Let's Encrypt said it will use Merkle Tree Certificates (MTCs) as its preferred approach for post-quantum authentication on the public web, arguing that conventional post-quantum signatures such as ML-DSA would make standard TLS certificate chains too large for reliable internet-scale handshakes. The model batches certificate issuance under a single signed Merkle tree head and delivers compact inclusion proofs, reducing handshake overhead while making Certificate Transparency inherent to issuance. Let’s Encrypt said current subscribers do not need to take immediate action, but future ACME clients and related tooling will need updates as the ecosystem moves toward the new format.
The move aligns Let’s Encrypt with broader work by Google, Cloudflare, Chrome, DigiCert, and the IETF, as browser and infrastructure vendors push for scalable post-quantum TLS ahead of government migration deadlines from the NSA, NIST, and the EU. Let’s Encrypt plans a staging environment for MTC issuance in late 2026 and a production-ready deployment in 2027, while continuing to track ML-DSA support for traditional X.509 use cases outside the browser ecosystem. It also said the more urgent near-term defense remains post-quantum encryption against harvest-now-decrypt-later threats, urging operators to enable hybrid key exchange such as:
X25519MLKEM768

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
In the same announcement, Let's Encrypt said it plans to offer a staging environment for MTC issuance in late 2026 and aims for a production-ready deployment in 2027. It also said it will continue standards work and ecosystem tracking around MTCs and ML-DSA support.
On June 3, 2026, Let's Encrypt announced that it will pursue Merkle Tree Certificates as its preferred approach for post-quantum-safe Web PKI authentication, citing the impractical size of conventional post-quantum signatures such as ML-DSA in standard TLS handshakes. The announcement said nothing changes immediately for current users and emphasized that hybrid post-quantum key exchange remains the more urgent near-term priority.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
7 references tracked. Mallory keeps watching after this page renders.
postquantum.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcetechtimes.com
Open sourcesecurityonline.info
Open sourceletsencrypt.org
Open sourceletsencrypt.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.