Executive summary: Cloudflare has announced it intends to become a public certificate authority (CA) and has applied to the Chrome, Apple, Microsoft, and Mozilla root programs. It isn't issuing certificates yet, but its first post-quantum Merkle Tree Certificates are planned for the first quarter of 2027. For anyone running TLS at scale, that means a second free, automated CA at internet scale, stricter renewal automation, and more certificates to keep track of.
Key takeaways:
- Cloudflare will issue certificates through ACME and only to clients that support ACME Renewal Information (ARI).
- A deal to acquire an established GlobalSign root means Cloudflare certificates should work on older devices from day one.
- More CAs, shorter lifetimes, and post-quantum formats all add up to more certificates, from more places, in your estate.
Cloudflare sits in front of more than 20% of global web request traffic. For 12 years it has been one of the biggest consumers of publicly trusted TLS certificates on the internet, without ever issuing one itself. That's about to change.
On September 29, 2026, Cloudflare announced it's applying to become a public certificate authority. A certificate authority (CA) is an organization that browsers and operating systems trust to issue the TLS certificates behind the padlock in your address bar. The move to 47-day certificates changed how often you renew. A Cloudflare certificate authority changes who you might renew with. It's the biggest certificate news since shorter lifecycles were agreed in 2025.
What Cloudflare announced
Cloudflare has applied to the four root programs that decide which CAs the web trusts, run by Chrome, Apple, Microsoft, and Mozilla.
Getting accepted is only half the battle. A brand-new root takes years to reach devices, and it never reaches the devices that have stopped getting updates. So Cloudflare has also signed a definitive agreement to acquire an existing GlobalSign root that's been trusted since 2012. That gives Cloudflare certificates wide device coverage from the start, while its new roots work through approval.
Cloudflare isn't issuing yet. The first dated milestone is production Merkle Tree Certificates (MTCs) in Q1 2027.
Why a Cloudflare certificate authority matters
Start with redundancy. Let's Encrypt is the dominant free CA, issuing around 10 million certificates a day and serving more than 500 million sites. Google Trust Services also issues free certificates through ACME, though you need a Google Cloud account to use it. That's still a small number of free options for a web that now runs on encryption by default. A third free CA with a name as well known as Cloudflare makes the whole system harder to knock over.
It's good news for Let's Encrypt too. Cloudflare is one of Let's Encrypt's biggest users, so every certificate Cloudflare issues for itself is capacity Let's Encrypt gets back for everyone else.
Then there's automation. Cloudflare says it will only issue to ACME clients that support ACME Renewal Information (ARI, standardized in RFC 9773). ARI lets a CA tell your client when to renew. In a mass revocation, the CA can pull renewal windows forward and spread replacements out, instead of hoping every customer notices an email in time. If your tooling can't do ARI, it won't get a Cloudflare certificate.
And then post-quantum. MTCs are a compact certificate format designed for post-quantum cryptography, where traditional certificate chains get large enough to slow TLS handshakes. Chrome has named MTCs its preferred path for post-quantum authentication. Cloudflare plans to issue classic certificates and MTCs from the same CA, so organizations can move across at their own pace rather than through a hard cutover.
Why it matters, according to Ivan Ristić

What it means for certificate users
Nothing changes today. Cloudflare isn't issuing yet, and your existing certificates aren't affected. But there are a few things worth getting ready for.
- Existing Cloudflare customers don't need to do anything. Cloudflare already manages certificates for sites on its network. At some point, you'll simply start seeing certificates issued by Cloudflare instead of, or alongside, its current partner CAs. Your monitoring should expect a new issuer name rather than flag it as a surprise.
- Check your ACME clients for ARI support. If you might move to Cloudflare, or just want faster recovery from revocation events with any CA, ARI support is the first thing to confirm.
- Expect more issuers in your estate. Cloudflare says switching will be as simple as changing an ACME directory URL. That's good for resilience, and it also means certificates can start appearing from a new CA without anyone flagging it.
- Plan for MTCs alongside classic certificates. The post-quantum transition will run for years, with both formats in use side by side.
- Keep the 47-day timeline in view. Under CA/Browser Forum ballot SC-081v3, maximum certificate lifetimes drop to 100 days in March 2027 and 47 days in March 2029. Our breakdown of shorter certificate lifecycles and PKI changes covers each milestone.
Where Red Sift fits
Red Sift is Cloudflare's preferred DMARC partner, so Cloudflare customers can use Red Sift OnDMARC to reach DMARC enforcement and stop domain spoofing. We'll be following Cloudflare's CA work closely as it moves through the root programs.
On the certificate side, Red Sift Certificates monitors every public certificate issued for your domains, whichever CA issued it. As Cloudflare joins the list of CAs your teams might use, that matters. You get one inventory, expiry alerts, and visibility of unexpected certificates, whether they came from Let's Encrypt, a commercial CA, or eventually Cloudflare. For a deeper look at running certificates at this pace, read our certificate lifecycle management guide.
Get a complete, always-current view of every certificate in your estate with Red Sift Certificates. Smaller teams can start with Red Sift Certificates Lite, free for up to 250 certificates.
Jack leads content, PR, GEO, and email security research at Red Sift.




