Skip to main content

Cloudflare applies to become a certificate authority: what changes (and what doesn't yet)

By CaptainDNS
Published on September 30, 2026

Updated on September 30, 2026

Status of Cloudflare's certificate authority project: application submitted to four root programs, no certificates issued, Merkle Tree certificates targeted for early 2027

Cloudflare has never issued a single TLS certificate: it gets them from 16 partner certificate authorities (CAs). On September 29, 2026, it announced that it wants to become a public CA. It does not issue any certificates yet.

TL;DR
  • Cloudflare has applied to the Chrome, Apple, Microsoft and Mozilla root programs, and signed an agreement to acquire a GlobalSign root. It does not issue any certificates yet.
  • It plans free certificates, via ACME and only for clients that support ARI (RFC 9773). Its first post-quantum Merkle Tree certificates are targeted for early 2027.
  • Nothing to change in your CAA for now: no certificates are issued and no CAA identifier has been published.

What Cloudflare announced on September 29, 2026

In a post dated September 29, 2026, Steve Goldsmith lays out the project. For browsers to accept its certificates, a CA has to get its root into their trust stores, through each vendor's root program. Cloudflare has applied to Chrome, Apple, Microsoft and Mozilla.

A new root takes time to spread, and older devices will never receive it. So Cloudflare signed a definitive agreement to acquire an established GlobalSign root, trusted since 2012 by browsers, operating systems and devices. The deal is announced, not yet in effect. In parallel, Cloudflare is submitting a new root, designed for policies that cap the age of roots.

The post is clear: "We are not issuing certificates yet, and it will be a little while before we do."

Do not confuse this project with Universal SSL: the certificates Cloudflare installs today on sites that go through its network are issued by its 16 partner CAs, which it keeps working with.

A second free issuer alongside Let's Encrypt

Cloudflare presents its project as a new source of free certificates, set against the dependence on Let's Encrypt. According to the figures Cloudflare cites, Let's Encrypt issues about 10 million certificates a day and serves more than 500 million sites. Cloudflare sees a risk for the whole web if the dominant free CA "has a bad week."

No pricing has been published: free issuance remains a commitment made in the announcement, for an offering that does not exist yet.

ACME only, ARI required for all issuance

Cloudflare plans to issue and renew its certificates only through ACME, the protocol that automates obtaining certificates. For a site already served by a free CA, the switch will come down, according to Cloudflare, to replacing the ACME directory URL in the client.

The real condition lies elsewhere: "We will only issue to clients that support ACME Renewal Information (ARI), standardized in RFC 9773." It applies to all issuance, not just post-quantum certificates. Your ACME client will have to query the CA's renewal endpoint, follow the published windows and indicate which certificate it is replacing. Cloudflare wants to be able to move those windows forward in the event of a mass revocation. A client that renews on a fixed schedule, without ARI, will not get a Cloudflare certificate. How ARI works is covered in our certificate lifecycle management guide.

Merkle Tree Certificates: the early 2027 target

The only announced timeline concerns Merkle Tree Certificates (MTCs), certificates designed to withstand future quantum computers. In a second post, Mari Galicer says Cloudflare is targeting inclusion in Chrome's Quantum-resistant Root Store in early 2027. Standard MTC issuance would be provided "at no cost."

Nothing is settled. Before issuing a single MTC, the CA will have to be evaluated by Chrome's program. Its draft policy requires at least two cosignatures, including one from an independent mirroring cosigner. The ACME server will be a fork of Boulder, the Let's Encrypt software. A single CA will serve both classic certificates and MTCs.

An experiment with Chrome Beta, completed in August 2026 and based on a mock "bootstrap" CA, measured "landmark" MTCs as 9% faster at the median. With this format, the browser receives reference points from the CA's log in advance, which lightens the proof sent on each connection. The experiment validates the technique, not the arrival of a Cloudflare CA in 2027.

CAA: nothing to change today

The CAA record states, in your DNS zone, which CAs may issue for your domain. Cloudflare has published no CAA identifier and issues no certificates. Our reading at CaptainDNS: nothing needs to change as long as that remains the case.

Once Cloudflare issues, a domain with a restrictive CAA will have to authorize the identifier Cloudflare will have published, or its request will be refused. A domain without CAA will have nothing to do. Check what yours publishes with the CAA record lookup. The issue, issuewild and iodef tags are explained in our complete guide to CAA records.

Check the certificate your site serves

Identify the issuer of your current certificate and its expiration date.

What this article is not

This post replaces neither the certificate lifecycle guide, for configuring an ACME client, nor the CAA guide. Shorter certificate lifetimes are covered in our article on the reduction to 47 days.

It does not compare paid CAs either. It sticks to the two Cloudflare posts cited below, and nothing they describe is available today.

FAQ

Can you get a Cloudflare certificate today?

No. Cloudflare has applied to the Chrome, Apple, Microsoft and Mozilla root programs, but it writes that it is not issuing certificates yet. It gives no date for classic certificates and is targeting early 2027 for its first Merkle Tree certificates.

Do I need to change my CAA record?

Not today. Cloudflare issues no certificates and has published no CAA identifier. Once it issues, a domain with a restrictive CAA will have to authorize the identifier Cloudflare will have published. A domain without CAA will have nothing to change.

What is ARI and why does Cloudflare require it?

ARI (ACME Renewal Information, RFC 9773) lets the CA publish a renewal window for each certificate. The client queries it and renews within that window. Cloudflare wants to be able to move those windows forward in the event of a mass revocation. It will therefore issue only to ACME clients that support ARI.

Will Merkle Tree certificates replace current certificates?

Cloudflare does not say so. It plans a single CA for classic certificates and Merkle Tree Certificates, and is targeting inclusion in Chrome's quantum-resistant root program in early 2027, after evaluation by that program.

Sources: Cloudflare announcement "Building a certificate authority for the whole Internet" and Cloudflare post on the post-quantum CA and Merkle Tree Certificates.

Similar articles