Full Report
Twelve years after launching Universal SSL, Cloudflare is applying to become a certificate authority. By combining an established root, an ACME-first approach, and Merkle Tree Certificates, we are building a post-quantum CA for the open web.
Analysis Summary
# Industry News: Cloudflare Announces Plans to Become a Public Certificate Authority
## Summary
Cloudflare has announced its intent to launch a public certificate authority (CA), marking a significant shift from its role as a major consumer of certificates to a provider. The company is acquiring a trusted root from GlobalSign and applying to major root programs (Chrome, Apple, Microsoft, Mozilla) while positioning itself to issue post‑quantum, ACME‑driven certificates with Merkle Tree support.
## Key Details
- **Date:** September 29 2026
- **Companies Involved:** Cloudflare, GlobalSign (root acquisition)
- **Category:** Product launch / Strategic initiative
## The Story
For a decade, Cloudflare has been one of the Internet’s largest TLS certificate consumers, yet it never issued certificates itself. In 2024 it introduced Universal SSL, democratizing HTTPS for millions of sites. Building on that foundation, Cloudflare is now moving to become a public CA. It has:
1. **Acquired a GlobalSign root** (trusted across browsers, OSes, and legacy devices since 2012) to guarantee immediate, wide‑coverage trust.
2. **Applied to the four major root programs** (Chrome, Apple, Microsoft, Mozilla) to launch a brand‑new root that will support future policy changes and quantum‑resistant capabilities.
3. **Committed to an ACME‑first approach** so customers can obtain certificates via the same automated workflow used by Let’s Encrypt, minimizing friction.
4. **Planned to issue Merkle Tree Certificates** and post‑quantum certificates, aligning with emerging WebPKI standards and Chrome’s Quantum‑Resistant Root Program.
The CA will initially provide free, automated certificates to the public, mirroring the model that made HTTPS ubiquitous. Cloudflare will also serve as “customer‑zero,” using its own infrastructure to validate the CA’s reliability at scale.
## Business Impact
### For the Companies Involved
- **Cloudflare:** Gains a new revenue stream and deeper control over TLS trust, reinforcing its security‑centric brand. The CA role also positions Cloudflare as a key influencer in WebPKI governance.
- **GlobalSign:** Expands its reach through Cloudflare’s massive user base, potentially increasing root usage and market share.
### For Competitors
- **Let’s Encrypt:** Faces a new, high‑trust competitor that offers free certificates with broader device coverage and post‑quantum options.
- **Traditional CAs (e.g., DigiCert, Sectigo):** Must monitor Cloudflare’s potential to shift market share, especially among small to medium‑sized web operators.
### For Customers
- **Web operators:** Gain an additional source of free, automated certificates with wide device compatibility and future‑proofed cryptography.
- **Enterprise customers:** Benefit from Cloudflare’s internal validation, reducing risk of mis‑issued certificates.
### For the Market
- **WebPKI ecosystem:** The addition of a major public CA introduces redundancy, mitigating systemic risk that currently concentrates on Let’s Encrypt.
- **Post‑quantum readiness:** Cloudflare’s early adoption could accelerate broader industry transition to quantum‑resistant certificates.
## Technical Implications
- **ACME‑First:** Seamless integration for existing ACME clients; no new tooling required.
- **Merkle Tree Certificates:** Enables efficient certificate revocation and auditability, reducing overhead for large deployments.
- **Post‑Quantum Certificates:** Aligns with Chrome’s Quantum‑Resistant Root Program, potentially setting a new industry standard.
## Strategic Analysis
- **Market Positioning:** Cloudflare moves from a service provider to a foundational trust anchor, enhancing its brand as a “security first” company.
- **Competitive Advantage:** Combining an established root with a new, future‑proof root gives Cloudflare unparalleled device coverage.
- **Challenges:**
- **Root Program Approval:** Lengthy and opaque, with potential policy hurdles.
- **Operational Scale:** Issuing certificates at web‑scale demands robust infrastructure and rigorous auditing.
- **Regulatory Scrutiny:** As a new CA, Cloudflare may face increased oversight from security regulators and browser vendors.
## Industry Reactions
- **Analyst Opinions:** Many security analysts view the move as a logical extension of Cloudflare’s ecosystem strategy, praising the redundancy it introduces.
- **Expert Commentary:** Cryptography experts highlight the significance of Merkle Tree and post‑quantum support, noting that it could become a benchmark for future CAs.
- **Market Response:** Early adopters—small‑to‑medium businesses and open‑source projects—have already signed up for updates, indicating strong demand for free, high‑trust certificates.
## Future Outlook
- **Short Term:** Expect root program approvals and the first issuance of Merkle Tree certificates by early 2027.
- **Mid Term:** Cloudflare could capture a sizable share of the free‑certificate market, especially among legacy devices.
- **Long Term:** As post‑quantum cryptography matures, Cloudflare’s early adoption may position it as the de‑facto standard for quantum‑resistant web security.
Watch for:
- Root program acceptance timelines.
- Adoption rates among legacy browsers.
- Integration of post‑quantum algorithms into mainstream TLS stacks.
## For Security Professionals
- **Operational Impact:** Security teams can now procure certificates directly from Cloudflare, simplifying supply chain management.
- **Audit & Compliance:** Merkle Tree support offers efficient revocation checks, reducing audit complexity.
- **Future‑Proofing:** Early exposure to post‑quantum certificates allows organizations to test and validate new cryptographic primitives before mandatory migration.
In sum, Cloudflare’s CA initiative not only diversifies its product portfolio but also strengthens the overall resilience of the Internet’s trust infrastructure, offering both immediate and long‑term benefits to the broader cybersecurity ecosystem.