Cloudflare plans to launch a public certificate authority (CA) for website operators, issuing classical web certificates and post-quantum Merkle Tree Certificates (MTCs) through one service.
To support broad trust in certificates issued by the planned CA, the cloud security company has agreed to acquire publicly trusted Root CA key material from GlobalSign. The transaction is expected to close within two months, subject to customary closing conditions.
Access deeper industry intelligence
Experience unmatched clarity with a single platform that combines unique data, AI, and human expertise.
Cloudflare said the established root would allow its certificates to be recognised immediately, including on older smartphones, operating systems and devices that no longer receive updates.
It has applied for inclusion in the Chrome, Apple, Microsoft and Mozilla root programmes.
Classical certificate issuance is planned after the browser root-programme application and acceptance process is completed, while production MTC issuance is scheduled for the first quarter of 2027.
Cloudflare said this builds on a successful experiment with Chrome.
The company said that trust in the web public key infrastructure is concentrated among a small number of dominant issuers, creating risk if one fails or is compromised. It said quantum computers capable of breaking current encryption are expected within years and much of the web is unprepared.
The planned CA would add an independent, high-scale issuer, according to the company.
Cloudflare CEO and co-founder Matthew Prince said: “Twelve years ago, Cloudflare made encryption free and automatic for millions of websites. Today, we’re taking the next step by building an open, transparent and reliable Certificate Authority for the entire Internet.
“Upgrading the web’s security before quantum computers can break it is one of the biggest coordination challenges in the history of the Internet. By balancing support for older devices with brand-new, post-quantum tech, we’re providing a permanent safety net—so the Internet stays fast, reliable, and secure for all devices, no matter what comes next.”
MTCs use lightweight proofs to confirm that a certificate has been logged in a trusted registry, avoiding the need to send heavy post-quantum signatures with every connection, Cloudflare said.
The company stated that website owners will manage conventional TLS certificates and MTCs in one system, allowing a transition without immediate cutovers or new tools or rebuilds.
Cloudflare also plans to publish operational and technical information, reproducible code builds and a live public health dashboard. It said automated renewal signalling under RFC 9773 will trigger background certificate replacements across millions of sites instantly, reducing the risk of mass outages during revocations or security updates.
In a separate development last month, Cloudflare launched the beta version of Radar Researcher, an AI tool that enables users to explore internet traffic and trend data through plain-language questions. The tool presents responses as interactive charts, removing the need to work directly with datasets or application programming interfaces.
