Let’s Encrypt declared on June 3, 2026, its commitment to deploying Merkle Tree Certificates (MTCs) to deliver a post-quantum-safe Web Public Key Infrastructure (PKI) without compromising TLS performance [1, 2]. This approach addresses the growing need for quantum-resistant authentication methods in web security.
Until recently, post-quantum cryptography efforts have focused primarily on encryption. However, authentication poses a critical challenge because quantum computers require real-time signature forgery capabilities to break existing TLS protections [1, 2]. Let’s Encrypt’s MTCs aim to overcome this hurdle.
Large signature sizes remain a key obstacle. For example, ML-DSA-44, a NIST-standardized post-quantum signature scheme recently added to Go 1.27’s standard library, produces signatures approximately 2,420 bytes long, much larger than current standards allow [1, 2]. This size impacts practical Web PKI deployment, making innovative approaches like Merkle trees necessary.
The shift to post-quantum cryptography is gaining urgency worldwide. The U.S. National Security Agency’s CNSA 2.0 suite outlined a transition to post-quantum algorithms between 2030 and 2035, mandating national security systems adopt these schemes within that timeframe [1, 2]. Similarly, NIST plans to deprecate widely used algorithms like RSA-2048 and P-256 after 2030, with disallowance after 2035 [1, 2].
In Europe, the Union targets post-quantum migration for high-risk systems by 2030, with broader adoption across all relevant infrastructure by 2035 [1, 2]. Large industry players are also preparing, with Google pledging to migrate its services to post-quantum algorithms by 2029, followed by Cloudflare [1, 2].
Let’s Encrypt’s approach with MTCs could help address these challenges by enabling scalable post-quantum authentication with manageable performance overheads. Their public commitment marks a concrete step toward readying the global Web PKI for a post-quantum future.
The next major milestones include Google’s migration to post-quantum algorithms by 2029 and the EU’s 2030 deadline for high-risk system upgrades, ahead of the NSA and NIST’s 2030–2035 timeline for broader adoption [1, 2].