Cloudflare today set out plans to become a publicly trusted certificate authority, disclosing that it has applied to the root programs run by Chrome, Apple, Microsoft and Mozilla and has signed a definitive agreement to acquire an established root from GlobalSign, while committing to issue production Merkle Tree Certificates from the first quarter of 2027.
In Short
Cloudflare, a company that sits in front of a large slice of the web, wants to start handing out the digital certificates that put the padlock next to a website's address in your browser. A large share of free certificates today comes from one organization, Let's Encrypt, and Cloudflare argues the web needs another large free source in case that one ever runs into trouble. Nothing changes for your site yet: Cloudflare is not issuing certificates, and the first ones of a new, more compact kind built for the quantum era are planned for early 2027.
What Cloudflare set out
The plan was published under the company's Birthday Week banner, the annual run of announcements marking Cloudflare's launch on September 27, 2010, the same day its free tier began. Written by Steve Goldsmith and tagged under cryptography, post-quantum, security and TLS, the post presents the move as a sequel to Universal SSL. During Birthday Week 2014, according to Cloudflare, the company switched on free TLS for every site behind its network, including sites that had never paid it anything, and nearly doubled the number of encrypted sites on the web overnight.
Twelve years later, Cloudflare describes itself as one of the largest consumers of publicly trusted certificates on the internet, yet it has never issued one. "That is changing," the post states.
Three milestones accompany the statement of intent. Cloudflare has applied for inclusion in the Chrome, Apple, Microsoft and Mozilla root programs, the curated lists that determine which certificate authorities browsers and operating systems accept. It has signed a definitive agreement to acquire a broadly trusted root from GlobalSign, so that its certificates carry the widest possible device reach from the first day of issuance. And it intends to be among the first authorities to serve post-quantum certificates, aimed at what the post calls Chrome's recently announced Quantum-resistant Root Program.
Nothing is being issued yet. Cloudflare is not issuing certificates, and the post states "it will be a little while before we do." The company says it will share milestones as they land while working with the root programs and the wider WebPKI community, the loose federation of browsers, operating systems, authorities and standards bodies that governs public web certificates. Two companion posts appeared the same day: one by Mari Galicer on building a post-quantum certificate authority with Merkle Tree Certificates, and one by Sharon Goldberg and Tiago Silva on using AI to chart the company's own post-quantum migration.
Why admission to a root store is the business
A web certificate binds a domain name to a cryptographic key. When a browser connects to a site over HTTPS, the certificate is how it confirms that the server answering is the one named in the address bar, not an impostor sitting between the two. The browser checks that the certificate chains up to a root it already holds. An authority whose roots are missing from those stores can issue as many certificates as it likes; no mainstream browser will accept them.
Control of that list has been fought over before. A 2021 draft of the European Union's eIDAS revision would have compelled browsers to trust certificate authorities approved by member states, bypassing the root programs that browsers operate. An open letter published on November 2, 2023 by ten organizations, among them Mozilla, Cloudflare and Fastly, warned that the provision was likely to weaken internet security. Cloudflare, a signatory to that warning, now goes through the browser-run programs as an applicant.
Two roots, two purposes
Reach across older devices
Why buy a root when a new one can be generated? The answer, according to Cloudflare, is propagation. Even after a root program accepts a new root, it must spread into operating systems, browsers and devices, and it never reaches the large population of hardware that has stopped receiving updates, or never received any. The company describes that long tail of older clients as the origin of a great deal of the world's internet traffic, and of a correspondingly large set of avoidable breakage.
The GlobalSign root has been trusted across browsers, operating systems and devices since 2012, according to the post, and reaches older clients that a fresh root never will. "The established root gives us reach across the devices of the past," Goldsmith wrote.
Several details are missing. The post does not identify which GlobalSign root is involved, the price, the expected completion date, or whether the transfer needs consent from the root programs. It says nothing about GlobalSign's role after the sale. An agreement has been signed; completion has not been reported.
Standing under newer rules
The second track is the new root Cloudflare is submitting to the programs. It is built for where the ecosystem is heading, according to the company, including root programs that are starting to cap how old a trusted root may be. That single line explains the dual approach better than any other in the post. A root first trusted in 2012 has now been in service for 14 years. The older key buys compatibility today; the newer one is meant to satisfy age limits that an older root cannot satisfy indefinitely. When an age cap would reach the GlobalSign root, the post does not say.
The Let's Encrypt question
The free, automated certificate model now carries most of the encrypted web, and much of it runs through one operator. Let's Encrypt, according to Cloudflare, issues on the order of ten million certificates a day, serves more than 500 million sites, and passed four billion active certificates in 2025. The post calls it one of the best things to happen to the internet in twenty years, and says so as one of its largest users.
