On September 29, Cloudflare announced that it is applying to become a public certificate authority (CA). It has submitted applications to the Chrome, Apple, Microsoft, and Mozilla root programs, signed a deal to buy an established root certificate from GlobalSign, and says it will hand out free, automated TLS certificates through ACME, the same protocol millions of servers already use with Let’s Encrypt.
There is one important catch: Cloudflare isn’t issuing certificates yet. This is the start of a public approval process, not a product you can switch to tomorrow.
The timing is notable. The announcement landed during Cloudflare’s 2026 Birthday Week, exactly twelve years after the company switched on Universal SSL and gave free HTTPS to every site behind its network.
Table of Contents
Why Cloudflare is doing this now
If you run a Linux server with HTTPS, there’s a good chance your certificate came from Let’s Encrypt. Cloudflare says Let’s Encrypt issues around ten million certificates a day and serves more than 500 million sites. That’s a huge success story, and Cloudflare is one of its biggest users.
It’s also a single point of failure. In its announcement, Cloudflare puts it bluntly: if the dominant free CA had a bad week, much of the web would have no comparable free, automated alternative ready to take the load.
Cloudflare already plans around this problem for its own customers. Every Universal SSL certificate ships with a backup certificate, issued by a different CA with a separate key, ready to deploy if the primary is revoked. The company says it relies on 16 partner CAs today. Running its own CA is the same backup idea, applied to the whole Internet.
The other reason is volume. Certificates are about to get much shorter-lived. The CA/Browser Forum has approved a schedule that cuts the maximum lifetime of public TLS certificates to 200 days this year, 100 days in 2027, and just 47 days by 2029. Shorter lifetimes mean more renewals, which means more issuance. Add post-quantum certificates on top, and Cloudflare expects the number of certificates it needs every year to keep climbing.
Why buy a root from GlobalSign?
If you’ve ever traced a certificate chain, you know everything ends at a root certificate that your browser or operating system already trusts. A brand-new root has a problem: even after root programs accept it, it takes years to reach real devices, and it never reaches the old phones, TVs, and embedded systems that stopped getting updates.
That’s why Cloudflare is doing two things at once. It is submitting a new root to the major root programs, built for newer policies that limit how old a trusted root can be. And it is buying an existing GlobalSign root that has been trusted across browsers, operating systems, and devices since 2012. The older root covers legacy clients on day one. The new one keeps Cloudflare eligible as the rules change.
Switching should be boring, which is the point
Cloudflare says it will be “ACME-first.” Automated issuance and renewal through ACME will be the only way to get a certificate, so moving from another free CA should mostly mean changing the directory URL your client talks to. With Certbot, for example, that’s the --server option:
See also: Mastering the Linux Command Line — Your Complete Free Training Guide
certbot certonly --server https://acme-v02.api.letsencrypt.org/directory -d example.com
Swap in Cloudflare’s directory once it exists, and the rest of your setup stays the same. Cloudflare hasn’t published that URL yet.
There’s a stricter requirement that matters more for sysadmins. Cloudflare will only issue certificates to clients that support ACME Renewal Information (ARI), standardized in RFC 9773. With ARI, the CA tells your client when it should renew:
ACME client ──asks──► CA renewal endpoint
◄─replies── "renew between Oct 10 and Oct 12"
ACME client ──renews──► new certificate, replacing the old one
This exists for a very practical reason. When a CA has to revoke a large batch of certificates, it often gets stuck between following the rules and keeping customer sites online, because too many people can’t replace certificates quickly. With ARI, Cloudflare can pull renewal windows forward, spread replacements across the available time, and watch them happen. The cost is that a cron job running an old ACME client may not qualify.
Cloudflare also promises unusual transparency for a CA. It plans to publish reproducible builds of its certificate-signing software, attest the hardware security modules that hold its keys, and run a public dashboard for issuance health and incidents. As the company points out, an audit only tells you a CA passed on one particular day.
Built for post-quantum certificates
The bigger long-term bet is post-quantum TLS. Post-quantum signatures are much larger than today’s, and stacking them into normal X.509 certificate chains makes TLS handshakes noticeably heavier.
Cloudflare plans to be one of the first CAs to issue production Merkle Tree Certificates (MTCs), with the first ones expected in the first quarter of 2027. MTCs are a proposed IETF standard for a much more compact way to prove a certificate is trusted, and Chrome has already named them its preferred path for post-quantum authentication. Cloudflare says it will issue classic certificates and MTCs from the same CA, so customers can move gradually instead of running two systems.
What it means
Nothing changes on your servers today. Your Let’s Encrypt certificates keep renewing, and Cloudflare won’t issue anything until root programs approve it.
But the direction is clear. If Cloudflare gets approved, the free certificate world goes from one dominant provider to at least two large ones, both speaking ACME. That’s good news for anyone who has watched a renewal fail and realized there was no plan B.
It’s also a nudge to check your automation now. Certificates are heading toward 47-day lifetimes, and new CAs like Cloudflare’s will expect ARI support. A renewal script that “has worked fine for years” is exactly the kind of thing worth reviewing before the rules tighten.
Cloudflare says the root program reviews will happen in public, and it will share updates as they land. You can register for updates if you want to be among the first to try it.




