Cloud & infrastructure

Cloudflare plans to become a public certificate authority for the internet

Cloudflare has applied to join major root programs and agreed to acquire a GlobalSign root to issue free, automated TLS certificates and post-quantum Merkle Tree Certificates.

Cloudflare announced on September 29, 2026, its intent to operate as a public certificate authority (CA). The company has applied for inclusion in the root programs of Chrome, Apple, Microsoft, and Mozilla while signing an agreement to acquire an existing trusted root from GlobalSign. This move aims to provide a redundant, free source of TLS certificates for the wider internet.

What happened

For over a decade, Cloudflare has been one of the largest consumers of publicly trusted certificates without issuing any itself. During its 2024 Birthday Week, the company enabled Universal SSL, which doubled the number of encrypted sites by providing free TLS to all customers. Now, twelve years later, Cloudflare is taking the next step by building its own CA infrastructure. The goal is to offer certificates with broad device compatibility from day one while preparing for future cryptographic standards.

To achieve immediate trust across older and newer devices, Cloudflare is pursuing a dual-root strategy. It has signed a definitive agreement to acquire an established root from GlobalSign, which has been trusted since 2012. This existing root ensures coverage for legacy clients that do not receive updates. Simultaneously, Cloudflare is submitting a new root for inclusion in modern root programs. This new root is designed to meet emerging policies, such as caps on root age, ensuring long-term compliance and security.

The announcement also highlights a commitment to redundancy in the web’s encryption infrastructure. Currently, Let's Encrypt issues approximately ten million certificates daily, serving more than 500 million sites. While this has been transformative for web security, it creates a systemic risk if the dominant provider experiences outages. Cloudflare intends to serve as a backup and alternative source, using the Automated Certificate Management Environment (ACME) protocol to ensure easy adoption for users already relying on other free CAs.

How it works

Cloudflare’s CA will be ACME-first, meaning it uses an open standard protocol for automated certificate issuance and renewal. Users can switch to Cloudflare’s CA by simply changing a directory URL in their existing tools, requiring no new software or architectural changes. To enhance reliability, the CA will mandate the use of ACME Renewal Information (ARI), standardized in RFC 9773. This requires subscribers to automate renewal polling and act on published renewal windows, reducing the risk of expired certificates causing downtime.

A key technical innovation is the planned issuance of Merkle Tree Certificates (MTCs). These are compact certificates designed for a post-quantum world, where traditional certificate chains become too large for efficient TLS handshakes. Chrome has identified MTCs as the preferred path for post-quantum authentication. Cloudflare aims to issue its first production MTCs in the first quarter of 2027. By supporting both classic certificates and MTCs under one CA, the company allows users to migrate gradually without running parallel systems.

Operational transparency is central to the design. Cloudflare plans to publish reproducible builds of its signing software and attest to the hardware security modules holding its keys. A public dashboard will display issuance health and incidents in real time, moving beyond point-in-time audits to show how the CA operates daily. This approach allows researchers and site owners to monitor reliability continuously.

Key details

  • Cloudflare has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs.
  • The company signed an agreement to acquire an existing trusted root from GlobalSign to ensure immediate broad compatibility.
  • The CA will be ACME-first, allowing easy migration for users of other free certificate providers.
  • Issuance will require support for ACME Renewal Information (ARI) to enforce automated renewal practices.
  • Cloudflare plans to issue its first production Merkle Tree Certificates (MTCs) in Q1 2027.
  • The service will provide both classic and post-quantum ready certificates through a single lifecycle.

Why it matters

For software engineers and IT leads, this development introduces a significant new option for managing TLS infrastructure. Relying on a single dominant free CA creates vulnerability to rate limits, validation errors, or outages. By adding a major, well-funded competitor to the space, Cloudflare helps decentralize trust and improves the resilience of the global encryption supply chain. This is particularly relevant as certificate validity periods shorten and the volume of automated agents increases.

The mandate for ACME Renewal Information also pushes the industry toward better automation practices. By requiring subscribers to handle renewal windows proactively, Cloudflare reduces the likelihood of sudden revocations causing widespread breakage. This shift encourages developers to build more robust certificate management workflows, which is critical as the internet transitions to post-quantum cryptography. The availability of MTCs will allow teams to prepare for larger key sizes without sacrificing performance.

What you can do

  • Register for updates from Cloudflare to track the progress of their root program applications.
  • Audit your current certificate issuance workflow to ensure it supports ACME Renewal Information (ARI).
  • Evaluate your dependency on a single certificate authority and consider adding a secondary provider for redundancy.
  • Review your TLS stack for compatibility with post-quantum algorithms and larger certificate chains.
  • Monitor the public dashboard once launched to understand operational patterns of the new CA.
  • Plan for a gradual migration to Merkle Tree Certificates starting in 2027 to avoid last-minute rushes.

Tools from the Bytechap store

Keep reading

All stories