Cloudflare Launches Free Certificate Authority for the Whole Internet
Cloudflare is seeking approval to run a free public CA with ACME and post-quantum certificates.
Cloudflare said it is seeking approval to become a public certificate authority and will offer free, automated TLS certificates, though it is not issuing them yet. It has applied to the Chrome, Apple, Microsoft, and Mozilla root programs and agreed to acquire an existing trusted GlobalSign root. The service will use ACME, require RFC 9773 renewal information, and is planned to issue post-quantum Merkle Tree Certificates in the first quarter of 2027. Cloudflare cited concentration risk, saying Let’s Encrypt issues about 10 million certificates a day and supports more than 500 million websites.
- Cloudflare applied to Chrome, Apple, Microsoft, and Mozilla root programs.
- It agreed to acquire an already trusted GlobalSign root.
- The free CA will use ACME and require RFC 9773 renewals.
- Post-quantum Merkle Tree Certificates are targeted for early 2027.
- Cloudflare says Let’s Encrypt issues about 10 million certificates daily.
Full article647 words · extracted from cybersecuritynews.com · click to collapse
Cloudflare has announced plans to become a public Certificate Authority, expanding its role in securing the global web. The company aims to offer free, automated digital certificates for websites while also preparing the Internet for post-quantum cryptography.
A Certificate Authority, or CA, is a trusted organization that issues digital certificates. These certificates let websites use HTTPS, encrypt traffic between visitors and web servers, and prove users are connecting to the correct domain rather than an impersonated site.
Cloudflare is not issuing certificates yet. However, it has started the approval process needed to become a widely trusted CA. The company has applied to the root programs operated by Google Chrome, Apple, Microsoft, and Mozilla. These programs decide which Certificate Authorities browsers, operating systems, and devices trust.
The company has also signed an agreement to acquire an existing trusted root from GlobalSign. This is important because a newly created root certificate can take years to reach browsers, phones, operating systems, and embedded devices.

An established GlobalSign root is already trusted across many older systems, helping Cloudflare provide broader compatibility once it begins issuing certificates.
Cloudflare Launches Free Certificate Authority
Cloudflare said its new CA will be based on the Automated Certificate Management Environment, or ACME, protocol. ACME is widely used to automate certificate issuance and renewal.
Website operators already using automated certificate services should be able to switch to Cloudflare by changing the ACME directory URL, rather than deploying new tools or rebuilding their certificate management workflow.
The move could also improve resilience in the Web Public Key Infrastructure ecosystem. Free certificate issuance is currently concentrated among a small number of providers.
Let’s Encrypt, one of the largest free CAs, issues around 10 million certificates per day, supports more than 500 million websites, and surpassed 4 billion active certificates in 2025, according to Cloudflare.
A major disruption at a dominant free CA could affect much of the encrypted web. Cloudflare’s planned service is designed to add another high-scale, automated, free alternative.

Cloudflare plans to require certificate subscribers to support ACME Renewal Information, defined in RFC 9773. This mechanism lets a CA notify customers when they should replace certificates.
It could help Cloudflare spread certificate renewals over time during security incidents, compliance problems, or large-scale revocation events, reducing the risk of sudden certificate expiry and website outages.
The company also plans to issue post-quantum Merkle Tree Certificates, or MTCs. These certificates are designed to provide more compact authentication for a future in which post-quantum cryptography may make conventional certificate chains larger and slower during TLS handshakes.
Cloudflare is targeting the first production MTC issuance in the first quarter of 2027. The company said it intends to support both classic WebPKI certificates and MTCs from the same CA, enabling organizations to adopt quantum-resistant authentication without operating separate certificate systems.
Cloudflare said it will publish reproducible builds for certificate-signing software, attest the hardware security modules that protect CA keys, and operate a public dashboard for issuance health and incidents.
The company also plans to use its own CA internally before wider availability, following its “Customer Zero” approach for testing new services at Cloudflare scale.
The announcement builds on Cloudflare’s 2014 Universal SSL launch, which provided free TLS to websites behind its network. With a public CA, Cloudflare is moving from being a major consumer of certificates to becoming a direct trust provider for the wider Internet.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.