Cloudflare Launches Free Certificate Authority for the Whole Internet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Cloudflare has announced plans to become a public Certificate Authority, expanding its role in securing the global web. The company aims to offer free, automated digital certificates for websites while also preparing the Internet for post-quantum cryptography.

A Certificate Authority, or CA, is a trusted organization that issues digital certificates. These certificates let websites use HTTPS, encrypt traffic between visitors and web servers, and prove users are connecting to the correct domain rather than an impersonated site.

Cloudflare is not issuing certificates yet. However, it has started the approval process needed to become a widely trusted CA. The company has applied to the root programs operated by Google Chrome, Apple, Microsoft, and Mozilla. These programs decide which Certificate Authorities browsers, operating systems, and devices trust.

The company has also signed an agreement to acquire an existing trusted root from GlobalSign. This is important because a newly created root certificate can take years to reach browsers, phones, operating systems, and embedded devices.

Public TLS Certificate Issuance Concentrated  (source : Cloudflare.com )
Public TLS Certificate Issuance Concentrated (source: Cloudflare.com )

An established GlobalSign root is already trusted across many older systems, helping Cloudflare provide broader compatibility once it begins issuing certificates.

Cloudflare Launches Free Certificate Authority

Cloudflare said its new CA will be based on the Automated Certificate Management Environment, or ACME, protocol. ACME is widely used to automate certificate issuance and renewal.

Website operators already using automated certificate services should be able to switch to Cloudflare by changing the ACME directory URL, rather than deploying new tools or rebuilding their certificate management workflow.

The move could also improve resilience in the Web Public Key Infrastructure ecosystem. Free certificate issuance is currently concentrated among a small number of providers.

Let’s Encrypt, one of the largest free CAs, issues around 10 million certificates per day, supports more than 500 million websites, and surpassed 4 billion active certificates in 2025, according to Cloudflare.

A major disruption at a dominant free CA could affect much of the encrypted web. Cloudflare’s planned service is designed to add another high-scale, automated, free alternative.

Cloudflare Builds Resilient CA With Automated Renewal (source : Cloudflare.com )
Cloudflare Builds Resilient CA With Automated Renewal (source: Cloudflare.com )

Cloudflare plans to require certificate subscribers to support ACME Renewal Information, defined in RFC 9773. This mechanism lets a CA notify customers when they should replace certificates.

It could help Cloudflare spread certificate renewals over time during security incidents, compliance problems, or large-scale revocation events, reducing the risk of sudden certificate expiry and website outages.

The company also plans to issue post-quantum Merkle Tree Certificates, or MTCs. These certificates are designed to provide more compact authentication for a future in which post-quantum cryptography may make conventional certificate chains larger and slower during TLS handshakes.

Cloudflare is targeting the first production MTC issuance in the first quarter of 2027. The company said it intends to support both classic WebPKI certificates and MTCs from the same CA, enabling organizations to adopt quantum-resistant authentication without operating separate certificate systems.

Cloudflare said it will publish reproducible builds for certificate-signing software, attest the hardware security modules that protect CA keys, and operate a public dashboard for issuance health and incidents.

The company also plans to use its own CA internally before wider availability, following its “Customer Zero” approach for testing new services at Cloudflare scale.

The announcement builds on Cloudflare’s 2014 Universal SSL launch, which provided free TLS to websites behind its network. With a public CA, Cloudflare is moving from being a major consumer of certificates to becoming a direct trust provider for the wider Internet.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Cloudflare Launches Free Certificate Authority for the Whole Internet appeared first on Cyber Security News.