Cloudflare’s New Quantum-Safe CA Uses Merkle Tree Certificates to Speed Up TLS

Cloudflare is developing a new certificate authority (CA) aimed at making post-quantum website authentication viable without overwhelming TLS handshakes with bulky signatures. This new system will issue standard digital certificates alongside “Merkle Tree Certificates” (MTCs), with plans to be included in Chrome’s upcoming Quantum-resistant Root Store as early as 2027. Importantly, Cloudflare intends for standard MTCs to be issued at no cost.

What’s the issue with quantum-safe authentication?

Current public key infrastructure trusts certificate authorities to verify domain control and bind domains to public keys, while Certificate Transparency (CT) logs record certificate issuance for auditing. But post-quantum signature schemes, which use much larger keys and signatures, risk inflating log storage demands—Cloudflare estimates an increase by a factor of 40. Combined with already substantial certificate and key exchanges in TLS handshakes, this could slow things down noticeably.

What are Merkle Tree Certificates?

MTCs replace the usual practice of individually signing each certificate and separately submitting it to logs. Instead, certificate data is written into an append-only Merkle tree structure. The CA signs a checkpoint that captures the tree’s current state. When a website receives its certificate, it also gets an inclusion proof: a chain of hashes proving its certificate is part of that signed tree. This makes certificate transparency an intrinsic part of issuance, rather than a separate step.

Cloudflare plans to use ACME for domain validation, leveraging software based on Let’s Encrypt’s Boulder—already being updated for MTC support. Once a domain is validated, certificate information goes into the log, a new checkpoint is signed, and a mirror (not under Cloudflare) co-signs to ensure consistency. Cooperative mirrors aim to catch any conflicting views of the log. After that, the system delivers a standalone MTC: the public key, inclusion proof, and necessary signatures.

Landmarks, speed gains, and deployment challenges

To trim TLS handshake size, MTCs introduce “landmarks,” trusted snapshots of portions of the Merkle tree delivered to browsers via channels outside of the handshake. During a connection, only lightweight inclusion proofs plus the public key and few signatures need transmission—replacing heavyweight post-quantum signatures. However, in cases where a browser lacks a current landmark or is in offline mode, standalone MTCs (with more data) are still needed.

In early trials—during rollout to about 50% of Chrome Beta 146 users—billions of certificates were issued for free-plan domains. The average handshake drop in data size (compared to traditional certificate chains) delivered about a 9% speed improvement. But this test still employed classical (non-post-quantum) signatures. Some of the speed gains owed to removing the intermediate certificate, not just to the structure of MTCs themselves.

Where it stands now and what’s ahead

MTCs are still being formalized. The design currently exists as an Internet-Draft under the IETF PLANTS working group, not yet finalized into a standard. Cloudflare must also pass Chrome’s root-store review before browsers officially trust these certificates. At scale, the greatest tests will be whether CA mirrors, independent monitors, and multiple issuers can reliably handle logs across the global internet.

Security teams implementing post-quantum authentication must stay alert. Legacy (traditional) certificates could create downgrade paths. Monitoring for their improper use or presence will remain crucial to maintaining the integrity of trust infrastructures.

Why it matters: The web is moving toward quantum-safe encryption because quantum computers threaten to break widely used cryptography. Cloudflare’s approach gives a way to make that transition without crippling performance or infrastructure costs. Landmarks and Merkle trees could reshape how certificates work in the quantum era.