Cloudflare has announced its intent to become a public certificate authority. The company has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs, and has signed a definitive agreement to acquire a broadly trusted root from GlobalSign. It also plans to be among the first CAs to serve post-quantum certificates, targeting Chrome's Quantum-resistant Root Program.

No certificates are being issued yet. Cloudflare says it is committing to the work publicly and will share milestones as they land, while working with the root programs and the WebPKI community.

Why an existing root, and why a new one

A brand-new root is not widely useful for years. Even after a root program accepts it, it must propagate into operating systems, browsers, and devices, and it never reaches the large set of devices that have stopped receiving updates or never received them at all. That long tail of older clients carries a great deal of Internet traffic and a correspondingly large share of avoidable breakage.

Buying an established root addresses that on day one. The GlobalSign root has been trusted across browsers, operating systems, and devices since 2012, and reaches older clients a fresh root never will. The new root being submitted for inclusion is built for where the ecosystem is heading, including programs that are starting to cap how old a trusted root may be. The established root provides reach across devices of the past; the new roots provide standing under the policies of the future. Cloudflare wants both for the widest customer compatibility.

A second free certificate source

The free, automated certificate model now carries most of the encrypted web, and much of it runs through a single operator. Let's Encrypt issues on the order of ten million certificates a day, serves more than 500 million sites, and passed four billion active certificates in 2025. Cloudflare calls it one of the best things to happen to the Internet in twenty years, and says so as one of its largest users.

That concentration is a systemic risk: if the dominant free CA had a bad week, much of the web would have no comparable free, automated alternative ready to take the load. At the certificate pack level, Cloudflare has already built this redundancy for its own customers — every Universal SSL certificate ships with a backup certificate, wrapped with a separate key and issued from a different authority, ready to deploy automatically if the primary is revoked or compromised. A public CA is that idea at the scale of the whole Internet.

Adoption is meant to be ACME-first. Automated issuance and renewal through the Automated Certificate Management Environment will be the way to get a certificate, so anyone already pointed at an existing free CA can move by changing a directory URL, with no new tooling and nothing to re-architect.

Issuance at Cloudflare scale

Cloudflare sits in front of more than 20 percent of global Internet request traffic and terminates TLS for millions of domains, relying on millions of certificates per year. It provisions those through multiple CAs, with primary and backup paths so customer services stay up through CA outages and revocation events.

Operating as a large consumer has exposed the company to rate limits, validation edge cases, revocation latency, chain building, and root distribution lag, and to the CA churn of recent years felt through its customers. Cloudflare frames reliable issuance as something it learned from the outside, because customers' uptime depended on resilience when an issuer had a bad day.

As the certificate maximum validity period decreases over the next few years, agentic activity increases, and PQ certificates go mainstream, Cloudflare expects the raw number of certificates it relies on annually to keep growing quickly — and it does not expect to be alone. The goal is not just to solve this for itself, but to add providers to the certificate supply chain for its customers.

Designing to fail small

Cloudflare says it intends to build a CA whose reliability depends not only on avoiding mistakes but, like the rest of its products, on limiting the impact of any single issue — designing and testing recovery before an incident occurs.

One concrete consequence: renewal automation will be a condition of issuance. The company will only issue to clients that support ACME Renewal Information (ARI), standardized in RFC 9773. Subscribers must maintain automation that polls the renewal endpoint, acts on published renewal windows, and identifies the certificate it is replacing.

This also addresses a pattern observed over 16 years, in which CAs get caught between timely revocation and keeping subscribers online because too many could not replace certificates quickly enough. When certificates must be retired — for a compliance issue or a security incident — renewal windows for affected certificates can be brought forward, replacements spread across the available time, and replacement issuance tracked.

Cloudflare plans to publish reproducible builds of the software that signs certificates, attest the hardware security modules holding its keys, and run a public dashboard for issuance health and incidents. Its argument: audits are point-in-time and tell you a CA passed, not how it runs on an ordinary Tuesday, so root programs, researchers, and site owners should be able to watch how a modern CA operates between audits.

One CA, classic and post-quantum

Cloudflare plans to be one of the first CAs to issue production Merkle Tree Certificates, with first certificates in the first quarter of 2027. MTCs are a far more compact way to deliver publicly trusted certificates, designed for a post-quantum world where traditional certificate chains grow large enough to strain TLS handshakes. Cloudflare has championed the standards-based MTC proposal at the IETF, and Chrome has named MTCs as the preferred path for post-quantum authentication.

The transition is not expected to be sudden. Much of the Internet will rely on classic certificates and the existing WebPKI for many more years, while MTCs take a steadily growing share of issuance. Carrying classic certificates and Merkle Tree Certificates under one CA, with one lifecycle and one set of guarantees, lets customers adopt at their own pace without a hard cutover — no picking a side of a multi-decade migration, running two systems, or rebuilding when the balance shifts.

Customer Zero and next steps

Beyond certificate packs via Universal SSL, Cloudflare consumes certificates from many CAs to run its own systems and operations. It will be Customer Zero for the new CA and its certificates, both WebPKI and MTC, ensuring the systems and processes meet its internal standards and that the infrastructure is exercised at Cloudflare scale.

The company is working through application and approval with each of the core web root key programs, processes that happen in the open, with updates to follow through to the first Merkle Tree Certificates in early 2027. It says it will continue working with the 16 partner public CAs it has relied on for years.