Trending: On-device modelsSearch
iHeartGeek
iTECH

Cloudflare applies to become a certificate authority

The company that encrypts a fifth of the web wants to issue the certificates too, and it is buying a trusted root to skip the queue.

Cloudflare's header graphic for the announcement, with the Cloudflare logo top left, the headline “Building a certificate authority for the whole Internet” in dark grey, and an orange illustration of sealed certificate scrolls and a wax-seal stamp on a white background

Cloudflare wants to issue the web's security certificates rather than just serve them, and it has started the paperwork to prove it. The company used its Birthday Week announcements to declare an intent to become a public certificate authority (CA), applied for inclusion in the Chrome, Apple, Microsoft and Mozilla root programmes, and signed a definitive agreement to buy an established, broadly trusted root from GlobalSign.

Certificate authorities are the notaries of the encrypted web. They are the bodies that sign a TLS certificate vouching that the server answering for a given domain really is that domain, and every browser ships with a list of roots it will trust. Anything signed through a chain leading back to one of those roots is accepted without a warning, which is why losing CA standing is close to a death sentence. Cloudflare sits in front of more than 20 per cent of global internet request traffic and has spent years buying certificates from 16 partner authorities. Now it wants to hold the pen.

Why it is buying trust instead of growing it

A brand-new root is close to useless for years. Even after a root programme accepts one, it has to propagate out into operating systems, browsers and devices — and it never reaches the long tail of hardware that stopped receiving updates years ago. That is what the GlobalSign deal is for. The root Cloudflare has agreed to acquire has been trusted across browsers, operating systems and devices since 2012, which gives it reach on the day it starts issuing. Cloudflare is also submitting a fresh root to the programmes, built for policies that are starting to cap how old a trusted root may be.

The company is not issuing certificates yet, and says it will be a while. When it does, it plans to be ACME-first — the open standard most automation already speaks — so moving to Cloudflare means changing a directory URL rather than rebuilding anything. Renewal automation will not be optional: Cloudflare says it will only issue to clients that support ACME Renewal Information, standardised as RFC 9773, so certificates can be replaced quickly when they have to be retired. It also promises reproducible builds of its signing software, attested hardware security modules and a public dashboard for issuance health, arguing that an audit tells you a CA passed rather than how it behaves on an ordinary Tuesday.

A second option for a web that leans on one

The pitch rests on concentration risk. Let's Encrypt issues on the order of ten million certificates a day, serves more than 500 million sites and passed four billion active certificates in 2025 — a remarkable success that also leaves most of the free, automated web in the hands of one operator. Cloudflare's argument is that it already builds exactly that kind of redundancy for its own customers, shipping every Universal SSL certificate with a backup issued by a different authority, and that a public CA scales the idea to the whole internet.

Post-quantum is the other half of it. Cloudflare says it intends to be one of the first CAs to issue production Merkle Tree Certificates (MTCs), with the first due in the first quarter of 2027, and has been pushing the standards-based proposal at the IETF. MTCs are a far more compact way to deliver publicly trusted certificates, designed for a post-quantum world in which ordinary certificate chains grow big enough to strain TLS handshakes. Chrome named them the preferred path for post-quantum authentication earlier this year. Cloudflare wants classic certificates and MTCs issued from a single CA with one lifecycle, so customers can cross over at their own pace instead of running two systems.

Our opinion

Trust in the web's certificate system has been rationed for years, and Cloudflare has just asked for a bigger share of it. The interesting part is not that a CDN wants to sell certificates; plenty of them do. It is that Cloudflare has gone shopping for an ageing root instead of pinning its hopes on a better new one. That is an honest reading of how the ecosystem actually works: a root that devices trusted in 2012 is worth more on launch day than a technically superior root sitting in nobody's trust store. Chrome, Apple, Microsoft and Mozilla now get to decide whether the argument clears their bars, and they are not known for hurrying.

The part worth watching is not the cryptography. Cloudflare has committed to requiring ACME Renewal Information before it will issue at all, and to running a public dashboard rather than pointing at last year's audit. If it means that, a CA that shows you how it behaves between audits would be a genuine improvement on an industry habit of publishing a pass mark and moving on. If it does not, the web has simply gained another large certificate seller with better branding, and the concentration problem Cloudflare says it wants to solve stays exactly where it is.