Cloudflare Plans Quantum-Safe TLS Certificates With Merkle Proofs
Cloudflare plans to issue quantum-safe TLS certificates using a Google-announced Merkle Tree design that has kept pilot handshake data near today’s roughly 40-kilobyte level.

Key takeaways · 3
- 01
Track whether Cloudflare’s rollout preserves the approximately 40-kilobyte handshake size demonstrated in limited pilots.
- 02
Evaluate compact Merkle Tree proofs as an alternative to replacing every signature in a WebPKI chain.
- 03
Keep certificate-transparency monitoring in scope because public append-only logs remain an industry requirement.
Compact Certificate Proofs
Cloudflare plans to issue quantum-safe TLS certificates. [1] Google announced a Merkle Tree solution in February, and Google and Cloudflare have tested the design in limited pilot programs. [1] The pilots reduce handshake data to about 40 kilobytes, roughly the amount processed today. [1]
The current WebPKI uses a multi-link chain of quantum-vulnerable signatures to prove certificate authenticity. [1] Rather than replacing each signature with a resource-prohibitive quantum-resistant one, compact Merkle Tree proofs let a certificate authority sign one tree head representing millions of certificates. [1]
Transparency And Quantum Risk
Industry-wide rules require TLS certificates to be published in append-only distributed ledgers known as public transparency logs. [1] Website owners check those logs in real time to ensure no rogue certificates have been issued for their domains. [1] The transparency programs followed the 2011 DigiNotar hack, which enabled 500 counterfeit certificates for Google and other websites, including certificates used to spy on web users in Iran. [1] Once viable, Shor’s algorithm could forge classical encryption signatures and the public keys of certificate logs, potentially enabling forged signed certificate timestamps. [1]
What it means
Cloudflare’s plan would move a design already tested with Google toward certificate issuance while keeping pilot handshake data near today’s level. The key comparison is with the current WebPKI: instead of swapping every quantum-vulnerable signature for a resource-prohibitive quantum-resistant one, the design compresses proof into a signed tree head representing millions of certificates. Public transparency logs remain part of the trust model, while the approach changes the certificate proof structure around them. The practical measure to watch is whether deployment retains the pilot’s roughly 40-kilobyte handshake profile without weakening rogue-certificate checks. What the sources don't address: when Cloudflare will begin issuance or how broadly the design will progress beyond limited pilots.
The proposal targets a concrete migration obstacle: directly substituting quantum-resistant signatures into existing certificate chains would be resource-prohibitive. Compact Merkle proofs offer a different verification structure while keeping pilot handshake sizes comparable to current levels.
Why it matters
Put this to work — one session a day, built for your industry.
Create a free account for a daily session — eight questions and one real-work challenge, on the news that affects your role.
Start freeHow this developed
30 September 2026
Cloudflare Plans Quantum-Safe TLS Certificates With Merkle Proofs
30 September 2026
Event created from source cluster.