Why We Need to Prepare for the Quantum Threat Now
I've been waiting for a major player to move in this direction. Cloudflare announced plans to issue quantum-resistant TLS certificates designed to withstand attacks from future quantum computers. The company will be one of the first certificate authorities to offer this kind of protection at scale. And importantly, the new hybrid certificates will be free for both paid and free users.
This is a big step for the whole internet. Almost every site today uses TLS certificates to encrypt traffic and verify authenticity. If quantum computers learn to break classical cryptography, banking, email, messengers, and corporate systems will all be at risk. Cloudflare wants to prepare the infrastructure ahead of time, not wait until the threat becomes real.
According to the company's plan, the transition should be as easy as possible for site owners. Millions of properties already on Cloudflare's network will be able to enable post-quantum protection with essentially one switch. And, as the provider promises, there won't be a noticeable drop in performance or an increase in page load latency.
How the Hybrid Certificates Work
The solution is built on an open-source platform that issues two types of certificates at once. The first is a classic TLS certificate, the kind used everywhere today. The second is its post-quantum counterpart, known as Merkle Tree Certificates.
This hybrid approach is considered the most practical during the transition. Old browsers and systems keep working with familiar cryptography, while new clients can verify the quantum-resistant signature. That avoids the situation where some users suddenly lose access to a site due to incompatibility.
Cloudflare also stresses transparency. All issued certificates must be logged in Certificate Transparency logs so nobody can secretly issue a fake certificate for someone else's domain. That's where one of the main technical challenges lies: post-quantum signatures are usually much heavier than classical ones, harder to transmit on every connection, and harder to store in logs.
Why Cloudflare Is Buying a Root From GlobalSign
To make the new system work everywhere right away, Cloudflare has agreed to acquire an already-trusted root certificate from certificate authority GlobalSign. And this is the key detail in the whole story.
The thing is, browsers and operating systems only trust a limited list of root CAs. Getting a new root from scratch and having it recognized across all devices is a process that takes years. Buying a ready-made trusted root from GlobalSign lets Cloudflare skip that long path and make post-quantum certificates recognized by default right away.
This move shows just how serious Cloudflare is about fast adoption. The company is essentially buying the ecosystem's trust so it doesn't have to wait for software makers to update their root stores. For site owners, this means fewer technical barriers and a faster transition to new standards.
Why Rebuilding WebPKI Will Take Years
Cloudflare's plans are only part of a much bigger rebuild of the internet's public key infrastructure, known as WebPKI. Moving to the post-quantum era will require fundamental architectural changes, not just swapping one algorithm for another.
The problem is the scale of the ecosystem. Engineers building operating systems, browsers, crypto libraries, certificate authorities, and network infrastructure all have to work on compatibility. Standards must be agreed on, protocols updated, signature verification code rewritten, and everything tested across billions of devices—from smartphones to servers to IoT sensors.
Experts have long warned about the "harvest now, decrypt later" scenario, where attackers intercept encrypted traffic today hoping to decrypt it years later using quantum machines. That's exactly why preparation can't wait until a powerful quantum computer exists. The sooner sites move to hybrid certificates, the less valuable data is at risk of retrospective decryption.
What It Means for Business and Regular Users
For businesses, Cloudflare's news is a signal to start preparing for the post-quantum transition now. This is especially true for banks, healthcare services, government agencies, marketplaces, and any company holding data with a long secrecy lifetime. Free certificates remove the financial barrier, and the promised lack of overhead makes the solution attractive even for high-traffic projects.
Regular users will likely not notice any changes at all. Sites will keep loading as before, and the padlock icon in the browser isn't going anywhere. The difference will be hidden inside the protocol: the connection becomes resistant to future attacks. In a world where more and more processes are handed to AI agents—from customer support to payment processing—this invisible protection becomes critical for trusting automation.
It's telling that an infrastructure giant is taking on the role of the locomotive for change. If Cloudflare's experiment succeeds, other certificate authorities and cloud providers will be forced to follow. And understanding how an AI agent automates sales while safely handling customer data in the new quantum-resistant environment is becoming more important for companies of any size.
