Let's Encrypt

Let's Encrypt Commits to Merkle Tree Certificates for Post-Quantum Authentication

Let's Encrypt Commits to Merkle Tree Certificates for Post-Quantum Authentication

Let's Encrypt announced it will adopt Merkle Tree Certificates as its path toward post-quantum web authentication, targeting a staging environment capable of issuing them by late 2026 and production readiness the following year. Given that Let's Encrypt issued the majority of public TLS certificates in the most recent quarter reported, this single decision effectively makes MTCs the practical standard for most of the encrypted web, rather than a niche alternative.

Why authentication, not just encryption

Most post-quantum discussion up to this point has focused on encryption — specifically the "harvest now, decrypt later" threat, where an adversary records encrypted traffic today to decrypt once a sufficiently powerful quantum computer exists. Authentication has received comparatively less attention, since forging a signature in real time requires that same quantum computer to already exist and be usable live, not retroactively. Let's Encrypt's announcement argues that calculation is shifting, citing NSA and NIST guidance both pointing toward a 2030-2035 window for cryptographically relevant quantum computing.

Building on existing infrastructure

Let's Encrypt has operated Merkle-tree-based Certificate Transparency logs since 2019, giving the organization direct production experience with the core data structure MTCs depend on — a meaningful head start compared to adopting an entirely unfamiliar architecture from scratch.

What this means for a typical site today

Nothing immediate. This is infrastructure planning with a multi-year horizon, not a change that affects how you request or install a certificate right now. It's worth knowing about mainly as context: the certificate ecosystem's quantum-readiness work is genuinely underway, not purely theoretical, and the specific approach the industry converges on is becoming clearer over the course of this year.

This is our own summary and analysis of publicly reported news, written independently — not a reproduction of any single source's article. Where we reference a specific announcement, we link to it or name the organization directly.