Those figures do not reconcile as published. At ten million certificates a day, an active pool of four billion would require the average certificate to stay valid for around 400 days, far longer than the 90-day certificates that have been Let's Encrypt's standard. The larger number may count certificates issued over time rather than those active at once. Cloudflare offers no clarification, and the inconsistency sits within its own text.
The argument itself concerns concentration rather than performance. If the dominant free authority had a bad week, the post contends, much of the web would have "no comparable free, automated alternative" ready to absorb the load. Cloudflare's Radar data shows what that dependence looks like for a single top-level domain: for .land domains over a seven-day window reported in October 2025, the Internet Security Research Group, which operates Let's Encrypt, accounted for 67% of certificates, against 17% for Google Trust Services, 7% for Sectigo and 5% for GoDaddy.
Cloudflare already applies the principle to its own customers. Every Universal SSL certificate ships with a backup certificate, wrapped with a separate key and issued from a different authority, ready to deploy automatically if the primary is revoked or compromised. A public authority, the post argues, is "that same idea, but at the scale of the whole Internet."
The section making this case is headed as a new source of free certificates. No pricing terms, rate limits, eligibility rules or validation levels were published alongside it.
Renewal automation as a condition of issuance
ACME first
Cloudflare intends to be ACME-first. The Automated Certificate Management Environment protocol is the open standard on which most free issuance already runs, and automated issuance and renewal through it will be the route to a Cloudflare certificate. According to the post, anyone already pointed at an existing free authority could move by changing a directory URL, with no new tooling and nothing to re-architect.
ARI as the gate
That promise carries a qualification, set out a few paragraphs later. Cloudflare will issue only to clients that support ACME Renewal Information, or ARI, standardized in RFC 9773. Subscribers must maintain automation that polls the authority's renewal endpoint, acts on the renewal windows it publishes, and identifies the certificate being replaced. A client pointed at another free issuer without ARI support would therefore need more than a new directory URL. The post does not list which ACME clients meet the requirement.
Revocation is the rationale. Over the past 16 years, according to Cloudflare, certificate authorities have been caught between revoking certificates on time and keeping subscribers' sites online, because too many subscribers could not replace their certificates quickly enough. With ARI mandatory, the company says it can bring forward renewal windows for affected certificates when they have to be retired, whether for a compliance issue or a security incident, spread the replacements across the time available and track replacement issuance.
Mass replacement is not hypothetical. On June 27, 2024, Google and Mozilla said they would stop trusting Entrust's public TLS certificates issued after set dates: Chrome for certificates whose earliest Signed Certificate Timestamp fell after November 11, 2024, and Firefox from November 30, 2024, across nine Entrust roots. Operators relying on them had to move to another authority before the cut-offs. The post refers more generally to the authority churn of recent years, which Cloudflare says it felt through its customers.
More certificates, shorter lives
Volumes are set to rise regardless. Cloudflare expects the number of certificates it relies on each year to grow quickly as maximum validity periods shrink, as agentic activity increases and as post-quantum certificates go mainstream - "and we are not alone," the post adds. The lifetime schedule is already fixed. Under a ballot adopted in 2025 by the CA/Browser Forum, the body in which certificate authorities and browser makers set shared rules, maximum validity fell to 200 days on March 15, 2026, drops to 100 days on March 15, 2027 and reaches 47 days on March 15, 2029. Each step multiplies renewal events for any organization running many hostnames.
The agent part of the argument is thinner. Growth in agentic AI traffic is visible in Cloudflare's own measurements: bots accounted for 57.4% of HTML requests in the week ending June 5, 2026, and chief executive Matthew Prince now expects automated traffic to reach 1,000 times human levels within five years. The post does not explain, however, the mechanism by which more agent activity produces more certificates.
Transparency and failing small
The renewal rule comes with commitments on disclosure. Cloudflare intends to publish reproducible builds of the software that signs certificates, attest the hardware security modules that hold its keys, and run a public dashboard for issuance health and incidents. Audits, the post argues, are point-in-time checks that show an authority passed rather than how it behaves on an ordinary working day; the dashboard is meant to let root programs, researchers and site owners observe operations between audits.
The design goal borrows language used across Cloudflare's other products. The company wants an authority whose reliability depends not only on avoiding mistakes but on its ability to "fail small" and contain the impact of any single issue. Recovery processes, according to Cloudflare, will be designed and tested before any incident occurs.
Merkle Tree Certificates and the size problem
The most technically ambitious element carries the only firm date. Cloudflare plans to be one of the first authorities to issue production Merkle Tree Certificates, or MTCs, with the first certificates issued in the first quarter of 2027.
