CLOUDFLARE has announced its plan to become a public Certificate Authority (CA), offering an open service that issues digital certificates to encrypt traffic and verify website identities. The new CA will support both traditional TLS certificates and post-quantum Merkle Tree Certificates (MTCs), giving websites a path to upgrade security as quantum computing advances, without requiring tool changes or full rebuilds.
As part of the move, Cloudflare intends to acquire publicly trusted Root CA key material from GlobalSign, which would speed recognition of Cloudflare-issued certificates across the web.
The initiative includes a commitment to transparency and modernised operations. Cloudflare describes “Glass-Box Operational Transparency” with detailed operational insights, reproducible code builds, and a live public health dashboard. It also outlines “Zero-Downtime Incident Response” using automated renewal signalling (RFC 9773) to replace certificates across millions of sites swiftly, and a scalable post-quantum approach through MTCs that are logged in a trusted registry with lightweight proofs.
The plan envisions managing both classic TLS and Merkle Tree Certificates within a single system to ease migration to post-quantum security.
Production milestones are targeted for 2027. Classical certificates will begin issuing once browser root program processes are completed, with production MTC issuance planned for the first quarter of 2027. The GlobalSign root acquisition is expected to close in the next two months, subject to customary conditions. Cloudflare is inviting site owners to follow updates and sign up for early access via its blog.