Every time you see that little padlock next to a web address, a quiet bit of math is vouching for the site you’re visiting. That math has a looming problem. Quantum computers could someday crack it, so the companies that run the web’s trust system are starting a rebuild that will take years to finish.
- Cloudflare announced in late September 2026 that it plans to become a public certificate authority issuing free, quantum-safe certificates.
- Its new post-quantum format, called Merkle Tree Certificates, is part of a broader redesign, since a simple algorithm swap would bloat every connection with extra data.
- No certificates are being issued yet, and the wider overhaul will involve browsers, operating systems, and infrastructure providers for years.
What Your Padlock Actually Does
When you type an address into your browser, how do you know you’ve reached the real site and not an impostor? That job falls to the Web Public Key Infrastructure, or WebPKI. It’s a sprawling system of policies, protocols, and operators that work together so you aren’t quietly sent somewhere you didn’t mean to go.
TLS certificates sit at the center of it. A certificate authority issues one to a website, and your browser checks it each time it opens a new session with that server. This step is part of the TLS handshake. It happens constantly, usually in a blink, and most people never give it a thought.
Much of the internet’s encryption leans on algorithms like RSA and ECC, and the web’s core security tools were designed for a different era of computing. Corporate VPN sessions, API traffic, and archived session logs all rely on methods that quantum advances could expose if nobody updates them.
Why a Simple Swap Won’t Work
The obvious fix sounds easy. Replace the old math with quantum-resistant math and move on. Sadly, it doesn’t work that way.
Quantum-proof versions of today’s standard X.509 certificates would add roughly 40 times the data needed for each TLS handshake. Multiply that by every page load, app connection, and API call on the planet, and the extra bandwidth and computing load would break the internet as we know it.
There’s another wrinkle. Certificates also get recorded in transparency logs, which help make sure counterfeit certificates don’t get assigned to real websites. Any new signature scheme has to be compact enough to travel inside web requests and still fit into those logs. That’s why engineers describe the job as an architectural redesign. OpenSSL’s president has made the same point, arguing that smarter design will solve this problem and bigger network pipes won’t.
Cloudflare’s Bet on Merkle Tree Certificates
In late September 2026, Cloudflare said it intends to become a public certificate authority. That makes it one of the first authorities to commit to issuing certificates built on cryptography widely believed to resist quantum attacks.
The company plans to run an open source platform that issues two kinds of certificates side by side. One is the classic TLS certificate in use today. The other is a post-quantum format called a Merkle Tree Certificate. These hybrid certificates will be free for paying and non-paying Cloudflare users alike.
Trust is the hard part for any new authority. To help reach the sprawling TLS ecosystem, Cloudflare is acquiring an already trusted certificate root from GlobalSign. The company says this will let millions of websites turn on post-quantum certificates with the flip of a switch and with no added performance overhead.
Don’t expect it tomorrow, though. Cloudflare has said plainly that it isn’t issuing these certificates yet and that it will be a while before it does. For now, it’s committing to build in public, share milestones as they land, and work with browser root programs and others in the WebPKI community.
What Changes for Visitors and Site Owners
If you’re just browsing, you shouldn’t have to do anything. The goal is to replace the plumbing behind the padlock without slowing your pages down. Some groundwork is already in place, too. Cloudflare, Akamai, and Chrome have started using hybrid post-quantum key exchange, which pairs traditional encryption with quantum-safe methods to protect traffic.
Website owners have a little more to watch. If your site runs through Cloudflare, the plan is for post-quantum certificates to become a free toggle eventually. If you use a different provider, keep an eye on its roadmap. The broader shift depends on browsers, operating systems, certificate authorities, and infrastructure companies all moving together, and that takes a huge number of engineers and several years.
Keeping the Padlock Trustworthy in the Quantum Years
Nobody needs to panic about quantum computers cracking the web this week. Still, the people who maintain the internet’s trust system can see the clock ticking, and they’re choosing a careful redesign over oversized patches. Cloudflare’s free hybrid certificates and the trusted root it’s acquiring are among the first concrete steps. For everyday users, the best outcome is never noticing a thing. For site owners, it makes sense to stay informed and be ready to switch on quantum-safe certificates once your provider offers them.
