Cloudflare announced its intention to enter the public certificate authority (CA) market, after spending more than a decade as a major consumer of trusted certificates without issuing them itself. The initial steps include submitting applications to join the trusted root programs of Chrome, Apple, Microsoft, and Mozilla, along with signing a definitive agreement to acquire an established, widely trusted root from GlobalSign.
The company aims to combine the compatibility coverage provided by the existing root with a new root designed according to the requirements of the future WebPKI ecosystem. Cloudflare says the relevant GlobalSign root has been trusted since 2012 across browsers, operating systems, and devices, including older devices that may not easily receive updates for new roots. The deal has not yet closed, and Cloudflare has not begun issuing certificates to users.
A Free, Automation-Based Alternative
Cloudflare intends to adopt the ACME protocol as the primary means of issuing and renewing certificates. This means that customers currently using free certificate authorities will, in principle, be able to migrate by changing the directory URL without building new tools or redesigning their operational infrastructure.
The company is also presenting this move as a way to increase diversity in the free certificate market. It notes that Let's Encrypt issues approximately ten million certificates daily, serves more than 500 million websites, and had more than four billion active certificates in 2025. According to Cloudflare, the internet's heavy reliance on a single free provider leaves the system vulnerable to widespread disruption if that provider experiences an operational problem.
What Will Cloudflare Change in Practice?
Cloudflare is drawing on its experience operating certificates for millions of domains. It says its services terminate TLS and rely on millions of certificates annually across multiple authorities and primary and backup paths. This experience has given it direct exposure to rate limits, complex validation cases, revocation delays, trust-chain construction, and delays in root distribution.
The company intends to make support for ACME Renewal Information (ARI), the standard specified in RFC 9773, a requirement for issuance. Customers will have to operate automation that monitors the renewal endpoint, tracks renewal windows, and identifies the certificate being replaced. Cloudflare also says it will publish reproducible software for the signing layer, provide attestations regarding the hardware security modules that safeguard the keys, and operate a public dashboard for monitoring issuance health and incidents.
Preparing for Post-Quantum Certificates
Cloudflare plans to be among the first certificate authorities to issue Merkle Tree Certificates (MTCs) in a production environment, targeting the issuance of the first certificates in the first quarter of 2027. The company presents these certificates as a more compact way to deliver trusted certificates, at a time when larger traditional certificate chains could increase pressure on TLS handshake operations in a post-quantum environment.
Cloudflare says Chrome has named MTCs the preferred path for quantum-resistant authentication, and that it is working to support the standards-based proposal within the IETF. The transition will not be immediate; the company expects traditional certificates to remain in use for years, with both types provided under one authority and one lifecycle so customers can transition gradually.
Limitations and Next Steps
Cloudflare remains in the application and approval phase with the major root programs and has not specified a date for beginning traditional public issuance. The acquisition of the GlobalSign root is also a central part of the plan, but it is not a substitute for completing the requirements of the new root programs.
In certi.news's editorial reading, the announcement's significance lies in combining two goals that are usually addressed separately: providing an additional competitor for issuing automated free certificates and preparing for changes in WebPKI certificate architecture as post-quantum requirements emerge. However, the project's practical value will later be determined by acceptance from the root programs, the success of the acquisition, and Cloudflare's ability to demonstrate reliability and transparency beyond the announcement's scope, particularly when handling large-scale revocation and renewal operations.