MTCs are a more compact way to deliver publicly trusted certificates, according to the post, designed for a post-quantum world in which traditional certificate chains grow large enough to strain TLS handshakes. Cloudflare has championed a standards-based MTC proposal at the IETF, and earlier this year Chrome named MTCs as its preferred path for post-quantum authentication, the post states. Work at the IETF typically takes years before a proposal becomes a standard, and the post does not describe how far the MTC draft has progressed.
The size problem can be measured. When Cloudflare's 1.1.1.1 resolver began validating ML-DSA-44 signatures on September 10, 2026, the published figures put an ML-DSA-44 signature at 2,420 bytes against 64 bytes for ECDSA P-256, and its public key at 1,312 bytes against 64. A TLS connection carries several signatures and keys: those on the site and intermediate certificates, certificate transparency proofs and the handshake signature itself. At those sizes, five signatures and two public keys would come to 14,724 bytes, against 448 bytes with ECDSA, by PPC Land's arithmetic. The count is illustrative; real chains vary.
Encryption has moved faster than authentication. Post-quantum key agreement reached 52% of TLS 1.3 traffic by November 2025, according to Cloudflare's annual review, having been enabled by default on its network in October 2022. Certificates are harder to change because every client that validates them has to accept the new format. Cloudflare's stated aim is full post-quantum security across its systems by 2029, framed around the possibility that a quantum computer able to break RSA and ECDSA keys at deployed sizes could exist by 2030.
The company does not expect a sudden switch. Much of the internet will rely on classic certificates and the existing WebPKI for many more years, according to Cloudflare, while MTCs take a steadily growing share of issuance. Its answer is a single service issuing both, under one authority, with one lifecycle and one set of guarantees, so that customers can adopt at their own pace without a hard cutover. "Customers should not have to pick a side of a multi-decade migration," according to the company.
As with its other products, Cloudflare will be Customer Zero. Beyond the certificate packs it provides through Universal SSL, the company consumes certificates from many authorities to run its own systems, and it says both WebPKI certificates and MTCs from the new authority will be exercised first on its own infrastructure, at Cloudflare scale.
The view from the receiving end
Cloudflare's claim to competence is operational. It sits in front of more than 20% of global internet request traffic and terminates TLS for millions of domains, relying on millions of certificates a year, according to the post; it cited a similar share when it released its Observatory monitoring platform in September 2025. Those certificates come from multiple authorities, with primary and backup paths designed to keep customer services running through authority outages and revocation events.
The consuming side has taught hard lessons, the company says, listing rate limits, validation edge cases, revocation latency, chain building and lags in root distribution. None of the existing relationships end with the new venture: Cloudflare says it will keep working with the 16 partner authorities it has relied on for years.
What remains unknown is mostly a matter of dates. The first classic certificates have none, and the root program reviews, which the post says take place in the open, will set the pace.
Why this matters for the marketing community
Certificates sit beneath every paid click. A landing page, a measurement tag, a conversion pixel and an ad server call all depend on a valid certificate, and Chrome is tightening the dependency: Chrome 154, due this October, will ask users for permission before the first visit to any public site without HTTPS, a change the Chrome Security Team estimated would affect between 1% and 5% of web traffic. An expired or distrusted certificate triggers a full-page browser warning, which ends a paid visit before it begins.
Root trust also protects the advertisement itself. A man-in-the-middle position was how Superfish adware, preinstalled on Lenovo consumer laptops from around late 2014, injected shopping ads into pages: it installed its own root certificate and re-signed every site certificate, so the browser raised no alarm. Who is allowed into the root stores is, in that sense, an advertising question as well as a security one.
The operational burden is heading one way. Publishers with hundreds of subdomains, ad tech vendors serving tags from many hostnames and agencies running campaign microsites all face renewal cycles that shorten in stages until 2029. An issuer that refuses clients lacking ARI will, by design, only serve those that have already automated.
Concentration cuts both ways. Cloudflare's case against depending on a single free authority applies in part to Cloudflare. A site that uses its CDN and, later, its certificates would have the proxy terminating its traffic and the authority vouching for its identity inside the same company. That position has shown its fragility: Cloudflare's November 18, 2025 outage was described by Prince as the company's worst since 2019. The arrangement is not new - Google runs both the Chrome root program and a certificate authority, Google Trust Services - and Cloudflare's backup-certificate design and its commitment to 16 partner authorities point toward redundancy rather than exclusivity. Whether sites diversify their issuers or consolidate them with their network provider is a question the post cannot answer.
