Cloudflare is preparing to take on a new role as a public Certificate Authority (CA), aiming to issue free SSL/TLS certificates for websites and move the web forward into the era of quantum-resistant encryption. The announcement marks a shift from its current position as a major user of certificates toward becoming a provider of trust for the entire internet.
What’s Changing: Free Certificates & Trusted Roots
To issue trusted certificates in browsers, operating systems, and devices, Cloudflare has applied to join the root trust programs of Google Chrome, Apple, Microsoft, and Mozilla. Without trusted roots, newly issued certificates won’t be recognized broadly. To accelerate trust adoption, Cloudflare has reached an agreement to acquire an already established root certificate from GlobalSign—a move that helps it sidestep years of waiting typically required for new CA roots to gain broad recognition.
The company plans to offer free certificate issuance based on the Automated Certificate Management Environment (ACME) protocol. This system is already widely used to automate certificate lifecycle tasks like issuance and renewal. Existing users who already automate with ACME tools should be able to switch to Cloudflare’s offering by changing the directory URL, rather than revamping their systems.
Post-Quantum Push, Safety Measures, and Internal Testing
To future-proof its service, Cloudflare will issue post-quantum Merkle Tree Certificates (MTCs), targeting its first production release in early 2027. These are intended to reduce the size and latency overhead that could come from quantum-resistant standards, while still supporting legacy-style WebPKI certificates from the same CA.
On the security side, Cloudflare promises to publish reproducible builds for its certificate-signing software and to provide visibility into the hardware security modules that protect its CA keys. An incident and issuance dashboard will also be made public. Before general release, the system will be tested internally under Cloudflare’s “Customer Zero” model.
This move builds on the legacy of Free Universal SSL, introduced in 2014, which offered free TLS certificates to all sites behind Cloudflare’s network. The company is now planning to scale that reach by becoming a trust root itself.
Where Free Certs Fit & Why They Matter
Currently, Let’s Encrypt dominates free certificate issuance—issuing roughly 10 million certs per day, serving over 500 million websites, and having surpassed 4 billion active certificates in 2025. That concentration means the internet depends heavily on a small number of CA services; any failure or security incident there could have widespread impact.
Cloudflare’s proposed CA aims to diversify that landscape with another large, automated, free alternative. Its adoption of ACME Renewal Information (from RFC 9773) also aims to spread renewal load more evenly, reducing risks of mass outages during incidents or revocations.
Estimated timeline: first production issuance of post-quantum MTCs in Q1 2027; broader rollout dependent on root program approvals and internal testing.
Analysis: Cloudflare stepping up as a free Certificate Authority is a major inflection point for web security. By combining scale, automation, and a path toward quantum-safe certs, it addresses both current vulnerabilities—like root CA concentration—and future threats posed by quantum computing. Watch closely for how quickly major root programs accept its CA status, how smoothly existing ACME-integrated sites migrate, and how organically adoption of post-quantum certificates moves. If executed well, this could reshape trust architectures across the internet.