Updated
Updated · The Cloudflare Blog · Sep 29
Cloudflare Moves to Become Public CA, Buying GlobalSign Root for 2027 Post-Quantum Push
Updated
Updated · The Cloudflare Blog · Sep 29

Cloudflare Moves to Become Public CA, Buying GlobalSign Root for 2027 Post-Quantum Push

3 articles · Updated · The Cloudflare Blog · Sep 29

Summary

  • Cloudflare said it has applied to the Chrome, Apple, Microsoft and Mozilla root programs and signed a definitive deal to acquire a broadly trusted GlobalSign root, though it is not issuing public certificates yet.
  • The company said buying an existing root gives immediate reach to older devices that a new root would take years to penetrate, while a fresh root application positions it for future trust-store policies.
  • Cloudflare framed the move as a resilience play for the web’s certificate supply chain, arguing the dominance of free provider Let’s Encrypt—which issues about 10 million certificates a day—creates systemic risk if it suffers an outage.
  • ACME-first issuance and mandatory renewal automation via ARI are central to the plan, which Cloudflare said will include public operational dashboards, reproducible builds and internal use as Customer Zero.
  • The broader goal is a dual-track CA for classic and post-quantum certificates, with production Merkle Tree Certificates targeted for the first quarter of 2027.

Insights

Why is Cloudflare buying a trusted root before approval, and what does that mean for old devices and instant compatibility?
Can Cloudflare’s new ACME-first public CA really reduce the web’s dependence on a single free certificate issuer?
Could Cloudflare’s plan to issue post-quantum certificates in 2027 reshape how websites migrate without breaking today’s WebPKI?