Cloudflare to become public certificate authority

Cloudflare

By Dylan Bushell-Embling
Friday, 02 October, 2026

Cloudflare to become public certificate authority

Cloudflare has revealed plans to become an open public certificate authority to issue the digital certificates websites need to encrypt traffic and validate their identity for visitors. The planned authority will support both traditional encryption and post-quantum Merkle Tree Certificates, helping website operators make the transition to the post-quantum world without the need to adopt new tools or rebuild their sites.

Cloudflare CEO and co-founder Matthew Prince said the company was a pioneer in the development of encryption capabilities for websites with the launch of Universal SSL in 2014, which offered free TLS certificates to millions of websites. Now the company plans to help website operators make the shift that will come with the development of quantum computers capable of breaking today’s equipment, which are expected within a few years, he said.

“Twelve years ago, Cloudflare made encryption free and automatic for millions of websites. Today, we’re taking the next step by building an open, transparent and reliable Certificate Authority for the entire internet,” Price said. “Upgrading the web’s security before quantum computers can break it is one of the biggest coordination challenges in the history of the internet. By balancing support for older devices with brand-new, post-quantum tech, we’re providing a permanent safety net — so the internet stays fast, reliable and secure for all devices, no matter what comes next.”

To ensure certificates work on older smartphones, operating systems and outdated devices, Cloudflare plans to acquire an established root certificate, which tells browsers and devices whether to trust a certificate authority. This will ensure that websites using Cloudflare-issued certificates will be recognised immediately.

As part of preparations for the launch, Cloudflare has also applied for inclusion in the Chrome, Apple, Microsoft and Mozilla root programs, and following a successful experiment with Chrome, plans to begin issuing production Merkle Tree Certificates in the first quarter of 2027.

By leveraging automated renewal signalling technology, the company will also be able to seamlessly trigger background certificate replacements across millions of sites instantly, minimising the risk of mass web outages.

Cloudflare plans to begin issuing classical certificates through the new authority following completion of browser root program application and acceptance process.

Image credit: iStock.com/Sashkinw

Related News

DigiCert aims to help tame rogue AI agents

DigiCert has announced support for NVIDIA's Open Agent Safety Platform to help equip...

ACSC raises critical alert for vulnerabilities in two Citrix products

The ACSC has raised a critical 'act now' alert for vulnerabilities in Citrix NetScaler...

Palo Alto launches frontier AI defence capability

Palo Alto's Unit 42 has launched an agentic offensive security service aimed at helping...


  • All content Copyright © 2026 Westwick-Farrow Pty Ltd