Cloudflare to launch public Certificate Authority
The service will introduce post-quantum certificates in the first quarter of 2027.
Cloudflare announced on September 29, 2026, its plan to become a public Certificate Authority to issue digital certificates for websites. The new service will support traditional TLS encryption as well as next-generation post-quantum Merkle Tree Certificates, known as MTCs.
To secure immediate recognition across legacy devices, Cloudflare agreed to acquire established Root CA key material from GlobalSign. The transaction is expected to close within two months, subject to customary closing conditions. Cloudflare has also submitted applications for inclusion in the browser root programs of Apple, Google Chrome, Microsoft, and Mozilla.
Twelve years ago, Cloudflare made encryption free and automatic for millions of websites. Today, we're taking the next step by building an open, transparent and reliable Certificate Authority for the entire Internet.
The company plans to start issuing classical certificates once browser root program acceptance is finalized. Production issuance of MTCs is scheduled to begin in the first quarter of 2027, using automated renewal signaling under RFC 9773 to manage background certificate updates without downtime.
Newsletter
Markets in your inbox, weekly
Latin America-focused analysis, investment themes and the week in finance.
Keep reading