version 0.3.0, requires at least two cosignatures on every standalone certificate and on every checkpoint served as a landmark. One comes from the issuing CA and, as Cloudflare reads the policy, one from a mirroring cosigner run by a separate organization, which keeps its own copy of the log and checks that it only grows. The policy also caps the trusted life of a CA cosigner key at six years, requires each operator to hold between three and six such keys, and obliges every MTC CA to offer both standalone and landmark certificates.
What Cloudflare announced on 29 September 2026: four root-program applications and a GlobalSign root
Cloudflare published three posts that day. The announcement says it has applied to the Chrome, Apple, Microsoft and Mozilla root programs and signed a definitive agreement to acquire an existing root from GlobalSign, trusted across browsers and devices since 2012. The acquired root covers old devices that a new root never reaches; the new roots are meant for programs that are starting to limit how old a trusted root may be. The company, which has consumed certificates from 16 partner CAs for years without issuing one, gives two reasons. Certificate volumes will rise as validity periods shrink and agents multiply. And the free, automated web now depends heavily on one operator: Let's Encrypt, which by Cloudflare's count issues on the order of ten million certificates a day and serves more than 500 million sites.
The operating commitments are specific. Issuance will run only through ACME, and only to clients that support ACME Renewal Information under RFC 9773, so that Cloudflare can bring renewal windows forward when certificates have to be replaced in a hurry. Cloudflare promises reproducible builds of its signing software, attested hardware security modules and a public dashboard of issuance health and incidents. The companion post on Merkle Tree Certificates adds that standard MTC issuance will be free, that the ACME server will be a fork of Let's Encrypt's Boulder, and that Cloudflare will run mirrors for other pilot CAs while requiring an independent cosignature on its own certificates.
Which dates come next: early 2027, 15 September 2027, and the 2029 target
Cloudflare's CA announcement targets its first Merkle Tree Certificates for the first quarter of 2027, and its MTC post says early 2027. Both depend on admission to Chrome's Quantum-resistant Root Store after what Cloudflare calls a rigorous evaluation, so the date is a target. Chrome's draft policy then makes pre-issuance linting mandatory from 15 September 2027: from that date a non-conforming certificate may not even be added to the issuance log. Cloudflare has set 2029 as the year to complete its own move to post-quantum cryptography. For public-sector planners the American reference point remains NIST IR 8547, whose November 2024 draft would deprecate quantum-vulnerable algorithms at the 112-bit security level, such as 2048-bit RSA, after 2030 and disallow all of them after 2035.
Key exchange followed a faster path because it needed no new trust infrastructure: libraries and browsers could switch it on, as Java 27 did with hybrid TLS by default. Authentication needs CAs, mirrors, monitors and root programs to agree, and the 15 percent origin figure shows how slowly even the easier half moves on the server side.
How Quentir Reads It
The Torrens register worked because the state stood behind it. Merkle Tree Certificates put the equivalent guarantee in two places: the cosigners who keep independent copies of each log, and the root programs that decide who may keep a log at all. In our reading, Chrome's root program is acting as the de facto regulator of post-quantum web authentication. The cosigners confirm that each log is consistent and only grows. Correct issuance still rests on each CA's own validation and on outside monitors, and no state fund stands behind any of it. Its draft policy sets key lifetimes, cosignature counts and a linting deadline in the language of MUST and SHOULD, and no legislature or standards body has set comparable dates for the web. For people using the web that is mostly good news: the rules are public and the logs are open to anyone. It also means that one browser vendor's draft policy, still at version 0.3.0, strongly shapes how sites that want Chrome compatibility will prove their identity once post-quantum signatures are in use.
Cloudflare's entry raises a question of market structure as well. A company that already terminates TLS for a large share of the web, runs certificate transparency logs and will run mirrors for other CAs now proposes to issue the certificates too. It offers redundancy against a single dominant free issuer, and it adds one more role held by the same firm. The independent-cosignature rule is the safeguard to watch, because it only works if mirrors run by other organizations actually appear. For readers who follow post-quantum authentication instrument by instrument, our Signature Brief editions answer one clearly framed question in depth, with the instruments, the dates and the questions to ask, under an internal-use license. The open question for 2027 is how many independent CAs and mirrors will be in Chrome's Quantum-resistant Root Store when the first certificates go live.
Sources: Cloudflare, Steve Goldsmith, "Building a certificate authority for the whole Internet" (29 September 2026); Cloudflare, Mari Galicer, "Building a post-quantum certificate authority with Merkle Tree Certificates" (29 September 2026); Cloudflare, Andrew Depke, Sophie Park and Sharon Goldberg, "Is your domain using post-quantum encryption? Now you can see for yourself" (29 September 2026); IETF PLANTS working group, draft-ietf-plants-merkle-tree-certs-06, Merkle Tree Certificates (Internet-Draft, 21 September 2026); Google Chrome, Chrome Quantum-resistant Root Program Policy, version 0.3.0 (draft) (accessed 30 September 2026); IETF, RFC 9773, ACME Renewal Information; NIST, IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards (November 2024); South Australia, Real Property Act 1858. Quentir, Cloudflare 1.1.1.1 and ML-DSA-44 in DNSSEC (September 2026) and Java 27 and JEP 527 (September 2026).
Published intelligence, built to inform your own decisions. Published: September 30, 2026.