Cloudflare Aims to Become Public Certificate Authority, Acquires GlobalSign Root
Cloudflare announced its intention to launch a public Certificate Authority (CA) and acquire an established root from GlobalSign to offer broad compatibility, including post-quantum certificates.

Cloudflare is taking a significant step towards securing the internet by announcing its intent to become a public Certificate Authority (CA). Building on its decade-long initiative of providing free Universal SSL to all its customers, the company aims to extend this model to the entire internet, offering free, automated TLS certificates.
To achieve broad compatibility from day one, Cloudflare has signed an agreement to acquire an established root from GlobalSign. This existing root, trusted since 2012, will ensure that certificates issued by Cloudflare's new CA will be compatible with a wide range of devices, including older clients that may not receive regular updates. Concurrently, Cloudflare is developing a new root for future inclusion in browser root programs, designed to meet evolving ecosystem standards and policies, including those that may limit the age of trusted roots.
The move is partly motivated by the systemic risks associated with relying on a single dominant free certificate authority, such as Let's Encrypt. Cloudflare, which processes a significant portion of global internet traffic, has experienced firsthand the challenges of certificate management, including rate limits, validation issues, and revocation latency. By becoming a CA, Cloudflare aims to introduce redundancy and resilience into the certificate supply chain for the entire internet, mirroring the backup certificate strategy it already employs for its own customers.
Cloudflare plans to operate its CA with an Automated Certificate Management Environment (ACME)-first approach, utilizing the open standard protocol widely adopted for automated certificate issuance and renewal. This strategy is intended to make it easy for existing users of free certificate services to migrate to Cloudflare's offering with minimal changes to their tooling or infrastructure.
In addition to providing broad compatibility and automated issuance, Cloudflare is also preparing for the future of cryptography. The company plans to be among the first CAs to issue post-quantum certificates, aligning with initiatives like Chrome's recently announced Quantum-resistant Root Program. This forward-looking approach aims to ensure that the certificates issued will be secure against the threat of future quantum computing capabilities.
While Cloudflare is not yet issuing certificates, it is committed to transparency throughout the development process. The company is publicly sharing its milestones and working closely with browser root programs and the broader WebPKI community to ensure a smooth and secure launch. This public commitment underscores Cloudflare's dedication to contributing to a more secure and encrypted internet.
The initiative is expected to significantly impact the digital trust landscape, offering a new, reliable, and free source of TLS certificates. As certificate validity periods continue to shorten and agentic activity increases, the demand for certificates is projected to grow rapidly. Cloudflare's entry as a public CA aims to meet this growing demand and enhance the overall security posture of the internet.
Cloudflare is further detailing its commitment to becoming a public Certificate Authority (CA) by announcing plans to support Merkle Tree Certificates (MTCs) by early 2027. This initiative aims to address the performance challenges of migrating the Web PKI to post-quantum cryptography by 2029, proposing MTCs as a scalable and efficient solution that integrates transparency as a core feature rather than an add-on.