FR
live

Cloudflare becomes a certificate authority and lines up post-quantum certificates for 2027

On 29 September 2026, Cloudflare announced its intent to become a public certificate authority, twelve years after launching Universal SSL, with a root acquired from GlobalSign and applications to the Chrome, Apple, Microsoft, and Mozilla root programs. It is targeting post-quantum certificates and Merkle Tree Certificates as early as Q1 2027: a second mass-scale free provider is taking shape, and your ACME deployment chain must be able to switch.

A steel chain with interlocking links laid on dark concrete, a single amber link glowing in the middle.

2014. Cloudflare launches Universal SSL and almost doubles the number of encrypted sites on the web overnight, giving free TLS to every site behind it. 29 September 2026. The company announces its intent to become a public certificate authority for the first time in its history, applying to the Chrome, Apple, Microsoft, and Mozilla root programs. First quarter 2027. It plans to issue its first post-quantum Merkle Tree Certificates. Why it matters: the encrypted web today rests on a single dominant free provider, and Cloudflare wants to be the redundancy that is missing.

Two paths to trust, and neither is symbolic

The announcement rests on two complementary moves. First, Cloudflare has filed for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs. Second, it has signed a definitive agreement to acquire an established root from GlobalSign, a root broadly trusted since 2012 across browsers, operating systems, and devices.

The reason for this double move is technical and pragmatic. A brand-new root takes years to propagate to clients around the world, and never reaches devices that no longer receive updates. The GlobalSign root covers that long tail from day one. The new root, meanwhile, is built for the policies of tomorrow — including the programs that are starting to cap how old a trusted root may be. Cloudflare wants both: the reach of the devices of the past and standing under the rules of the future. That dual approach mirrors how it already runs Universal SSL — every certificate ships with a backup, wrapped with a separate key and issued from a different authority — but this is the first time the logic is applied to the authority itself rather than to a single customer certificate.

The redundancy the encrypted web is missing

Cloudflare’s diagnosis of the state of the WebPKI is the heart of the announcement. Let’s Encrypt issues on the order of ten million certificates a day, serves more than 500 million sites, and passed four billion active certificates in 2025. It is, in Cloudflare’s own words, one of the best things to happen to the internet in twenty years.

But that success concentrates a systemic risk: if the dominant free authority had a bad week, the web would have no comparable free, automated alternative ready to take the load. Cloudflare knows this risk from the inside, because it already provisions its own certificates through multiple authorities, with primary and backup paths. A public certificate authority, the company says, is the same idea of redundancy, but at the scale of the whole internet.

Transparency becomes a product

Cloudflare’s pitch goes beyond redundancy. The company promises to publish reproducible builds of the software that signs certificates, to attest the hardware security modules (HSMs) that hold its keys, and to run a public dashboard for issuance health and incidents. The reasoning fits in one sentence: an audit is a point-in-time snapshot that proves a CA passed, not how it runs on an ordinary Tuesday. Cloudflare wants root programs, researchers, and ordinary site owners to watch the authority operate between audits.

That promise lands in a context Cloudflare says it has lived from the inside: “the CA churn of recent years,” felt through its customers as rate limits, validation edge cases, revocation latency, and root-distribution lag. The gradual reduction of the maximum certificate validity period, driven by the CA/Browser Forum (ballot SC081v3), the rise of agentic activity, and the mainstreaming of post-quantum certificates will mechanically push up the number of certificates the web needs each year. Cloudflare does not hide that solving this problem for itself — it relies on “millions of certificates per year” — is a major motivation for entering the business.

ACME and ARI: a switch with no re-architecture

To make adoption trivial, Cloudflare’s authority will be ACME-first — the open standard protocol already used by Let’s Encrypt and other authorities. Concretely, anyone already pointed at an existing free authority will be able to move by changing a directory URL, with no new tooling and nothing to re-architect. The barrier to entry is deliberately near zero.

The company goes further by making automation a condition of issuance. It will only issue to clients that support ACME Renewal Information (ARI), standardized in RFC 9773. Subscribers must maintain automation that polls the renewal endpoint, acts on the published windows, and identifies the certificate it is replacing. That is a deliberate “fail small” choice: limit the impact of an incident by ensuring every subscriber can renew quickly, rather than discovering at revocation time that half the estate cannot renew itself.

The post-quantum bet and Merkle Tree Certificates

The most forward-looking part concerns cryptography. Cloudflare plans to be one of the first authorities to serve post-quantum certificates, targeting the Quantum-resistant Root Program recently announced by Chrome. Above all, it plans to issue Merkle Tree Certificates (MTCs), with the first certificates in the first quarter of 2027.

MTCs are a new and far more compact way to deliver publicly trusted certificates, designed for a post-quantum world where traditional certificate chains grow large enough to strain TLS handshakes. Where a classical chain must carry several public keys — including post-quantum keys, markedly heavier than ECDSA or RSA — an MTC aggregates the proofs into a single compact structure, lightening the exchange. Cloudflare has championed this standards-based proposal at the IETF for several years, and Chrome named it earlier this year among the paths toward efficient, quantum-resistant HTTPS. It is the most technical part of the announcement, but also the most consequential for the years ahead.

What it changes for an operator

For a CISO or an SRE, the announcement has three concrete consequences. First, watch for Cloudflare’s authority to appear in the root programs, then for its ACME endpoint: having a second mass-scale free provider is a resilience option to document now, even though Cloudflare is not issuing yet. Second, check that your renewal tooling supports ARI (RFC 9773) — it is the entry condition for Cloudflare, and good practice regardless. Third, follow the MTC and post-quantum timeline: those are the two workstreams that, by 2027, will change the shape and byte cost of your certificate chains.

Verdict

If you depend on a single free certificate provider, Cloudflare’s arrival is resilience news, not a reason to migrate today — the authority is not issuing yet, and Let’s Encrypt remains the standard. If you are preparing your estate for post-quantum, watch the MTCs and Chrome’s root program closely: that is where your TLS chain compatibility will be decided by 2027. If you run certificate automation, use the announcement to verify ARI and the robustness of your renewals — it is the only immediately actionable part, and it matters regardless of your provider. WebPKI redundancy is being built now, but it does not absolve anyone of having a renewal chain that stands on its own.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

The DNS root changes its key on 11 October and will silence frozen resolvers

On 11 October 2026 the DNS root zone replaces its key-signing key KSK-2017 with KSK-2024, the second rollover since the root was first signed in 2010. Any DNSSEC-validating resolver that does not already trust the new key will stop resolving every name: the job is to find, before Sunday, the resolvers whose trust anchor has been frozen.

An RPKI-valid BGP hijack diverted Softaculous updates toward malware

Between 28 and 30 August 2026, an attacker announced a more-specific Hetzner prefix with a forged origin that passed RPKI validation, obtained a fraudulent TLS certificate, and delivered a malicious Virtualizor update. The full APNIC and Kentik analysis, published on 22 September, shows RPKI alone is not enough: tighten your ROAs, reject invalid routes, and deploy ASPA.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss