Cloudflare to Become Public Certificate Authority, Offer Free Automated TLS Certificates
Cloudflare announced plans to become a public Certificate Authority (CA), offering free automated TLS certificates via the ACME protocol. The company is seeking inclusion in major root certificate programs and plans to acquire an existing root certificate for broad trust.

Cloudflare has announced its intention to establish itself as a public Certificate Authority (CA), a move that would expand its role in internet security infrastructure. The company is actively seeking approval to be included in the root certificate programs of major browser and operating system vendors, including Chrome, Apple, Microsoft, and Mozilla.
To ensure widespread trust from the outset, Cloudflare plans to acquire an existing root certificate through an agreement with GlobalSign. This strategic acquisition aims to enable its issued certificates to be recognized across a vast range of operating systems, browsers, and devices without the lengthy process typically required for new root certificates to gain global adoption.
The company will leverage the Automated Certificate Management Environment (ACME) protocol for managing certificates. This standardized protocol allows for the automation of certificate issuance and renewal, enabling users to migrate their existing certificate management workflows to Cloudflare with minimal disruption. Cloudflare highlights a desire to increase redundancy and competition in the market for free certificate services.
Looking ahead, Cloudflare also intends to address future security challenges, particularly those posed by quantum computing. The company is preparing to issue Merkle Tree Certificates (MTC) starting in the first quarter of 2027. These certificates are designed to mitigate potential performance issues arising from increasingly long certificate chains in a post-quantum cryptographic landscape.