Timeline
- September 27, 2010 - Cloudflare goes live, with its free tier starting the same day
- 2012 - The GlobalSign root covered by the new agreement becomes trusted across browsers, operating systems and devices
- Birthday Week 2014 - Cloudflare turns on Universal SSL, nearly doubling the number of encrypted sites overnight
- October 2022 - Cloudflare enables post-quantum key agreement by default on its network
- June 27, 2024 - Google and Mozilla say they will stop trusting newly issued Entrust TLS certificates
- November 11, 2024 - Chrome's cut-off for Entrust certificates takes effect; Firefox follows on November 30
- 2025 - Let's Encrypt passes four billion active certificates, according to Cloudflare, a figure the post does not reconcile with its issuance rate
- September 26, 2025 - Cloudflare releases Observatory, describing its network as handling traffic for over 20% of the web
- October 2025 - Cloudflare Radar publishes certificate issuer shares by top-level domain, with the Internet Security Research Group at 67% for .land
- October 28, 2025 - The Chrome Security Team says Chrome 154 will ask permission before loading public sites without HTTPS
- November 2025 - Post-quantum key agreement reaches 52% of TLS 1.3 traffic
- 2026, date not given - Chrome names Merkle Tree Certificates as its preferred path for post-quantum authentication, according to Cloudflare
- Week ending June 5, 2026 - Bots account for 57.4% of HTML requests on Cloudflare Radar
- September 10, 2026 - Cloudflare's 1.1.1.1 resolver begins validating ML-DSA-44 DNSSEC signatures
- September 28, 2026 - Matthew Prince's forecast of automated traffic at 1,000 times human levels within five years is published
- September 29, 2026 (today) - Cloudflare discloses root program applications, the GlobalSign root agreement and its plan to operate a public certificate authority
- October 2026 - Chrome 154 is due with secure connections enforced by default
- First quarter of 2027 - Cloudflare's first production Merkle Tree Certificates are scheduled
- 2029 - Cloudflare's goal for full post-quantum security across its systems
- 2030 - Date by which Cloudflare's planning allows for a quantum computer able to break deployed RSA and ECDSA keys
Related PPC Land coverage
- Cloudflare's 1.1.1.1 now validates 2,420-byte quantum-safe DNS signatures - Post-quantum signature sizes, the downgrade problem and Cloudflare's 2029 target.
- Chrome and Mozilla to distrust Entrust TLS Certificates in late 2024 - The browser decisions that forced site operators to change certificate authority.
- Chrome enforces secure connections by default in October 2026 - Chrome 154's permission prompt for public sites without HTTPS and the share of traffic affected.
- Cloudflare launches comprehensive TLD tracking on Radar platform - Certificate transparency data and issuer shares for each top-level domain.
- AI crawlers now consume 4.2% of web traffic as internet grows 19% in 2025 - Cloudflare's 2025 review, with post-quantum key agreement at 52% of TLS 1.3 traffic.
- Cloudflare launches Observatory and Smart Shield for website performance - A September 2025 Birthday Week release that described Cloudflare's reach as over 20% of the web.
- Bots now outnumber humans on the web - and most aren't here to search - Radar data putting automated traffic at 57.4% of HTML requests.
- Cloudflare CEO expects bot traffic to hit 1,000 times human within 5 years - Matthew Prince's forecast for machine traffic and what it means for ad-funded sites.
- Cloudflare reinforces Free Tier commitment with 15 new features announcement - The 2024 anniversary release and the free tier's origins in 2010.
- How web standards shape the internet's governing framework - Why protocols such as those at the IETF take years to become standards.
- Cloudflare opens anonymized speed data from 10,000 top websites - The BEACON performance dataset, released under the same Birthday Week banner.
Summary
Who: Cloudflare, through a post by Steve Goldsmith, with GlobalSign as the counterparty to the root agreement and the Chrome, Apple, Microsoft and Mozilla root programs as the bodies reviewing its applications. Let's Encrypt is the dominant free issuer the plan is positioned against, and site owners, publishers, ad tech vendors and advertisers are among those who depend on the certificates involved.
What: Cloudflare intends to become a publicly trusted certificate authority. It has applied to four root programs, signed a definitive agreement to acquire a GlobalSign root trusted since 2012, and will issue only through ACME to clients supporting ACME Renewal Information (RFC 9773). It commits to reproducible builds, attested hardware security modules and a public incident dashboard, and plans a single service for classic certificates and Merkle Tree Certificates.
When: Disclosed today, September 29, 2026, during Birthday Week. The first production Merkle Tree Certificates are scheduled for the first quarter of 2027; no date is given for classic certificates or for completion of the GlobalSign agreement.
Where: On the Cloudflare blog, with applications before root programs that serve browsers and operating systems worldwide. Cloudflare sits in front of more than 20% of global internet request traffic, according to the company.
Why: Cloudflare cites systemic risk from reliance on one dominant free authority, rapid growth in certificate volumes as lifetimes shrink toward 47 days by 2029, and the need for compact post-quantum authentication. For marketers, the stakes are the certificates underneath every landing page, tag and ad call, and the question of whether issuance diversifies or concentrates further with a company that already sits in front of more than a fifth of web requests.
Discussion