Lifestyle
Cloudflare plans to become a public certificate authority, agrees to buy a GlobalSign root and targets post-quantum certificates
On September 29, 2026, Cloudflare said it intends to issue the digital certificates that secure HTTPS websites. It has applied to the Chrome, Apple, Microsoft and Mozilla root programs, signed an agreement to buy a GlobalSign root, and plans its first Merkle Tree Certificates in Q1 2027. Nothing changes for web users yet, but site owners could gain another free certificate source.
About 7 min read

What Cloudflare announced
When you visit a website over HTTPS, your browser checks a digital certificate to confirm the site is genuine before setting up an encrypted connection. The encryption protocol behind this is called TLS. Certificates are issued by certificate authorities. Browsers and operating systems only trust a CA whose "root certificate" has been accepted into their root program, which is the list of trusted roots that each vendor maintains.
According to Cloudflare's official blog, the company has for more than a decade been one of the largest users of publicly trusted certificates on the Internet, yet it has never issued one itself. On September 29, 2026, Cloudflare announced its intention to become a public CA and published its first milestones. It has applied to the root programs of Chrome, Apple, Microsoft and Mozilla. It has also signed a definitive agreement with GlobalSign to acquire an existing, widely trusted root certificate.
Read the full description
Sources are collected, independently checked, then reviewed by Jev.
Cloudflare compared the move to Universal SSL, which it launched during Birthday Week 2014 to give free TLS to every website behind Cloudflare. The company also stressed that it has not started issuing certificates yet and that issuance is still some time away.
Why buy an old root and apply for a new one at the same time
Cloudflare said a brand-new root takes years to reach operating systems, browsers and devices, even after the root programs accept it. It also never reaches devices that no longer receive updates. According to Cloudflare, GlobalSign's existing root has been widely trusted since 2012 and can reach those older clients. The new root is built for where the ecosystem is heading, including root programs that are starting to cap how old a trusted root may be.
| Item | Purpose (according to Cloudflare) | Current status |
|---|---|---|
| Acquired GlobalSign root | Covers older devices and clients; trusted since 2012 | Definitive agreement signed |
| Newly submitted root | Meets future root program policies | Applied to the Chrome, Apple, Microsoft and Mozilla root programs |
| Merkle Tree Certificates | Compact certificates for the post-quantum era | First issuance planned for Q1 2027 |
Another source of free certificates, and how Cloudflare says it will run it
Figures cited by Cloudflare show that Let's Encrypt issues on the order of ten million certificates a day, serves more than 500 million websites, and passed 4 billion active certificates in 2025. Cloudflare argues that if the dominant free CA ran into trouble, the web would have no comparable free, automated alternative. It presents its public CA as that backup. Cloudflare also said it sits in front of more than 20% of global Internet request traffic and relies on millions of certificates each year. It said every Universal SSL certificate already ships with a backup certificate issued by a different authority.
- ACME first: ACME is an open standard protocol for requesting and renewing certificates automatically. Cloudflare said anyone already using another free CA can switch simply by changing a directory URL.
- Mandatory automatic renewal: Cloudflare said it will only issue to clients that support ACME Renewal Information (ARI, RFC 9773). ARI is automation that checks Cloudflare's renewal endpoint and acts on the renewal windows it publishes.
- Revocation response: if certificates must be withdrawn, Cloudflare said it can bring renewal windows forward, spread replacements over the available time and track progress. This follows a "fail small" principle of limiting the impact of any one issue.
- Transparent operations: Cloudflare said it will publish reproducible builds of its signing software, provide attestation for the hardware security modules that hold its keys and run a public dashboard for issuance health and incidents.
Post-quantum certificates: Cloudflare and Chrome timelines
"Post-quantum" cryptography is designed to stay secure even against future quantum computers. On February 27, 2026, Google announced a new Chrome program to make HTTPS certificates secure against quantum computers. Google said Chrome has no immediate plan to add traditional certificates in the standard X.509 format that use post-quantum cryptography to the Chrome Root Store. Instead, it is developing Merkle Tree Certificates. With MTCs, a CA signs a single "Tree Head" representing potentially millions of certificates, and the browser receives only a lightweight proof that a site's certificate is included.
According to Google, phase one is a feasibility study with Cloudflare, and every MTC connection in it is backed by a traditional X.509 certificate. In phase two, in Q1 2027, Google plans to invite qualifying Certificate Transparency log operators to help start public MTCs. In phase three, in Q3 2027, more CAs will be able to join an MTC-only Chrome Quantum-resistant Root Store, which will run alongside the existing Chrome Root Program. Cloudflare said it plans to issue its first production MTCs in Q1 2027 and to offer both traditional certificates and MTCs from the same CA.
What it means for readers and site administrators
If Cloudflare's plan goes ahead as described, free automated certificates will have one more source, and websites will have an alternative if a single certificate authority runs into trouble. For site administrators, Cloudflare said it will only issue to clients that support ARI automatic renewal. Those interested can register for updates through Cloudflare. On post-quantum certificates, both Google and Cloudflare describe a gradual transition rather than a one-time switch.
Frequently asked questions
Can Cloudflare issue certificates now?
Not yet. Cloudflare said it has not issued any certificates and is going through the application and approval process with the root programs.
Why is Cloudflare acquiring a GlobalSign root certificate?
Cloudflare said a brand-new root takes years to spread and cannot reach older devices that no longer update. Acquiring the GlobalSign root, trusted since 2012, lets it cover more devices from the moment it starts issuing.
What are Merkle Tree Certificates?
According to Google, MTCs replace the traditional chain of signatures with a compact Merkle Tree proof. A CA signs one Tree Head representing a large number of certificates, and the browser receives only a lightweight proof of inclusion. The aim is to keep connections fast when larger post-quantum algorithms are adopted.
When will Cloudflare issue post-quantum certificates?
Cloudflare said it plans to issue its first production MTCs in Q1 2027. In Google's Chrome timeline, phase two is also in Q1 2027 and phase three is in Q3 2027.
Will this replace Let's Encrypt?
Cloudflare did not say so. It praised Let's Encrypt and described itself as one of its largest users. It presents its CA as an additional free certificate source and backup, and said it will keep working with the 16 public CAs it has long partnered with.
Who is the source for these plans?
Cloudflare's CA plan, acquisition agreement and application status come from Cloudflare's own announcement. Chrome's MTC program and timeline come from Google's announcement.
Browse the latest news in this topic
Lifestyle
Cloudflare open-sources Streamline: a demo of using its cloud services to add graphics to live streams and burn subtitles into videos
On October 2, 2026, Cloudflare launched and open-sourced Streamline, a developer playground showing how developers can combine Stream, Workers, Containers and Durable Objects to build their own video processing pipelines, such as adding graphics to live streams in real time or adding subtitles to videos. This article explains what it is, how it works, its limitations, and what it means for viewers and developers.
Lifestyle
Google unveils Gemini 4 Argon: cyber defenders get it first, everyone else still has to wait
On September 30, 2026, Google announced Gemini 4 Argon, which it calls its new frontier (most advanced) AI model. For now it is available only to trusted cyber defenders through the Fairwind Program. Here is what Google says the model can do, what it will cost developers, how Google says it is managing the risks, and what it means for everyday users. All figures come from Google itself.
Lifestyle
NVIDIA: CoreWeave Begins Offering Vera Rubin NVL72, With Cognition as First Production Customer
According to the NVIDIA blog, AI cloud provider CoreWeave now offers NVIDIA's next-generation Vera Rubin NVL72 systems, plans to offer the Vera CPU and launched CoreWeave Forge. This matters mainly to companies building AI agents, and could eventually mean faster AI tools for everyday users.
Lifestyle
Google Cloud makes Spanner Omni generally available: its Spanner database can now run in companies' own data centers and on other clouds
Google Cloud says Spanner Omni, a version of its Spanner database that businesses run themselves, is now ready for real-world use in their own data centers, on other clouds or on a laptop. This matters to organizations that want Spanner outside Google Cloud, but they take on the running of it. Here are the features, licences and trade-offs Google Cloud describes.
Latest travel guides

GuideTokyo
Where to Stay in Tokyo: Comparing Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza, Plus Airport Access, Accommodation Tax, and Luggage Delivery
Where should you stay in Tokyo? Compare Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza by the same criteria: access from Narita and Haneda, transit routes, nearby attractions, neighborhood character, and who each area suits. Includes a comparison table, a Yamanote Line diagram, Tokyo’s accommodation tax as verified in 2026/9 (changing to 3% in 2027/4), and Airport TA-Q-BIN luggage shipping rules.
- Budget
- Hotels

GuideTokyo
How to Choose Tokyo Transit Passes: Are Suica, Welcome Suica, the Tokyo Subway Ticket, and the JR Pass Worth It?
On a first Tokyo trip, start with an IC card and pay per ride (Welcome Suica has no deposit and is valid for 28 days). If you take four or more subway rides in a day, add a 72-hour Tokyo Subway Ticket for 2,000 yen; a JR Pass is never worthwhile if you stay in Tokyo and do not go to Kansai. See what TOURIST PASMO, Suica on iPhone, and the Tokyo Metro day pass do and do not cover, with a decision chart. Prices verified in September 2026.
- Transport
- Budget

GuideTokyo
Tokyo Disneyland and DisneySea Guide: Ticket Prices, Fantasy Springs, Disney Premier Access (DPA), Standby Pass, and Which Park to Choose for Your First Visit
Tokyo Disney one-day Passport prices vary: most weekdays in 9/2026 cost ¥9,900 and weekends ¥10,900. At 14:00 daily, tickets go on sale for the same date two months later. Free Priority Pass is no longer on the official service list; only paid Disney Premier Access (¥1,000–3,500 per person per use) shortens waits. Covers hours, the 25th anniversary, Standby Pass, Entry Request, Fantasy Springs access and first-visit park choice; checked on the official site in 9/2026.
- Itineraries
- Family