Tuesday, September 29, 2026 Newsletter Advertise
Breaking
Cyber

Cloudflare applies to become a public certificate authority

The company says it has applied to four root programs and agreed to buy a trusted root from GlobalSign, with free ACME-based issuance and post-quantum certificates planned.

Cloudflare applies to become a public certificate authority. Source: Cloudflare

Cloudflare said on September 29, 2026 that it intends to become a public certificate authority, announcing that it has applied for inclusion in the Chrome, Apple, Microsoft and Mozilla root programs and signed a definitive agreement to acquire an established root from GlobalSign. The company said it is not issuing certificates yet and that "it will be a little while before we do."

What Cloudflare announced

In a Birthday Week blog post, Cloudflare said that for more than a decade it has been one of the largest consumers of publicly trusted certificates on the Internet and has never issued one itself. That is changing, the company said, with its announced intent to operate a public certificate authority (CA).

The first concrete milestones, according to Cloudflare, are applications to the four core web root programs and a definitive agreement to acquire a root from GlobalSign so it can "offer certificates with the widest possible device reach the day we begin issuing." Cloudflare said the existing GlobalSign root has been trusted across browsers, operating systems and devices since 2012.

Cloudflare said it will pursue two paths to trust: the acquired root for reach across older clients that no longer receive updates, and a new root submitted for inclusion to meet root program policies that are starting to cap how old a trusted root may be.

Free certificates and ACME-first issuance

Cloudflare framed the effort partly as redundancy for the free certificate ecosystem. It said Let's Encrypt "issues on the order of ten million certificates a day, serves more than 500 million sites, and passed four billion active certificates in 2025," describing it as one of the best things to happen to the Internet in twenty years and saying Cloudflare is one of its largest users.

The company said that concentration carries systemic risk, because if the dominant free CA had a bad week much of the web would lack a comparable free, automated alternative. Its own Universal SSL certificates, it said, already ship with a backup certificate wrapped with a separate key and issued from a different authority.

Issuance will be ACME-first, Cloudflare said, so that anyone already pointed at an existing free CA could move by changing a directory URL, with no new tooling. The company added that it will only issue to clients supporting ACME Renewal Information (ARI), standardized in RFC 9773, and that subscribers must maintain automation that polls its renewal endpoint and acts on published renewal windows.

Post-quantum plans and transparency commitments

Cloudflare said it plans to be one of the first CAs to issue production Merkle Tree Certificates (MTCs), with the first certificates issued in the first quarter of 2027, and to target Chrome's recently announced Quantum-resistant Root Program. It said Chrome named MTCs as the preferred path for post-quantum authentication earlier this year and that Cloudflare has been championing the proposal at the IETF.

The company said it does not expect a sudden transition and will carry classic certificates and MTCs under one CA so customers can adopt at their own pace.

On operations, Cloudflare said it will publish reproducible builds of the software that signs certificates, attest the hardware security modules holding its keys, and run a public dashboard for issuance health and incidents. It said it will also be "Customer Zero" for the new CA and will continue working with the 16 partner public CAs it relies on today.

What to do

  • If you plan to use Cloudflare's future CA, ensure your ACME client supports ACME Renewal Information (ARI) as defined in RFC 9773, since Cloudflare says it will only issue to clients that support it.
  • Be prepared for your automation to poll Cloudflare's renewal endpoint, act on the renewal windows it publishes, and identify the certificate it is replacing, which Cloudflare says will be a condition of issuance.
  • Site operators who want early access can register for updates through the link in Cloudflare's announcement; the company says it will share milestones publicly as root program applications proceed.
Key facts and where they come from
  • Cloudflare announced its intent to become a public certificate authority.
    Cloudflare is announcing our intent to become a public certificate authority (CA).
  • It applied to the Chrome, Apple, Microsoft and Mozilla root programs and agreed to acquire a GlobalSign root.
    We have applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs, and we have signed a definitive agreement to acquire an established, broadly trusted root from GlobalSign
  • The acquired GlobalSign root has been trusted since 2012.
    The existing GlobalSign root has been trusted across browsers, operating systems, and devices since 2012
  • Cloudflare is not yet issuing certificates.
    We are not issuing certificates yet, and it will be a little while before we do.
  • Issuance will be ACME-first, with migration by changing a directory URL.
    anyone already pointed at any existing free CA can move to us by changing a directory URL, with no new tooling and nothing to re-architect
  • Only clients supporting ACME Renewal Information (RFC 9773) will be issued certificates.
    We will only issue to clients that support ACME Renewal Information (ARI), standardized in RFC 9773.
  • Production Merkle Tree Certificates are planned for Q1 2027.
    We plan to be one of the first CAs to issue production Merkle Tree Certificates (MTCs), with the first certificates issued in the first quarter of 2027.
  • Cloudflare says it sits in front of more than 20 percent of global Internet request traffic.
    Cloudflare sits in front of more than 20 percent of global Internet request traffic and terminates TLS for millions of domains
  • Cloudflare cites Let's Encrypt scale figures.
    Let's Encrypt issues on the order of ten million certificates a day, serves more than 500 million sites, and passed four billion active certificates in 2025.

Read the original from Cloudflare →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Cyber