ChannelLife India - Industry insider news for technology resellers
India
Cloudflare to launch public Certificate Authority service

Cloudflare to launch public Certificate Authority service

Wed, 30th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Cloudflare intends to become a public Certificate Authority, expanding the pool of issuers that provide the digital certificates used to secure websites.

Its planned service would issue both traditional TLS certificates and post-quantum Merkle Tree Certificates from the same system. The company said this is designed to let website operators manage existing encryption and newer post-quantum formats without changing tools or rebuilding systems.

Certificate Authorities sit at the centre of the web's trust model. They verify website identities and allow browsers to establish encrypted connections. Cloudflare argued that this role is concentrated among a small number of issuers, leaving the internet exposed if one provider suffers an outage or security breach.

The announcement also reflects a broader industry push to prepare for the possibility that quantum computers could eventually break widely used cryptographic methods. Although the timing remains uncertain, companies that run internet infrastructure have been testing replacements designed to withstand more advanced forms of computing.

"Twelve years ago, Cloudflare made encryption free and automatic for millions of websites. Today, we're taking the next step by building an open, transparent and reliable Certificate Authority for the entire Internet," said Matthew Prince, Chief Executive Officer and Co-Founder of Cloudflare.

"Upgrading the web's security before quantum computers can break it is one of the biggest coordination challenges in the history of the Internet. By balancing support for older devices with brand-new, post-quantum tech, we're providing a permanent safety net-so the Internet stays fast, reliable and secure for all devices, no matter what comes next," Prince added.

Legacy support

One immediate obstacle for any new Certificate Authority is browser and device trust. To address that, Cloudflare plans to acquire an established root certificate, which browsers, operating systems and devices use to decide whether to trust certificates issued by an authority.

If completed, that would allow certificates issued by Cloudflare to be recognised by older hardware and software, including devices that no longer receive updates. It has also applied to be included in the root programmes run by Chrome, Apple, Microsoft and Mozilla, which govern trust in new certificate issuers.

That dual-track approach matters because compatibility remains a practical concern for website operators. Many still need to support older smartphones, embedded systems and ageing operating systems, even as the industry discusses a shift to post-quantum cryptography.

Post-quantum path

Cloudflare plans to issue production Merkle Tree Certificates following earlier work with Chrome. MTCs are designed to prove that a certificate has been recorded in a trusted log while reducing the amount of cryptographic data exchanged during a connection. That feature is intended to make post-quantum methods easier to deploy at internet scale.

The company presented the planned service as a single system for both current and next-generation certificates. That contrasts with the prospect of running parallel systems or forcing abrupt migrations, either of which could complicate adoption for hosting providers, developers and site owners.

Cloudflare also outlined a broader set of measures tied to post-quantum readiness. These include quantum downgrade protection for IPsec, which it described as a way to stop attackers from weakening encryption on network infrastructure; tools to show whether web traffic is protected against future quantum decryption; and AI-based software to identify older cryptography in codebases.

Market context

Cloudflare has been part of web encryption infrastructure for more than a decade through its Universal SSL service, which distributed free TLS certificates to websites. Free and automated certificate issuance has since become standard across much of the web, but the market remains dominated by a limited number of issuers.

By entering that market directly as a public Certificate Authority, Cloudflare would move from distributing certificates issued within the existing system to becoming one of the trust anchors itself. That would place it in more direct competition with established certificate providers and give it a stronger role in how post-quantum standards are introduced on the web.

Cloudflare said it would start issuing classical certificates after completing the relevant browser root acceptance processes. Production issuance of Merkle Tree Certificates is scheduled to begin in the first quarter of 2027.