Cloudflare Announced Plan to Become Certificate Authority
The company has initiated an acquisition of root key material to launch a public certificate authority service.
Updated on Sept. 29, 2026 in Quantum Computing

Live Poll
Do you trust decentralized systems more than dominant entities to keep your personal data secure?
Cloudflare has announced its intent to become a public Certificate Authority, aiming to modernize digital trust infrastructure. The company plans to support both traditional encryption and post-quantum Merkle Tree Certificates.
Why it matters
Current certificate trust remains concentrated among a few dominant issuers, while most existing infrastructure predates the rise of practical quantum computing. Cloudflare seeks to address these vulnerabilities by preparing for a post-quantum security landscape.
The new service will support traditional encryption alongside post-quantum Merkle Tree Certificates. Cloudflare has already applied for inclusion in major root programs, including those managed by Chrome, Apple, Microsoft, and Mozilla.
The players
Cloudflare
Cloudflare is a web infrastructure and website security company that provides content delivery network and distributed DNS services.
GlobalSign
GlobalSign is a global identity services company that provides cloud-based Public Key Infrastructure solutions to enterprises and organizations.
The details
To facilitate this transition, Cloudflare agreed to acquire publicly trusted Root CA key material from GlobalSign. The company will also implement automated renewal signaling to manage background certificate replacements while maintaining a public health dashboard for operational transparency.
Timeline
Cloudflare launched Universal SSL in 2014.
The intent to become a public CA was announced on September 29, 2026.
The acquisition of GlobalSign root certificate assets is expected to close in late 2026.
Production issuance of Merkle Tree Certificates is scheduled to begin in the first quarter of 2027.
The Tech Race
Cloudflare is pivoting to address the future of cryptographic security as quantum computing approaches the capability to break current encryption standards. This development replaces legacy certificate infrastructure that was designed long before quantum threats became a practical concern.
Users can expect a more secure digital environment as websites adopt post-quantum encryption standards supported by this new service. The transition will largely occur in the background through automated renewal signaling, minimizing manual intervention for site operators.
The takeaway
As quantum computing approaches the ability to compromise modern encryption, companies are proactively transitioning to post-quantum standards. Organizations should begin evaluating their certificate lifecycle management to ensure readiness for these emerging security protocols.
What happens next
The acquisition of GlobalSign root certificate assets is expected to conclude in late 2026, with production issuance of post-quantum certificates slated for the first quarter of 2027.
Further reading
Find more context on the evolving Quantum Computing landscape on our site.
Live Poll
Do you trust decentralized systems more than dominant entities to keep your personal data secure?










