CLOUDFLARE has announced its intention to become a public certificate authority (CA), marking a major shift from primarily consuming publicly trusted certificates to issuing them. The company says it has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs and has signed a definitive agreement to acquire an established, broadly trusted root from GlobalSign.
This move aims to give their certificates immediate reach across a wide range of devices while they prepare to issue, with ACME-first issuance planned to minimise tooling changes for users who already rely on free CAs. Cloudflare also intends to support post-quantum certificates and participate in Chrome’s Quantum-resistant Root Program.
The announcement stresses resilience and transparency. Cloudflare operates in front of more than 20% of global Internet traffic and already runs backup certificates for its own TLS termination, illustrating the need for a large, redundant ecosystem if a dominant CA experiences issues. To address this, Cloudflare plans to publish reproducible builds, attest hardware security modules, and run a public issuance health dashboard, with audits viewed as snapshots rather than the full picture of operations.
They also signal a post-quantum path, aiming to issue Merkle Tree Certificates (MTCs) in production in early 2027, alongside classic certificates, to ease the transition for customers and the wider Internet. The context remains collaborative, with continued reliance on existing public CAs as the ecosystem evolves.