Imagine a city where every front door uses the same brand of lock, and a locksmith announces that a machine capable of picking all of them will exist eventually. Nobody knows when. The machine does not exist yet. But the locks take years to replace, and the doors keep opening a few billion times a day. Do you wait for the burglar, or do you start swapping cylinders now?
Cloudflare has picked the second option. On September 29, 2026, the company announced its intent to become a public Certificate Authority — the kind of organization that issues the digital certificates websites use to encrypt traffic and prove they are who they claim to be. It plans to issue both traditional certificates and post-quantum ones, built on a format called Merkle Tree Certificates. Production MTC issuance is scheduled for the first quarter of 2027.
Why a reviewer of AI tools cares about certificate plumbing
I spend most of my time poking holes in agent frameworks, and my usual complaint is that nobody counts the cost of the boring parts. An autonomous agent does not make one request. It makes hundreds. It fans out across APIs, scrapes pages, calls models, retries on failure, and does it again on a schedule. Every one of those calls rides on a TLS handshake, and every handshake carries certificate data.
Post-quantum cryptography has a known tax: the keys and signatures are bigger than what we use today. For a human loading a webpage once, bigger is an annoyance. For a fleet of agents hammering endpoints on loops, bigger is a line item. Cloudflare’s framing around Merkle Tree Certificates leans on exactly this point — making quantum-safe TLS faster rather than just making it exist. That is the part of this announcement that should interest anyone building agents, and it is the part that will get the least coverage, because “certificate format reduces handshake overhead” does not trend.
What is actually being promised
Strip the announcement down and you get four concrete things:
- Cloudflare intends to operate as a public CA, described as an open service rather than a closed product for its own customers.
- It will issue traditional certificates alongside post-quantum ones, which means no forced migration cliff.
- The platform will be open source.
- It is acquiring a trusted certificate root from GlobalSign to smooth the transition.
That last item is the least glamorous and the most important. A certificate authority is only useful if browsers already trust its root. Building trust from scratch takes years of audits and waiting for root programs to include you. Buying an existing root skips the line. It is a procurement decision, not a cryptography decision, and it is the reason the 2027 date is even plausible.
The skeptic’s column
Here is where I apply the same standard I use on AI products. An announcement of intent is not a shipped service. The gap between “we plan to become a CA” and “your browser trusts our post-quantum certificate and nothing breaks” is wide, and it runs through browser vendors, standards bodies, and every piece of middleware that has ever choked on an unfamiliar certificate field. Cloudflare controls its own side of that chain. It does not control the rest.
There is also the concentration question. Cloudflare already sits in front of an enormous share of web traffic. Adding certificate issuance to that stack is convenient and also puts more of the internet’s trust machinery in one place. Open sourcing the platform helps. It does not change where the traffic flows.
And the threat itself is still theoretical. No public quantum computer breaks today’s encryption. The argument for moving now is harvest-now-decrypt-later: traffic captured today can be stored and cracked whenever the hardware arrives. That argument is sound, and it is also unfalsifiable in the short term, which makes it excellent marketing material. I would rather have a CA that moved early than one that waited, but I am not going to pretend the urgency is measurable.
What I would watch
Between now and early 2027, the useful signals are not press releases. They are whether the open-source platform gets real external contributors, whether browser root programs publicly commit to the new format, and whether anyone outside Cloudflare publishes handshake measurements under agent-style load. If MTCs genuinely cut the post-quantum size penalty, that shows up in latency numbers, not in blog posts.
For now, file this under infrastructure doing its job quietly and correctly. Cloudflare is replacing the locks before the burglar exists, using a format designed to make the new locks cheaper to carry. That is unglamorous, defensible engineering. In a space where most announcements promise transformation and deliver a demo, I will take it.
🕒 Published: