Cloudflare Is Building Its Own Certificate Authority to Harden the Web Against Quantum Computers

The internet infrastructure giant wants to issue its own digital trust certificates, buying a head start from GlobalSign and promising post-quantum protection before most of the web even knows it needs it.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
A macro photograph of a dense cluster of fiber optic cable ends glowing in shifting blue and green light, shot straight-on filling the entire frame edge to edge
Share

Key points

  • Cloudflare announced on 29 September 2026 its plan to become a public Certificate Authority, meaning it will issue the digital certificates that prove a website is legitimate and encrypt its traffic.
  • Cloudflare has agreed to acquire established root certificate key material from GlobalSign, letting older devices trust Cloudflare-issued certificates immediately, before the company's own root clears browser approval processes.
  • Production issuance of next-generation Merkle Tree Certificates, a lighter post-quantum certificate format co-authored by Cloudflare, is scheduled for Q1 2027.
  • Cloudflare has applied for inclusion in the root programs run by Chrome, Apple, Microsoft and Mozilla, each of which must approve a certificate authority independently before browsers will trust it.
  • The announcement affects every website owner who relies on Cloudflare today, though no immediate action is required.

Every secure website carries a small digital document called a certificate. It proves the site is who it claims to be and switches on the padlock that encrypts your connection. A Certificate Authority, or CA, is the organisation that checks a website's identity and signs those documents. Right now a handful of companies dominate that role. Cloudflare wants to add itself to that list.

The announcement landed on 29 September 2026 via a Cloudflare press release.

Why does this matter to ordinary website visitors?

For most people, nothing changes today. Certificates work invisibly. What matters is what happens when things go wrong, or when computing power advances.

The longer concern is quantum computing. A sufficiently powerful quantum computer could break the encryption securing most web traffic right now. Researchers widely expect machines capable of that within years, not decades. We've tracked this pressure building since our CISA and G7 piece on 3 September, and Cloudflare's new CA is a direct response to it. Its core offering is a newer kind of certificate called a Merkle Tree Certificate, or MTC, which uses maths that quantum computers can't easily crack. MTCs also transmit faster than traditional post-quantum certificates because they use compact proofs instead of heavy signatures.

For now, those certificates exist only in a Chrome experiment. Full production issuance is set for Q1 2027.

How does the GlobalSign deal fit in?

Browsers and operating systems maintain lists of CAs they already trust, called root programs. Getting onto those lists takes time. Buying root certificate key material from GlobalSign gives Cloudflare a shortcut: devices that no longer receive software updates will recognise a Cloudflare certificate immediately because GlobalSign's root is already baked into their software. The acquisition is expected to close within two months.

Cloudflare has also submitted applications to Chrome, Apple, Microsoft and Mozilla's root programs. Until those applications complete, the acquired GlobalSign material carries the weight.

Should website owners do anything now?

Not immediately. Cloudflare says site owners will manage both classic certificates and Merkle Tree Certificates inside a single system, with no forced cutover. Automated renewal, governed by a technical standard called RFC 9773, means certificate replacements happen in the background without downtime.

The meaningful decision point arrives if Cloudflare's root applications are approved and the company begins issuing standard certificates at scale. Site owners using other CAs will face no pressure to switch, but those already on Cloudflare's platform may find the transition largely automatic.

This is infrastructure plumbing, not a security emergency, but it's the right kind of boring. Concentrating certificate issuance in two or three dominant providers has always been a systemic fragility. Adding a credible independent issuer with built-in post-quantum support is a genuine improvement, provided Cloudflare's transparency commitments hold up in practice rather than just in press releases.

© 2026 Threat Vectr