MikhbarMIKHBAR
Web

Cloudflare Announces Intent to Become a Public Certificate Authority

Twelve years after launching Universal SSL, Cloudflare is taking the next step to become a public certificate authority with plans to offer post-quantum certificates.

Cloudflare Announces Intent to Become a Public Certificate Authority

Expanding From Consumer to Issuer

Twelve years ago, during Birthday Week 2014, [we turned on Universal SSL](https://blog.cloudflare.com/introducing-universal-ssl/) and nearly doubled the number of encrypted sites on the web overnight by providing free TLS to every site behind Cloudflare. Encryption transitioned from an expensive, time-intensive undertaking into the default standard for the web.

For Birthday Week this year, Cloudflare announced its intent to become a public certificate authority (CA). Despite being one of the largest consumers of publicly trusted certificates on the Internet for over a decade, the company has never issued a single certificate itself. That operational reality is now changing as the organization formally applies to become a public CA.

Building a certificate authority for the whole Internet
Image related to the report from Cloudflare Blog · Source: Cloudflare Blog

Root Programs and GlobalSign Acquisition

Cloudflare has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs. Additionally, the company has signed a definitive agreement to acquire an established, broadly trusted root from GlobalSign to offer certificates with the widest possible device reach from day one.

A brand-new root typically requires years to propagate into operating systems, browsers, and devices, often missing older clients that have stopped receiving updates. Acquiring an existing root with a high degree of trust store coverage solves that gap immediately. The GlobalSign root has been trusted across diverse clients since 2012, helping reach older devices while newer roots align with evolving root program policies.

Post-Quantum Goals and Ecosystem Redundancy

Cloudflare also announced plans to be among the first certificate authorities to serve post-quantum certificates, targeting Chrome’s recently announced [Quantum-resistant Root Program](https://blog.google/security/cultivating-a-robust-and-efficient-quantum-safe-https/).

While free and automated certificate models like Let's Encrypt handle a massive share of the encrypted web, reliance on a single dominant operator introduces systemic risk. Cloudflare aims to provide broader redundancy for the ecosystem, drawing on its experience provisioning certificates through multiple CAs to keep customer services operational during outages and revocation events.

Cloudflare Announces Intent to Become a Public Certificate Authority
Image related to the report from Cloudflare Blog · Source: Cloudflare Blog

ACME-First Approach and Automated Renewal

To streamline adoption, Cloudflare will employ an [ACME](https://www.globalsign.com/en/acme-automated-certificate-management)-first approach utilizing the widely accepted open standard protocol. Automated issuance and renewal through ACME will allow users of existing free certificate authorities to transition by changing a directory URL without new tooling or re-architecting.

As [certificate maximum validity period decreases](https://cabforum.org/2025/04/11/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods/#ballot-contents) over the coming years, agentic activity increases, and post-quantum certificates go mainstream, raw certificate volume is expected to grow rapidly across the Internet.

Cloudflare Announces Intent to Become a Public Certificate Authority
Image related to the report from Cloudflare Blog · Source: Cloudflare Blog

Designing for Resilience and Compliance

In building its own CA, Cloudflare is focusing on reliability, designing recovery processes, and adopting standards such as [ACME Renewal Information](https://www.rfc-editor.org/info/rfc9773/). Making renewal automation a condition of issuance will require subscribers to maintain automation that polls renewal endpoints and tracks replacement certificates.

By incorporating these strategies alongside [standards-based proposal](https://datatracker.ietf.org/doc/draft-ietf-plants-merkle-tree-certs/) efforts like Merkle Tree Certificates, the initiative intends to limit the impact of operational issues and support the broader transition outlined [in a blog post on the topic](http://blog.cloudflare.com/pq-ca-with-mtcs).

Sources

Continue chronologically

Related entity coverage