Cloudflare Moved to Become Public Certificate Authority

The network security firm intends to issue post-quantum certificates by early 2027 to address future cryptographic threats.

Updated on Sept. 29, 2026 in Quantum Computing

Bold flat-color editorial illustration featuring a geometric key symbol over a structural platform, representing digital security and quantum encryption infrastructure.
Cloudflare plans to launch a public certificate authority by 2027, integrating post-quantum encryption standards to address future security vulnerabilities. AI Illustration. Upload story photo >

Live Poll

Do you trust decentralized systems more than dominant entities to keep your personal data secure?

Cloudflare has announced plans to establish itself as a public Certificate Authority, a move supported by the acquisition of root certificate assets from GlobalSign. This announced initiative will support both standard encryption and post-quantum Merkle Tree Certificates.

Why it matters

Current digital trust is concentrated among a few legacy issuers, many of which operate on infrastructure predating modern quantum computing concerns. Cloudflare aims to expand the availability of quantum-resistant security standards to protect against future cryptographic threats.

The new Certificate Authority will facilitate post-quantum Merkle Tree Certificates, a cryptographic structure that organizes data to verify security without relying on math vulnerable to future quantum computers. Production issuance of these certificates is scheduled to begin in the first quarter of 2027.

The players

Cloudflare

A global provider of edge-based network security, content delivery, and distributed infrastructure services.

GlobalSign

A managed identity services company providing cloud-based PKI solutions and digital certificate infrastructure.

The details

Cloudflare will utilize automated renewal signaling to trigger background certificate replacements, reducing the operational burden on users. By operating as a public Certificate Authority, the company intends to increase transparency through a public health dashboard and shared operational insights. The infrastructure integrates support for post-quantum algorithms, which are cryptographic methods designed to remain secure even when faced with the processing power of theoretical quantum computers.

Timeline

  1. 2014: Cloudflare launched Universal SSL for its users.

  2. September 29, 2026: Cloudflare announced its intent to become a public Certificate Authority.

  3. Late 2026: The company expects to close its acquisition of root certificate assets from GlobalSign.

  4. Q1 2027: Cloudflare plans to begin the production issuance of Merkle Tree Certificates.

The Tech Race

This initiative represents an evolution of the company's long-term strategy to standardize web security, following the precedent set by its 2014 launch of Universal SSL. By integrating quantum-ready standards now, the company aims to move faster than current legacy certificate issuers.

Users should expect smoother certificate management as the company implements automated renewal signaling for background replacements. This transition will prioritize long-term browser and device compatibility for the new quantum-resistant certificates starting in 2027.

The takeaway

Cloudflare is positioning itself to lead the transition toward quantum-secure digital infrastructure through this expansion of its certificate services. Watch for the scheduled Q1 2027 start of production for Merkle Tree Certificates as a key benchmark for the industry's adoption of post-quantum standards.

What happens next

Cloudflare expects the acquisition of GlobalSign root certificate assets to close in late 2026, followed by the planned commencement of production Merkle Tree Certificate issuance in the first quarter of 2027.

Further reading

For broader context on current cryptographic standards and emerging threats, visit Quantum Computing.

Live Poll

Do you trust decentralized systems more than dominant entities to keep your personal data secure?