Home » AI News » Cloudflare Announces Public Certificate Authority for a More Secure Internet

Cloudflare Announces Public Certificate Authority for a More Secure Internet

Facebook
X
LinkedIn
Pinterest
Cloudflare announces public certificate authority for a more secure internet.

Cloudflare announced on September 29, 2026, that it intends to become a public Certificate Authority (CA), adding another large scale issuer to the Web Public Key Infrastructure (Web PKI). The planned service will provide automated certificates and support traditional TLS alongside post-quantum Merkle Tree Certificates (MTCs).

Cloudflare’s announcement is not a full public CA launch. The company has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs and agreed to acquire publicly trusted root CA key material from GlobalSign. Classical certificate issuance is planned after the browser root-program acceptance process, while production MTC issuance is targeted for the first quarter of 2027.

Why Is Cloudflare Building a Public CA?

A Certificate Authority issues digital certificates that help websites prove their identity and establish encrypted connections. Certificate issuance is concentrated among a relatively small group of major providers. Cloudflare says its new CA could add another independent, high-scale issuer to the Web PKI.

The initiative builds on Cloudflare’s Universal SSL program, which made free TLS certificates widely available to websites using its network. The planned public CA would make certificate issuance part of Cloudflare’s infrastructure rather than relying entirely on other public CAs. This could simplify certificate management for operators.

What Will Make Cloudflare’s CA Different?

Cloudflare says its planned CA will focus on transparency, automation, incident response, and post-quantum readiness. The company also plans to use automated renewal signaling based on RFC 9773. This could allow certificates to be replaced in the background when mass revocation or security updates are necessary, reducing disruption for websites.

For organizations managing cloud application security, automated certificate lifecycle management can reduce the burden of tracking expirations and replacements across internet-facing applications.

Post Quantum Security With Merkle Tree Certificates

A major part of the announcement is Cloudflare’s plan to support Merkle Tree Certificates. MTCs use cryptographic inclusion proofs and a signed Merkle tree to authenticate certificates efficiently. The company is targeting production MTC issuance for early 2027 and says standard MTC issuance will be provided at no cost. Cloudflare describes MTCs as a way to combine certificate issuance and transparency while reducing the overhead associated with post-quantum signatures.

This matters because future quantum computers could threaten cryptographic systems used across the Internet. Moving toward post-quantum security requires coordination among browsers, certificate authorities, servers, and applications.

What Does This Mean for Website Owners?

Most website owners do not need to rebuild their sites because of this announcement. Cloudflare is designing the planned CA to support classical certificates and MTCs, allowing organizations to transition as ecosystem support develops.

For teams responsible for ai security infrastructure, certificate management should connect with asset inventories and incident-response processes. Certificates are part of a website’s trust chain, so failures can create security or availability problems.

Why It Matters for AI and Cloud Security

AI platforms, APIs, agentic applications, and cloud services depend on encrypted connections to protect data moving between users, services, and infrastructure. As agentic ai attack techniques evolve, secure communication remains one layer of a broader defense strategy. Certificate security does not stop prompt injection, data poisoning, or credential theft, but strong transport security helps protect communication channels used by AI systems.

For readers following AI security and cloud security, Cloudflare’s initiative is worth watching as the Web PKI moves toward post-quantum readiness.

What Happens Next?

Cloudflare’s next milestones include browser root program review, completion of its planned GlobalSign root acquisition, and preparation for certificate issuance. The company has not announced that its public CA is already generally available.

As AiSecMaster and security master resources track the transition, the key question is how effectively Cloudflare can combine broad compatibility, automated certificates, and post-quantum technology at Internet scale.

Frequently Asked Questions (FAQs)

Can Cloudflare be trusted?

Cloudflare is a publicly traded U.S. company that provides security, performance, and connectivity services to millions of organizations. Its SSL/TLS certificates are publicly trusted and are currently issued through established certificate authorities including Let’s Encrypt, Google Trust Services, SSL.com, and Sectigo.

What is a Cloudflare certificate?

A Cloudflare certificate is a digital SSL/TLS certificate that helps authenticate a website and encrypt HTTPS traffic between visitors and the website. Cloudflare’s Universal SSL provides free, automatically renewed, publicly trusted certificates for domains activated on its network.

Who owns Cloudflare?

Cloudflare, Inc. is a publicly traded company listed on the New York Stock Exchange under NET, so it is owned by its shareholders rather than one private individual. The company was founded by Matthew Prince, Michelle Zatlyn, and Lee Holloway. Matthew Prince is currently co-founder and CEO, while Michelle Zatlyn is co-founder and President.

Will Cloudflare certificates be free?

Cloudflare says standard MTC issuance will be provided at no cost. The broader CA initiative is designed around automated certificates.

When will Cloudflare support post quantum certificates?

Cloudflare is targeting production Merkle Tree Certificate issuance for the first quarter of 2027.

Related Post

Leave a Reply

Your email address will not be published. Required fields are marked *

follow Us

Popular posts

Your daily updates

Subscribe now. We’ll make sure you never miss a thing.

categories