Skip to main content

Cloudflare Launches Public Certificate Authority

Cloudflare launches public certificate authority

On September 29, 2026, Cloudflare announced that it is creating its own public certificate authority. It will issue free TLS certificates for encrypting traffic at the transport layer and, in the future, support post-quantum technologies. For now, the new certificate authority is going through the required approval processes.

Cloudflare has decided to create its own public certificate authority and issue free TLS certificates for websites. The company has already applied to the trusted root certificate programs operated by Chrome, Apple, Microsoft, and Mozilla. However, certificate issuance has not started yet because the new certificate authority must first complete the necessary approval procedures.

In the future, Cloudflare also plans to issue post-quantum certificates designed to protect infrastructure against future threats from quantum computers. The company plans to issue the first production versions in the first quarter of 2027.

Why the internet needs another certificate authority

Certificate authorities are part of the internet's trust infrastructure. They verify control of a domain and issue TLS certificates, which allow browsers to verify a website's authenticity and establish a secure connection with it. If a major certificate provider experiences an outage or security incident, the consequences can affect many websites. That is why the ability to obtain certificates from different providers is important for the resilience of this system.

Cloudflare already uses this approach in practice. Since 2014, the company has automatically provided its customers' websites with free TLS certificates issued by partner certificate authorities. To improve reliability, Cloudflare can obtain a backup certificate from another certificate authority in advance. If the primary certificate is revoked or the organization that issued it experiences problems, the backup certificate can be used instead.

Cloudflare now wants to become an additional free certificate authority itself. The company notes that a significant portion of automated certificate issuance depends on Let's Encrypt, the largest free certificate authority, which serves more than 500 million websites. If such a large service experiences a serious outage, replacing it quickly could be difficult. Cloudflare aims to reduce this dependency.

How it works technically

For the certificate authority to become publicly trusted, its root certificates must be included in the trusted stores of browsers and operating systems. Cloudflare has therefore submitted applications to Chrome, Apple, Microsoft, and Mozilla, but the process takes time.

To maintain compatibility with older devices, the company has also signed an agreement to acquire an existing GlobalSign root certificate. It has been included in the trusted stores of many browsers and operating systems since 2012. As a result, Cloudflare will be able to issue certificates trusted by devices that no longer receive updates.

Cloudflare plans to automate TLS certificate issuance and renewal through the ACME protocol, so website owners will not have to renew certificates manually. The company also intends to use the ARI mechanism, which allows a certificate authority to recommend early renewal when necessary, for example after an incident.

Preparing for the post-quantum era

One of the directions for Cloudflare's new certificate authority is preparing for post-quantum protection. Modern TLS certificates rely on cryptographic algorithms that could eventually become vulnerable to sufficiently powerful quantum computers. Developers are therefore looking for replacements for these algorithms in advance.

One possible approach to post-quantum certificates is Merkle Tree Certificates, or MTC. In this system, multiple certificates are combined into a common structure, and the browser verifies that the required entry is present. This mechanism reduces the amount of data transmitted when establishing a connection.

Cloudflare has already tested this technology together with Chrome. The experiment used conventional cryptographic signatures, however, so its results cannot be considered a full test of a post-quantum system.

Protect yourself from dangerous websites automatically

A TLS certificate does not guarantee that a website is safe: scammers can also use HTTPS. Kaspersky Premium detects phishing and dangerous pages and helps protect your personal data while you browse the internet.

Try Kaspersky Premium free

What this means for website owners and users

Website owners do not need to change anything right now. Cloudflare has not yet started issuing certificates through its new certificate authority and is still going through the required approval procedures. The company has also not announced an exact launch date for regular public TLS certificates.

After the launch, website owners will be able to choose Cloudflare as another free certificate provider and automate certificate issuance through ACME. For users, the changes should be virtually invisible: browsers will continue to verify website certificates and establish secure connections. Encryption helps protect data while it is being transmitted between a device and a website.

At the same time, having a TLS certificate does not by itself mean that a website is safe. Scammers can also use HTTPS, so users should continue to check the web address carefully and be cautious with websites that request payment details or other confidential information.

Useful articles:

Recommended products:

Cloudflare Launches Public Certificate Authority

Cloudflare has announced a public certificate authority (CA) and plans to issue free TLS certificates. Learn what this means for internet security, compatibility with older devices, and the transition to the post-quantum era.
Kaspersky logo

Related articles