Cloudflare seeks to become a public certificate authority, acquires GlobalSign root
Cloudflare announced plans to become a publicly trusted certificate authority, applying for inclusion in Chrome, Apple, Microsoft and Mozilla root programs. It has also signed a definitive agreement to acquire an established root from GlobalSign to ensure broad device compatibility once it starts issuing certificates, and plans to be among the first CAs supporting post-quantum certificates under Chrome's Quantum-resistant Root Program. The company says it is not yet issuing certificates but is publicly committing to the milestones ahead.
GoKawiil's interpretation of the reporting above, not reported fact.
Becoming its own CA could reduce Cloudflare's reliance on third-party certificate issuers and give it more control over how encryption is deployed across the vast number of sites it serves. Acquiring an existing trusted root, rather than starting from scratch, suggests Cloudflare wants to shortcut the years-long process of gaining device and browser trust, especially for older clients still running outdated software. Its early move toward post-quantum certificates positions it as an early adopter in the industry's response to future cryptographic threats.
- Cloudflare has applied to Chrome, Apple, Microsoft, and Mozilla root programs to become a certificate authority.
- It signed a deal to acquire an existing trusted root from GlobalSign for immediate broad device compatibility.
- Cloudflare plans to be among the first CAs to issue post-quantum certificates via Chrome's new root program.
Source: blog.cloudflare.com, 2026-09-29
Published there as: “Building a certificate authority for the whole Internet”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.