Cloudflare applies to become a public CA: ACME-first issuance, post-quantum certs in Q1 2027
Cloudflare applied to the four major root programs to become a public CA, with ACME-first issuance and post-quantum certificates planned for Q1 2027.

Cloudflare announced on September 29, during its Birthday Week, that it has applied to become a public certificate authority — twelve years after Universal SSL put HTTPS within everyone’s reach, it now wants to turn certificate supply itself into public infrastructure, and give Let’s Encrypt a peer at the same scale.
Facts
- Pending approval: Cloudflare has applied to the Chrome, Apple, Microsoft and Mozilla root programs; it is not issuing certificates yet, and says that will take a while.
- How you get certs: ACME-first automated issuance and renewal; Cloudflare says you can point existing ACME directory URLs at Cloudflare without redesigning your deployment.
- Legacy reach: Cloudflare has signed a deal to acquire an established root from GlobalSign, trusted since 2012, so old devices are covered from day one.
- Post-quantum: the first production Merkle Tree Certificates are targeted for Q1 2027, aligned with Chrome’s quantum-resistant root program; one CA will serve both classic and MTC certificates to avoid a hard cutover.
- Renewal is a condition: ARI (RFC 9773) automated renewal is a condition of issuance, alongside commitments to reproducible builds of signing software, HSM attestations and a public issuance-health dashboard.
Editorial take
Let’s Encrypt made certificates free; Cloudflare wants a second player at scale on the supply side. For developers that is redundancy, and the migration path is a one-line ACME directory swap. Two things to watch: root-program approval progress, and the fine print on free issuance quotas — no pricing has been announced yet, so leave existing chains alone until then. A site health check with a tool like Web Check is a good way to prepare.