Cloudflare has announced plans to become a public certificate authority, expanding its role from distributing certificates issued by other providers to operating part of the trust infrastructure that underpins encrypted web traffic.

The company said on September 30 that the planned service will issue conventional Transport Layer Security certificates as well as Merkle Tree Certificates, a proposed format intended to make post-quantum authentication practical at Internet scale. Cloudflare is not issuing certificates yet, and several technical and approval steps remain before the service becomes operational.

Cloudflare seeks browser and device trust

A certificate authority verifies control of a domain and issues the digital certificate that browsers use to authenticate a website and establish an encrypted connection. For a new authority, the central challenge is getting its root certificates accepted across browsers, operating systems and devices.

Cloudflare said it has applied for inclusion in the root programs operated by Chrome, Apple, Microsoft and Mozilla. It has also signed a definitive agreement to acquire publicly trusted root certificate key material from GlobalSign. The transaction is expected to close within two months, subject to customary closing conditions.

The established root is intended to give Cloudflare-issued certificates compatibility with older devices that may no longer receive software updates. The new root applications, meanwhile, are designed to meet the current and emerging policies of the major browser and operating-system trust programs.

Cloudflare said it will begin issuing conventional certificates after completing the relevant root-program application and acceptance processes. The company has not provided a firm launch date for classical certificate issuance.

Merkle Tree Certificates target post-quantum scale

The planned authority will also support Merkle Tree Certificates, or MTCs. The format is being developed through the Internet Engineering Task Force and is designed to reduce the overhead created by post-quantum digital signatures.

In the current public-key infrastructure model, a certificate authority signs individual certificates and submits them to public transparency logs. Under the proposed MTC approach, certificates are added to an append-only Merkle tree, and the authority signs the tree root. A browser can then verify a certificate using a compact proof that it was included in the tree.

Cloudflare estimates that post-quantum signatures could increase the amount of data stored in certificate-transparency logs by about 40 times if the existing model were used without redesign. The company said MTCs would couple issuance and transparency more directly while reducing the amount of cryptographic data carried in a connection.

Cloudflare plans to begin issuing production MTCs in the first quarter of 2027. It is also targeting inclusion in Chrome’s quantum-resistant root program. Those timelines remain plans rather than completed deployments.

The service will emphasize automation and transparency

Cloudflare said the new authority will use the Automated Certificate Management Environment protocol as its primary issuance method. ACME is an open protocol widely used to automate certificate requests and renewals, allowing operators to change certificate providers without replacing their existing management tools.

The company also plans to require subscribers to support ACME Renewal Information, standardized as RFC 9773. That mechanism lets a certificate authority signal when a certificate should be replaced, including during a security incident or a large revocation event.

Cloudflare said it intends to publish reproducible builds of its certificate-signing software, provide attestations for the hardware security modules holding its keys, and maintain a public dashboard covering issuance health and incidents. The company will initially use the service internally before broader availability.

Broader post-quantum work continues

The certificate-authority announcement is part of a wider set of post-quantum updates from Cloudflare. The company also introduced downgrade protection for Internet Protocol Security connections, visibility tools that show whether web traffic uses post-quantum protection, and software intended to identify older cryptographic code.

Cloudflare has set a goal of completing its post-quantum readiness work by 2029. Its public certificate-authority plan, the GlobalSign transaction, root-program applications and 2027 MTC target are forward-looking and depend on technical development, third-party acceptance and closing conditions.

Singapore’s cryptography solution firm pQCee raises $3.9M seed round to scale quantum-safe encryption globally